Blake Bjordahl
Compliance Technology Expert & RIA Consultant

RIA CCOs are responsible for ensuring that client compliance data is protected from unauthorized access under Regulation S-P, while remaining accessible to the right people, including regulators, almost immediately when requested. That dual responsibility, protecting data and keeping it producible on demand, sits at the center of how the SEC now evaluates cybersecurity readiness at registered investment advisory firms.
It's a harder balance than it sounds. Lock data down too tightly and your own team struggles to retrieve records during an exam. Keep it too loosely organized and you're exposed to unauthorized access risk. CCOs are expected to manage both sides at once.
The CCO does not need to be a technical security expert to fulfill this responsibility. What the role does require is ownership of three things:
The SEC's 2026 examination priorities explicitly name information security and operational resiliency as a continued focus area, with particular attention to access controls, account management, and how firms respond to and recover from incidents. CCOs must demonstrate this focus is backed by actual practice, not just a written policy.
Newer Regulation S-P amendments expand the obligations RIAs carry around protecting customer information; requiring RIAs to maintain written policies and procedures to monitor information systems and protect them against unauthorized access, maintain an incident response program that includes customer notification procedures, oversee service providers who handle customer information on the firm's behalf, and update recordkeeping and information disposal practices to meet the expanded definition of customer information.
The definition of "customer information" is broad — it includes nonpublic personal information the firm holds about its own clients and, in many cases, information about clients of other financial institutions that the firm receives in the course of business. The scope of what needs protecting is larger than most firms initially assume.
We understand the instinct when thinking about data security is to restrict access as much as possible. However, if compliance records are locked down so tightly that your own team cannot retrieve them quickly, you have traded one risk for another.
The better model is role-based access control inside a single, organized system rather than scattered records protected individually across different platforms. When compliance data lives in one secure, cloud-based platform, your firm can grant the right people the right level of access without creating a maze of separate permissions across different tools. Security and accessibility stop being in tension because they are managed in the same place, by the same system.
When SEC examiners evaluate a firm's cybersecurity and information protection program, they typically request the written policies and procedures themselves, evidence that staff have acknowledged and been trained on those policies, records of any cybersecurity incidents and how they were handled, documentation of service provider oversight and contractual safeguards, and evidence of ongoing risk assessment and testing.
The 2026 SEC exam priorities specifically call out training and the controls firms use to identify and respond to emerging risks. That means examiners are not just checking whether a policy document exists; they are looking for evidence that the policy is implemented, tested, and understood by the people responsible for following it.
RIA Compliance Technology stores all client compliance data on AWS infrastructure, giving registered investment advisers enterprise-grade security without requiring an in-house IT security team to maintain it. Access is managed through the platform, so CCOs can control who sees what without creating separate logins and permission structures across multiple disconnected tools.
Simple Compliance Portal maintains a complete, timestamped record of policy acknowledgments and training completion; giving CCOs the documentation examiners ask for without having to track it down separately. Simple Email Archive keeps every firm communication retained and searchable, supporting all recordkeeping obligations. When a request comes in for documentation, the answer is retrievable in minutes because the data was never scattered to begin with.
Q: What does Regulation S-P require from RIA compliance programs?
Regulation S-P requires registered investment advisers to maintain written policies and procedures reasonably designed to protect customer information from unauthorized access, maintain an incident response program with customer notification procedures, oversee third-party service providers who handle customer data, and retain documentation demonstrating the program is implemented in practice. RIA Compliance Technology stores compliance data on AWS infrastructure and maintains a complete, timestamped record of every compliance action that is retrievable on demand.
Q: How do RIAs keep client data secure without making it inaccessible during an exam?
RIAs keep client data both secure and accessible by centralizing it in a cloud-based platform, designed specifically for RIAs, with role-based access controls. Meaning only authorized users can view sensitive records while examiners can receive a complete, organized response to any document request in minutes. RIA Compliance Technology gives CCOs a single searchable record of all compliance activity without creating the access barriers that complicate exam production.
Cybersecurity for an RIA compliance program is not just about keeping data locked away, it is about controlling who has access to sensitive information while making sure the right people can get to it the moment it's needed.
RIA Compliance Technology gives CCOs the infrastructure to do both at once: secure, organized, and immediately accessible. See how Simple Compliance Portal and Simple Email Archive work together by booking a demo at https://riacomptech.com/.
Compliance Technology Expert & RIA Consultant
Blake specializes in helping RIAs implement cost-effective compliance solutions. With extensive experience in regulatory technology, he focuses on making compliance simple and automated for investment advisory firms.
Stop worrying about compliance tasks and start focusing on what matters most - your clients. Get organized with our compliance calendar solution.