Scrutineer.ai

Scrutineer · By framework

Regulation S-P compliance software for the SEC Reg S-P amendments

Both compliance dates have passed: December 3, 2025 for larger entities and June 3, 2026 for smaller ones. Every covered institution now owes the whole rule.

Scrutineer maps your controls to each requirement and keeps the incident response and vendor oversight evidence behind them current.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with regulation s-p compliance software

Size changed your deadline, not your obligations

The larger and smaller entity split in the amendments was a phase-in schedule and nothing else. A $200 million adviser owes the same written incident response program, the same 30-day notice duty and the same service provider clause as a $50 billion one. Scrutineer maps the full requirement set for every covered institution, because the rule does not thin out below a threshold the way NYDFS Part 500 and the FTC Safeguards Rule do.

The 30-day clock starts at awareness, not at the end of your investigation

Notice is due as soon as practicable and no later than 30 days after you become aware that unauthorized access has occurred or is reasonably likely to have occurred. The investigation happens inside those 30 days, not before they start. Scrutineer timestamps the awareness date and tracks the investigation against it, so the deadline is calculated from the date an examiner would use.

The 72-hour vendor clause is a contract project, not a monitoring one

The rule expects your service providers to notify you no later than 72 hours after they become aware of a breach, and it expects that to sit in writing you can produce. That is a repapering exercise across your vendor base. Scrutineer tracks which contracts carry the clause, which are still open, and which due diligence files are current.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps your control set to the amended safeguards rule, disposal rule and recordkeeping duties in 17 CFR 248.30
  • Holds the written incident response program and the records showing it was actually followed
  • Timestamps the awareness date on an incident and runs the 30-day notification clock from it
  • Records the reasonable investigation and the written determination when you conclude notice is not required
  • Tracks which service provider contracts carry the 72-hour notification clause and which still need repapering
  • Keeps vendor due diligence files current so oversight is evidenced rather than asserted
  • Flags where you hold nonpublic personal information about another financial institution's customers
  • Reuses the same access, encryption and vendor evidence for SOC 2, ISO 27001 and 23 NYCRR Part 500
REGULATION S-P COMPLIANCE SOFTWARE readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Scope reference

What the amended Regulation S-P requires, and whether your firm size changes any of it

Read the third column down the table. It reads "no" on every substantive row, and that is the finding worth taking away: the larger and smaller entity split in the amendments set two compliance dates and never reduced the obligations. That is a real difference from the two US regimes it gets compared to, since NYDFS 500.19(a) exempts small covered entities from ten sections and the FTC Safeguards Rule drops four provisions below 5,000 consumers.

Requirement Where it sits Does your firm size change it? Evidence an SEC examiner asks for
Written safeguards program 17 CFR 248.30(a) No. The written policies and procedures, with dates and the approval behind them.
Incident response program Amended safeguards rule, 248.30(a) No. The written program, plus records from a real or tabletop incident showing it was followed.
Customer notification within 30 days 248.30(a)(4) No. The awareness date, the investigation file, the notice sent and the date it went out.
The determination that lets you skip notice 248.30(a)(4)(i) No. A written conclusion from a reasonable investigation that the information is not reasonably likely to be misused.
Service provider oversight 248.30(a)(5) No. Due diligence records for sampled vendors and evidence of ongoing monitoring.
72-hour service provider notification clause 248.30(a)(5)(i) No. Executed contracts containing the clause, for the vendors that touch customer information systems.
Scope covering another institution's customers 248.30(d)(5)(i) No. A data map showing where nonpublic personal information sits, including data received from other firms.
Disposal rule 248.30(b) No. Disposal procedures and records of proper disposal for consumer report information.
Recordkeeping 248.30(c) No, but the retention period varies by entity type. Written records documenting compliance, kept three years for broker-dealers and transfer agents and five for advisers.
Compliance date Adopting release Yes, and this is the only row where it did. December 3, 2025 for larger entities and June 3, 2026 for smaller ones. Both have passed.

Section citations are to 17 CFR 248.30 as amended by the release adopted May 16, 2024 and published in the Federal Register on June 3, 2024, current at August 2026. Retention periods track each institution's existing books and records rules rather than a single Reg S-P period, so confirm yours against the adopting release and your counsel. Scrutineer prepares and maintains the evidence; your firm makes the notification decision and any filing.

Good questions

Questions about regulation s-p compliance software

Regulation S-P is the SEC rule governing how broker-dealers, investment companies, registered investment advisers and transfer agents protect and dispose of customer information. Codified at 17 CFR Part 248, it has carried a privacy notice component since 2000 and a safeguards component requiring written policies to protect customer records. Amendments adopted May 16, 2024 added an incident response program, customer breach notification, service provider oversight and recordkeeping duties.
The amendments adopted May 16, 2024 require every covered institution to maintain a written incident response program, notify affected individuals within 30 days of becoming aware of a breach of sensitive customer information, oversee service providers and secure notification from them within 72 hours, and make and keep written records documenting compliance. They also extended the safeguards and disposal rules to transfer agents and widened what counts as customer information.
There were two. Larger entities had to comply by December 3, 2025 and smaller entities by June 3, 2026, measured as 18 and 24 months from the June 3, 2024 Federal Register publication. Both dates have now passed, so every covered institution is fully subject to the amended rule and the phase-in no longer offers anyone cover.
No. This is the most common misreading of the amendments. The larger and smaller entity distinction set two different compliance dates and nothing more. It does not reduce the requirement set, unlike 23 NYCRR 500.19(a), which genuinely exempts small covered entities from ten sections, or 16 CFR 314.6, which drops four provisions for firms serving fewer than 5,000 consumers. Under Reg S-P a small adviser owes the identical program.
Broker-dealers registered with the SEC, investment companies, registered investment advisers and transfer agents registered with the SEC or another appropriate regulatory agency. Transfer agents were brought inside both the safeguards rule and the disposal rule by the 2024 amendments, which is the scope change most likely to catch a firm by surprise.
Investment companies with net assets of $1 billion or more, registered investment advisers with $1.5 billion or more in assets under management, and those broker-dealers and transfer agents that are not small entities under the Commission's rules. Everyone else was a smaller entity and got the June 3, 2026 date. The classification only ever determined which deadline applied to you.
You must notify affected individuals as soon as practicable, and no later than 30 days, after becoming aware that unauthorized access to or use of sensitive customer information has occurred or is reasonably likely to have occurred. The notice has to describe the incident, the information involved and what the individual can do to protect themselves. Notice may be delayed only when the Attorney General determines in writing that it poses a substantial risk to national security or public safety.
The 72 hours belongs to your service providers, not to you. Your written policies must be reasonably designed to require a service provider to notify you as soon as possible and no later than 72 hours after it becomes aware of a breach affecting a customer information system it maintains. People frequently confuse it with the 30-day customer notice. The two clocks are nested: a provider that uses all 72 hours consumes three of your 30 days before you even know an incident happened.
When you become aware that unauthorized access has occurred or is reasonably likely to have occurred, not when your investigation concludes. That ordering matters more than anything else in the rule, because it means the forensic work, the scoping and the drafting all have to fit inside the same 30 days. Firms that read the clock as starting after the investigation build a process that is late by design.
Effectively yes, unless you affirmatively conclude otherwise. Notice is required unless the covered institution determines, after a reasonable investigation of the facts and circumstances, that the sensitive customer information has not been and is not reasonably likely to be used in a way that would result in substantial harm or inconvenience. The default is to notify, and the exception has to be reasoned and documented rather than assumed.
Customer information the compromise of which could create a reasonably likely risk of substantial harm or inconvenience to an individual. The rule deliberately does not enumerate data elements or define substantial harm, so the determination turns on the facts of the incident. In practice it covers identifiers that would let someone log in to or open an account, such as Social Security numbers, account numbers with access credentials, and biometric records.
Often yes. Customer information under the amended rule includes records containing nonpublic personal information about a customer of a financial institution, whether or not that customer is yours. A sub-adviser, fund administrator or private fund manager that receives investor data from another institution is holding customer information and owes the safeguards program on it. This is the scope expansion firms most often miss when they conclude the rule is not their problem.
It depends on the entity type, because the amendments tracked each institution's existing books and records regime rather than setting one period. Broker-dealers and transfer agents generally keep the written policies for three years after they stop using them, and documentation of detected unauthorized access for three years from the date the record was made. Investment advisers work to their usual five-year period, the first two in an easily accessible place. Confirm your own period against the adopting release.
Yes. Reg S-P is an SEC rule that binds registered broker-dealers directly, and FINRA member firms are broker-dealers. FINRA does not issue a separate version of it, though it has published cybersecurity guidance reminding members of the compliance dates. A member firm answers to the SEC on the rule itself and should expect FINRA examiners to ask about it.
They cover different institutions under the same statute. Both implement the Gramm-Leach-Bliley Act, but Reg S-P applies to SEC-registered entities and the FTC Safeguards Rule at 16 CFR Part 314 applies to non-bank financial institutions the FTC supervises, such as auto dealers, mortgage brokers and tax preparers. The Safeguards Rule enumerates nine required program elements and exempts very small firms from four of them; Reg S-P is less prescriptive about program content and exempts nobody.
No. Scrutineer maps your controls, holds the evidence and runs the clocks, so you can see where you stand before an examiner asks. The notification decision, the notice itself and any regulatory filing are made by your firm and signed by people who carry the accountability. We are explicit about that line, and no platform can honestly promise otherwise.

Keep reading

Guides that go deeper on what Reg S-P asks you to evidence

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification