Regulation S-P AI Vendor Due Diligence: A Questionnaire for Smaller Advisers
The 2024 amendments to Regulation S-P are now in force for advisers of every size — the smaller-entity compliance date passed on June 3, 2026. For a firm adopting AI tools, the practical center of gravity is the service-provider oversight duty: an AI vendor that receives customer information in prompts is a service provider under the rule, owed due diligence, monitoring, and a 72-hour breach-notification term. As of 2026-08-28, this guide explains what the amended rule requires and provides a ten-question due-diligence addendum written for firms without a dedicated technology function.
What the 2024 amendments actually require
Regulation S-P's safeguards and disposal rule (17 CFR 248.30) was amended in 2024 by Release Nos. 34-100155. Five things in it matter most for AI adoption at a smaller firm.
01Who is covered — including your firm
- What it says:
- A covered institution is any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission or another appropriate regulatory agency; funding portals comply with the requirements as they apply to brokers. There is no small-firm carve-out from the substance of the amendments — size only changed the compliance date.
- What it means for AI use:
- A Commission-registered adviser of any size is inside the rule; state-registered advisers are not covered institutions under it and fall under the Federal Trade Commission's Safeguards Rule (16 CFR part 314) instead. If customer information reaches an AI tool your firm uses, the tool sits inside your safeguards program, not outside it.
02An incident response program, in writing
- What it says:
- Covered institutions must adopt an incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, as part of the written policies and procedures under 17 CFR 248.30.
- What it means for AI use:
- Detect, respond, recover — each verb assumes you can see what happened. For AI use, that means per-request records of who sent what, where it went, and what came back; without them, the program exists on paper only.
03Customer notification on a 30-day clock
- What it says:
- The institution must notify each affected individual whose sensitive customer information was, or was reasonably likely to have been, accessed or used without authorization — as soon as practicable, but not later than 30 days after becoming aware that the incident occurred or is reasonably likely to have occurred. Sensitive customer information means any component of customer information whose compromise could create a reasonably likely risk of substantial harm or inconvenience to the identified individual.
- What it means for AI use:
- Thirty days is short when the breach happened at a vendor. Every day the vendor delays telling you, and every day spent working out which customers' information was in the affected prompts, comes out of your clock.
04Service-provider oversight — due diligence and monitoring
- What it says:
- Policies and procedures must be reasonably designed to require oversight, including through due diligence and monitoring, of the institution's service providers — including reasonably designed measures to ensure service providers (A) protect against unauthorized access to or use of customer information, and (B) notify the institution as soon as possible, but no later than 72 hours, after becoming aware of a breach in security resulting in unauthorized access to a customer information system. A service provider is any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution.
- What it means for AI use:
- An AI vendor that receives your prompts is a service provider the moment customer information can appear in them — and so, through the vendor, is the model provider behind it. The questionnaire below is the due-diligence half of this obligation; the 72-hour term belongs in the contract.
05The compliance dates have both passed
- What it says:
- The amendments took effect August 2, 2024, with compliance required 18 months from the June 3, 2024 Federal Register publication for larger entities and 24 months for smaller entities — December 3, 2025 and June 3, 2026 respectively. For investment advisers, larger means $1.5 billion or more in assets under management; smaller is everyone else.
- What it means for AI use:
- As of June 3, 2026, the smaller-entity runway is gone. A sub-$1.5 billion adviser adopting AI tools today is building against a rule that is already in force for it, not one on the horizon.
Why AI vendors are exactly this problem
An AI workspace is not one system; it is a chain. Prompts can transit a gateway, land in a conversation store, spawn extracted text and embeddings, pass to a model provider, and settle into backups — each store with its own operator and its own retention clock. The zero data retention vs no training guide maps those planes one by one. Regulation S-P does not care which plane is fashionable: its terms attach to customer information wherever it sits, and its oversight duty attaches to whoever operates the store. Due diligence on an AI vendor is therefore mostly the discipline of making the chain visible — which is what the questionnaire below is engineered to do.
The questionnaire addendum
Ten questions to append to whatever vendor due diligence your firm already runs. Send them as written; file the answers with your due-diligence records; move the commitments that matter into the contract. Each question names the provision it supports.
Q01List every third party — model providers, inference hosts, gateways, monitoring services — that receives our prompts, outputs, or uploaded files through your product, and what each one retains and for how long.
- Why it matters:
- Your oversight duty runs through the chain, and undisclosed inference providers are the most common gap in AI vendor stacks. A vendor that cannot produce this list has answered the due-diligence question already — in the wrong direction.
- Provision:
- Supports service-provider oversight through due diligence and monitoring under the amended 17 CFR 248.30.
Q02Provide a data map for a single request: every system the content transits or lands on — conversation store, gateway, files and extracted text, embeddings and vector index, abuse monitoring, backups, audit log — with the retention clock on each.
- Why it matters:
- One AI request can leave content on eight distinct planes, and 'we retain nothing' is usually a statement about only one of them. The map is what turns a brochure claim into something your program can actually evaluate.
- Provision:
- Supports scoping the safeguards program to every system that holds customer information.
Q03Which of those stores can contain customer information as Regulation S-P defines it, and what safeguards protect each one?
- Why it matters:
- The rule's terms attach to customer information wherever it sits — including inside a vector index or a log. A vendor who has never asked itself this question has never scoped your data correctly.
- Provision:
- Supports the written safeguards policies and procedures of 17 CFR 248.30.
Q04When we delete data — or terminate the contract — what exactly is destroyed, on what schedule, and how do backups age out? Provide the written procedure, not a summary.
- Why it matters:
- Deletion is not deletion until backups age out, and a termination that leaves customer information behind leaves your obligation behind with it. The procedure should name each store from the data map.
- Provision:
- Supports the disposal and retention discipline of the safeguards program; the retention crosswalk on this site maps the clocks.
Q05If you become aware of a breach in security resulting in unauthorized access to a system holding our data, how quickly will you notify us — and is that timeframe a contract term? Our baseline is: as soon as possible, no later than 72 hours after you become aware.
- Why it matters:
- This is the one number the amendments hand you directly. A vendor unwilling to commit to it in writing is asking you to run your 30-day customer-notification clock on their goodwill.
- Provision:
- Maps to the required service-provider notification measure — no later than 72 hours — under the amended 17 CFR 248.30.
Q06In a breach, what will your notice to us contain, and what will you provide for our investigation — affected records, access logs, scope, timeline — and how fast?
- Why it matters:
- Your notification duty runs to each individual whose sensitive customer information was, or was reasonably likely to have been, accessed. You cannot draw that circle of individuals without the vendor's records, and every day of vendor lag is subtracted from your thirty.
- Provision:
- Supports the incident response program and the 30-day individual-notification clock.
Q07Can we export a complete per-request audit record — authenticated user, timestamp, model, event type — date-ranged and machine-readable, ourselves, without filing a support ticket?
- Why it matters:
- Detect, respond, recover, and demonstrate all draw on the same records. If export requires the vendor's help, the vendor's queue becomes your response time.
- Provision:
- Supports the incident response program's detect-and-respond design; the audit log schema template on this site shows the record shape to ask for.
Q08Do you or any provider in your chain train models on our data, and is zero retention at the model provider a contractual term? Provide both commitments in writing.
- Why it matters:
- Retention and training are separate promises on separate axes — neither implies the other, and neither can be verified from outside. That is exactly why both belong in the contract rather than in marketing copy.
- Provision:
- Supports protecting against unauthorized use of customer information across the service-provider chain.
Q09Which of your personnel can access our content, under what access controls, and is that access itself logged and reviewable?
- Why it matters:
- Support and operations access is the quiet path into customer information. Least-privilege, logged access is the answer you want; 'engineers can see everything in production' is the answer you often get.
- Provision:
- Supports the safeguards program's protection against unauthorized access to customer information.
Q10Where does the deployment boundary sit — which systems run in your infrastructure versus ours — and what moves under our direct control in each deployment option you offer?
- Why it matters:
- Every store that runs inside your own environment is one you can inspect directly instead of overseeing contractually. The honest vendor answer distinguishes the two lists plainly rather than blurring them.
- Provision:
- Supports proportionate oversight: due diligence where you must trust, direct inspection where you can verify.
Two companion pages make the answers easier to evaluate: the audit log schema template shows what a real per-request export should contain field by field, and the prompt log retention crosswalk maps which retention clock should govern which record type — including the rows where deletion, not retention, is the discipline. Firms that also run a model-risk program will find the vendor questions echoed there: the SR 11-7 and generative AI update covers the 2026 supersession and its vendor-model row. And for a standing, cross-vertical vendor-review process beyond this rule-specific addendum, the AI vendor security questionnaire carries 21 questions across seven domains with evidence, red-flag, and contract-clause columns — this addendum is its adviser overlay.
How PrivateStack answers this questionnaire
We built PrivateStack to answer these questions without hedging: hosted inference runs zero-retention through a disclosed subprocessor under contractual terms, with no training on your data; every request is logged with user identity, timestamp, and model identity, and audit logs export date-ranged and machine-readable from the console; and the Enterprise deployment runs the data plane inside the customer's own AWS account, which moves the conversation store, files, and logs under your direct control instead of ours. The honest limits: your due-diligence program, your incident response program, and your vendor contracts are your firm's own to run — no vendor answer, including ours, substitutes for them, and this page is not legal advice. The full control set is on the security page.
Questions people actually ask
- Does Regulation S-P apply to AI tools?
- It applies to your firm's handling of customer information, wherever that information flows — the rule is about the data, not the tool category. The moment customer information can appear in prompts, uploads, or outputs, the AI tool's stores sit inside your safeguards program, and the vendor operating them meets the rule's service-provider definition: any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution.
- We are a small adviser. When did the 2024 amendments start applying to us?
- June 3, 2026 — 24 months from the June 3, 2024 Federal Register publication, the compliance date for smaller entities, which for investment advisers means under $1.5 billion in assets under management. Larger advisers' date was December 3, 2025. Both dates have passed: the incident response program, the 30-day notification duty, and the service-provider oversight requirements are in force for advisers of every size now.
- Is our AI vendor really a 'service provider' under the rule?
- Apply the definition, not the label: a service provider is anyone who receives, maintains, processes, or is otherwise permitted access to customer information through services provided directly to your firm. An AI workspace that receives prompts containing client names, holdings, or account details fits squarely. And because your vendor's own model and hosting providers can receive the same content, your due diligence should reach the chain — which is what the subprocessor-disclosure question exists to surface.
- What exactly must a vendor notify us about, and how fast?
- Under the amended rule, your policies and procedures must be reasonably designed to ensure service providers notify you as soon as possible, but no later than 72 hours, after becoming aware of a breach in security resulting in unauthorized access to a customer information system. The practical move for a smaller firm is to put that number, and the contents of the notice, into the contract — the questionnaire's incident questions are written to produce exactly that term.
- What should a small firm actually do first?
- Three steps, in order. First, inventory where AI touches customer information today — including tools individual staff adopted on their own. Second, send the questionnaire on this page to each vendor in that inventory and file the answers with your due-diligence records. Third, fix the contracts: the 72-hour notification term, the no-training and retention commitments, and the deletion procedure. None of this requires a technology function — it requires asking vendors questions they should already be able to answer.
Evaluating the audit-trail side of vendor selection more broadly? The audit trail requirements checklist covers the ten controls examiners ask about, and the closed-API comparison shows where each deployment model leaves them.
Primary sources
Every provision, date, and threshold above traces to one of these publications. Read the rule before any vendor's interpretation — including ours.
- Release Nos. 34-100155 — Regulation S-P final rule (June 3, 2024) — The Securities and Exchange Commission's 2024 amendments: the incident response program, the 30-day individual-notification requirement, the service-provider oversight and 72-hour notification provisions, the sensitive-customer-information definition, and the 18/24-month compliance dates with the $1.5 billion adviser threshold.
- 17 CFR 248.30 — The safeguards and disposal rule as amended — written policies and procedures for administrative, technical, and physical safeguards, the incident response program, and service-provider oversight.
- 17 CFR Part 248, Subpart A — Regulation S-P in full — privacy notices, the definitions the safeguards rule relies on, and the surrounding consumer financial information provisions.