Scheduled Actions: Every Recurring Compliance Technology Task in the Library
In plain language
This is every recurring task the library implies, in one table, with how often it happens and who normally does it. If you are building a compliance calendar, start here rather than reading nine sections. Each row has a stable identifier so it can be tracked in a ticket queue or handed to a provider without ambiguity.
The nine sections of the Compliance Library each end with the recurring work that section implies. This page is the union of all of them, aggregated automatically, so nothing here can drift from its source section.
Three views of the same set follow: every action grouped by section, the same actions grouped by cadence for calendar building, and grouped by owner archetype for assigning work.
Cadence is an operating rhythm, not a regulatory deadline, unless the linked source says otherwise. Where a rule fixes the interval — the annual compliance review, the annual identity theft program update, the annual supervisory control report — the source link goes to the rule text. Where it does not, the cadence reflects what keeps the control demonstrable between examinations.
Owner archetypes are starting points. CCO is the compliance program’s administrator, IT is internal technology staff, and MSP is an outsourced provider. An action listing two owners usually means one produces the evidence and the other owns the conclusion. Firms assign differently and that is fine, as long as each action has exactly one accountable owner at your firm.
Use the action-id values as the vocabulary in tickets, statements of work, and calendars.
They are stable: a section can be rewritten without the identifier changing.
Every scheduled action in the library
58 actions aggregated from 9 library sections. Cadences are the operating rhythm the underlying rules imply; they are not regulatory deadlines unless the source says so.
| Action | Cadence | Owner archetype | Source | action-id |
|---|---|---|---|---|
| Regulation S-P: Safeguards, Incident Response, and the Notification Clocks | ||||
| Re-verify the inventory of systems and vendors that store, process, or can reach customer information, including anything added by a new tool, integration, or acquisition. | Quarterly | CCO, MSP | 17 CFR 248.30 | act.reg-s-p.customer-info-inventory-review |
| Review and re-approve the written incident response program, including the assessment, containment, and notification procedures, and record who approved it. | Annually | CCO | SEC Release 34-100155 | act.reg-s-p.ir-program-review |
| Run a tabletop that exercises the customer notification decision specifically: who determines scope, who drafts the notice, who approves it, and how the 30-day clock is documented. | Annually | CCO, MSP | SEC Release 34-100155 | act.reg-s-p.notification-tabletop |
| Confirm every service provider with access to customer information is under an agreement carrying the 72-hour breach notification obligation, and log the exceptions that are still open. | Annually | CCO, IT | SEC Release 34-100155 | act.reg-s-p.service-provider-clause-audit |
| Verify that decommissioned media, retired endpoints, and expired records containing consumer report information were disposed of under the Disposal Rule, and keep the certificates. | Quarterly | IT, MSP | 17 CFR 248.30(b) | act.reg-s-p.disposal-verification |
| Before a new system goes live, determine whether it will hold customer information and, if it will, add it to the inventory and bring it under the safeguards and notification program. | On change | IT, MSP | 17 CFR 248.30 | act.reg-s-p.new-system-scope-check |
| Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program | ||||
| Complete the annual review of the compliance program's technology components and record what was tested, what was found, and what was changed. | Annually | CCO | 17 CFR 275.206(4)-7 | act.advisers-act.annual-compliance-review |
| Refresh the technology risk assessment that the policies are designed against, so the program reflects the systems the firm uses now rather than the ones it used at adoption. | Annually | CCO, MSP | SEC IM Guidance 2015-02 | act.advisers-act.risk-assessment-refresh |
| Record every material change to a technology policy or procedure with its date, reason, and approver, so the program's version history is reconstructable. | On change | CCO | 17 CFR 275.204-2(a)(17) | act.advisers-act.policy-change-log |
| Deliver security awareness training covering phishing, wire-transfer verification, and reporting, and retain the completion records by person. | Annually | CCO, MSP | SEC IM Guidance 2015-02 | act.advisers-act.security-awareness-training |
| Read the Division of Examinations priorities when published and note which technology items apply to the firm, and which of those the program does not yet address. | Annually | CCO | SEC Division of Examinations | act.advisers-act.exam-priorities-read |
| Confirm the CCO receives technology incident and exception reporting on a defined interval, rather than on request, and that the last interval's report exists. | Quarterly | CCO, MSP | 17 CFR 275.206(4)-7 | act.advisers-act.cco-escalation-review |
| Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2 | ||||
| Review the retention schedule against the record categories the firm actually generates, and confirm each category maps to a system with the correct retention period. | Annually | CCO, IT | 17 CFR 275.204-2 | act.books-records.retention-schedule-review |
| Run a production test: pick a person and a date range, retrieve the responsive communications, and time it. Record the result including anything that could not be retrieved. | Quarterly | CCO, MSP | 17 CFR 240.17a-4(j) | act.books-records.production-test |
| Re-inventory the communication channels in use — email, chat, SMS, collaboration tools, social — and confirm each is either captured or prohibited, with the prohibition enforced somewhere other than a policy document. | Quarterly | CCO, IT, MSP | FINRA Rule 4511 | act.books-records.channel-inventory |
| Reconcile the archive against the mail and messaging systems for a sample period to confirm nothing is being dropped in transit. | Quarterly | IT, MSP | 17 CFR 240.17a-4(f) | act.books-records.archive-completeness-check |
| When someone joins or leaves, confirm their communications are brought into or preserved within the archive, including mobile devices used for business. | On change | IT, MSP | 17 CFR 275.204-2 | act.books-records.onboarding-offboarding-capture |
| Confirm a legal hold can be applied and will actually suspend deletion, by testing it on a sample account rather than by reading the vendor's documentation. | Annually | CCO, IT | 17 CFR 240.17a-4 | act.books-records.legal-hold-drill |
| FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls | ||||
| Review the written supervisory procedures for technology accuracy: named systems, named reviewers, sampling basis, and evidencing method. | Annually | CCO, IT | FINRA Rule 3110 | act.finra-supervision.wsp-technology-review |
| Perform the electronic correspondence review on the stated sampling basis and evidence it, including what the reviewer looked at and what was escalated. | Monthly | CCO | FINRA Rule 3110(b)(4) | act.finra-supervision.correspondence-review |
| Test and verify that the supervisory procedures are reasonably designed, and produce the annual report to senior management. | Annually | CCO | FINRA Rule 3120 | act.finra-supervision.supervisory-control-test |
| Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed. | Annually | CCO, IT, MSP | FINRA Rule 4370 | act.finra-supervision.bcp-review-and-test |
| Inspect offices on the firm's stated cycle, covering the technology conditions at each location: device compliance, network, physical document handling, and use of approved channels. | Annually | CCO, IT | FINRA Rule 3110(c) | act.finra-supervision.branch-and-remote-inspection |
| Review current FINRA cybersecurity guidance and examination findings, and note which items the firm does not yet address. | Annually | CCO, MSP | FINRA cybersecurity topic page | act.finra-supervision.cyber-guidance-review |
| Regulation S-ID: Identity Theft Red Flags, at a High Level | ||||
| Re-assess whether the firm offers or maintains covered accounts, and record the determination with the reasoning, including for new products or account types. | Annually | CCO | 17 CFR 248.201 | act.reg-s-id.covered-account-determination |
| Update the identity theft prevention program to reflect changes in identity theft risk, the firm's methods of detection and response, service provider arrangements, and account types offered. | Annually | CCO | 17 CFR 248.201(d)(2) | act.reg-s-id.program-update |
| Review the firm's selected red flags against actual incidents and attempted fraud from the period, and add or retire flags accordingly. | Annually | CCO, MSP | 17 CFR 248.201, Appendix A | act.reg-s-id.red-flag-list-review |
| Train staff who handle covered accounts on the red flags relevant to their role and on the escalation path, and retain completion records. | Annually | CCO | 17 CFR 248.201(e) | act.reg-s-id.staff-training |
| Report to the board, a board committee, or designated senior management on the effectiveness of the program, significant incidents, and recommended changes. | Annually | CCO | 17 CFR 248.201(e) | act.reg-s-id.board-report |
| Review the alerting rules that implement technical red flags — address changes, contact detail changes, anomalous logins, unusual disbursement patterns — for false negatives and alert fatigue. | Quarterly | IT, MSP | SEC Release 34-69359 | act.reg-s-id.detection-rule-tuning |
| Vendor and Service-Provider Oversight for Regulated Financial Firms | ||||
| Reconcile the vendor register against accounts payable, the identity provider's connected-application list, and SaaS discovery data to find providers that entered without procurement. | Quarterly | CCO, IT, MSP | 17 CFR 248.30 | act.vendor-oversight.register-reconciliation |
| Perform the periodic review for each vendor at the depth its tier requires, and record the date, the reviewer, and what was examined. | Annually | CCO | 17 CFR 275.206(4)-7 | act.vendor-oversight.tiered-review |
| Obtain and actually read the current SOC 2, SOC 1, or equivalent attestation for tier-one vendors, recording the report period, scope, exceptions, and complementary user entity controls. | Annually | CCO, IT | 17 CFR 248.30 | act.vendor-oversight.attestation-refresh |
| Confirm each in-scope vendor's agreement carries the breach notification obligation with the 72-hour timing, and track the ones that do not to an owner and a renewal date. | Annually | CCO | SEC Release 34-100155 | act.vendor-oversight.notification-clause-check |
| Before a new vendor receives access, determine its tier, complete the diligence that tier requires, and record the data it will hold and the access it will have. | On change | CCO, IT | 17 CFR 248.30 | act.vendor-oversight.onboarding-diligence |
| On termination, revoke the vendor's access, confirm return or destruction of firm data, and record the confirmation. | On change | IT, MSP | 17 CFR 248.30(b) | act.vendor-oversight.offboarding-verification |
| Review concentration and substitutability: which single vendor failures would stop the firm operating, and what the interim plan is for each. | Annually | CCO, IT | FINRA Rule 4370 | act.vendor-oversight.concentration-review |
| Access Control and MFA for RIAs, Broker-Dealers, and Funds | ||||
| Review every account holding administrative or elevated privilege, confirm each is still required, and remove the ones that are not. | Quarterly | IT, MSP | 17 CFR 248.30 | act.access-mfa.privileged-access-review |
| Review standard user access to systems holding customer information, confirm entitlements match current role, and record the removals. | Annually | CCO, IT | 17 CFR 248.30 | act.access-mfa.user-access-review |
| Produce an MFA coverage report across all identities — staff, vendors, service accounts, shared mailboxes — and reconcile the unenrolled list against the approved exception register. | Quarterly | IT, MSP | SEC IM Guidance 2015-02 | act.access-mfa.mfa-coverage-report |
| Review each MFA and access-control exception against its expiry date, and either close it or re-approve it with a new date and a reason. | Quarterly | CCO, IT | 17 CFR 275.206(4)-7 | act.access-mfa.exception-expiry-review |
| Provision, change, or revoke access within the firm's stated window of a joiner, role change, or departure, and record the completion against the person. | On change | IT, MSP | 17 CFR 248.30 | act.access-mfa.joiner-mover-leaver |
| Re-inventory non-human identities — service accounts, API keys, integration credentials, shared mailboxes — with an owner and a justification for each, and retire the unclaimed ones. | Quarterly | IT, MSP | 17 CFR 248.30 | act.access-mfa.service-account-inventory |
| Rotate shared and service credentials that cannot be replaced with managed identities, and record the rotation. | Quarterly | IT, MSP | SEC IM Guidance 2015-02 | act.access-mfa.credential-rotation |
| Incident Response and Exam Evidence for Financial Firms | ||||
| Review and re-approve the written incident response program, confirming that named roles, contacts, and escalation paths reflect current staff and current vendors. | Annually | CCO | SEC Release 34-100155 | act.incident-response.program-review |
| Run a tabletop exercise against a realistic scenario and record the decisions, the timings, and the gaps it exposed. | Annually | CCO, IT, MSP | SEC Release 34-100155 | act.incident-response.tabletop |
| Verify that identity, email, endpoint, and remote access logs are being retained for the stated period and are searchable across that whole period. | Quarterly | IT, MSP | 17 CFR 248.30 | act.incident-response.log-retention-verification |
| Perform a restore test from backup into a usable state, record the elapsed time, and record what failed. | Quarterly | IT, MSP | FINRA Rule 4370 | act.incident-response.restore-test |
| Verify the out-of-band contact list — staff, counsel, insurer, custodians, key vendors, law enforcement — by confirming the details rather than assuming them. | Quarterly | CCO, MSP | FINRA Rule 4370 | act.incident-response.contact-list-verification |
| Refresh the standing exam evidence file so the current version of each core artifact is present and dated, rather than assembled on request. | Quarterly | CCO | SEC Division of Examinations | act.incident-response.exam-file-refresh |
| After any incident, including contained ones with no impact, complete a written review covering timeline, decisions, root cause, and changes made. | On incident | CCO, IT, MSP | SEC Release 34-100155 | act.incident-response.post-incident-review |
| Private Fund and PE Adviser Technology Notes | ||||
| Refresh the standing operational due diligence pack — security overview, vendor list, BCP summary, test results, insurance details — so investor requests are answered from current material. | Annually | CCO, MSP | 17 CFR 275.206(4)-7 | act.private-funds.ddq-artifact-refresh |
| Review who retains access to each active and closed deal room or investor data room, and remove participants whose involvement has ended. | Quarterly | IT, MSP | 17 CFR 248.30 | act.private-funds.data-room-access-review |
| Review the technical controls supporting the firm's information barriers and restricted list — who can reach deal folders, whether access is logged, whether the barrier is enforced or merely stated. | Annually | CCO, IT | 17 CFR 275.206(4)-7 | act.private-funds.mnpi-control-review |
| Confirm fund-level records — investor communications, valuation support, performance calculation backup, capital account records — are captured in a system with the correct retention, not only on a shared drive. | Annually | CCO, IT | 17 CFR 275.204-2 | act.private-funds.fund-records-retention-check |
| Review the fund administrator, custodian, and auditor as tier-one service providers, including their attestations and the complementary controls they assume the adviser operates. | Annually | CCO | 17 CFR 275.206(4)-2 | act.private-funds.administrator-and-custodian-review |
| Confirm the technical boundary between adviser systems and portfolio company systems: no shared identity tenant, no shared credentials, no commingled deal and operating data. | Annually | IT, MSP | 17 CFR 248.30 | act.private-funds.portfolio-boundary-check |
| At each closing or exit, provision or revoke access for deal participants, advisers, and counsel, and record the change against the transaction. | On change | IT, MSP | 17 CFR 248.30 | act.private-funds.transaction-onboarding-offboarding |
Grouped by cadence
The same actions, arranged the way a compliance calendar is built.
Monthly (1)
- Perform the electronic correspondence review on the stated sampling basis and evidence it, including what the reviewer looked at and what was escalated.
— CCO · FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls ·
act.finra-supervision.correspondence-review
Quarterly (18)
- Re-verify the inventory of systems and vendors that store, process, or can reach customer information, including anything added by a new tool, integration, or acquisition.
— CCO, MSP · Regulation S-P: Safeguards, Incident Response, and the Notification Clocks ·
act.reg-s-p.customer-info-inventory-review - Verify that decommissioned media, retired endpoints, and expired records containing consumer report information were disposed of under the Disposal Rule, and keep the certificates.
— IT, MSP · Regulation S-P: Safeguards, Incident Response, and the Notification Clocks ·
act.reg-s-p.disposal-verification - Confirm the CCO receives technology incident and exception reporting on a defined interval, rather than on request, and that the last interval's report exists.
— CCO, MSP · Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program ·
act.advisers-act.cco-escalation-review - Run a production test: pick a person and a date range, retrieve the responsive communications, and time it. Record the result including anything that could not be retrieved.
— CCO, MSP · Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2 ·
act.books-records.production-test - Re-inventory the communication channels in use — email, chat, SMS, collaboration tools, social — and confirm each is either captured or prohibited, with the prohibition enforced somewhere other than a policy document.
— CCO, IT, MSP · Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2 ·
act.books-records.channel-inventory - Reconcile the archive against the mail and messaging systems for a sample period to confirm nothing is being dropped in transit.
— IT, MSP · Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2 ·
act.books-records.archive-completeness-check - Review the alerting rules that implement technical red flags — address changes, contact detail changes, anomalous logins, unusual disbursement patterns — for false negatives and alert fatigue.
— IT, MSP · Regulation S-ID: Identity Theft Red Flags, at a High Level ·
act.reg-s-id.detection-rule-tuning - Reconcile the vendor register against accounts payable, the identity provider's connected-application list, and SaaS discovery data to find providers that entered without procurement.
— CCO, IT, MSP · Vendor and Service-Provider Oversight for Regulated Financial Firms ·
act.vendor-oversight.register-reconciliation - Review every account holding administrative or elevated privilege, confirm each is still required, and remove the ones that are not.
— IT, MSP · Access Control and MFA for RIAs, Broker-Dealers, and Funds ·
act.access-mfa.privileged-access-review - Produce an MFA coverage report across all identities — staff, vendors, service accounts, shared mailboxes — and reconcile the unenrolled list against the approved exception register.
— IT, MSP · Access Control and MFA for RIAs, Broker-Dealers, and Funds ·
act.access-mfa.mfa-coverage-report - Review each MFA and access-control exception against its expiry date, and either close it or re-approve it with a new date and a reason.
— CCO, IT · Access Control and MFA for RIAs, Broker-Dealers, and Funds ·
act.access-mfa.exception-expiry-review - Re-inventory non-human identities — service accounts, API keys, integration credentials, shared mailboxes — with an owner and a justification for each, and retire the unclaimed ones.
— IT, MSP · Access Control and MFA for RIAs, Broker-Dealers, and Funds ·
act.access-mfa.service-account-inventory - Rotate shared and service credentials that cannot be replaced with managed identities, and record the rotation.
— IT, MSP · Access Control and MFA for RIAs, Broker-Dealers, and Funds ·
act.access-mfa.credential-rotation - Verify that identity, email, endpoint, and remote access logs are being retained for the stated period and are searchable across that whole period.
— IT, MSP · Incident Response and Exam Evidence for Financial Firms ·
act.incident-response.log-retention-verification - Perform a restore test from backup into a usable state, record the elapsed time, and record what failed.
— IT, MSP · Incident Response and Exam Evidence for Financial Firms ·
act.incident-response.restore-test - Verify the out-of-band contact list — staff, counsel, insurer, custodians, key vendors, law enforcement — by confirming the details rather than assuming them.
— CCO, MSP · Incident Response and Exam Evidence for Financial Firms ·
act.incident-response.contact-list-verification - Refresh the standing exam evidence file so the current version of each core artifact is present and dated, rather than assembled on request.
— CCO · Incident Response and Exam Evidence for Financial Firms ·
act.incident-response.exam-file-refresh - Review who retains access to each active and closed deal room or investor data room, and remove participants whose involvement has ended.
— IT, MSP · Private Fund and PE Adviser Technology Notes ·
act.private-funds.data-room-access-review
Annually (31)
- Review and re-approve the written incident response program, including the assessment, containment, and notification procedures, and record who approved it.
— CCO · Regulation S-P: Safeguards, Incident Response, and the Notification Clocks ·
act.reg-s-p.ir-program-review - Run a tabletop that exercises the customer notification decision specifically: who determines scope, who drafts the notice, who approves it, and how the 30-day clock is documented.
— CCO, MSP · Regulation S-P: Safeguards, Incident Response, and the Notification Clocks ·
act.reg-s-p.notification-tabletop - Confirm every service provider with access to customer information is under an agreement carrying the 72-hour breach notification obligation, and log the exceptions that are still open.
— CCO, IT · Regulation S-P: Safeguards, Incident Response, and the Notification Clocks ·
act.reg-s-p.service-provider-clause-audit - Complete the annual review of the compliance program's technology components and record what was tested, what was found, and what was changed.
— CCO · Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program ·
act.advisers-act.annual-compliance-review - Refresh the technology risk assessment that the policies are designed against, so the program reflects the systems the firm uses now rather than the ones it used at adoption.
— CCO, MSP · Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program ·
act.advisers-act.risk-assessment-refresh - Deliver security awareness training covering phishing, wire-transfer verification, and reporting, and retain the completion records by person.
— CCO, MSP · Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program ·
act.advisers-act.security-awareness-training - Read the Division of Examinations priorities when published and note which technology items apply to the firm, and which of those the program does not yet address.
— CCO · Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program ·
act.advisers-act.exam-priorities-read - Review the retention schedule against the record categories the firm actually generates, and confirm each category maps to a system with the correct retention period.
— CCO, IT · Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2 ·
act.books-records.retention-schedule-review - Confirm a legal hold can be applied and will actually suspend deletion, by testing it on a sample account rather than by reading the vendor's documentation.
— CCO, IT · Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2 ·
act.books-records.legal-hold-drill - Review the written supervisory procedures for technology accuracy: named systems, named reviewers, sampling basis, and evidencing method.
— CCO, IT · FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls ·
act.finra-supervision.wsp-technology-review - Test and verify that the supervisory procedures are reasonably designed, and produce the annual report to senior management.
— CCO · FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls ·
act.finra-supervision.supervisory-control-test - Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed.
— CCO, IT, MSP · FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls ·
act.finra-supervision.bcp-review-and-test - Inspect offices on the firm's stated cycle, covering the technology conditions at each location: device compliance, network, physical document handling, and use of approved channels.
— CCO, IT · FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls ·
act.finra-supervision.branch-and-remote-inspection - Review current FINRA cybersecurity guidance and examination findings, and note which items the firm does not yet address.
— CCO, MSP · FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls ·
act.finra-supervision.cyber-guidance-review - Re-assess whether the firm offers or maintains covered accounts, and record the determination with the reasoning, including for new products or account types.
— CCO · Regulation S-ID: Identity Theft Red Flags, at a High Level ·
act.reg-s-id.covered-account-determination - Update the identity theft prevention program to reflect changes in identity theft risk, the firm's methods of detection and response, service provider arrangements, and account types offered.
— CCO · Regulation S-ID: Identity Theft Red Flags, at a High Level ·
act.reg-s-id.program-update - Review the firm's selected red flags against actual incidents and attempted fraud from the period, and add or retire flags accordingly.
— CCO, MSP · Regulation S-ID: Identity Theft Red Flags, at a High Level ·
act.reg-s-id.red-flag-list-review - Train staff who handle covered accounts on the red flags relevant to their role and on the escalation path, and retain completion records.
— CCO · Regulation S-ID: Identity Theft Red Flags, at a High Level ·
act.reg-s-id.staff-training - Report to the board, a board committee, or designated senior management on the effectiveness of the program, significant incidents, and recommended changes.
— CCO · Regulation S-ID: Identity Theft Red Flags, at a High Level ·
act.reg-s-id.board-report - Perform the periodic review for each vendor at the depth its tier requires, and record the date, the reviewer, and what was examined.
— CCO · Vendor and Service-Provider Oversight for Regulated Financial Firms ·
act.vendor-oversight.tiered-review - Obtain and actually read the current SOC 2, SOC 1, or equivalent attestation for tier-one vendors, recording the report period, scope, exceptions, and complementary user entity controls.
— CCO, IT · Vendor and Service-Provider Oversight for Regulated Financial Firms ·
act.vendor-oversight.attestation-refresh - Confirm each in-scope vendor's agreement carries the breach notification obligation with the 72-hour timing, and track the ones that do not to an owner and a renewal date.
— CCO · Vendor and Service-Provider Oversight for Regulated Financial Firms ·
act.vendor-oversight.notification-clause-check - Review concentration and substitutability: which single vendor failures would stop the firm operating, and what the interim plan is for each.
— CCO, IT · Vendor and Service-Provider Oversight for Regulated Financial Firms ·
act.vendor-oversight.concentration-review - Review standard user access to systems holding customer information, confirm entitlements match current role, and record the removals.
— CCO, IT · Access Control and MFA for RIAs, Broker-Dealers, and Funds ·
act.access-mfa.user-access-review - Review and re-approve the written incident response program, confirming that named roles, contacts, and escalation paths reflect current staff and current vendors.
— CCO · Incident Response and Exam Evidence for Financial Firms ·
act.incident-response.program-review - Run a tabletop exercise against a realistic scenario and record the decisions, the timings, and the gaps it exposed.
— CCO, IT, MSP · Incident Response and Exam Evidence for Financial Firms ·
act.incident-response.tabletop - Refresh the standing operational due diligence pack — security overview, vendor list, BCP summary, test results, insurance details — so investor requests are answered from current material.
— CCO, MSP · Private Fund and PE Adviser Technology Notes ·
act.private-funds.ddq-artifact-refresh - Review the technical controls supporting the firm's information barriers and restricted list — who can reach deal folders, whether access is logged, whether the barrier is enforced or merely stated.
— CCO, IT · Private Fund and PE Adviser Technology Notes ·
act.private-funds.mnpi-control-review - Confirm fund-level records — investor communications, valuation support, performance calculation backup, capital account records — are captured in a system with the correct retention, not only on a shared drive.
— CCO, IT · Private Fund and PE Adviser Technology Notes ·
act.private-funds.fund-records-retention-check - Review the fund administrator, custodian, and auditor as tier-one service providers, including their attestations and the complementary controls they assume the adviser operates.
— CCO · Private Fund and PE Adviser Technology Notes ·
act.private-funds.administrator-and-custodian-review - Confirm the technical boundary between adviser systems and portfolio company systems: no shared identity tenant, no shared credentials, no commingled deal and operating data.
— IT, MSP · Private Fund and PE Adviser Technology Notes ·
act.private-funds.portfolio-boundary-check
On change (7)
- Before a new system goes live, determine whether it will hold customer information and, if it will, add it to the inventory and bring it under the safeguards and notification program.
— IT, MSP · Regulation S-P: Safeguards, Incident Response, and the Notification Clocks ·
act.reg-s-p.new-system-scope-check - Record every material change to a technology policy or procedure with its date, reason, and approver, so the program's version history is reconstructable.
— CCO · Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program ·
act.advisers-act.policy-change-log - When someone joins or leaves, confirm their communications are brought into or preserved within the archive, including mobile devices used for business.
— IT, MSP · Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2 ·
act.books-records.onboarding-offboarding-capture - Before a new vendor receives access, determine its tier, complete the diligence that tier requires, and record the data it will hold and the access it will have.
— CCO, IT · Vendor and Service-Provider Oversight for Regulated Financial Firms ·
act.vendor-oversight.onboarding-diligence - On termination, revoke the vendor's access, confirm return or destruction of firm data, and record the confirmation.
— IT, MSP · Vendor and Service-Provider Oversight for Regulated Financial Firms ·
act.vendor-oversight.offboarding-verification - Provision, change, or revoke access within the firm's stated window of a joiner, role change, or departure, and record the completion against the person.
— IT, MSP · Access Control and MFA for RIAs, Broker-Dealers, and Funds ·
act.access-mfa.joiner-mover-leaver - At each closing or exit, provision or revoke access for deal participants, advisers, and counsel, and record the change against the transaction.
— IT, MSP · Private Fund and PE Adviser Technology Notes ·
act.private-funds.transaction-onboarding-offboarding
On incident (1)
- After any incident, including contained ones with no impact, complete a written review covering timeline, decisions, root cause, and changes made.
— CCO, IT, MSP · Incident Response and Exam Evidence for Financial Firms ·
act.incident-response.post-incident-review
Grouped by owner archetype
Who normally carries the action. A firm may assign it differently; the archetype is a starting point, not an org chart. Actions owned jointly appear under each owner.
CCO (42)
- Re-verify the inventory of systems and vendors that store, process, or can reach customer information, including anything added by a new tool, integration, or acquisition. (Quarterly)
- Review and re-approve the written incident response program, including the assessment, containment, and notification procedures, and record who approved it. (Annually)
- Run a tabletop that exercises the customer notification decision specifically: who determines scope, who drafts the notice, who approves it, and how the 30-day clock is documented. (Annually)
- Confirm every service provider with access to customer information is under an agreement carrying the 72-hour breach notification obligation, and log the exceptions that are still open. (Annually)
- Complete the annual review of the compliance program's technology components and record what was tested, what was found, and what was changed. (Annually)
- Refresh the technology risk assessment that the policies are designed against, so the program reflects the systems the firm uses now rather than the ones it used at adoption. (Annually)
- Record every material change to a technology policy or procedure with its date, reason, and approver, so the program's version history is reconstructable. (On change)
- Deliver security awareness training covering phishing, wire-transfer verification, and reporting, and retain the completion records by person. (Annually)
- Read the Division of Examinations priorities when published and note which technology items apply to the firm, and which of those the program does not yet address. (Annually)
- Confirm the CCO receives technology incident and exception reporting on a defined interval, rather than on request, and that the last interval's report exists. (Quarterly)
- Review the retention schedule against the record categories the firm actually generates, and confirm each category maps to a system with the correct retention period. (Annually)
- Run a production test: pick a person and a date range, retrieve the responsive communications, and time it. Record the result including anything that could not be retrieved. (Quarterly)
- Re-inventory the communication channels in use — email, chat, SMS, collaboration tools, social — and confirm each is either captured or prohibited, with the prohibition enforced somewhere other than a policy document. (Quarterly)
- Confirm a legal hold can be applied and will actually suspend deletion, by testing it on a sample account rather than by reading the vendor's documentation. (Annually)
- Review the written supervisory procedures for technology accuracy: named systems, named reviewers, sampling basis, and evidencing method. (Annually)
- Perform the electronic correspondence review on the stated sampling basis and evidence it, including what the reviewer looked at and what was escalated. (Monthly)
- Test and verify that the supervisory procedures are reasonably designed, and produce the annual report to senior management. (Annually)
- Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed. (Annually)
- Inspect offices on the firm's stated cycle, covering the technology conditions at each location: device compliance, network, physical document handling, and use of approved channels. (Annually)
- Review current FINRA cybersecurity guidance and examination findings, and note which items the firm does not yet address. (Annually)
- Re-assess whether the firm offers or maintains covered accounts, and record the determination with the reasoning, including for new products or account types. (Annually)
- Update the identity theft prevention program to reflect changes in identity theft risk, the firm's methods of detection and response, service provider arrangements, and account types offered. (Annually)
- Review the firm's selected red flags against actual incidents and attempted fraud from the period, and add or retire flags accordingly. (Annually)
- Train staff who handle covered accounts on the red flags relevant to their role and on the escalation path, and retain completion records. (Annually)
- Report to the board, a board committee, or designated senior management on the effectiveness of the program, significant incidents, and recommended changes. (Annually)
- Reconcile the vendor register against accounts payable, the identity provider's connected-application list, and SaaS discovery data to find providers that entered without procurement. (Quarterly)
- Perform the periodic review for each vendor at the depth its tier requires, and record the date, the reviewer, and what was examined. (Annually)
- Obtain and actually read the current SOC 2, SOC 1, or equivalent attestation for tier-one vendors, recording the report period, scope, exceptions, and complementary user entity controls. (Annually)
- Confirm each in-scope vendor's agreement carries the breach notification obligation with the 72-hour timing, and track the ones that do not to an owner and a renewal date. (Annually)
- Before a new vendor receives access, determine its tier, complete the diligence that tier requires, and record the data it will hold and the access it will have. (On change)
- Review concentration and substitutability: which single vendor failures would stop the firm operating, and what the interim plan is for each. (Annually)
- Review standard user access to systems holding customer information, confirm entitlements match current role, and record the removals. (Annually)
- Review each MFA and access-control exception against its expiry date, and either close it or re-approve it with a new date and a reason. (Quarterly)
- Review and re-approve the written incident response program, confirming that named roles, contacts, and escalation paths reflect current staff and current vendors. (Annually)
- Run a tabletop exercise against a realistic scenario and record the decisions, the timings, and the gaps it exposed. (Annually)
- Verify the out-of-band contact list — staff, counsel, insurer, custodians, key vendors, law enforcement — by confirming the details rather than assuming them. (Quarterly)
- Refresh the standing exam evidence file so the current version of each core artifact is present and dated, rather than assembled on request. (Quarterly)
- After any incident, including contained ones with no impact, complete a written review covering timeline, decisions, root cause, and changes made. (On incident)
- Refresh the standing operational due diligence pack — security overview, vendor list, BCP summary, test results, insurance details — so investor requests are answered from current material. (Annually)
- Review the technical controls supporting the firm's information barriers and restricted list — who can reach deal folders, whether access is logged, whether the barrier is enforced or merely stated. (Annually)
- Confirm fund-level records — investor communications, valuation support, performance calculation backup, capital account records — are captured in a system with the correct retention, not only on a shared drive. (Annually)
- Review the fund administrator, custodian, and auditor as tier-one service providers, including their attestations and the complementary controls they assume the adviser operates. (Annually)
IT (33)
- Confirm every service provider with access to customer information is under an agreement carrying the 72-hour breach notification obligation, and log the exceptions that are still open. (Annually)
- Verify that decommissioned media, retired endpoints, and expired records containing consumer report information were disposed of under the Disposal Rule, and keep the certificates. (Quarterly)
- Before a new system goes live, determine whether it will hold customer information and, if it will, add it to the inventory and bring it under the safeguards and notification program. (On change)
- Review the retention schedule against the record categories the firm actually generates, and confirm each category maps to a system with the correct retention period. (Annually)
- Re-inventory the communication channels in use — email, chat, SMS, collaboration tools, social — and confirm each is either captured or prohibited, with the prohibition enforced somewhere other than a policy document. (Quarterly)
- Reconcile the archive against the mail and messaging systems for a sample period to confirm nothing is being dropped in transit. (Quarterly)
- When someone joins or leaves, confirm their communications are brought into or preserved within the archive, including mobile devices used for business. (On change)
- Confirm a legal hold can be applied and will actually suspend deletion, by testing it on a sample account rather than by reading the vendor's documentation. (Annually)
- Review the written supervisory procedures for technology accuracy: named systems, named reviewers, sampling basis, and evidencing method. (Annually)
- Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed. (Annually)
- Inspect offices on the firm's stated cycle, covering the technology conditions at each location: device compliance, network, physical document handling, and use of approved channels. (Annually)
- Review the alerting rules that implement technical red flags — address changes, contact detail changes, anomalous logins, unusual disbursement patterns — for false negatives and alert fatigue. (Quarterly)
- Reconcile the vendor register against accounts payable, the identity provider's connected-application list, and SaaS discovery data to find providers that entered without procurement. (Quarterly)
- Obtain and actually read the current SOC 2, SOC 1, or equivalent attestation for tier-one vendors, recording the report period, scope, exceptions, and complementary user entity controls. (Annually)
- Before a new vendor receives access, determine its tier, complete the diligence that tier requires, and record the data it will hold and the access it will have. (On change)
- On termination, revoke the vendor's access, confirm return or destruction of firm data, and record the confirmation. (On change)
- Review concentration and substitutability: which single vendor failures would stop the firm operating, and what the interim plan is for each. (Annually)
- Review every account holding administrative or elevated privilege, confirm each is still required, and remove the ones that are not. (Quarterly)
- Review standard user access to systems holding customer information, confirm entitlements match current role, and record the removals. (Annually)
- Produce an MFA coverage report across all identities — staff, vendors, service accounts, shared mailboxes — and reconcile the unenrolled list against the approved exception register. (Quarterly)
- Review each MFA and access-control exception against its expiry date, and either close it or re-approve it with a new date and a reason. (Quarterly)
- Provision, change, or revoke access within the firm's stated window of a joiner, role change, or departure, and record the completion against the person. (On change)
- Re-inventory non-human identities — service accounts, API keys, integration credentials, shared mailboxes — with an owner and a justification for each, and retire the unclaimed ones. (Quarterly)
- Rotate shared and service credentials that cannot be replaced with managed identities, and record the rotation. (Quarterly)
- Run a tabletop exercise against a realistic scenario and record the decisions, the timings, and the gaps it exposed. (Annually)
- Verify that identity, email, endpoint, and remote access logs are being retained for the stated period and are searchable across that whole period. (Quarterly)
- Perform a restore test from backup into a usable state, record the elapsed time, and record what failed. (Quarterly)
- After any incident, including contained ones with no impact, complete a written review covering timeline, decisions, root cause, and changes made. (On incident)
- Review who retains access to each active and closed deal room or investor data room, and remove participants whose involvement has ended. (Quarterly)
- Review the technical controls supporting the firm's information barriers and restricted list — who can reach deal folders, whether access is logged, whether the barrier is enforced or merely stated. (Annually)
- Confirm fund-level records — investor communications, valuation support, performance calculation backup, capital account records — are captured in a system with the correct retention, not only on a shared drive. (Annually)
- Confirm the technical boundary between adviser systems and portfolio company systems: no shared identity tenant, no shared credentials, no commingled deal and operating data. (Annually)
- At each closing or exit, provision or revoke access for deal participants, advisers, and counsel, and record the change against the transaction. (On change)
MSP (31)
- Re-verify the inventory of systems and vendors that store, process, or can reach customer information, including anything added by a new tool, integration, or acquisition. (Quarterly)
- Run a tabletop that exercises the customer notification decision specifically: who determines scope, who drafts the notice, who approves it, and how the 30-day clock is documented. (Annually)
- Verify that decommissioned media, retired endpoints, and expired records containing consumer report information were disposed of under the Disposal Rule, and keep the certificates. (Quarterly)
- Before a new system goes live, determine whether it will hold customer information and, if it will, add it to the inventory and bring it under the safeguards and notification program. (On change)
- Refresh the technology risk assessment that the policies are designed against, so the program reflects the systems the firm uses now rather than the ones it used at adoption. (Annually)
- Deliver security awareness training covering phishing, wire-transfer verification, and reporting, and retain the completion records by person. (Annually)
- Confirm the CCO receives technology incident and exception reporting on a defined interval, rather than on request, and that the last interval's report exists. (Quarterly)
- Run a production test: pick a person and a date range, retrieve the responsive communications, and time it. Record the result including anything that could not be retrieved. (Quarterly)
- Re-inventory the communication channels in use — email, chat, SMS, collaboration tools, social — and confirm each is either captured or prohibited, with the prohibition enforced somewhere other than a policy document. (Quarterly)
- Reconcile the archive against the mail and messaging systems for a sample period to confirm nothing is being dropped in transit. (Quarterly)
- When someone joins or leaves, confirm their communications are brought into or preserved within the archive, including mobile devices used for business. (On change)
- Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed. (Annually)
- Review current FINRA cybersecurity guidance and examination findings, and note which items the firm does not yet address. (Annually)
- Review the firm's selected red flags against actual incidents and attempted fraud from the period, and add or retire flags accordingly. (Annually)
- Review the alerting rules that implement technical red flags — address changes, contact detail changes, anomalous logins, unusual disbursement patterns — for false negatives and alert fatigue. (Quarterly)
- Reconcile the vendor register against accounts payable, the identity provider's connected-application list, and SaaS discovery data to find providers that entered without procurement. (Quarterly)
- On termination, revoke the vendor's access, confirm return or destruction of firm data, and record the confirmation. (On change)
- Review every account holding administrative or elevated privilege, confirm each is still required, and remove the ones that are not. (Quarterly)
- Produce an MFA coverage report across all identities — staff, vendors, service accounts, shared mailboxes — and reconcile the unenrolled list against the approved exception register. (Quarterly)
- Provision, change, or revoke access within the firm's stated window of a joiner, role change, or departure, and record the completion against the person. (On change)
- Re-inventory non-human identities — service accounts, API keys, integration credentials, shared mailboxes — with an owner and a justification for each, and retire the unclaimed ones. (Quarterly)
- Rotate shared and service credentials that cannot be replaced with managed identities, and record the rotation. (Quarterly)
- Run a tabletop exercise against a realistic scenario and record the decisions, the timings, and the gaps it exposed. (Annually)
- Verify that identity, email, endpoint, and remote access logs are being retained for the stated period and are searchable across that whole period. (Quarterly)
- Perform a restore test from backup into a usable state, record the elapsed time, and record what failed. (Quarterly)
- Verify the out-of-band contact list — staff, counsel, insurer, custodians, key vendors, law enforcement — by confirming the details rather than assuming them. (Quarterly)
- After any incident, including contained ones with no impact, complete a written review covering timeline, decisions, root cause, and changes made. (On incident)
- Refresh the standing operational due diligence pack — security overview, vendor list, BCP summary, test results, insurance details — so investor requests are answered from current material. (Annually)
- Review who retains access to each active and closed deal room or investor data room, and remove participants whose involvement has ended. (Quarterly)
- Confirm the technical boundary between adviser systems and portfolio company systems: no shared identity tenant, no shared credentials, no commingled deal and operating data. (Annually)
- At each closing or exit, provision or revoke access for deal participants, advisers, and counsel, and record the change against the transaction. (On change)
Frequently Asked Questions
Are these cadences regulatory deadlines?
Mostly no. A few are fixed by rule — the annual compliance review under Rule 206(4)-7, the annual identity theft program update, the annual supervisory control report. The rest are operating rhythms chosen to keep a control demonstrable between examinations. Each row links its primary source so the difference is checkable.
How should we adapt this to our firm?
Start by removing what does not apply. A firm with no covered accounts drops the Reg S-ID rows; a non-broker-dealer drops the FINRA rows. Then adjust the cadence where your risk profile justifies it, and record why. A documented decision to review something annually rather than quarterly is defensible; an undocumented gap is not.
What are the owner archetypes?
CCO is the chief compliance officer or the person administering the compliance program. IT is internal technology staff. MSP is an outsourced managed service or managed security provider. Many actions list more than one because the evidence is produced by one party and the conclusion is owned by another.
Companion rollup: monitor and review. Back to the Compliance Library hub.
- Author
- Rachel Lannon and Byron Foley
- Reviewed by
- Tim Quinn
- Last updated
This is operational technology guidance for regulated firms, not legal advice. Confirm how each requirement applies to your firm with your compliance counsel.