Scheduled Actions: Every Recurring Compliance Technology Task in the Library

In plain language

This is every recurring task the library implies, in one table, with how often it happens and who normally does it. If you are building a compliance calendar, start here rather than reading nine sections. Each row has a stable identifier so it can be tracked in a ticket queue or handed to a provider without ambiguity.

The nine sections of the Compliance Library each end with the recurring work that section implies. This page is the union of all of them, aggregated automatically, so nothing here can drift from its source section.

Three views of the same set follow: every action grouped by section, the same actions grouped by cadence for calendar building, and grouped by owner archetype for assigning work.

Cadence is an operating rhythm, not a regulatory deadline, unless the linked source says otherwise. Where a rule fixes the interval — the annual compliance review, the annual identity theft program update, the annual supervisory control report — the source link goes to the rule text. Where it does not, the cadence reflects what keeps the control demonstrable between examinations.

Owner archetypes are starting points. CCO is the compliance program’s administrator, IT is internal technology staff, and MSP is an outsourced provider. An action listing two owners usually means one produces the evidence and the other owns the conclusion. Firms assign differently and that is fine, as long as each action has exactly one accountable owner at your firm.

Use the action-id values as the vocabulary in tickets, statements of work, and calendars. They are stable: a section can be rewritten without the identifier changing.

Every scheduled action in the library

58 actions aggregated from 9 library sections. Cadences are the operating rhythm the underlying rules imply; they are not regulatory deadlines unless the source says so.

ActionCadenceOwner archetypeSourceaction-id
Regulation S-P: Safeguards, Incident Response, and the Notification Clocks
Re-verify the inventory of systems and vendors that store, process, or can reach customer information, including anything added by a new tool, integration, or acquisition.QuarterlyCCO, MSP17 CFR 248.30act.reg-s-p.customer-info-inventory-review
Review and re-approve the written incident response program, including the assessment, containment, and notification procedures, and record who approved it.AnnuallyCCOSEC Release 34-100155act.reg-s-p.ir-program-review
Run a tabletop that exercises the customer notification decision specifically: who determines scope, who drafts the notice, who approves it, and how the 30-day clock is documented.AnnuallyCCO, MSPSEC Release 34-100155act.reg-s-p.notification-tabletop
Confirm every service provider with access to customer information is under an agreement carrying the 72-hour breach notification obligation, and log the exceptions that are still open.AnnuallyCCO, ITSEC Release 34-100155act.reg-s-p.service-provider-clause-audit
Verify that decommissioned media, retired endpoints, and expired records containing consumer report information were disposed of under the Disposal Rule, and keep the certificates.QuarterlyIT, MSP17 CFR 248.30(b)act.reg-s-p.disposal-verification
Before a new system goes live, determine whether it will hold customer information and, if it will, add it to the inventory and bring it under the safeguards and notification program.On changeIT, MSP17 CFR 248.30act.reg-s-p.new-system-scope-check
Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program
Complete the annual review of the compliance program's technology components and record what was tested, what was found, and what was changed.AnnuallyCCO17 CFR 275.206(4)-7act.advisers-act.annual-compliance-review
Refresh the technology risk assessment that the policies are designed against, so the program reflects the systems the firm uses now rather than the ones it used at adoption.AnnuallyCCO, MSPSEC IM Guidance 2015-02act.advisers-act.risk-assessment-refresh
Record every material change to a technology policy or procedure with its date, reason, and approver, so the program's version history is reconstructable.On changeCCO17 CFR 275.204-2(a)(17)act.advisers-act.policy-change-log
Deliver security awareness training covering phishing, wire-transfer verification, and reporting, and retain the completion records by person.AnnuallyCCO, MSPSEC IM Guidance 2015-02act.advisers-act.security-awareness-training
Read the Division of Examinations priorities when published and note which technology items apply to the firm, and which of those the program does not yet address.AnnuallyCCOSEC Division of Examinationsact.advisers-act.exam-priorities-read
Confirm the CCO receives technology incident and exception reporting on a defined interval, rather than on request, and that the last interval's report exists.QuarterlyCCO, MSP17 CFR 275.206(4)-7act.advisers-act.cco-escalation-review
Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2
Review the retention schedule against the record categories the firm actually generates, and confirm each category maps to a system with the correct retention period.AnnuallyCCO, IT17 CFR 275.204-2act.books-records.retention-schedule-review
Run a production test: pick a person and a date range, retrieve the responsive communications, and time it. Record the result including anything that could not be retrieved.QuarterlyCCO, MSP17 CFR 240.17a-4(j)act.books-records.production-test
Re-inventory the communication channels in use — email, chat, SMS, collaboration tools, social — and confirm each is either captured or prohibited, with the prohibition enforced somewhere other than a policy document.QuarterlyCCO, IT, MSPFINRA Rule 4511act.books-records.channel-inventory
Reconcile the archive against the mail and messaging systems for a sample period to confirm nothing is being dropped in transit.QuarterlyIT, MSP17 CFR 240.17a-4(f)act.books-records.archive-completeness-check
When someone joins or leaves, confirm their communications are brought into or preserved within the archive, including mobile devices used for business.On changeIT, MSP17 CFR 275.204-2act.books-records.onboarding-offboarding-capture
Confirm a legal hold can be applied and will actually suspend deletion, by testing it on a sample account rather than by reading the vendor's documentation.AnnuallyCCO, IT17 CFR 240.17a-4act.books-records.legal-hold-drill
FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls
Review the written supervisory procedures for technology accuracy: named systems, named reviewers, sampling basis, and evidencing method.AnnuallyCCO, ITFINRA Rule 3110act.finra-supervision.wsp-technology-review
Perform the electronic correspondence review on the stated sampling basis and evidence it, including what the reviewer looked at and what was escalated.MonthlyCCOFINRA Rule 3110(b)(4)act.finra-supervision.correspondence-review
Test and verify that the supervisory procedures are reasonably designed, and produce the annual report to senior management.AnnuallyCCOFINRA Rule 3120act.finra-supervision.supervisory-control-test
Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed.AnnuallyCCO, IT, MSPFINRA Rule 4370act.finra-supervision.bcp-review-and-test
Inspect offices on the firm's stated cycle, covering the technology conditions at each location: device compliance, network, physical document handling, and use of approved channels.AnnuallyCCO, ITFINRA Rule 3110(c)act.finra-supervision.branch-and-remote-inspection
Review current FINRA cybersecurity guidance and examination findings, and note which items the firm does not yet address.AnnuallyCCO, MSPFINRA cybersecurity topic pageact.finra-supervision.cyber-guidance-review
Regulation S-ID: Identity Theft Red Flags, at a High Level
Re-assess whether the firm offers or maintains covered accounts, and record the determination with the reasoning, including for new products or account types.AnnuallyCCO17 CFR 248.201act.reg-s-id.covered-account-determination
Update the identity theft prevention program to reflect changes in identity theft risk, the firm's methods of detection and response, service provider arrangements, and account types offered.AnnuallyCCO17 CFR 248.201(d)(2)act.reg-s-id.program-update
Review the firm's selected red flags against actual incidents and attempted fraud from the period, and add or retire flags accordingly.AnnuallyCCO, MSP17 CFR 248.201, Appendix Aact.reg-s-id.red-flag-list-review
Train staff who handle covered accounts on the red flags relevant to their role and on the escalation path, and retain completion records.AnnuallyCCO17 CFR 248.201(e)act.reg-s-id.staff-training
Report to the board, a board committee, or designated senior management on the effectiveness of the program, significant incidents, and recommended changes.AnnuallyCCO17 CFR 248.201(e)act.reg-s-id.board-report
Review the alerting rules that implement technical red flags — address changes, contact detail changes, anomalous logins, unusual disbursement patterns — for false negatives and alert fatigue.QuarterlyIT, MSPSEC Release 34-69359act.reg-s-id.detection-rule-tuning
Vendor and Service-Provider Oversight for Regulated Financial Firms
Reconcile the vendor register against accounts payable, the identity provider's connected-application list, and SaaS discovery data to find providers that entered without procurement.QuarterlyCCO, IT, MSP17 CFR 248.30act.vendor-oversight.register-reconciliation
Perform the periodic review for each vendor at the depth its tier requires, and record the date, the reviewer, and what was examined.AnnuallyCCO17 CFR 275.206(4)-7act.vendor-oversight.tiered-review
Obtain and actually read the current SOC 2, SOC 1, or equivalent attestation for tier-one vendors, recording the report period, scope, exceptions, and complementary user entity controls.AnnuallyCCO, IT17 CFR 248.30act.vendor-oversight.attestation-refresh
Confirm each in-scope vendor's agreement carries the breach notification obligation with the 72-hour timing, and track the ones that do not to an owner and a renewal date.AnnuallyCCOSEC Release 34-100155act.vendor-oversight.notification-clause-check
Before a new vendor receives access, determine its tier, complete the diligence that tier requires, and record the data it will hold and the access it will have.On changeCCO, IT17 CFR 248.30act.vendor-oversight.onboarding-diligence
On termination, revoke the vendor's access, confirm return or destruction of firm data, and record the confirmation.On changeIT, MSP17 CFR 248.30(b)act.vendor-oversight.offboarding-verification
Review concentration and substitutability: which single vendor failures would stop the firm operating, and what the interim plan is for each.AnnuallyCCO, ITFINRA Rule 4370act.vendor-oversight.concentration-review
Access Control and MFA for RIAs, Broker-Dealers, and Funds
Review every account holding administrative or elevated privilege, confirm each is still required, and remove the ones that are not.QuarterlyIT, MSP17 CFR 248.30act.access-mfa.privileged-access-review
Review standard user access to systems holding customer information, confirm entitlements match current role, and record the removals.AnnuallyCCO, IT17 CFR 248.30act.access-mfa.user-access-review
Produce an MFA coverage report across all identities — staff, vendors, service accounts, shared mailboxes — and reconcile the unenrolled list against the approved exception register.QuarterlyIT, MSPSEC IM Guidance 2015-02act.access-mfa.mfa-coverage-report
Review each MFA and access-control exception against its expiry date, and either close it or re-approve it with a new date and a reason.QuarterlyCCO, IT17 CFR 275.206(4)-7act.access-mfa.exception-expiry-review
Provision, change, or revoke access within the firm's stated window of a joiner, role change, or departure, and record the completion against the person.On changeIT, MSP17 CFR 248.30act.access-mfa.joiner-mover-leaver
Re-inventory non-human identities — service accounts, API keys, integration credentials, shared mailboxes — with an owner and a justification for each, and retire the unclaimed ones.QuarterlyIT, MSP17 CFR 248.30act.access-mfa.service-account-inventory
Rotate shared and service credentials that cannot be replaced with managed identities, and record the rotation.QuarterlyIT, MSPSEC IM Guidance 2015-02act.access-mfa.credential-rotation
Incident Response and Exam Evidence for Financial Firms
Review and re-approve the written incident response program, confirming that named roles, contacts, and escalation paths reflect current staff and current vendors.AnnuallyCCOSEC Release 34-100155act.incident-response.program-review
Run a tabletop exercise against a realistic scenario and record the decisions, the timings, and the gaps it exposed.AnnuallyCCO, IT, MSPSEC Release 34-100155act.incident-response.tabletop
Verify that identity, email, endpoint, and remote access logs are being retained for the stated period and are searchable across that whole period.QuarterlyIT, MSP17 CFR 248.30act.incident-response.log-retention-verification
Perform a restore test from backup into a usable state, record the elapsed time, and record what failed.QuarterlyIT, MSPFINRA Rule 4370act.incident-response.restore-test
Verify the out-of-band contact list — staff, counsel, insurer, custodians, key vendors, law enforcement — by confirming the details rather than assuming them.QuarterlyCCO, MSPFINRA Rule 4370act.incident-response.contact-list-verification
Refresh the standing exam evidence file so the current version of each core artifact is present and dated, rather than assembled on request.QuarterlyCCOSEC Division of Examinationsact.incident-response.exam-file-refresh
After any incident, including contained ones with no impact, complete a written review covering timeline, decisions, root cause, and changes made.On incidentCCO, IT, MSPSEC Release 34-100155act.incident-response.post-incident-review
Private Fund and PE Adviser Technology Notes
Refresh the standing operational due diligence pack — security overview, vendor list, BCP summary, test results, insurance details — so investor requests are answered from current material.AnnuallyCCO, MSP17 CFR 275.206(4)-7act.private-funds.ddq-artifact-refresh
Review who retains access to each active and closed deal room or investor data room, and remove participants whose involvement has ended.QuarterlyIT, MSP17 CFR 248.30act.private-funds.data-room-access-review
Review the technical controls supporting the firm's information barriers and restricted list — who can reach deal folders, whether access is logged, whether the barrier is enforced or merely stated.AnnuallyCCO, IT17 CFR 275.206(4)-7act.private-funds.mnpi-control-review
Confirm fund-level records — investor communications, valuation support, performance calculation backup, capital account records — are captured in a system with the correct retention, not only on a shared drive.AnnuallyCCO, IT17 CFR 275.204-2act.private-funds.fund-records-retention-check
Review the fund administrator, custodian, and auditor as tier-one service providers, including their attestations and the complementary controls they assume the adviser operates.AnnuallyCCO17 CFR 275.206(4)-2act.private-funds.administrator-and-custodian-review
Confirm the technical boundary between adviser systems and portfolio company systems: no shared identity tenant, no shared credentials, no commingled deal and operating data.AnnuallyIT, MSP17 CFR 248.30act.private-funds.portfolio-boundary-check
At each closing or exit, provision or revoke access for deal participants, advisers, and counsel, and record the change against the transaction.On changeIT, MSP17 CFR 248.30act.private-funds.transaction-onboarding-offboarding

Grouped by cadence

The same actions, arranged the way a compliance calendar is built.

Monthly (1)

Quarterly (18)

Annually (31)

On change (7)

On incident (1)

Grouped by owner archetype

Who normally carries the action. A firm may assign it differently; the archetype is a starting point, not an org chart. Actions owned jointly appear under each owner.

CCO (42)

  • Re-verify the inventory of systems and vendors that store, process, or can reach customer information, including anything added by a new tool, integration, or acquisition. (Quarterly)
  • Review and re-approve the written incident response program, including the assessment, containment, and notification procedures, and record who approved it. (Annually)
  • Run a tabletop that exercises the customer notification decision specifically: who determines scope, who drafts the notice, who approves it, and how the 30-day clock is documented. (Annually)
  • Confirm every service provider with access to customer information is under an agreement carrying the 72-hour breach notification obligation, and log the exceptions that are still open. (Annually)
  • Complete the annual review of the compliance program's technology components and record what was tested, what was found, and what was changed. (Annually)
  • Refresh the technology risk assessment that the policies are designed against, so the program reflects the systems the firm uses now rather than the ones it used at adoption. (Annually)
  • Record every material change to a technology policy or procedure with its date, reason, and approver, so the program's version history is reconstructable. (On change)
  • Deliver security awareness training covering phishing, wire-transfer verification, and reporting, and retain the completion records by person. (Annually)
  • Read the Division of Examinations priorities when published and note which technology items apply to the firm, and which of those the program does not yet address. (Annually)
  • Confirm the CCO receives technology incident and exception reporting on a defined interval, rather than on request, and that the last interval's report exists. (Quarterly)
  • Review the retention schedule against the record categories the firm actually generates, and confirm each category maps to a system with the correct retention period. (Annually)
  • Run a production test: pick a person and a date range, retrieve the responsive communications, and time it. Record the result including anything that could not be retrieved. (Quarterly)
  • Re-inventory the communication channels in use — email, chat, SMS, collaboration tools, social — and confirm each is either captured or prohibited, with the prohibition enforced somewhere other than a policy document. (Quarterly)
  • Confirm a legal hold can be applied and will actually suspend deletion, by testing it on a sample account rather than by reading the vendor's documentation. (Annually)
  • Review the written supervisory procedures for technology accuracy: named systems, named reviewers, sampling basis, and evidencing method. (Annually)
  • Perform the electronic correspondence review on the stated sampling basis and evidence it, including what the reviewer looked at and what was escalated. (Monthly)
  • Test and verify that the supervisory procedures are reasonably designed, and produce the annual report to senior management. (Annually)
  • Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed. (Annually)
  • Inspect offices on the firm's stated cycle, covering the technology conditions at each location: device compliance, network, physical document handling, and use of approved channels. (Annually)
  • Review current FINRA cybersecurity guidance and examination findings, and note which items the firm does not yet address. (Annually)
  • Re-assess whether the firm offers or maintains covered accounts, and record the determination with the reasoning, including for new products or account types. (Annually)
  • Update the identity theft prevention program to reflect changes in identity theft risk, the firm's methods of detection and response, service provider arrangements, and account types offered. (Annually)
  • Review the firm's selected red flags against actual incidents and attempted fraud from the period, and add or retire flags accordingly. (Annually)
  • Train staff who handle covered accounts on the red flags relevant to their role and on the escalation path, and retain completion records. (Annually)
  • Report to the board, a board committee, or designated senior management on the effectiveness of the program, significant incidents, and recommended changes. (Annually)
  • Reconcile the vendor register against accounts payable, the identity provider's connected-application list, and SaaS discovery data to find providers that entered without procurement. (Quarterly)
  • Perform the periodic review for each vendor at the depth its tier requires, and record the date, the reviewer, and what was examined. (Annually)
  • Obtain and actually read the current SOC 2, SOC 1, or equivalent attestation for tier-one vendors, recording the report period, scope, exceptions, and complementary user entity controls. (Annually)
  • Confirm each in-scope vendor's agreement carries the breach notification obligation with the 72-hour timing, and track the ones that do not to an owner and a renewal date. (Annually)
  • Before a new vendor receives access, determine its tier, complete the diligence that tier requires, and record the data it will hold and the access it will have. (On change)
  • Review concentration and substitutability: which single vendor failures would stop the firm operating, and what the interim plan is for each. (Annually)
  • Review standard user access to systems holding customer information, confirm entitlements match current role, and record the removals. (Annually)
  • Review each MFA and access-control exception against its expiry date, and either close it or re-approve it with a new date and a reason. (Quarterly)
  • Review and re-approve the written incident response program, confirming that named roles, contacts, and escalation paths reflect current staff and current vendors. (Annually)
  • Run a tabletop exercise against a realistic scenario and record the decisions, the timings, and the gaps it exposed. (Annually)
  • Verify the out-of-band contact list — staff, counsel, insurer, custodians, key vendors, law enforcement — by confirming the details rather than assuming them. (Quarterly)
  • Refresh the standing exam evidence file so the current version of each core artifact is present and dated, rather than assembled on request. (Quarterly)
  • After any incident, including contained ones with no impact, complete a written review covering timeline, decisions, root cause, and changes made. (On incident)
  • Refresh the standing operational due diligence pack — security overview, vendor list, BCP summary, test results, insurance details — so investor requests are answered from current material. (Annually)
  • Review the technical controls supporting the firm's information barriers and restricted list — who can reach deal folders, whether access is logged, whether the barrier is enforced or merely stated. (Annually)
  • Confirm fund-level records — investor communications, valuation support, performance calculation backup, capital account records — are captured in a system with the correct retention, not only on a shared drive. (Annually)
  • Review the fund administrator, custodian, and auditor as tier-one service providers, including their attestations and the complementary controls they assume the adviser operates. (Annually)

IT (33)

  • Confirm every service provider with access to customer information is under an agreement carrying the 72-hour breach notification obligation, and log the exceptions that are still open. (Annually)
  • Verify that decommissioned media, retired endpoints, and expired records containing consumer report information were disposed of under the Disposal Rule, and keep the certificates. (Quarterly)
  • Before a new system goes live, determine whether it will hold customer information and, if it will, add it to the inventory and bring it under the safeguards and notification program. (On change)
  • Review the retention schedule against the record categories the firm actually generates, and confirm each category maps to a system with the correct retention period. (Annually)
  • Re-inventory the communication channels in use — email, chat, SMS, collaboration tools, social — and confirm each is either captured or prohibited, with the prohibition enforced somewhere other than a policy document. (Quarterly)
  • Reconcile the archive against the mail and messaging systems for a sample period to confirm nothing is being dropped in transit. (Quarterly)
  • When someone joins or leaves, confirm their communications are brought into or preserved within the archive, including mobile devices used for business. (On change)
  • Confirm a legal hold can be applied and will actually suspend deletion, by testing it on a sample account rather than by reading the vendor's documentation. (Annually)
  • Review the written supervisory procedures for technology accuracy: named systems, named reviewers, sampling basis, and evidencing method. (Annually)
  • Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed. (Annually)
  • Inspect offices on the firm's stated cycle, covering the technology conditions at each location: device compliance, network, physical document handling, and use of approved channels. (Annually)
  • Review the alerting rules that implement technical red flags — address changes, contact detail changes, anomalous logins, unusual disbursement patterns — for false negatives and alert fatigue. (Quarterly)
  • Reconcile the vendor register against accounts payable, the identity provider's connected-application list, and SaaS discovery data to find providers that entered without procurement. (Quarterly)
  • Obtain and actually read the current SOC 2, SOC 1, or equivalent attestation for tier-one vendors, recording the report period, scope, exceptions, and complementary user entity controls. (Annually)
  • Before a new vendor receives access, determine its tier, complete the diligence that tier requires, and record the data it will hold and the access it will have. (On change)
  • On termination, revoke the vendor's access, confirm return or destruction of firm data, and record the confirmation. (On change)
  • Review concentration and substitutability: which single vendor failures would stop the firm operating, and what the interim plan is for each. (Annually)
  • Review every account holding administrative or elevated privilege, confirm each is still required, and remove the ones that are not. (Quarterly)
  • Review standard user access to systems holding customer information, confirm entitlements match current role, and record the removals. (Annually)
  • Produce an MFA coverage report across all identities — staff, vendors, service accounts, shared mailboxes — and reconcile the unenrolled list against the approved exception register. (Quarterly)
  • Review each MFA and access-control exception against its expiry date, and either close it or re-approve it with a new date and a reason. (Quarterly)
  • Provision, change, or revoke access within the firm's stated window of a joiner, role change, or departure, and record the completion against the person. (On change)
  • Re-inventory non-human identities — service accounts, API keys, integration credentials, shared mailboxes — with an owner and a justification for each, and retire the unclaimed ones. (Quarterly)
  • Rotate shared and service credentials that cannot be replaced with managed identities, and record the rotation. (Quarterly)
  • Run a tabletop exercise against a realistic scenario and record the decisions, the timings, and the gaps it exposed. (Annually)
  • Verify that identity, email, endpoint, and remote access logs are being retained for the stated period and are searchable across that whole period. (Quarterly)
  • Perform a restore test from backup into a usable state, record the elapsed time, and record what failed. (Quarterly)
  • After any incident, including contained ones with no impact, complete a written review covering timeline, decisions, root cause, and changes made. (On incident)
  • Review who retains access to each active and closed deal room or investor data room, and remove participants whose involvement has ended. (Quarterly)
  • Review the technical controls supporting the firm's information barriers and restricted list — who can reach deal folders, whether access is logged, whether the barrier is enforced or merely stated. (Annually)
  • Confirm fund-level records — investor communications, valuation support, performance calculation backup, capital account records — are captured in a system with the correct retention, not only on a shared drive. (Annually)
  • Confirm the technical boundary between adviser systems and portfolio company systems: no shared identity tenant, no shared credentials, no commingled deal and operating data. (Annually)
  • At each closing or exit, provision or revoke access for deal participants, advisers, and counsel, and record the change against the transaction. (On change)

MSP (31)

  • Re-verify the inventory of systems and vendors that store, process, or can reach customer information, including anything added by a new tool, integration, or acquisition. (Quarterly)
  • Run a tabletop that exercises the customer notification decision specifically: who determines scope, who drafts the notice, who approves it, and how the 30-day clock is documented. (Annually)
  • Verify that decommissioned media, retired endpoints, and expired records containing consumer report information were disposed of under the Disposal Rule, and keep the certificates. (Quarterly)
  • Before a new system goes live, determine whether it will hold customer information and, if it will, add it to the inventory and bring it under the safeguards and notification program. (On change)
  • Refresh the technology risk assessment that the policies are designed against, so the program reflects the systems the firm uses now rather than the ones it used at adoption. (Annually)
  • Deliver security awareness training covering phishing, wire-transfer verification, and reporting, and retain the completion records by person. (Annually)
  • Confirm the CCO receives technology incident and exception reporting on a defined interval, rather than on request, and that the last interval's report exists. (Quarterly)
  • Run a production test: pick a person and a date range, retrieve the responsive communications, and time it. Record the result including anything that could not be retrieved. (Quarterly)
  • Re-inventory the communication channels in use — email, chat, SMS, collaboration tools, social — and confirm each is either captured or prohibited, with the prohibition enforced somewhere other than a policy document. (Quarterly)
  • Reconcile the archive against the mail and messaging systems for a sample period to confirm nothing is being dropped in transit. (Quarterly)
  • When someone joins or leaves, confirm their communications are brought into or preserved within the archive, including mobile devices used for business. (On change)
  • Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed. (Annually)
  • Review current FINRA cybersecurity guidance and examination findings, and note which items the firm does not yet address. (Annually)
  • Review the firm's selected red flags against actual incidents and attempted fraud from the period, and add or retire flags accordingly. (Annually)
  • Review the alerting rules that implement technical red flags — address changes, contact detail changes, anomalous logins, unusual disbursement patterns — for false negatives and alert fatigue. (Quarterly)
  • Reconcile the vendor register against accounts payable, the identity provider's connected-application list, and SaaS discovery data to find providers that entered without procurement. (Quarterly)
  • On termination, revoke the vendor's access, confirm return or destruction of firm data, and record the confirmation. (On change)
  • Review every account holding administrative or elevated privilege, confirm each is still required, and remove the ones that are not. (Quarterly)
  • Produce an MFA coverage report across all identities — staff, vendors, service accounts, shared mailboxes — and reconcile the unenrolled list against the approved exception register. (Quarterly)
  • Provision, change, or revoke access within the firm's stated window of a joiner, role change, or departure, and record the completion against the person. (On change)
  • Re-inventory non-human identities — service accounts, API keys, integration credentials, shared mailboxes — with an owner and a justification for each, and retire the unclaimed ones. (Quarterly)
  • Rotate shared and service credentials that cannot be replaced with managed identities, and record the rotation. (Quarterly)
  • Run a tabletop exercise against a realistic scenario and record the decisions, the timings, and the gaps it exposed. (Annually)
  • Verify that identity, email, endpoint, and remote access logs are being retained for the stated period and are searchable across that whole period. (Quarterly)
  • Perform a restore test from backup into a usable state, record the elapsed time, and record what failed. (Quarterly)
  • Verify the out-of-band contact list — staff, counsel, insurer, custodians, key vendors, law enforcement — by confirming the details rather than assuming them. (Quarterly)
  • After any incident, including contained ones with no impact, complete a written review covering timeline, decisions, root cause, and changes made. (On incident)
  • Refresh the standing operational due diligence pack — security overview, vendor list, BCP summary, test results, insurance details — so investor requests are answered from current material. (Annually)
  • Review who retains access to each active and closed deal room or investor data room, and remove participants whose involvement has ended. (Quarterly)
  • Confirm the technical boundary between adviser systems and portfolio company systems: no shared identity tenant, no shared credentials, no commingled deal and operating data. (Annually)
  • At each closing or exit, provision or revoke access for deal participants, advisers, and counsel, and record the change against the transaction. (On change)

Frequently Asked Questions

Are these cadences regulatory deadlines?

Mostly no. A few are fixed by rule — the annual compliance review under Rule 206(4)-7, the annual identity theft program update, the annual supervisory control report. The rest are operating rhythms chosen to keep a control demonstrable between examinations. Each row links its primary source so the difference is checkable.

How should we adapt this to our firm?

Start by removing what does not apply. A firm with no covered accounts drops the Reg S-ID rows; a non-broker-dealer drops the FINRA rows. Then adjust the cadence where your risk profile justifies it, and record why. A documented decision to review something annually rather than quarterly is defensible; an undocumented gap is not.

What are the owner archetypes?

CCO is the chief compliance officer or the person administering the compliance program. IT is internal technology staff. MSP is an outsourced managed service or managed security provider. Many actions list more than one because the evidence is produced by one party and the conclusion is owned by another.

Companion rollup: monitor and review. Back to the Compliance Library hub.

Author
Rachel Lannon and Byron Foley
Reviewed by
Tim Quinn
Last updated

This is operational technology guidance for regulated firms, not legal advice. Confirm how each requirement applies to your firm with your compliance counsel.