Specialization
Readiness for firms that hold client money and client data.
Registered investment advisers, wealth management firms and financial businesses carry security obligations their technology was never deliberately built to meet. We do the gap analysis, close the technical gaps, and get the documentation and evidence into a state that holds up - working alongside your CCO and counsel, not in place of them.
Scope of practice BetterOps provides readiness, remediation and evidence-preparation services. We are not a law firm, an auditor, or a compliance consultancy; we do not provide legal or regulatory advice, do not represent firms during examinations, and do not guarantee any regulatory outcome.
The policies are rarely what is actually missing
Most firms in this position already have a binder. What they often do not have is an environment that matches it: access broader than anyone realized, logging not retained long enough to reconstruct an incident, a tenant configured years ago by someone who has since left, and a vendor list nobody can produce on request.
That gap is engineering work, and it is the same work we do for businesses with no regulatory obligation at all - which is why we treat it as one practice rather than two. The controls that satisfy a rule are the controls that make a firm defensible.
It is also what makes it safe to automate. Identity, access, logging and data boundaries are the prerequisites for both, so firms here usually find the readiness project and the AI project are substantially the same project.
Which rules apply to you
Registration status and what customer information you hold decide which of these you are answerable to. Establishing that is the first conversation, because it drives everything downstream.
SEC
Regulation S-P
SEC-registered advisers, broker-dealers, investment companies, transfer agents
Implements the privacy provisions of Gramm-Leach-Bliley for SEC registrants: written policies to safeguard customer records, initial and annual privacy notices, and proper disposal of consumer report information.
- The 2024 amendments added a written incident response program requirement
- Customer notification as soon as practicable, and generally no later than 30 days, after determining sensitive customer information was or was likely accessed without authorization
- Formal oversight of service providers with access to customer information
- Both compliance dates have now passed - December 2025 for larger firms, June 2026 for smaller ones
SEC
Rule 206(4)-7
SEC-registered investment advisers
The compliance program rule. Written policies and procedures reasonably designed to prevent violations, reviewed at least annually, with a designated chief compliance officer.
- Technology, access and vendor controls fall inside the annual review
- The review has to be evidenced, not merely performed
- Policies are expected to describe how the firm actually operates
FTC
Safeguards Rule
Non-bank financial institutions, including many state-registered advisers
The FTC's implementation of Gramm-Leach-Bliley for financial institutions outside SEC and banking oversight. More prescriptive than Reg S-P about specific technical controls.
- A written information security program with a named Qualified Individual accountable for it
- Written risk assessment, access controls, encryption in transit and at rest, and MFA for anyone accessing information systems
- Service provider oversight, change management, logging and monitoring, and a written incident response plan
- Firms holding information on fewer than 5,000 consumers are exempt from several of these requirements - worth confirming before assuming the full burden applies
FINRA
Rule 4370 and cyber expectations
Broker-dealers and dual-registered firms
Business continuity and emergency preparedness obligations, alongside long-standing supervisory expectations around cybersecurity, vendor management and recordkeeping.
- A continuity plan that reflects the systems the firm runs today, not the ones it ran when the plan was written
- Evidence that the plan has been tested rather than filed
- Relevant where a firm is dual-registered - if you are advisory-only, this one does not apply to you
Summarized for orientation, not as legal guidance, and rules change. Confirm what applies to your firm with your compliance counsel - and we are glad to be in that conversation.
What readiness work covers
Scoped to the regime that actually applies to you, and sequenced so the dependencies come first.
01
Gap analysis
A review of your environment against the requirements that actually apply to you, with each gap written up as what is missing, what it takes to close, and what depends on it.
02
Written information security program
A safeguards policy set built around how your firm genuinely operates. Boilerplate that contradicts your real workflow is a finding waiting to happen, not a control.
03
Incident response program
A written program covering detection, escalation and recovery - plus the part firms most often lack: a documented procedure for deciding whether a notification obligation has been triggered, and by when.
04
Technical remediation
The engineering underneath it. Identity and access, MFA and conditional access, encryption, logging and retention, endpoint and email protection, backup and tested recovery, Microsoft 365 configuration.
05
Vendor and third-party oversight
An inventory of every provider that touches customer information, what each can reach, what diligence exists on them, and a review cadence that produces a record.
06
Evidence and records
Training records, access reviews, approvals, change history and vendor files organized so they can be produced on request rather than reconstructed under pressure.
AI governance
Using AI in a firm that holds client data
Advisers and financial firms are adopting AI for meeting notes, client correspondence, research summaries and back-office work. The question examiners and clients will ask is not whether you use it - it is what it can reach, what it retains, and who decided.
We answer that as part of the same engagement, because the controls involved are the ones readiness already requires.
Acceptable use policy
Which tools are approved, for what, and what may never be pasted into one.
Data boundaries
What client information an AI tool or workflow may access, retain, or send outside your tenant.
Supervision and records
Where AI touches client communication, what gets retained and how it is reviewed.
Vendor diligence
Treating AI providers as the third parties they are, with the same oversight as any other.
How a readiness engagement runs
-
Scoping conversation
Which regime actually applies - SEC, FTC, or both - what customer information you hold, and where it lives. Registration status and data footprint decide most of the cost from here.
-
Gap analysis
A structured review of the environment against the applicable requirements, producing a written gap register with effort and dependencies against each item.
-
Remediation
We close the technical gaps and build the documentation, working in the order dependencies dictate rather than in requirement order. Your CCO stays in the loop throughout.
-
Readiness and upkeep
Evidence organized, incident response tested through a tabletop, documentation current, and a cadence to keep it that way as the environment keeps changing.
Start with a scoping conversation.
Thirty minutes on your registration status, what client information you hold, and which rules actually apply - the question that decides most of the cost.
Questions about readiness
Are you a compliance consultant or a law firm?
Will you represent us during an SEC examination?
We are state-registered, not SEC-registered. Does any of this apply?
What changed with Reg S-P, and are we late?
We already have policies from a template vendor. Is that enough?
How does this relate to the AI and automation work you do?
Do we need to do the AI Workflow Assessment first?
Talk to us about readiness.
We will be straightforward about what applies to you, what it will take, and where you need counsel rather than us.