Skip to content
BetterOps logo

Specialization

Readiness for firms that hold client money and client data.

Registered investment advisers, wealth management firms and financial businesses carry security obligations their technology was never deliberately built to meet. We do the gap analysis, close the technical gaps, and get the documentation and evidence into a state that holds up - working alongside your CCO and counsel, not in place of them.

Scope of practice BetterOps provides readiness, remediation and evidence-preparation services. We are not a law firm, an auditor, or a compliance consultancy; we do not provide legal or regulatory advice, do not represent firms during examinations, and do not guarantee any regulatory outcome.

The policies are rarely what is actually missing

Most firms in this position already have a binder. What they often do not have is an environment that matches it: access broader than anyone realized, logging not retained long enough to reconstruct an incident, a tenant configured years ago by someone who has since left, and a vendor list nobody can produce on request.

That gap is engineering work, and it is the same work we do for businesses with no regulatory obligation at all - which is why we treat it as one practice rather than two. The controls that satisfy a rule are the controls that make a firm defensible.

It is also what makes it safe to automate. Identity, access, logging and data boundaries are the prerequisites for both, so firms here usually find the readiness project and the AI project are substantially the same project.

Which rules apply to you

Registration status and what customer information you hold decide which of these you are answerable to. Establishing that is the first conversation, because it drives everything downstream.

SEC

Regulation S-P

SEC-registered advisers, broker-dealers, investment companies, transfer agents

Implements the privacy provisions of Gramm-Leach-Bliley for SEC registrants: written policies to safeguard customer records, initial and annual privacy notices, and proper disposal of consumer report information.

  • The 2024 amendments added a written incident response program requirement
  • Customer notification as soon as practicable, and generally no later than 30 days, after determining sensitive customer information was or was likely accessed without authorization
  • Formal oversight of service providers with access to customer information
  • Both compliance dates have now passed - December 2025 for larger firms, June 2026 for smaller ones

SEC

Rule 206(4)-7

SEC-registered investment advisers

The compliance program rule. Written policies and procedures reasonably designed to prevent violations, reviewed at least annually, with a designated chief compliance officer.

  • Technology, access and vendor controls fall inside the annual review
  • The review has to be evidenced, not merely performed
  • Policies are expected to describe how the firm actually operates

FTC

Safeguards Rule

Non-bank financial institutions, including many state-registered advisers

The FTC's implementation of Gramm-Leach-Bliley for financial institutions outside SEC and banking oversight. More prescriptive than Reg S-P about specific technical controls.

  • A written information security program with a named Qualified Individual accountable for it
  • Written risk assessment, access controls, encryption in transit and at rest, and MFA for anyone accessing information systems
  • Service provider oversight, change management, logging and monitoring, and a written incident response plan
  • Firms holding information on fewer than 5,000 consumers are exempt from several of these requirements - worth confirming before assuming the full burden applies

FINRA

Rule 4370 and cyber expectations

Broker-dealers and dual-registered firms

Business continuity and emergency preparedness obligations, alongside long-standing supervisory expectations around cybersecurity, vendor management and recordkeeping.

  • A continuity plan that reflects the systems the firm runs today, not the ones it ran when the plan was written
  • Evidence that the plan has been tested rather than filed
  • Relevant where a firm is dual-registered - if you are advisory-only, this one does not apply to you

Summarized for orientation, not as legal guidance, and rules change. Confirm what applies to your firm with your compliance counsel - and we are glad to be in that conversation.

What readiness work covers

Scoped to the regime that actually applies to you, and sequenced so the dependencies come first.

01

Gap analysis

A review of your environment against the requirements that actually apply to you, with each gap written up as what is missing, what it takes to close, and what depends on it.

02

Written information security program

A safeguards policy set built around how your firm genuinely operates. Boilerplate that contradicts your real workflow is a finding waiting to happen, not a control.

03

Incident response program

A written program covering detection, escalation and recovery - plus the part firms most often lack: a documented procedure for deciding whether a notification obligation has been triggered, and by when.

04

Technical remediation

The engineering underneath it. Identity and access, MFA and conditional access, encryption, logging and retention, endpoint and email protection, backup and tested recovery, Microsoft 365 configuration.

05

Vendor and third-party oversight

An inventory of every provider that touches customer information, what each can reach, what diligence exists on them, and a review cadence that produces a record.

06

Evidence and records

Training records, access reviews, approvals, change history and vendor files organized so they can be produced on request rather than reconstructed under pressure.

AI governance

Using AI in a firm that holds client data

Advisers and financial firms are adopting AI for meeting notes, client correspondence, research summaries and back-office work. The question examiners and clients will ask is not whether you use it - it is what it can reach, what it retains, and who decided.

We answer that as part of the same engagement, because the controls involved are the ones readiness already requires.

Acceptable use policy

Which tools are approved, for what, and what may never be pasted into one.

Data boundaries

What client information an AI tool or workflow may access, retain, or send outside your tenant.

Supervision and records

Where AI touches client communication, what gets retained and how it is reviewed.

Vendor diligence

Treating AI providers as the third parties they are, with the same oversight as any other.

How a readiness engagement runs

  1. Scoping conversation

    Which regime actually applies - SEC, FTC, or both - what customer information you hold, and where it lives. Registration status and data footprint decide most of the cost from here.

  2. Gap analysis

    A structured review of the environment against the applicable requirements, producing a written gap register with effort and dependencies against each item.

  3. Remediation

    We close the technical gaps and build the documentation, working in the order dependencies dictate rather than in requirement order. Your CCO stays in the loop throughout.

  4. Readiness and upkeep

    Evidence organized, incident response tested through a tabletop, documentation current, and a cadence to keep it that way as the environment keeps changing.

Start with a scoping conversation.

Thirty minutes on your registration status, what client information you hold, and which rules actually apply - the question that decides most of the cost.

Questions about readiness

Are you a compliance consultant or a law firm?
Neither. BetterOps is a technology and operations firm. We do the engineering, documentation and evidence work that readiness requires, and we work alongside your chief compliance officer, compliance consultant or counsel where a question is genuinely legal or regulatory. We do not provide legal or regulatory advice, we are not auditors, and we do not guarantee any regulatory outcome.
Will you represent us during an SEC examination?
No - that is your CCO's and your counsel's role, and it should be. What we can do is make sure the technical and documentary answers exist before the request list arrives, and be available to your team for questions about the environment while an examination is underway.
We are state-registered, not SEC-registered. Does any of this apply?
Usually yes, just under a different regime. Reg S-P applies to SEC registrants; state-registered advisers frequently fall under the FTC Safeguards Rule instead, alongside state data-protection law and your state regulator's own expectations. The practical work is broadly similar. Establishing which set applies to you is the first thing we do, because assuming the harder regime applies is a common and expensive mistake - as is assuming the easier one does.
What changed with Reg S-P, and are we late?
The SEC adopted amendments in May 2024 that added a written incident response program requirement, a customer notification obligation - as soon as practicable and generally within 30 days of determining sensitive customer information was or was likely accessed without authorization - and formal service provider oversight. Both compliance dates have passed: December 2025 for larger firms and June 2026 for smaller ones. If your incident response program has not been revisited since, that is worth addressing now rather than discovering during an examination or, worse, during an actual incident.
We already have policies from a template vendor. Is that enough?
Often not. Generic templates tend to describe a firm that does not exist - referencing systems you do not run and procedures nobody follows. A policy that contradicts your actual practice is worse than no policy, because it documents the gap. We rewrite to your real workflows.
How does this relate to the AI and automation work you do?
Closely, and it is the reason we treat them as one practice. Access control, encryption, logging, vendor oversight and documented ownership are exactly what a regulator expects - and exactly what has to be true before you let an automation read your mailbox or write to your CRM on behalf of a firm holding customer financial data. Firms in this position usually find the readiness project and the AI project are substantially the same project, which is a meaningful saving over running them as two.
Do we need to do the AI Workflow Assessment first?
Not necessarily. If a regulatory deadline or an examination is driving the timeline, we can start with a scoping conversation and go straight into gap analysis. The assessment is the better starting point where the driver is operational rather than regulatory, because it looks at the whole picture - including where the firm is losing time, not only where it is exposed.

Talk to us about readiness.

We will be straightforward about what applies to you, what it will take, and where you need counsel rather than us.