Does Regulation S-P name who must sign off?
No. 17 CFR 248.30(a)(1) through (a)(3) require a written safeguards policy and a written incident response program, but nothing in the rule's own text designates an owner, an approver, or a signatory for either. That silence was not an oversight. During the 2024 rulemaking, a commenter opposed adding any requirement that an adviser designate an employee with specific qualifications and experience, or hire a similarly qualified third party, to coordinate the incident response program. The SEC's adopting release agreed, and said so directly: "we did not propose, and are not adopting, specific steps a covered institution must take when carrying out its incident response program, and we are not specifically designating who must undertake oversight responsibilities, thus providing covered institutions flexibility to determine whether and how to appropriately assign or divide such responsibilities." The Commission's stated reason was that covered institutions need the flexibility to develop policies and procedures suited to their own size, complexity, and activities. That incident response program requirement now binds every covered institution, larger and smaller alike, so the ownership question below applies to all of them. The rule leaves the ownership question to the firm on purpose.
What does an explicit designation requirement actually look like?
Two adjacent frameworks show what the SEC chose not to write, and one of them turns out to reach some advisory firms directly, just not the ones you would expect. The FTC's Safeguards Rule applies only to financial institutions over which the FTC has jurisdiction under GLBA Section 505(a)(7), which by its own terms excludes an institution another listed regulator already covers, exactly why it never reaches an SEC-registered adviser or broker-dealer; those firms answer to Reg S-P instead. But 16 CFR 314.1(b) expressly lists "investment advisers that are not required to register with the Securities and Exchange Commission" among the institutions the rule does cover, which means a state-registered adviser sits squarely inside it. That rule requires the covered business to "designate a qualified individual responsible for overseeing and implementing" the information security program, and to have that person "report in writing, regularly and at least annually, to your board of directors or equivalent governing body," or to a senior officer where no such body exists. A size threshold switches off only that second, reporting duty: Section 314.6 exempts a firm holding customer information on fewer than 5,000 consumers from it, but the designation duty itself applies at every size. New York's cybersecurity regulation goes further still, for the narrower set of firms it actually binds: since its 2023 amendment, section 500.17(b)(2) requires the annual submission, whether a certification of material compliance under (b)(1)(i) or an acknowledgment of non-compliance under (b)(1)(ii), to be signed by both the covered entity's highest-ranking executive and its CISO, or, where the entity has no CISO, by the senior officer responsible for its cybersecurity program. That rule binds DFS licensees, which for most advisory firms means a dually chartered trust company or an affiliated bank, not the RIA or broker-dealer itself directly. Together they show that a designation or dual-signature requirement is a real, drafted regulatory choice; Reg S-P is that kind of rule for a state-registered adviser, through the FTC's rule, but not for SEC-registered advisers and broker-dealers.
Who ends up owning the program at an SEC-registered adviser?
The compliance officer the adviser already has to name for an entirely different reason. Advisers Act Rule 206(4)-7(c) requires an SEC-registered adviser to "designate an individual (who is a supervised person) responsible for administering the policies and procedures," and (b) requires the adviser to "review, no less frequently than annually, the adequacy of the policies and procedures" and the effectiveness of their implementation. Neither paragraph mentions Reg S-P by name, and 206(4)-7(a) by its own terms reaches the Advisers Act and the rules adopted under it, not the separate GLBA-based rule 248.30 sits in. The SEC's own guidance closes that gap in practice rather than by mandate: the 2024 Reg S-P release itself notes a covered institution "can, however, adopt a single set of policies and procedures covering Regulation S-P and other rules, provided that the policies and procedures meet the requirements of each rule," and the Commission's long-standing compliance-program guidance already lists safeguarding client records among the topics an adviser's 206(4)-7 policies should address. Most advisers take that option, which puts the Reg S-P sections inside the same manual the designated chief compliance officer (CCO) already administers. Advisers Act Rule 204-2(a)(17)(ii) is the actual retention hook: it requires the adviser to keep records documenting that annual review, preserved five years under Rule 204-2(e)(1). The rule prescribes no particular format, so it does not itself demand a date or a signature, but a record carrying neither is a weak answer when an examiner asks who reviewed the program and when. A CCO who never touches Reg S-P specifically, because a technology vendor or an internal IT lead handles the mechanics, is still the name an examiner will ask for first.
Who ends up owning it at a FINRA member firm?
A chain that runs from the CCO to the CEO to the board, on a schedule the firm cannot skip. FINRA Rule 3130(a) requires every member to designate one or more principals as chief compliance officer. Rule 3130(b) requires the member's "chief executive officer(s) (or equivalent officer(s))" to certify annually that the firm has processes to establish, maintain, review, test and modify its written compliance policies and supervisory procedures, and that the CEO has met with the CCO at least once in the preceding 12 months to discuss those processes. Rule 3130(c) sets out what the certification itself must say, and the certification rests on a compliance report that gets reviewed by the CEO and CCO and then goes to the firm's board of directors and audit committee or equivalent bodies; only a member with no governing body of any kind is excused from that submission entirely, under Supplementary Material .09. Rule 3130 does not name Reg S-P, cybersecurity, or information security anywhere in its text, but it does not need to: 3130(c)(1)(A) has the CEO certify to processes reasonably designed to achieve compliance with "applicable FINRA rules, MSRB rules and federal securities laws and regulations," and Reg S-P is a federal securities regulation. Those same procedures also sit inside the written supervisory procedures Rule 3110 already requires. Either route puts Reg S-P on the CEO's desk; neither rule singles it out by name.
What about a state-registered adviser?
A different pattern, not the same one. A state-registered adviser sits outside Reg S-P entirely, but it does not sit outside every designation requirement the way an SEC-registered adviser does: the FTC's Safeguards Rule, discussed above, reaches it directly, and Section 314.4(a) hands that firm a role Reg S-P never wrote for anyone. On the state-law side, a state's written-program requirement raises the same question: who signed the annual review of the program, and when. NASAA's model rule requires the same at-least-annual review Rule 206(4)-7 requires, in nearly identical words, and it does not name a required signatory either. So a state-registered adviser's own state rule leaves the same gap Reg S-P leaves for an SEC-registered adviser, but the FTC rule closes part of it at the federal level in a way nothing closes for the SEC-registered side.
Eight questions to ask about who owns your program
- Has the firm designated its CCO in writing, and does that person actually administer the Reg S-P sections of the compliance program, not only the sections that name the rule directly?
- For an adviser, is the at-least-annual review under Rule 206(4)-7(b) documented under 204-2(a)(17)(ii), with a date and the reviewer's name attached, not just a memory that it happened?
- For a FINRA member, has the CEO actually met with the CCO in the preceding 12 months, as Rule 3130(b) requires, and is that meeting itself documented rather than assumed?
- Has the compliance report behind that certification reached the board and audit committee, or equivalent governing bodies, and if the firm genuinely has neither, is that documented as an exemption under Supplementary Material .09 rather than just running behind?
- For a state-registered adviser, has the firm actually designated the Qualified Individual the FTC's Safeguards Rule requires, in writing, or has that requirement gone unnoticed because everyone was watching Reg S-P instead?
- If the firm is a hybrid, an adviser with an affiliated broker-dealer, does each entity have its own separate sign-off chain, or has one been assumed to cover both?
- If the outsourced IT provider changed something in the program's technical controls this year, did the designated owner actually sign off on that change, or only find out about it later?
- Would the firm's own answer to who owns this survive being asked cold, without notice, by an examiner?
What does s90 do, and what stays with the firm?
s90 provides the evidence a designated owner reviews before signing, not a substitute for the signature itself. Every quarter, a Technology Posture Report shows the state of your IT, and a separate Compliance Posture Report for Regulation S-P lays out each requirement, the control behind it and the evidence that it's working. We run the technical safeguards behind those reports, including device management and patching, sign-in protection, monitoring and staff security training, and we keep the documentation current. The administrative and physical safeguards 248.30(a)(1) also names stay with the firm's own procedures and premises. s90 doesn't designate the chief compliance officer, hold the meeting between the CEO and the chief compliance officer that Rule 3130(b) requires, or sign the annual review under Rule 206(4)-7. Those decisions, like whether the firm is compliant, stay with the firm.

