Asset Management
SEC, fiduciary obligations, and fund compliance
Asset managers must navigate SEC regulations, fiduciary obligations, and increasing cybersecurity requirements while protecting client assets and data. Thalorin provides compliance infrastructure tailored to the unique requirements of investment advisers, fund managers, and wealth management firms.
Asset managers came under materially expanded SEC cybersecurity obligations with the Regulation S-P amendments adopted in May 2024. The amendments require covered institutions — including registered investment advisers, broker-dealers, and investment companies — to maintain written incident response programmes and, critically, to notify affected individuals within 30 days of becoming aware that unauthorised access to sensitive customer information has occurred or is reasonably likely to have occurred.
The compliance dates were tiered by size, with larger entities obligated earlier than smaller ones. The practical effect is a firm-level notification duty that did not previously exist in that form, and a corresponding need to determine quickly whether an incident meets the threshold.
Public asset managers carry a second, separate obligation: the SEC's cybersecurity disclosure rules require reporting material cybersecurity incidents on Form 8-K Item 1.05 within four business days of determining materiality, alongside annual disclosure of risk management, strategy, and governance. Materiality determination is the hinge, and it is a judgement the filing must be able to defend.
Thalorin binds incident evidence to the determination it supports, so both the 30-day Reg S-P notification and the four-business-day materiality determination rest on a reconstructible record rather than a recollection.
Financial institutions operate under intense scrutiny
Two clocks, two thresholds
Reg S-P requires individual notification within 30 days of awareness of unauthorised access to sensitive customer information; the disclosure rules require an 8-K within four business days of a materiality determination. They measure different things from different starting points.
Materiality is a defensible judgement, not a checkbox
Item 1.05 turns on materiality, which is assessed against a reasonable investor standard rather than a technical severity score. The record behind the determination matters as much as the determination.
Service provider oversight
Advisers depend heavily on administrators, custodians, and technology providers. Reg S-P expects oversight sufficient to ensure providers can meet the notification obligations the adviser carries.
Examination readiness on an ongoing basis
SEC examinations probe whether written programmes are actually operated. A policy that exists but produces no evidence of operation is a familiar deficiency finding.
How Thalorin helps
SEC Regulation S-P compliance
Maintain the written incident response programme Reg S-P requires as an operated process with evidence, not a stored document.
Fiduciary cybersecurity documentation
Track the 30-day customer notification clock from awareness, with the determination record attached.
Fund-level compliance tracking
Support materiality assessment for Item 1.05 disclosure with a reconstructible evidence trail.
Client data protection
Carry service provider oversight obligations, including providers' ability to meet notification duties.
Trading system security
Evidence annual risk management, strategy, and governance disclosures from live control state.
Custody and safekeeping controls
Prepare examination artifacts continuously rather than assembling them per examination.
Asset Management: common questions
What did the 2024 Regulation S-P amendments require?
Covered institutions — registered investment advisers, broker-dealers, investment companies, and transfer agents — must maintain written incident response programmes addressing unauthorised access to customer information, and must notify affected individuals within 30 days of becoming aware that unauthorised access to sensitive customer information occurred or is reasonably likely to have occurred. Compliance dates were tiered, with larger entities obligated first.
How is the 8-K materiality standard different from the Reg S-P threshold?
They are unrelated tests. Reg S-P turns on unauthorised access to sensitive customer information and drives individual notification. Item 1.05 turns on whether a cybersecurity incident is material to a reasonable investor and drives public disclosure within four business days of that determination. An incident can trigger one, both, or neither.
Can we delay the 8-K disclosure?
Only in narrow circumstances. Disclosure may be delayed where the United States Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety and notifies the Commission in writing. This is not a general-purpose extension, and firms should not plan around it.
Does Reg S-P apply to us if we have no retail clients?
It depends on whether you hold customer information within the rule's scope rather than on client sophistication alone. Advisers serving institutional clients frequently still hold information about natural persons connected to those clients. The analysis is about the data held, not the client type, and assuming exemption on the basis of an institutional client base is a common error.
What do SEC examiners actually test?
Whether the written programmes are operated. Examiners routinely ask for evidence that a policy produced activity — incident response tests actually run, vendor reviews actually performed, access reviews actually completed — and a programme that exists only as a document is a recurring source of deficiency letters.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Asset Management.
See how one evidence artifact satisfies Asset Management requirements alongside every other framework you carry.