Six degrees of separation, the idea popularised by Stanley Milgram’s 1967 experiment, holds that any two people are connected through a short chain of acquaintances.
According to Leo RegTech, financial compliance officers are learning a similar lesson the hard way: client data rarely stays with the client. It moves through fund administrators, cloud hosts, subcontractors and marketing vendors, and regulators now expect firms to account for every link in that chain.
RIAs already operate under Advisers Act Rule 206(4)-7, which requires written policies reasonably designed to prevent violations. Compliance counsel has long read vendor risk into that requirement, but in May 2024 the SEC made the expectation explicit.
Its overhaul of Regulation S-P, the first since 2000, requires broker-dealers, RIAs, funds, funding portals and transfer agents to maintain a written incident response programme, notify affected individuals within 30 days of a breach, and actively oversee service providers rather than relying on a one-off onboarding form. Large entities faced a December 2025 deadline; smaller entities have until June 2026.
Other regulators have echoed the same message. NFA Compliance Rule 2-9 and its 2021 Interpretive Notice 9079 require CPOs and CTAs to diligently supervise agents, including a written framework for onboarding, ongoing review and exit planning.
FINRA’s Notice to Members 05-48 established in 2005 that outsourcing does not remove supervisory responsibility, and Regulatory Notice 21-29 extended that principle to cybersecurity, business continuity and recordkeeping obligations that follow outsourced activity wherever it goes.
Enforcement history shows why. R.T. Jones Capital Equities paid $75,000 in 2015 after hackers breached a third-party web server. Eight firms paid between $200,000 and $300,000 each in August 2021 after contractor and employee cloud email accounts were compromised.
A $35m penalty followed in 2022 over mishandled data disposal affecting 15m records, and Robinhood’s broker-dealers paid $45m combined in January 2025, partly for Safeguards Rule failures. In each case, the breach originated outside the firm’s own infrastructure.
The consistent recommendation from compliance counsel is to map the vendor network, tier it by risk and revisit it on a fixed schedule, rather than tracking diligence through spreadsheets and email chains that quietly go stale.
Platforms such as Leo RegTech aim to replace that manual process with centralised service provider due diligence, automated risk scoring, and built-in Reg S-P incident tracking covering the 72-hour vendor notice and 30-day client notice windows.
Read Leo RegTech’s full post here.
Copyright © 2026 FinTech Global



