Key Takeaways
- The implementation gap is structural. Compliance firms identify what needs to change. They don’t typically do the work of changing it. Findings sit open for months.
- Six phases close the gap: triage and prioritize, identity and access, email and data, endpoints and monitoring, vendor oversight, and documentation.
- Timeline: 60–120 days with dedicated ownership. 18 months without.
- “Done” means: an examiner asks a question, and you answer with a document, screenshot, or log query in the same meeting.
Most RIAs we meet have a stack of compliance recommendations they haven’t implemented yet.
It usually comes from the same place: an annual risk assessment, a mock SEC exam, a SOC 2 readiness review, or a cybersecurity assessment from their outsourced CCO or compliance consultant. The deliverable is thorough and well-written. The findings are valid. The recommendations are reasonable.
And then 90 days later, most of them are still open.
This isn’t a failure of intent. It’s a structural problem. Compliance firms identify what needs to change. They don’t typically do the work of changing it. The CCO, who would normally run point on implementation, is also running point on Form ADV updates, vendor reviews, employee certifications, and a dozen other things. Implementation falls into the cracks between the people who recommend and the people who execute.
This post is the framework we use to close that gap. It’s not theoretical. It’s the same six-phase sequence we run when an RIA hands us their cybersecurity report and asks us to make the findings go away.
Why now
If your firm is a smaller entity under the SEC’s amended Regulation S-P (less than $1.5B AUM), the compliance deadline is June 3, 2026. Larger firms were already required to comply by December 3, 2025. That deadline is the most concrete forcing function the industry has seen in years — and it’s the reason we’re seeing more compliance reports land on more desks than ever, with more findings, and more pressure to actually close them out.
Phase 1 — Triage and prioritize
Not every finding has equal weight. Open findings should be sorted into three buckets: regulatory (required for compliance), risk-driven (real exposure even if not strictly required), and best-practice (worth doing eventually). The first two get implemented this quarter. The third goes on a roadmap.
What it looks like in practice: a single tracker — a spreadsheet, a Jira board, anything that lives in one place — with every finding, its bucket, an owner, and a due date. The act of building this tracker often surfaces findings that overlap or contradict each other, which is its own clarity.
Phase 2 — Identity and access
This is almost always where the highest-impact, lowest-cost wins live. If your firm uses Microsoft 365 or Google Workspace, you already own most of the controls; they’re just not configured yet.
- MFA enforced on every account, including admin and service accounts. No exceptions for “the one user who keeps complaining.”
- Conditional access policies that block sign-ins from outside the U.S. (or wherever your firm operates), restrict legacy authentication, and require compliant devices for sensitive applications.
- Privileged access separated from daily-use accounts. The CCO’s admin password should not be the password they use for email.
- Quarterly access reviews documented in writing. Who has what, who shouldn’t.
Phase 3 — Email and data protection
Email is where most incidents start, and it’s where the most sensitive data lives outside your CRM.
- Email authentication: SPF, DKIM, DMARC configured, and DMARC enforcement set to at least quarantine.
- External email tagging so users can see at a glance when a message is from outside the firm.
- DLP rules that flag or block attachments containing Social Security numbers, account numbers, and other patterns of sensitive data.
- Encrypted client communications for anything containing sensitive customer information.
Phase 4 — Endpoints and monitoring
Every device that touches firm data needs to be managed and monitored. “Managed” means inventoried, patched, and configured to firm standard. “Monitored” means an EDR platform with alerts that go to a human who responds.
- Endpoint inventory complete — including the part-time bookkeeper’s laptop, the founder’s personal device that has the firm’s email on it, and the conference-room iPad nobody owns.
- EDR deployed on every endpoint with alerts routed to a documented response process.
- Patch management automated and reported on monthly.
- Mobile device management for phones and tablets that access firm email or systems.
Phase 5 — Vendor oversight
Your firm relies on vendors. Reg S-P expects you to oversee them.
- Inventory of every vendor that handles client data, with a SOC 2 (or equivalent) on file for each.
- Contracts that require 72-hour breach notification — a specific Reg S-P requirement.
- A documented re-review cadence: annually for high-risk vendors, every two years for low-risk.
- A documented offboarding process for when a vendor is terminated.
Phase 6 — Documentation and proof
This is the phase that separates “we did the work” from “we can prove we did the work.”
- A written incident response program with named roles, decision rules, and notification templates.
- Risk assessments documented annually.
- Policies that match what you actually do (the most common audit finding is policies that don’t reflect reality).
- Training records, vendor reviews, and change logs all kept in one place with version history.
How to know when you’re done
“Done” is not a finding-by-finding checkbox. “Done” is when an examiner asks you a question and you can answer it with a document, a screenshot, or a log query — within the same meeting, not next week. If your team can do that across all six phases, you’re in a defensible position. If you can’t, you have implementation work left.
Most firms get here in 60 to 120 days when implementation has a dedicated owner and the work runs in parallel rather than sequentially. Without dedicated ownership, the same work takes 18 months and never quite finishes.
Where Rival IT fits
We do not interpret regulations. Your compliance consultant or outsourced CCO does that, and they’re better at it than we will ever be. What we do is take their findings and implement them — across identity, email, endpoints, vendors, and documentation — and continue to manage the environment afterward so the work doesn’t decay.
If you’re holding a recent compliance report and looking at the implementation work ahead, we’d be happy to walk through it with you. No pitch deck. We’ll look at the findings, tell you which ones are 30-minute fixes versus multi-week projects, and let you decide what to do with that information.
Ready to close the gap?
Walk us through your current state and we’ll tell you, candidly, where the implementation gaps are. No pitch deck. No commitment.
Schedule a Readiness Review → Call (704) 960-9739