WISP for state-registered investment advisers
State-registered investment advisers need a WISP when the business is covered by the FTC Safeguards Rule category investment advisor that is not required to register with the SEC. The practical coverage trigger is that the firm provides investment advice for compensation and is state-registered rather than SEC-registered. Client information lives in Form ADV files, advisory agreements, suitability or planning notes, custodial account data, portfolio-management tools, email, portals, billing records, and household financial plans. The WISP should distinguish custodian systems from adviser-controlled records.
Key facts
- State-registered investment advisers should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: provides investment advice for compensation and is state-registered rather than SEC-registered.
- The data map should be vertical-specific: Client information lives in Form ADV files, advisory agreements, suitability or planning notes, custodial account data, portfolio-management tools, email, portals, billing records, and household financial plans. The WISP should distinguish custodian systems from adviser-controlled records.
- Many state RIAs are small enough for 16 CFR 314.6, but household records, prospects, and former clients should be counted carefully. The exception does not remove the program or safeguards.
Key takeaways
- State-registered investment advisers should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: provides investment advice for compensation and is state-registered rather than SEC-registered.
- The data map should be vertical-specific: Client information lives in Form ADV files, advisory agreements, suitability or planning notes, custodial account data, portfolio-management tools, email, portals, billing records, and household financial plans. The WISP should distinguish custodian systems from adviser-controlled records.
- Many state RIAs are small enough for 16 CFR 314.6, but household records, prospects, and former clients should be counted carefully. The exception does not remove the program or safeguards.
- The custodian already secures the account. Custodian security does not protect the adviser's own CRM, planning files, email, billing records, laptops, or vendor access.
Why state-registered investment advisers are covered
State-registered investment advisers are covered when their business activity fits investment advisor that is not required to register with the SEC. FTC guidance lists investment advisers that are not required to register with the SEC, and 16 CFR 314.2(h)(2)(xii) identifies investment advisory companies.
The coverage test is factual. For this vertical, Policywright treats the trigger as: provides investment advice for compensation and is state-registered rather than SEC-registered. The sources block below is limited to primary-source or regulator materials so the page does not drift into unsourced compliance folklore.
The page does not invent a coverage theory beyond the cited category and factual trigger.
Where customer information lives
Client information lives in Form ADV files, advisory agreements, suitability or planning notes, custodial account data, portfolio-management tools, email, portals, billing records, and household financial plans. The WISP should distinguish custodian systems from adviser-controlled records.
That data-flow map changes the WISP. A tax preparer worries about portals and e-file records; a collection agency worries about placement files, dialers, and dispute queues; an auto dealer worries about the credit application, F&I office, DMS, and lender portals.
A useful written program should name the systems, roles, vendors, access paths, retention points, and evidence records that fit the trade.
Common objection
The custodian already secures the account. Custodian security does not protect the adviser's own CRM, planning files, email, billing records, laptops, or vendor access.
Policywright handles that objection by writing the factual basis into the packet rather than hiding it. If coverage is unclear, the firm should preserve the question for counsel instead of turning a WISP into an unsupported legal conclusion.
Related obligations - not covered by this packet: state adviser books-and-records and examination rules may require separate records retention, advertising, billing, custody, and compliance files. Policywright's WISP packet does not satisfy those securities-recordkeeping duties.
Under-5,000-consumer analysis
Many state RIAs are small enough for 16 CFR 314.6, but household records, prospects, and former clients should be counted carefully. The exception does not remove the program or safeguards.
16 CFR 314.6 exempts smaller covered firms only from 314.4(b)(1), (d)(2), (h), and (i). It does not remove the written-program duty or the need to protect customer information with reasonable administrative, technical, and physical safeguards.
A serious small-firm packet should document the count assumption and keep the fuller controls where they are operationally useful.
| Question | Vertical-specific answer | Source |
|---|---|---|
| Coverage trigger | provides investment advice for compensation and is state-registered rather than SEC-registered | FTC Safeguards Rule business guidance |
| Customer data flow | Client information lives in Form ADV files, advisory agreements, suitability or planning notes, custodial account data, portfolio-management tools, email, portals, billing records, and household financial plans. The WISP should distinguish custodian systems from adviser-controlled records. | Document in WISP data inventory |
| Common objection | The custodian already secures the account. Custodian security does not protect the adviser's own CRM, planning files, email, billing records, laptops, or vendor access. | FTC Safeguards Rule business guidance |
| Small-firm exception | Many state RIAs are small enough for 16 CFR 314.6, but household records, prospects, and former clients should be counted carefully. The exception does not remove the program or safeguards. | 16 CFR 314.6 |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
What makes state-registered investment advisers different from tax preparers?
The data flow and objection pattern are different. State-registered investment advisers need a WISP that follows Client information lives in Form ADV files, advisory agreements, suitability or planning notes, custodial account data, portfolio-management tools, email, portals, billing records, and household financial plans. The WISP should distinguish custodian systems from adviser-controlled records.
Does Policywright cover related non-Safeguards obligations?
Related obligations - not covered by this packet: state adviser books-and-records and examination rules may require separate records retention, advertising, billing, custody, and compliance files. Policywright's WISP packet does not satisfy those securities-recordkeeping duties.
Sources
Build a WISP for state-registered investment advisers.
Answer plain questions and receive a source-cited policy packet tailored to the firm's systems, vendors, and gaps.
Build my plan