The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
Primary source: FTC Safeguards Rule business guidance
What documents does the Safeguards Rule actually require for a state-registered investment adviser?
Details
Policywright splits the operating record into a WISP, incident response plan, acceptable use policy, and access control policy. For a state-registered investment adviser, those documents should map to Client information lives in Form ADV files, advisory agreements, suitability or planning notes, custodial account data, portfolio-management tools, email, portals, billing records, and household financial plans. The WISP should distinguish custodian systems from adviser-controlled records.
Primary source: FTC Safeguards Rule business guidance.
Related obligations - not covered by this packet: state adviser books-and-records and examination rules may require separate records retention, advertising, billing, custody, and compliance files. Policywright's WISP packet does not satisfy those securities-recordkeeping duties.
FAQ
What documents does the Safeguards Rule actually require for a state-registered investment adviser?
The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
What is the data-flow issue for a state-registered investment adviser?
Client information lives in Form ADV files, advisory agreements, suitability or planning notes, custodial account data, portfolio-management tools, email, portals, billing records, and household financial plans. The WISP should distinguish custodian systems from adviser-controlled records.
Is this legal advice?
No. It is source-cited educational content for a template product, not legal advice.