
March 2026 Compliance News: Cybersecurity, Vendor Oversight, and Records Controls
March compliance news highlights a clear shift for RIAs: cybersecurity and vendor oversight are now core compliance controls, not separate technology projects. Examiners increasingly expect firms to show how data, access, and outsourced systems are governed.
Cybersecurity Programs Must Be Testable
Written cybersecurity policies are no longer enough. RIAs should be prepared to show risk assessments, access reviews, phishing training, incident response exercises, vulnerability management, business continuity testing, and evidence that findings were escalated to management. The compliance function does not need to become the IT department, but it must be able to demonstrate oversight.
A strong 2026 cybersecurity file should identify critical systems, client data locations, privileged users, vendor access points, and incident reporting responsibilities. Firms should also define what counts as a material incident internally and who decides whether client, regulator, or contractual notices are required.
Access
Review privileged accounts, terminated users, shared credentials, and multi-factor authentication.
Vendors
Track due diligence, contracts, security reports, and monitoring cadence for critical providers.
Records
Confirm retention, retrieval, audit trails, and backup practices for books and records.
Vendor Oversight Is Getting More Detailed
RIA compliance programs should classify vendors by risk. A portfolio accounting system, CRM, email platform, cloud storage provider, AI tool, or outsourced compliance provider may require deeper review than a low-risk administrative vendor. Due diligence should cover security controls, data handling, subcontractors, service continuity, contractual rights, and incident notification obligations.
Vendor reviews should not happen only at onboarding. Firms should set a refresh cycle and document whether the vendor still performs as expected. If a vendor supports trading, billing, reporting, cybersecurity, marketing, or client communications, compliance should know the business owner and the escalation path for issues.
Electronic Records Controls Are in Focus
As RIAs rely on cloud platforms and collaboration tools, records controls must keep pace. Compliance teams should confirm that required records are retained in approved systems, protected from unauthorized deletion, and retrievable during an exam. The risk is not only missing records. It is also inconsistent storage across inboxes, chat tools, local drives, and vendor portals.
Firms should review retention schedules, legal hold processes, backup procedures, and supervision of electronic communications. If employees use new productivity or AI tools, policies should explain what information may be entered and how outputs are reviewed and preserved when they become business records.
Key Takeaways for RIAs
- Treat cybersecurity testing as compliance evidence, not just IT activity.
- Classify vendors by risk and refresh due diligence on a defined schedule.
- Review contracts for incident notice, data protection, and service continuity terms.
- Map where books and records are created, stored, archived, and retrieved.
- Update policies for AI tools, collaboration platforms, and cloud workflows.
Strengthen technology oversight
NextReg helps RIAs turn cybersecurity, vendor, and records obligations into practical compliance controls.
Schedule a Consultation