True West | News & Insights

Regulatory Round-Up September 2026

Written by True West | Sep 04 2026
 

Navigating Change with Confidence

As the regulatory landscape continues to evolve, September's focus is on one consistent theme: governance. Whether it's artificial intelligence, cybersecurity, supervisory controls, or conflicts of interest, the SEC continues to emphasize that firms must demonstrate not only that policies exist, but that they are actively implemented, monitored, and documented.

This month's Round-Up highlights several areas receiving increased regulatory attention and provides practical steps your firm can take to strengthen its compliance program before year-end.

AI Governance: The Conversation Has Changed

Artificial intelligence is no longer a future consideration for Registered Investment Advisers - it's here, and regulators are paying close attention.

The SEC recently reinforced its commitment to responsible AI adoption through its Artificial Intelligence Program, emphasizing innovation while maintaining strong governance and investor protection. As AI tools become increasingly integrated into business operations, firms are shifting away from asking whether AI should be used and instead asking how it can be governed responsibly.

What the SEC Is Looking For

While there are currently no AI-specific rules for RIAs, examiners are increasingly focused on how firms oversee AI technologies, including:

  • AI vendor due diligence
  • Policies and procedures governing AI use
  • Employee training
  • Data privacy and client confidentiality
  • Human oversight of AI-generated work
  • Recordkeeping and documentation

Firms should expect examiners to ask not only what AI tools are being used, but how they are supervised and controlled.

True West Take

The strongest AI governance programs aren't built around restricting technology - they're built around managing risk.

Treat AI like any other critical vendor:

  • Conduct due diligence.
  • Limit use to approved enterprise solutions.
  • Document your governance process.
  • Maintain human oversight.
  • Train employees regularly.

As with every compliance program, documentation is your best defense.

Reg S-P: When the Clock Starts

Cybersecurity incidents continue to increase across every industry.

Under the SEC's updated Regulation S-P requirements, once your firm becomes aware of unauthorized access to sensitive customer information, the notification timeline begins.

That means firms generally have 30 days to notify affected individuals when notification is required. Waiting until an investigation is complete can significantly reduce the time available to respond.

Is Your Firm Prepared?

Before an incident occurs, every RIA should know:

  • Who leads the investigation?
  • Which breach attorney will you contact?
  • Who coordinates client communications?
  • Can your IT provider perform forensic investigations?
  • Are responsibilities clearly documented?

True West Recommendation

Conduct an annual tabletop cybersecurity exercise.

Testing your incident response plan before a real event helps identify gaps, clarify responsibilities, and ensure your team understands regulatory expectations before the pressure of an actual breach.

Compliance Spotlight

Effective Supervision Starts at the Top

Rule 206(4)-7 continues to serve as the foundation of every RIA compliance program.

The SEC expects firms to maintain written policies that are not only well designed but actively supervised, tested, and updated as risks evolve.

An effective compliance program includes:

  • A knowledgeable Chief Compliance Officer with appropriate authority
  • Ongoing employee training
  • Regular supervisory reviews
  • Annual compliance testing
  • Documentation demonstrating policies are followed—not simply written

Strong supervision supports your fiduciary obligations and helps build a culture of compliance throughout the organization.

We're Here to Help

Compliance is about building a stronger, more resilient firm, not just meeting regulatory expectations.

Whether you're reviewing AI governance, preparing for Regulation S-P requirements, strengthening supervisory controls, or conducting annual testing, True West partners with RIAs to simplify compliance so you can stay focused on serving your clients.

One Team. One Trail.

Questions? Contact the True West Compliance Team to discuss any of the topics covered in this month's Regulatory Round-Up.