Guaranteed Expert Consultation Within 1 Hour. Click Here!

Guaranteed Expert Consultation Within 1 Hour. Click Here!

The SEC Marketing Rule, Rule 204-2 Books and Records, Regulation S-P and S-ID, Form ADV Disclosure and Electronic Communication Archiving: Compliance for US RIA Software

This article is part of our series on Custom RIA And Wealth Advisor CRM Development for US Registered Investment Advisors: Building a Custodian Data, Household And Compliance Archiving Platform

Introduction: Software That Generates Records Whether You Meant It To or Not

RIA software compliance starts with recognizing that platform activity creates regulated records. Communications become records, while templated performance content can become advertising requiring review and substantiation. Brochure delivery also requires evidence, making these software design questions rather than policy exercises.

Principals and compliance teams need custom software development that preserves records, controls communications, and supports evidence trails. Performance claims require substantiation, while client-facing content needs review before delivery through the platform. These controls must be designed into workflows rather than added after implementation.

Privacy requirements now include incident response and notification obligations that firms should verify before implementation. Web application development must therefore support appropriate access controls, logging, and protection of customer information. Firms should also verify the recently adopted anti-money laundering program requirements, while treating this content as educational, not legal advice.

The SEC Marketing Rule 

What Counts as an Advertisement

The SEC marketing rule broadly covers communications offering advisory services to prospective clients. Certain communications to existing clients about new services can also fall within its scope.

Compensated endorsements and testimonials are separately covered. Client service can also become advertising through templated notes containing performance or website content.

For CRM design, firms should treat potentially covered communications as regulated records. Broad application should be assumed, with requirements verified before implementing related features.

Performance Presentation Requirements

Performance content treated as advertising requires controlled presentation within the CRM. Net performance should accompany gross performance, using prescribed periods rather than selectively chosen periods. Extracted and predecessor performance require specific treatment within the presentation workflow.

Hypothetical performance carries additional conditions, including policies governing the audience that may receive it. These requirements should shape feature design, review workflows, and supporting records within the platform. The details matter, so firms should verify applicable requirements before building any performance presentation feature.

Testimonials, Endorsements and Substantiation

Testimonials and endorsements require disclosure and oversight, with additional requirements when compensation is involved. Third-party ratings carry separate conditions that must be addressed within the firm’s content review process.

Advisers need a reasonable basis for believing material statements of fact can be substantiated. Supporting records should remain alongside the related advertisement within the CRM.

The platform should require content review before client delivery. Template approval with versioning should preserve approved versions and substantiation records for each advertisement.

Rule 204-2 Books and Records 

Rule 204-2 determines what advisers must keep, in what form, for how long, and how accessibly. This obligation directly shapes how a relationship platform creates, preserves, retrieves, and produces records. The CRM therefore needs to function as a books-and-records system.

Relevant records include communications concerning recommendations or advice, advertisements, supporting performance records, client agreements, and disclosure delivery records. Documentation supporting material claims also requires preservation. Each record should remain connected to its originating relationship or activity.

Retention requirements should be configured by record type, with applicable requirements verified before implementation. Electronic records require preservation, protection from alteration, and prompt production in usable form. The platform should support immutability, controlled retention, search, retrieval, and export.

Deletion should remain a controlled function rather than a user capability. Migration should carry the complete archive without leaving records behind. Access controls should protect preserved records while enabling authorized retrieval.

For broader feature requirements, see RIA CRM Features. These capabilities make recordkeeping structural rather than dependent on individual user behavior.

Electronic Communication Archiving and the Off-Channel Problem

The off-channel communication problem is an enforcement concern for advisory technology. Communications relating to advice or recommendations must be preserved across channels. Text messages, messaging applications, social media direct messages, and meeting chats can carry communications.

Regulators have brought actions against firms whose personnel used unpreserved channels. These actions have included penalties and remedial undertakings. Policies prohibiting these practices cannot substitute for systems that detect and capture communications.

Platform design should identify every channel the firm permits for business use. Each permitted channel should capture content and context, with capture verified rather than assumed. Monitoring should detect when capture stops and trigger a response.

Supervisory review should occur within the platform, with evidence recorded. Firms should establish an enforceable position concerning communications through personal devices. These controls should inform Custom CRM Consulting when defining regulated communication workflows.

Content produced by an assistant and sent to a client requires capture treatment. Its origin does not change its preservation requirement. The platform should capture the content and communication context.

Communication capture should remain functionality rather than an optional policy feature. Detection, capture, verification, supervision, and personal-device controls should operate together. This approach addresses enforcement through platform capability rather than employee instructions.

Regulation S-P and S-ID 

Regulation S-P amendments add significant incident-response requirements to established adviser privacy obligations. Advisers must provide privacy notices describing information practices and applicable opt-out rights. They must also maintain written safeguards protecting customer records and information.

The amendments require an incident response program addressing unauthorized access to customer information. That program should support assessing, containing, and controlling incidents after unauthorized access or use. Notification to affected individuals also applies after awareness, with prescribed content and phased compliance dates.

This shifts privacy from a policy exercise toward an operational capability with a response clock. It also affects service providers whose systems hold customer information for advisers. Firms should verify current requirements, notification details, and applicable compliance dates before implementation.

Alongside these obligations, Regulation S-ID addresses identity theft prevention for firms with covered accounts. The required program should identify relevant red flags, detect them, and support appropriate responses. This adds another operational requirement for platforms handling customer information.

Platform architecture should include access controls, encryption, and logging sufficient to establish what information was accessed. Incident detection should support the response capabilities assumed by the incident response program. These controls should be designed into the platform rather than treated as separate administrative processes.

Form ADV Disclosure and Delivery 

Form ADV delivery is straightforward in principle, but proving delivery remains a recurring examination concern. Delivery requires evidence showing what was provided, to whom, and when. The platform should therefore preserve delivery evidence rather than relying on completed workflows alone.

The firm’s brochure must be delivered to clients and updated annually. Material changes must also be communicated, while retail investors receive a separate relationship summary with its own obligations. Privacy notices have separate delivery requirements that should be tracked independently.

The common failure is proving an earlier delivery when version history is incomplete. The platform should store each document’s current version and effective date. It should record delivery by household or person, identify the delivered version, and capture acknowledgments where obtained.

Portal delivery should be logged like other delivery activity within the CRM. This creates an accessible record when firms need to demonstrate prior delivery. Delivery requirements differ between documents, so firms should verify applicable requirements before configuring workflows.

Anti-Money Laundering, Custody and Other Obligations 

An anti-money laundering program requirement brings program, reporting, and recordkeeping obligations to previously excluded advisers. Firms should verify its current position, applicability, and compliance date before implementation.

Custody requirements apply to firms deemed to have custody of client assets. Surprise examinations and other obligations may apply, while proposed changes require verification before treating requirements as settled.

Written policies and procedures require annual review and a designated chief compliance officer. The code of ethics covers access-person trading and related reporting obligations the platform may support. State registration also applies below the federal threshold, with separate requirements.

Final Thoughts

NewAgeSysIT is an RIA software development company building platforms that generate and preserve regulated records. Learn more about digital transformation solutions from one of the leading AI software companies in the United States.The CRM treats communications as records and performance content as advertising.

Our platforms connect communications, disclosures, advertisements, and supporting documentation within controlled workflows. Review, preservation, retrieval, and evidence should be built into the platform architecture.

For advisory firms, this means compliance requirements shape the technology itself. NewAgeSysIT builds around these requirements so regulated records remain structured, accessible, and connected.

FAQ

What compliance requirements should custom RIA software support?

Depending on the firm, software may need to support Rule 204-2 recordkeeping, Marketing Rule workflows, Regulation S-P privacy and incident response, Regulation S-ID controls, Form ADV and Form CRS delivery, Code of Ethics records, and communication archiving. Requirements should be mapped to the firm’s SEC or state registration status rather than applied as one universal RIA ruleset.

What counts as an advertisement under the SEC Marketing Rule?

The first advertising prong generally covers adviser communications offering securities-related advisory services to prospective clients or new advisory services to existing clients. Most one-to-one communications are excluded, subject to special treatment for hypothetical performance. Compensated testimonials and endorsements can also fall under the rule’s separate second prong.

Does every client performance communication require Marketing Rule approval?

No. A client communication does not automatically become an advertisement merely because it includes performance. Most one-to-one communications are excluded from the first advertising prong, although hypothetical performance receives special treatment. Firms can still impose broader internal review requirements as a supervisory policy, but that should be distinguished from what the Marketing Rule itself requires.

What records must an SEC-registered adviser keep under Rule 204-2?

Rule 204-2 covers numerous record categories, including advisory agreements, accounting records, certain written communications, advertisements, performance-supporting materials, compliance records, and other specified documents. Many records follow a five-year retention framework, although particular categories can have different requirements. Software should therefore assign retention rules by record type rather than using one deletion schedule for everything.

Does an RIA need to archive every email, text message, and chat?

Not every message automatically becomes a required Rule 204-2 record. Preservation depends largely on content and the applicable record category. Communications concerning advice, recommendations, securities transactions, client funds, or performance can trigger recordkeeping requirements. Many firms capture approved business channels broadly because determining which messages must be retained after the fact creates operational and compliance risk.

Does Rule 204-2 require immutable or WORM storage?

No. SEC rules for investment advisers do not require the broker-dealer WORM standard. Electronic records must instead be maintained with procedures reasonably designed to protect them from loss, alteration, or destruction. Access should be appropriately restricted, and records must remain locatable, retrievable, reproducible, and available promptly when requested by the SEC.

How should RIA software address off-channel communications?

Firms should identify approved business communication channels and ensure required records from those channels are captured and retrievable. Text messages, messaging applications, social media, and other tools can create recordkeeping issues when personnel conduct advisory business through unapproved channels. Monitoring should also detect archive failures instead of assuming every permitted communication source continues to capture correctly.

What does amended Regulation S-P require from RIA software?

Covered SEC-registered advisers need written incident-response procedures designed to detect, respond to, and recover from unauthorized access to customer information. The amendments also address service-provider oversight and customer notification. When notification is required, affected individuals generally must be notified as soon as practicable and no later than 30 days, subject to the rule’s conditions and exceptions. This is fully binding now, not an upcoming deadline: larger advisers had to comply by December 3, 2025, and smaller advisers by June 3, 2026, so every covered firm should already have these procedures in place.

Explore more categories