The Securities and Exchange Commission amended its custody rule in October 2023, imposing new safeguarding, recordkeeping, and account statement requirements on registered investment advisers. The amended rule—formally Rule 223-1 under the Investment Advisers Act—applies whether an adviser maintains direct custody of client assets or exercises control sufficient to access those assets.

The compliance date depends on adviser size and custody arrangements, but the substantive challenge is immediate: leadership must coordinate custody procedures, information security controls, and supervisory oversight across historically separate functions. The rule does not distinguish between operational custody failures and cybersecurity incidents that produce the same client harm.

Why Safeguarding Client Assets Demands Executive Attention

An adviser's duty to safeguard client assets has always existed, but the amended rule makes specific what was previously general. The SEC now requires written policies, documented controls, and periodic verification that assets remain protected from both operational error and unauthorized digital access.

The consequences of inadequate safeguarding are institutional. Regulatory enforcement actions against investment advisers have included civil penalties, client restitution, and enhanced supervisory obligations that persist for years. Beyond formal sanctions, a custody failure damages client relationships in ways that operational improvement cannot easily repair.

The business problem is fragmented ownership. Custody procedures typically reside with operations or compliance. Access controls, authentication, and network security fall to information technology. Risk oversight belongs to the chief compliance officer or general counsel. Each function holds part of the safeguarding obligation, but no single executive is accountable for the integrated result the SEC requires.

What the Amended Custody Rule Requires

The amended rule establishes three core obligations: safeguarding client assets, maintaining accurate records, and delivering account statements. Each obligation intersects with cybersecurity controls in ways that many advisers have not yet addressed.

Safeguarding Obligations

Advisers with custody must protect client assets from loss, including loss from cyber-related events such as unauthorized transfer or credential compromise. The rule does not prescribe specific technical controls, but it requires that controls be documented, tested, and appropriate to the nature and sensitivity of the assets held.

This includes physical custody controls—segregation, dual authorization, reconciliation—and digital custody controls: authentication mechanisms, access logging, change management, and procedures to detect and respond to unauthorized activity. An adviser cannot satisfy the safeguarding requirement through operational procedures alone if the supporting systems lack adequate access controls.

Recordkeeping and Documentation

The amended rule specifies records that advisers must create and retain: records of asset location, records of transactions affecting custody, and records sufficient to verify compliance with safeguarding obligations. Many advisers interpret this narrowly as transactional documentation, but the SEC has stated that records of safeguarding controls—including technical security measures—fall within the requirement.

This means access logs, authentication records, system change histories, and incident documentation are compliance records under the custody rule, not merely IT artifacts. Retention, completeness, and availability of these records become supervisory obligations.

Account Statements and Verification

Advisers must ensure clients receive periodic account statements, either directly from a qualified custodian or, where that is not feasible, from the adviser subject to verification procedures. The verification requirement extends to confirming that the systems producing those statements have not been compromised in ways that could misstate asset positions.

Where Cybersecurity Controls Intersect Custody Obligations

The custody rule does not explicitly require cybersecurity controls, but every safeguarding obligation depends on them. Unauthorized digital access can produce the same client harm as physical theft or operational error, and the amended rule holds advisers accountable for the outcome regardless of the mechanism.

Consider the practical implications: An adviser must protect assets from unauthorized transfer. That protection requires not only dual authorization and transaction monitoring, but also controls that prevent credential compromise, session hijacking, or privilege escalation. An adviser must maintain accurate records of asset location and transactions. That requires logging, integrity verification, and protection against record tampering.

An adviser relying on a third-party custodian must still ensure its own systems do not introduce vulnerabilities that could lead to unauthorized instructions being submitted to that custodian. The custody obligation does not end at the custodial boundary; it extends to the controls governing adviser access to custodial systems.

This is where many advisers encounter difficulty. Information security teams understand authentication, access control, and logging. Compliance teams understand custody obligations, recordkeeping, and supervisory procedures. But few organizations have a single executive responsible for ensuring these capabilities align to satisfy the SEC's safeguarding standard.

Who Owns Safeguarding and What Adequate Ownership Looks Like

The chief compliance officer is typically responsible for interpreting regulatory obligations and supervising adherence. The chief operating officer or head of operations owns custody procedures, transaction processing, and client-facing documentation. The chief information officer or technology leader controls the technical infrastructure that enforces access and maintains records.

None of these roles, individually, can satisfy the integrated safeguarding obligation. Adequate ownership requires an executive who can translate regulatory requirements into control objectives, determine what controls satisfy those objectives across operational and technical domains, and report to leadership on whether the aggregate control environment meets the standard.

That executive function is the virtual chief information security officer role. A [virtual CISO](/vciso/) does not replace the chief compliance officer, the chief operating officer, or the technology leader. It provides the coordinating authority that ensures custody procedures, access controls, incident response, and documentation work together to produce the safeguarding outcome the SEC requires.

In practical terms, adequate ownership includes:

  • A governance structure that assigns custody-related control decisions to a single accountable executive
  • Documented control objectives derived directly from the amended rule's safeguarding obligations
  • A mapping between those control objectives and the specific operational and technical controls the adviser has implemented
  • Regular verification that controls remain effective and that changes to systems or procedures do not introduce gaps
  • A reporting mechanism that gives the board, general counsel, or chief executive visibility into safeguarding posture without requiring technical fluency

Without this structure, safeguarding becomes a coordination problem rather than a compliance problem. Each function does its part competently, but no one confirms that the parts combine to meet the regulatory standard.

How This Relates to Regulatory and Framework Readiness

The amended custody rule is one of several intersecting regulatory obligations that require coordinated technical and operational controls. Investment advisers also face obligations under Regulation S-P (privacy and data security), Regulation S-ID (identity theft prevention), and state breach notification statutes. Advisers managing retirement accounts encounter ERISA fiduciary obligations that include prudent safeguarding of plan assets.

These requirements do not operate in isolation. A control that satisfies the custody rule's safeguarding obligation may also satisfy Regulation S-P's security requirement and ERISA's prudent processes standard. Conversely, a gap in access control can produce simultaneous violations across multiple frameworks.

Regulatory and framework readiness is the discipline of maintaining an integrated control environment that satisfies multiple obligations through a coherent, defensible structure. The NIST Cybersecurity Framework provides one such structure: it organizes controls by outcome—identify, protect, detect, respond, recover—rather than by regulation, allowing an organization to demonstrate how a single set of implemented controls meets several regulatory standards simultaneously.

For investment advisers, this approach offers material efficiency. Rather than building separate compliance programs for custody, privacy, breach response, and fiduciary obligations, leadership can establish a unified governance model that addresses the shared control requirements and documents the regulatory bases satisfied by each control.

Practical Next Steps for Leadership

Leadership should begin by clarifying who holds final accountability for the safeguarding outcome. That accountability should rest with a single named executive who has authority to direct both operational and technical resources. If no existing role has that authority, creating an interim governance structure or engaging a virtual CISO resolves the ambiguity.

Next, document the specific control objectives derived from the amended rule. These are not technical specifications; they are statements of what must be achieved: prevent unauthorized access to custodial systems, detect anomalous transfer activity, maintain tamper-evident transaction records, verify asset positions periodically. Write these in language the board and general counsel can evaluate.

Then map each control objective to the operational and technical controls currently in place. Where a control objective lacks corresponding implementation, document the gap and determine whether it represents a compliance deficiency or an acceptable residual risk given the nature and scale of assets under custody. Do not assume that because a third-party custodian holds the assets, the adviser has no safeguarding obligation. The rule applies based on the adviser's control, not physical possession.

Establish a review cadence. Controls degrade. Systems change. Vendors introduce new access methods. Custody procedures evolve. A quarterly or semiannual review ensures that the control environment documented at the compliance deadline remains accurate six months later.

Finally, prepare to explain the safeguarding program to examiners, auditors, and the board without technical jargon. The test of adequate governance is whether leadership can state clearly what controls exist, why they satisfy the regulatory standard, and how the organization would know if they stopped working.

If these steps reveal gaps in ownership, expertise, or capacity, that is a governance signal, not a technical failure. Leadership's responsibility is not to implement every control personally, but to ensure someone is accountable for the integrated result. Where that accountability does not currently exist, establishing it is the immediate priority.

Heights Consulting Group provides virtual CISO leadership to investment advisers navigating this transition. If your organization lacks a clear owner for the safeguarding outcome, or if compliance, operations, and technology functions are working in parallel without integration, a confidential consultation can clarify the structure, sequence, and measurement approach your situation requires. That consultation is offered once, at the point where the decision is live, and comes with no subsequent obligation.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Regulatory and Framework Readiness

Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.

Read about Regulatory and Framework Readiness