The Securities and Exchange Commission's October 2023 amendments to the Recordkeeping Rule require registered investment advisers to take specific steps when outsourcing recordkeeping or other functions to third-party service providers. The amendments establish minimum contractual terms, impose ongoing monitoring obligations, and assign clear accountability for outcomes the firm cannot delegate. For chief compliance officers, chief operating officers and general counsel, the challenge is not technical complexity but organizational ownership: who decides what adequate oversight looks like, who interprets the regulatory standard in context, and who reports to the board that the obligation has been met.
What the Rule Requires
The amended Rule 204-2 under the Investment Advisers Act of 1940 addresses the outsourcing of recordkeeping and books-and-records functions. When an investment adviser uses a third party to maintain required records, the adviser remains responsible for ensuring those records are accessible, accurate and preserved according to regulatory standards. The rule does not prohibit outsourcing; it makes explicit that delegation of custody or maintenance does not transfer accountability.
The amendments require that agreements with third-party service providers include terms that give the adviser, the SEC and other regulators the ability to access records maintained by the provider. The agreement must also address the provider's obligation to preserve records in the format and for the period required by the rule. These are not suggested best practices. They are minimum contractual terms that must be present for the outsourcing arrangement to be compliant.
What Must Be in Third-Party Agreements
The rule specifies that written agreements with third-party service providers must include provisions that address access, preservation and continuity. The adviser must retain the right to access records promptly and without obstruction. The SEC and other authorized regulators must have equivalent access. The provider must commit to preserving records in the required format and for the required retention period, even if the relationship terminates.
These provisions must be specific enough to be enforceable. General language about cooperation or reasonable assistance is unlikely to satisfy the standard. The agreement should specify what records are covered, how access will be provided, in what timeframe, and what happens if the provider ceases operations or the contract ends. It should also address what the adviser will do if the provider is unwilling or unable to meet its obligations.
Monitoring Obligations
Having the right contract is necessary but not sufficient. The adviser must monitor the provider's ongoing compliance with the contractual terms and with the broader recordkeeping standard. This means periodic review of the provider's controls, confirmation that records remain accessible, and verification that retention practices have not changed in ways that introduce risk.
The rule does not prescribe how often monitoring must occur or what methods are acceptable. It assigns the adviser responsibility for determining what monitoring is adequate given the nature of the records, the criticality of the provider's role, and the risk profile of the arrangement. This discretion creates accountability: the adviser must decide, document the decision and be prepared to explain why the chosen approach is reasonable.
Who Is Accountable Inside the Organization
The rule assigns ultimate responsibility to the investment adviser as a legal entity, which means accountability rests with senior leadership and the board. In practice, compliance officers often manage the process, operations teams negotiate agreements, and technology or vendor management functions conduct monitoring. The problem is not the distribution of tasks but the absence of a single executive owner who can make risk-informed decisions, interpret the regulatory expectation in context, and report to leadership that the obligation is being met.
Without that owner, compliance becomes a checklist exercise. Contracts are reviewed for the presence of required language rather than for enforceability. Monitoring becomes a scheduled task rather than a judgment about adequacy. Leadership receives reports that obligations are being addressed but has no clear basis for concluding that they are being satisfied.
Relationship to Vendor and Third-Party Oversight
The recordkeeping rule is a specific regulatory obligation, but it intersects with the broader practice of [vendor and third-party oversight](/vciso/). Many advisers already have vendor management programs that include contract review, due diligence and periodic assessments. The rule does not replace those programs; it establishes a regulatory floor for one category of provider. The question for leadership is whether existing oversight processes are designed to satisfy this specific obligation or whether additional governance is required.
For providers that maintain client data, financial records or other sensitive information, the oversight obligation extends beyond recordkeeping to include security, availability and business continuity. An effective program integrates regulatory requirements with operational risk management and information security, rather than treating each as a separate workstream. This integration requires a risk perspective that most vendor management functions are not resourced to provide.
Business Consequences of Inadequate Compliance
The immediate consequence of noncompliance is regulatory exposure. If the SEC examines an adviser and determines that third-party agreements do not meet the rule's requirements or that monitoring is inadequate, the adviser may face enforcement action, remediation mandates or heightened scrutiny in future examinations. The indirect consequences are often more significant. Inadequate oversight of third-party recordkeeping creates operational risk: if a provider fails, is acquired or changes its practices, the adviser may lose access to records it is legally obligated to maintain. Reconstructing those records or explaining their absence to regulators or clients is costly and may be impossible.
There is also reputational risk. Clients and investors expect that their investment adviser has visibility into and control over the records that document their accounts and transactions. Learning that the adviser cannot promptly access those records because of a provider dispute or failure undermines confidence in the adviser's operational competence and governance.
What Adequate Ownership Looks Like
Adequate ownership of this obligation means a designated executive who can do three things: make risk-informed decisions about what level of oversight is sufficient for each third-party arrangement; translate regulatory requirements into specific operational expectations that can be measured and reported; and provide the board and senior leadership with a defensible conclusion that the obligation is being met. This is not a full-time operational role. It is a governance role that requires regulatory judgment, risk assessment and the authority to direct changes when gaps are identified.
For many advisers, the chief compliance officer is the logical candidate, but CCOs are often consumed with disclosure, marketing review and examination preparation. The chief operating officer may have operational visibility but not the regulatory perspective. The general counsel has the legal judgment but may not have operational oversight. The gap is not about capability; it is about mandate and availability. Someone must own the regulatory position, decide what adequate looks like, and report upward with confidence.
The Role of vCISO Leadership
A [virtual Chief Information Security Officer](/vciso/) provides the executive ownership that closes this gap. The vCISO interprets regulatory requirements in the context of the adviser's operations, provider relationships and risk tolerance. The vCISO designs oversight processes that satisfy the rule's monitoring obligation without creating unnecessary administrative burden. The vCISO works with compliance, operations and legal to ensure that third-party agreements include enforceable terms and that those terms are being honored. Most importantly, the vCISO provides leadership with a clear answer to the question: are we meeting the obligation, and how do we know?
This is not about replacing compliance or operations. It is about providing the strategic layer that translates regulatory mandates into risk decisions and risk decisions into reportable outcomes. The vCISO becomes the single point of accountability for the security and governance aspects of third-party oversight, allowing compliance to focus on regulatory interpretation and operations to focus on service delivery.
Practical Next Steps for Leadership
Leadership should begin by identifying who currently owns the obligation to ensure third-party compliance with the recordkeeping rule. If the answer is unclear or distributed across multiple functions, that is the first gap to address. Next, review existing third-party agreements to confirm that they include the required access and preservation terms. If agreements are silent or use only general language, amendments are necessary. Then assess the monitoring process: what is being checked, how often, by whom, and how leadership is informed of the results. If monitoring is informal or inconsistent, design a process that produces documented evidence of oversight.
For advisers that lack the internal capacity to provide ongoing executive oversight of third-party risk, a confidential consultation with a vCISO can clarify what that ownership looks like in practice, what resources it requires, and how it fits within existing governance structures. Heights Consulting Group offers such consultations to chief compliance officers, chief operating officers and general counsel in registered investment advisers. The consultation is confidential, without obligation, and focused on identifying the most direct path to defensible compliance. To arrange a consultation, contact Heights Consulting Group directly.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Vendor, MSP and Third-Party Oversight
Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.