Your RIA Just Received an Exam Notice. The Question Is What You Can Produce.

It arrives from the Texas State Securities Board or the SEC, by letter or by email, and it is polite. It names a period, lists what the examiner wants to see, and gives you a date.

Then you go looking, and the picture is not what you hoped. The written supervisory procedures were drafted when the firm was smaller. The information security policy is a template somebody downloaded. Nobody is certain where the last risk assessment went, or whether there was one.

Nothing has gone wrong yet. But the clock is running, and an exam is not a test of whether your advisory firm is careful. It is a test of what it can hand over.

Which rulebook reaches your firm

Before anything else, one fact decides which rules an examiner will hold you to: how your firm is registered.

State-registered with the Texas State Securities Board. The Board’s rules in 7 TAC Chapter 116 apply to your firm in full.

SEC-registered. Regulation S-P applies to your firm. The Chapter 116 program duties are written for a registered investment adviser and do not reach you.

SEC-registered but serving Texas clients through a notice filing. This is the case worth reading carefully. A notice filing buys the form, consent to service, and the fee — not the Chapter 116 program duties. But the vulnerable-adult rule is written to reach every investment adviser, not only registered ones, so it applies to you even though the rest of Chapter 116 does not.

A firm is never in both books and never falls through both. Knowing which one you are in is the first thing we establish, because it changes the entire list of what you must be able to produce.

What a Texas examiner could ask for, and how fast

For a state-registered adviser, Chapter 116 sets out what the Board could require. It is more specific than firms often expect it to be.

Records, in thirteen categories. Kept five years, and three years for financial records and correspondence. The first two years have to be easily accessible.

Electronic records held to a format standard. Non-rewriteable, non-erasable, time-dated, with verification of the quality of the recording.

Production within forty-eight hours. On request, records must be produced at a Board office inside two days. That is the sentence worth reading twice. It is not a deadline to start looking.

The Commissioner may inspect without notice.

A written supervisory system, and written policies preventing misuse of material nonpublic information.

A written system for vulnerable adults, with assessment and reporting to the Commissioner, and the authority to place a hold.

Forty-eight hours is achievable if the records exist in a known place, in a known format, with someone who knows where they are. It is not achievable if the answer starts with “let me find out who has that.”

If you are SEC-registered, the security rule has already bitten

Regulation S-P was amended in 2024, and both compliance dates have now passed — the later of the two, for smaller entities, was June 3 2026. The rule is fully in force.

What it requires:

  • written policies to safeguard customer information, covering administrative, technical and physical safeguards
  • an incident response program to detect, respond to and recover from unauthorized access
  • customer notice as soon as practicable, and no later than thirty days after becoming aware
  • a contractual expectation that a service provider tells you within seventy-two hours of becoming aware of a breach
  • written policies for proper disposal of consumer and customer information

The service provider clause is worth checking against your actual agreements. It is not enough to use good vendors. The obligation runs to what your contracts say and whether you could show it.

The cybersecurity notice that runs alongside the others

Texas added a rule in 2020 that is triggered by other people’s deadlines rather than its own.

If your firm gives notice of a cybersecurity incident to any state or federal agency, to a self-regulatory organization, or to your customers under the Texas breach notification statute, you also owe notice to the Texas State Securities Board.

It runs alongside those other notices. It never replaces one of them. A firm that handles a breach competently everywhere else can still end up out of compliance here, simply because nobody knew the Board was on the list.

What an exam actually tests

Examiners are not looking for a firm that has never had a problem. They are looking for a firm that can show its work.

The pattern is the same across every duty above. Is it written down. Is it current. Is it yours, rather than a template with another firm’s name changed. Can you produce it, in the window you are given, without a scramble.

That is a documentation problem more than a security problem. A firm can have a control running correctly and still have no record that proves it was running on the date the examiner is asking about. The control and the evidence of it are two different things, and only one of them can be handed over.

See the eleven obligations that reach Texas legal and financial firms →

If the notice is already on your desk

You are not going to rebuild a compliance program before the examiner arrives, and you should not try to make it look as though you did.

Establish which rulebook applies. State-registered, SEC-registered, or notice-filed. Every other decision follows from it.

Find what exists, honestly. A real inventory of what you can produce today beats a reconstruction. Backdating a document is a far worse problem than not having one.

Put the gaps in writing yourself, with a dated plan to close them. A firm that has identified its own gaps and is working through them is in a different conversation than a firm that was surprised by them.

Then close them properly, so the next exam is a matter of retrieval.

How Briggs IT Services helps

We start with a Compliance Readiness Review. We gather what your firm actually has, then review it against what your registration basis requires you to be able to produce — Chapter 116 or Regulation S-P, and the Texas rules that reach the firm either way.

You get a written report: what you could hand an examiner today, where the gaps are, and what closing each one takes.

From there we create the plan. If you have IT, internal or outside, we guide them through the changes and they do the hands-on work. If you have no IT, we do the hands-on work ourselves, inside a scoped remediation phase with a defined end.

Then we build the documentation and keep it current, so a notice becomes a filing exercise rather than a fire drill.

Common questions

How long do Texas state-registered advisers have to produce records in an exam?

On request, records must be produced at a Texas State Securities Board office within forty-eight hours. The Commissioner may also inspect without notice. Two days is workable if records are where you expect them, in the required format, with someone who knows the answer.

Does Regulation S-P apply to a state-registered adviser?

No. Regulation S-P reaches an adviser by being registered with the Commission. A state-registered Texas adviser is governed by the Board’s rules in 7 TAC Chapter 116 instead. Firms are never in both books.

We are SEC-registered and notice-filed in Texas. Which Texas rules reach us?

A notice filing covers the form, consent to service, and the fee, not the Chapter 116 program duties. The vulnerable-adult rule is written to reach every investment adviser rather than only registered ones, so it does apply to you.

Do we have to tell the Texas State Securities Board about a cybersecurity incident?

Yes, if you are already giving notice of that incident to a state or federal agency, to a self-regulatory organization, or to your customers under the Texas breach notification statute. The Board notice runs alongside those, it does not replace them.

What kinds of things does an exam ask a firm to produce?

Current written supervisory procedures that match how the firm actually operates, the written policies each rule requires, and evidence that a control was in place during the period under review. The last one is where a gap tends to show, because a working control and a record proving it was working are two different things.

Find out what you could hand an examiner today