The compliance file BrainTrust builds for a $750M RIA.
Tradecraft Advisors is a firm we invented so you can see, before you join, representative output from the core BrainTrust tools. The firm is fictional. The documents are what the tools produce. One firm, five moments its compliance program has to work.
Tradecraft Advisors LLC
A deliberately ordinary mid-size adviser. If your firm looks anything like this, the documents below are what your BrainTrust output looks like, generated from your own answers instead of ours.
The technology the program has to cover
Product categories shown for realism. No affiliation with or endorsement by any vendor is implied.
Build the written program
Tradecraft Advisors' manual was last touched in 2021. Reg S-P was amended in 2024, the firm adopted two AI tools nobody wrote down, and the annual review is 90 days out. The CCO needs an adopted, current written program, not a template with the firm name pasted in.
Generated with the Policies & Procedures Manual Builder, the AI Toolkit, and the Regulatory Map.
Definitions
“Customer Information” means any record containing nonpublic personal information about a customer of a financial institution, whether in paper, electronic, or other form, that is handled or maintained by the Firm or on its behalf. (17 C.F.R. § 248.30(d)(5).) For clarity, Customer Information includes records of customers of other financial institutions that the Firm holds, processes, or has access to.
“Cybersecurity Incident” means any actual or reasonably suspected unauthorized access to or use of Customer Information or Firm Information, or any event affecting the confidentiality, integrity, or availability of the Firm's Information Systems.
Access Controls (reviewer red-line copy)
The Firm enforces multi-factor authentication for all users of the Microsoft 365 environment, consistent with the firm profile provided at generation. Exceptions require written IT vendor CCO approval and are recorded in the exception log maintained under Section 12…
4.2 Approved Tools
The Firm maintains a register (Appendix A) of every AI tool approved for business use, the approved use cases for each, and the data classes each tool may receive. A tool not on the register is not approved.
Basis: Rule 206(4)-7 (adequacy of written policies); 17 C.F.R. § 248.30(a)(1) (safeguards for customer information).
Status: Required. Evidence: Appendix A register, reviewed quarterly.
6.1 Data Protection
No employee may enter Customer Information or Sensitive Customer Information into any AI tool that has not been approved for that data class in Appendix A. Client-identifying detail is removed or…
Behind both documents sits the Regulatory Map: every cited rule tracked with its live status (in force, proposed, withdrawn, vacated), flagging changes for the firm to review, so the manual adopted in March gets rechecked, not forgotten, by October.
Train the people
Tradecraft Advisors' biggest attack surface is not a server. It is 22 inboxes. A written program only counts if the people named in it can recognize the Tuesday-morning wire fraud before it happens, and when an examiner asks how the firm trains its employees, the answer has to be a record, not a recollection.
Delivered through FieldCraft, MTradecraft's Employee Cybersecurity Training. Included with membership for up to 50 users, with completion tracking built in.
| Module | Assigned | Complete | Status |
|---|---|---|---|
| Phishing and email fraud | 22 | 22 | [ COMPLETE ] |
| Wire transfer verification | 22 | 21 | [ 1 OVERDUE ] |
| Handling client information | 22 | 22 | [ COMPLETE ] |
| Ransomware and device safety | 14 | 12 | [ IN PROGRESS ] |
Overdue learners are re-notified automatically; per-learner completion records follow on page 2 and are retained in the firm's compliance file as evidence the program operates…
Evaluate a vendor
Reg S-P now requires written service-provider oversight, including due diligence and monitoring. Tradecraft Advisors' most important vendor is also its biggest: Microsoft 365 touches more of the firm's customer information than any other system. "It's Microsoft, it's fine" is not a due-diligence file.
Generated from the Vendor Due Diligence Portal: a 600+ vendor catalog, ~78 researched fields per vendor, every answer cited to a live source or flagged for vendor attestation.
What it is
Cloud productivity, email, and file storage. For this firm it is a principal repository of Customer Information and the main channel through which sensitive documents move.
Gets full Reg S-P oversight treatment because Tradecraft marked this vendor as receiving customer information.Evidence synopsis
- SOC 2 Type II and ISO/IEC 27001 certificates current at review; scope checked against the services the firm actually uses. Source: Microsoft Service Trust Portal, reviewed Aug 2026.
- Contractual breach-notice commitments reviewed against the Reg S-P 72-hour service-provider notice requirement. Source: Microsoft Products and Services Data Protection Addendum, security-incident notification terms.
- Data-residency and subprocessor disclosures on file. Source: Microsoft subprocessor list, published disclosure, Aug 2026.
Watch-outs and open items
- Tenant-level controls (MFA enforcement, external-sharing limits) are the firm's responsibility, not the vendor's; two items route to the firm's decision log…
Institution's decision
| ☐ Approve ☒ Approve with conditions ☐ Decline |
| Conditions: confirm tenant MFA report quarterly; close two open items by [DATE] |
| Reviewed by: ____________________ Title: CCO Date: ____________ |
Handle an incident
Tuesday, 9:40 a.m.: an operations associate reports that a client "confirmed" wire instructions the firm never sent. This is the moment the program is for. The plan activates, the team assesses what was accessed, and the deadline is unforgiving: once the firm becomes aware that unauthorized access to customer information occurred or is reasonably likely, it has no more than 30 days to notify affected customers. If the breach sits at a service provider, the 72-hour provider notice the firm's vendor oversight secured in advance is what tells it at all.
Generated with the Incident Response Plan Builder (before the incident) and the Incident Response Assistant (during it).
8. Customer Notification
The Firm will notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. Notice will be provided as soon as practicable, but not later than 30 days after the Firm becomes aware. (17 C.F.R. § 248.30(a)(4)(iii).) The 30-day clock runs from that awareness, not from completion of the harm assessment.
4. Detection and Identification
Alerts and escalations from the Firm's managed IT / security provider [FILL IN: MSP NAME], including endpoint, email, and network monitoring. Any employee who suspects an incident must report it immediately; there is no penalty for a good-faith report that proves…
Routes detection through an MSP because Tradecraft answered: IT is outsourced.| Time | Action | Status |
|---|---|---|
| 09:40 | Associate reports client-confirmed wire instructions not originated by the Firm; plan activated | Report logged |
| 09:52 | Custodian contacted; hold requested on pending disbursement | |
| 10:15 | Affected mailbox isolated; credentials reset; MSP engaged for log preservation | |
| 10:40 | Assessment opened: was customer information accessed or used without authorization, and whose? Awareness of unauthorized access starts the 30-day customer-notification clock | Assessing |
Determination record, notification decision, and 204-2(a)(25) retention checklist follow on pages 2–3…
Prepare for scrutiny
A records request arrives from the Division of Examinations. The question is not only whether the firm has policies. It is whether the file proves the program operates. Tradecraft Advisors ran the Mock SEC Cyber Exam a quarter earlier, on purpose, to find the gaps before an examiner did.
Generated with the Mock SEC Cyber Exam. Free to run; answers never leave the browser.
| Item | Governing rule | Status |
|---|---|---|
| Written incident response program adopted and current | §248.30(a)(3) | [ SATISFIED ] |
| Service-provider oversight: due diligence documented for material vendors | §248.30(a)(5) | [ PARTIAL ] |
| Incident records retained 5 years, first 2 easily accessible | 204-2(a)(25), (e)(1) | [ SATISFIED ] |
| Annual review documents adequacy AND effectiveness | 206(4)-7 | [ OPEN ] |
| Identity-theft red flags program reviewed for covered accounts | Reg S-ID | [ PARTIAL ] |
| Employee cybersecurity training assigned and completion documented | 206(4)-7, §248.30(a)(1) | [ SATISFIED ] |
Sections: Program governance · Reg S-P incident response · Privacy & identity theft · Books & records · Safeguards in practice · Training & exam readiness…
Everything above is one membership
Tradecraft Advisors' file is representative of what a BrainTrust Premium membership produces for a real firm, generated from that firm's own answers. Also included, beyond what fits on this page:
Stop starting from blank templates. Describe your firm once, generate the working file, and adopt it through your own governance. Manual, vendor reports, incident plans, and training records, all from your answers.