RIA Cybersecurity Compliance Templates & Library

What the examiner asks for — already written, already mapped.

An SEC examination request list asks for specific things by name: your written policies, your vendor due-diligence file, your training records, your incident response plan. Premium membership is those things, already built. The template library is the same set of policies and frameworks we use in our own consulting engagements. Vendor due diligence comes pre-researched — a 600+ vendor catalog, with independently sourced answers concentrated on the high-sensitivity providers against Reg S-P. Employee training runs on its own and keeps the completion records examiners request. And incident response is covered from both ends: the Plan Builder writes your firm’s plan before you need it, and the Incident Response Assistant walks you through the day you do.

Membership works as a four-step program — Assess your documentation (free), Map your vendors and data, Build the written program, Operate & Respond — backed by three interactive tools, 61 editable templates, FieldCraft training, and the Quarterly External Exposure Snapshot (beta). See how the program works →

Why Premium

Everything a compliance program needs — in one membership.

BrainTrust Premium is more than a document library. It packages the work an SEC-registered firm is most often asked to show: that it vets its vendors, that it trains its people, that its policies are written down and mapped to the rules — and now, tools that build those documents for you.

Vendor Due Diligence Portal

The Reg S-P vendor program, already built

A living evidence database of 600+ vendors RIAs actually use — CRMs, custodians, planning, portfolio, AI platforms — each scored against a 90-field due-diligence questionnaire. Every answer independently verified from a public source with a citation and capture date, or flagged for direct vendor attestation. Select your stack, print your Rule 204-2 vendor file.

FieldCraft Training

Security awareness, automated

Phishing simulations, quiz tracking, and audit-ready completion reports for up to 50 employees — the training evidence Reg S-P's Safeguards Rule expects.

Incident Response Tools New

Your incident response plan, generated

Answer five minutes of questions; the IRP Builder generates your firm's complete Reg S-P incident response plan as an editable Word document — every section mapped to §248.30, with a printable quick-reference card. And if an incident ever starts, the Incident Response Assistant walks you through it live and produces the timestamped record Rule 204-2 expects.

Template Library

Every policy the request list names

Sixty-one editable Word templates spanning thirteen categories — from the cybersecurity policy manual to exam-production checklists — enough to build the written program end to end.

AI Governance Kit New

Adopt AI without failing an exam

The AI Compliance Framework, governance workbook, output validation protocol, and AI marketing claims checklist — plus an AI supplemental track inside the vendor portal.

Quarterly External Exposure Snapshot Beta

See what the internet sees — every quarter

A passive scan of your firm’s public exposure — look-alike domains, forgotten subdomains, email-spoofing gaps, exposed services — summarized against Reg S-P and Reg S-ID and delivered to Premium members quarterly. Nothing to install — tell us your domains once and it runs every quarter.

Direct Access

Email support on compliance questions

Members email MTradecraft directly with cybersecurity compliance questions — answers from the practice, not a help desk.

All of it — $2,500 a year, flat. The same library and tools our $36,000 consulting engagements are built on.

The Flagship — Vendor Due Diligence

The Reg S-P Vendor Due Diligence Portal.

Evidence for the service-provider oversight procedures amended Reg S-P now requires — already researched and continuously maintained. A living database of the vendors RIAs rely on, each scored against our 90-field due-diligence questionnaire, now including an AI supplemental section covering model training, data retention, and AI subprocessors. Every answer is independently verified from a public source (with a link and capture date) or flagged as requiring direct vendor attestation. High-sensitivity vendors are fully covered today; coverage expands continuously.

Free — preview the full vendor catalog Premium — full records, sources & attestation gaps

Explore the Vendor DD Portal →

What's Inside

Maintained as the rules change — and cited to them.

The BrainTrust is not a marketing handout. Every template cites the specific rule it supports — Reg S-P, Rule 206(4)-7, Rule 204-2 — and the library is revised as SEC rulemaking and examination priorities move, so the version you download reflects current requirements.

Cybersecurity Program

Cybersecurity Policies & Procedures Manual (Reg S-P), NPI Data Inventory, Access Control & MFA, Annual Risk Assessment, Data Disposal.

Incident Response & Fraud

Incident Response Plan, Tabletop Exercise Kit, Wire-Transfer & Disbursement Verification — plus the interactive IRP Builder and the live-incident Incident Response Assistant.

AI Governance

AI Compliance Framework & Governance Workbook, AI Output Validation Protocol, AI Marketing Claims Review Checklist.

Vendor & Third-Party

Vendor Due-Diligence Questionnaire and Confidentiality Agreement — alongside the 600-vendor evidence portal.

Annual Compliance

206(4)-7 Annual Review, Compliance Calendar, Compliance Meeting Agenda.

Code of Ethics & Conflicts

Code of Ethics, Conflicts of Interest, Gifts & Entertainment, Political Contributions, Outside Business Activity.

Client Disclosures & Privacy

Client Communication Letter Suite, Form ADV Amendment Checklist, Reg S-ID Red Flags.

Marketing & Social Media

Marketing Procedures Policy, Firm & Employee Social Media Policies, Promoter & Solicitor Oversight.

Trading, Custody & Operations

Best Execution Evaluation, Trade Error Policy & Log, Proxy Voting, Custody Rule Compliance Checklist.

Employee Agreements

Employee Technology Use Agreement, Whistleblower Policy, and acknowledgement forms.

Governance & Records

Business Continuity Plan, Books & Records Policy, Written Supervisory Procedures.

Examination & Reference

SEC Exam Document Production Checklist, First-Time Examination Guide, Cybersecurity Request Bundle.

61 editable templates across 13 categories, each mapped to the rule it supports. Browse the full library →

Included Free

Start before you subscribe

The Securing Compliance report, the SEC Exam Cybersecurity Preparedness Brief, the Reg S-P Impact Summary, and our ongoing BrainTrust posts — no payment required.

FieldCraft Training

Security awareness for up to 50 staff

Phishing simulations, quiz tracking, and audit-ready completion reports — the training evidence retained for your examination file.

Membership Tiers

Two tiers. One Premium price.

The Free tier is built to put real material into the hands of CCOs and IT managers who are still organizing their cybersecurity program. The Premium tier adds everything above — the Reg S-P vendor due-diligence portal, automated employee training, the full policy and framework library, and the interactive builders.

Free Tier

The BrainTrust

Free account required

A practical starting point for firms that need better direction before engaging a consultant or building a more formal cybersecurity compliance program.

  • Securing Compliance — what SEC examiners actually ask for
  • BrainTrust Posts — cybersecurity commentary and SEC enforcement updates
  • SEC Exam Cybersecurity Preparedness Brief
  • Mock SEC Cyber Exam
  • Cybersecurity Compliance Document Review Matrix
  • Reg S-P 2024 Compliance Impact Summary
Create Free Account
Who Buys This

Built for firms in a specific situation.

A Premium membership fits if…

  • You are a CCO or IT manager at an SEC-registered firm and you need real policy templates — not generic ones.
  • You are a small RIA without the budget for a $36K consulting engagement but with examination obligations you cannot ignore.
  • You are a compliance consultant who needs a defensible cybersecurity policy library to deliver to your own clients.
  • You want to run FieldCraft Security Awareness Training for your staff without a separate training vendor relationship.

Premium is not the right fit if…

  • You need someone else to operate the cybersecurity program, not just provide the documentation. The Cyber Compliance Consultant engagement exists for that.
  • An insurance carrier or DDQ requires a named CISO. The Remote CISO engagement exists for that.
  • You want active SEC examination support and direct involvement from cybersecurity counsel. That is consulting, not membership.
Membership Details

Questions members ask before subscribing.

Can I cancel anytime?

Yes. The subscription is managed through Memberful. You can cancel future charges at any time from your account portal — no phone calls, no penalty. You retain access through the end of the paid period.

Are the documents customized to my firm?

No. BrainTrust templates are provided as editable Word documents that the member adapts to their firm's specifics. If you need documents drafted to your firm, that is a Cyber Compliance Consultant engagement.

Can I list MTradecraft as my cybersecurity expert?

No. A BrainTrust membership is a resource subscription, not a consulting relationship. For DDQ and examination purposes requiring a named cybersecurity expert or CISO, the Remote CISO engagement is what's required.

What does FieldCraft cost beyond 50 users?

The Premium membership includes FieldCraft for up to 50 users. If your firm exceeds 50 users, additional seats can be added on a separate FieldCraft subscription at $4.00 per user per month (billed annually).

Will the templates pass an SEC examination?

Templates do not pass examinations — implemented programs do. A BrainTrust template gives you a defensible starting point written by a knowledgeable party. Whether your firm passes an exam depends on how the policies are adopted, implemented, reviewed, and documented over time.

Ready

Premium is $2,500 a year — and starts the moment you subscribe.

Free account first if you want to read the Securing Compliance report and access our posts. Upgrade to Premium when the exam notice, the carrier questionnaire, or the client DDQ makes it real.

By creating an account or subscribing you agree to the BrainTrust Member Policy.