Fictional demonstration firm. Tradecraft Advisors LLC does not exist. Every document below is an illustrative BrainTrust output, not legal advice.
Sample deliverables, one example firm

The compliance file BrainTrust builds for a $750M RIA.

Tradecraft Advisors is a firm we invented so you can see, before you join, representative output from the core BrainTrust tools. The firm is fictional. The documents are what the tools produce. One firm, five moments its compliance program has to work.

The example firm

Tradecraft Advisors LLC

A deliberately ordinary mid-size adviser. If your firm looks anything like this, the documents below are what your BrainTrust output looks like, generated from your own answers instead of ours.

Tradecraft Advisors LLC
FICTIONAL FIRM PROFILE
Registration
SEC RIA
Investment adviser
Regulatory AUM
$750M
~310 HNW households
Employees
22
Dallas + Austin
Compliance
1 CCO
Also runs operations
IT
Outsourced
Managed service provider
Custody
1 primary
Plus e-signature, CRM
Stated assumptions: MFA is enforced across Microsoft 365; the firm stores no payment-card data; there are no internally hosted production systems. We state these because the generated documents depend on them, the same way they will depend on your answers.

The technology the program has to cover

Productivity + email
Microsoft 365
Where client PII actually lives day to day
CRM
Cloud CRM
Client records, notes, household data
Portfolio + reporting
Cloud portfolio platform
Holdings, performance, billing
Custodian
Custodian portal
Money movement, the wire-fraud surface
Signatures
E-signature platform
Account docs in transit
Security
MSP-managed EDR
Detection the firm relies on but does not run

Product categories shown for realism. No affiliation with or endorsement by any vendor is implied.

How the documents get made
1
You answer plain-English questions
Firm profile, technology, vendors, who does what. No legal drafting.
2
BrainTrust maps your answers to the rules
Rule 206(4)-7, Reg S-P, Reg S-ID, Rule 204-2, tracked live in the Regulatory Map.
3
You get editable, cited working drafts
Word documents with the regulatory basis shown and [FILL IN] markers where your judgment is required.
Moment one

Build the written program

Tradecraft Advisors' manual was last touched in 2021. Reg S-P was amended in 2024, the firm adopted two AI tools nobody wrote down, and the annual review is 90 days out. The CCO needs an adopted, current written program, not a template with the firm name pasted in.

Generated with the Policies & Procedures Manual Builder, the AI Toolkit, and the Regulatory Map.

SAMPLE
Cybersecurity Policies and Procedures
Tradecraft Advisors LLC · Adopted pursuant to SEC Regulation S-P (as amended 2024), Rule 206(4)-7, and Rule 204-2

Definitions

“Customer Information” means any record containing nonpublic personal information about a customer of a financial institution, whether in paper, electronic, or other form, that is handled or maintained by the Firm or on its behalf. (17 C.F.R. § 248.30(d)(5).) For clarity, Customer Information includes records of customers of other financial institutions that the Firm holds, processes, or has access to.

“Cybersecurity Incident” means any actual or reasonably suspected unauthorized access to or use of Customer Information or Firm Information, or any event affecting the confidentiality, integrity, or availability of the Firm's Information Systems.

Access Controls (reviewer red-line copy)

The Firm enforces multi-factor authentication for all users of the Microsoft 365 environment, consistent with the firm profile provided at generation. Exceptions require written IT vendor CCO approval and are recorded in the exception log maintained under Section 12

Says this because Tradecraft answered: MFA enforced tenant-wide on Microsoft 365.
Illustrative output for a fictional firm. Not legal advice.
SAMPLE
AI Use Policies & Procedures Manual
Tradecraft Advisors LLC · Package of six documents, incl. Tool Register and Employee Attestation

4.2 Approved Tools

The Firm maintains a register (Appendix A) of every AI tool approved for business use, the approved use cases for each, and the data classes each tool may receive. A tool not on the register is not approved.

Basis: Rule 206(4)-7 (adequacy of written policies); 17 C.F.R. § 248.30(a)(1) (safeguards for customer information).
Status: Required. Evidence: Appendix A register, reviewed quarterly.

6.1 Data Protection

No employee may enter Customer Information or Sensitive Customer Information into any AI tool that has not been approved for that data class in Appendix A. Client-identifying detail is removed or…

Illustrative output for a fictional firm. Not legal advice.
Rule 206(4)-7Reg S-P §248.30(a)Rule 204-2Regulatory Map: 359 requirements · 11 regulators

Behind both documents sits the Regulatory Map: every cited rule tracked with its live status (in force, proposed, withdrawn, vacated), flagging changes for the firm to review, so the manual adopted in March gets rechecked, not forgotten, by October.

Moment two

Train the people

Tradecraft Advisors' biggest attack surface is not a server. It is 22 inboxes. A written program only counts if the people named in it can recognize the Tuesday-morning wire fraud before it happens, and when an examiner asks how the firm trains its employees, the answer has to be a record, not a recollection.

Delivered through FieldCraft, MTradecraft's Employee Cybersecurity Training. Included with membership for up to 50 users, with completion tracking built in.

SAMPLE
FieldCraft Employee Cybersecurity Training: Completion Report
Tradecraft Advisors LLC · Q3 2026 cycle · 22 enrolled learners across Dallas and Austin
ModuleAssignedCompleteStatus
Phishing and email fraud2222[ COMPLETE ]
Wire transfer verification2221[ 1 OVERDUE ]
Handling client information2222[ COMPLETE ]
Ransomware and device safety1412[ IN PROGRESS ]

Overdue learners are re-notified automatically; per-learner completion records follow on page 2 and are retained in the firm's compliance file as evidence the program operates…

Illustrative output for a fictional firm. Not legal advice.
Rule 206(4)-7Reg S-P §248.30(a)(1) safeguardsExam-file evidence
Moment three

Evaluate a vendor

Reg S-P now requires written service-provider oversight, including due diligence and monitoring. Tradecraft Advisors' most important vendor is also its biggest: Microsoft 365 touches more of the firm's customer information than any other system. "It's Microsoft, it's fine" is not a due-diligence file.

Generated from the Vendor Due Diligence Portal: a 600+ vendor catalog, ~78 researched fields per vendor, every answer cited to a live source or flagged for vendor attestation.

SAMPLE
Vendor Due Diligence Report: Microsoft 365
Prepared for Tradecraft Advisors LLC · Reg S-P §248.30(a)(5) service-provider oversight

What it is

Cloud productivity, email, and file storage. For this firm it is a principal repository of Customer Information and the main channel through which sensitive documents move.

Gets full Reg S-P oversight treatment because Tradecraft marked this vendor as receiving customer information.

Evidence synopsis

  • SOC 2 Type II and ISO/IEC 27001 certificates current at review; scope checked against the services the firm actually uses. Source: Microsoft Service Trust Portal, reviewed Aug 2026.
  • Contractual breach-notice commitments reviewed against the Reg S-P 72-hour service-provider notice requirement. Source: Microsoft Products and Services Data Protection Addendum, security-incident notification terms.
  • Data-residency and subprocessor disclosures on file. Source: Microsoft subprocessor list, published disclosure, Aug 2026.

Watch-outs and open items

  • Tenant-level controls (MFA enforcement, external-sharing limits) are the firm's responsibility, not the vendor's; two items route to the firm's decision log…

Institution's decision

☐  Approve    ☒  Approve with conditions    ☐  Decline
Conditions: confirm tenant MFA report quarterly; close two open items by [DATE]
Reviewed by: ____________________   Title: CCO   Date: ____________
Illustrative output for a fictional firm. Not legal advice.
Reg S-P §248.30(a)(5)§248.30(a)(5)(i)(B) 72-hr noticeRule 204-2(a)(25)
Moment four

Handle an incident

Tuesday, 9:40 a.m.: an operations associate reports that a client "confirmed" wire instructions the firm never sent. This is the moment the program is for. The plan activates, the team assesses what was accessed, and the deadline is unforgiving: once the firm becomes aware that unauthorized access to customer information occurred or is reasonably likely, it has no more than 30 days to notify affected customers. If the breach sits at a service provider, the 72-hour provider notice the firm's vendor oversight secured in advance is what tells it at all.

Generated with the Incident Response Plan Builder (before the incident) and the Incident Response Assistant (during it).

SAMPLE
Incident Response Plan
Tradecraft Advisors LLC · Working draft for adoption · Master template v1.2

8. Customer Notification

The Firm will notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. Notice will be provided as soon as practicable, but not later than 30 days after the Firm becomes aware. (17 C.F.R. § 248.30(a)(4)(iii).) The 30-day clock runs from that awareness, not from completion of the harm assessment.

4. Detection and Identification

Alerts and escalations from the Firm's managed IT / security provider [FILL IN: MSP NAME], including endpoint, email, and network monitoring. Any employee who suspects an incident must report it immediately; there is no penalty for a good-faith report that proves…

Routes detection through an MSP because Tradecraft answered: IT is outsourced.
Illustrative output for a fictional firm. Not legal advice.
SAMPLE
Incident Response Record
Tradecraft Advisors LLC · CONFIDENTIAL · Playbook: Wire fraud / payment redirection
TimeActionStatus
09:40Associate reports client-confirmed wire instructions not originated by the Firm; plan activatedReport logged
09:52Custodian contacted; hold requested on pending disbursement
10:15Affected mailbox isolated; credentials reset; MSP engaged for log preservation
10:40Assessment opened: was customer information accessed or used without authorization, and whose? Awareness of unauthorized access starts the 30-day customer-notification clockAssessing

Determination record, notification decision, and 204-2(a)(25) retention checklist follow on pages 2–3…

Illustrative output for a fictional firm. Not legal advice.
Reg S-P §248.30(a)(3)§248.30(a)(4)(iii) 30-day noticeRule 204-2(a)(25)
Moment five

Prepare for scrutiny

A records request arrives from the Division of Examinations. The question is not only whether the firm has policies. It is whether the file proves the program operates. Tradecraft Advisors ran the Mock SEC Cyber Exam a quarter earlier, on purpose, to find the gaps before an examiner did.

Generated with the Mock SEC Cyber Exam. Free to run; answers never leave the browser.

SAMPLE
Compliance File Assessment: Gap Report
Tradecraft Advisors LLC · Six sections, each item mapped to its governing rule
ItemGoverning ruleStatus
Written incident response program adopted and current§248.30(a)(3)[ SATISFIED ]
Service-provider oversight: due diligence documented for material vendors§248.30(a)(5)[ PARTIAL ]
Incident records retained 5 years, first 2 easily accessible204-2(a)(25), (e)(1)[ SATISFIED ]
Annual review documents adequacy AND effectiveness206(4)-7[ OPEN ]
Identity-theft red flags program reviewed for covered accountsReg S-ID[ PARTIAL ]
Employee cybersecurity training assigned and completion documented206(4)-7, §248.30(a)(1)[ SATISFIED ]

Sections: Program governance · Reg S-P incident response · Privacy & identity theft · Books & records · Safeguards in practice · Training & exam readiness…

Illustrative output for a fictional firm. Not legal advice.
Rule 206(4)-7Reg S-PReg S-IDRule 204-2

Everything above is one membership

Tradecraft Advisors' file is representative of what a BrainTrust Premium membership produces for a real firm, generated from that firm's own answers. Also included, beyond what fits on this page:

Template library
~70 documents across the compliance lifecycle: Assess, Build, Operate, Prove, Respond
Quarterly exposure scan
External exposure review of your firm's public footprint
Regulatory Map + Horizon
359 requirements, 592 cited rules, 11 regulators, tracked as they change

Stop starting from blank templates. Describe your firm once, generate the working file, and adopt it through your own governance. Manual, vendor reports, incident plans, and training records, all from your answers.

What stays your responsibility. BrainTrust tools produce firm-specific working drafts with the regulatory reasoning shown. Your firm reviews them, completes the marked items, adopts them through its own governance, and operates them. The tools map to the rules; they do not promise an exam outcome, and nothing here is legal advice.