Six Degrees of Compliance: Your Diligence Doesn’t Stop at the Client

Janice Kioko

In 1929, Hungarian writer Frigyes Karinthy proposed a theory: any two people on Earth are connected by a short chain of acquaintances. Stanley Milgram tested it in 1967 and found the number hovered around five or six.  The world is smaller — and more interconnected — than it looks.

Vendor risk isn’t linear — it’s a web. And regulators now expect you to manage every strand.  

Compliance officers at RIAs, CPOs/CTAs, and broker‑dealers know this instinctively, even if they’ve never called it “six degrees.” Client data doesn’t stay with the client. It flows to the fund administrator, then to the administrator’s cloud host, then maybe to a subcontractor nobody at the firm ever vetted. An employee’s personal brokerage account touches a clearing broker. A marketing vendor’s CRM plugs directly into firm systems. Clients, service providers, professional advisors, brokers, employees — one network, one risk surface. Regulators have made it clear: no node in that chain is “someone else’s problem.”

The rule that started it — and the one that just got sharper

RIAs already operate under Advisers Act Rule 206(4)-7: written policies and procedures reasonably designed to prevent violations, reviewed annually for effectiveness.

Compliance counsel has long interpreted that rule to include vendor risk — a vendor failure touching client assets or data is a compliance failure, full stop.

In May 2024, the SEC made part of that expectation explicit. The first major overhaul of Regulation S‑P since 2000 requires covered institutions — broker‑dealers, RIAs, funds, funding portals, transfer agents — to maintain a written incident response program, notify affected individuals within 30 days of a breach, and adopt policies that actually oversee service providers through real due diligence and ongoing monitoring, not a one‑time onboarding form. Large entities were due by December 3, 2025; smaller entities had until June 3, 2026.

Every regulator, same question

The SEC isn’t alone. NFA Compliance Rule 2‑9 requires member CPOs and CTAs to diligently supervise their agents. Since 2021, Interpretive Notice 9079 makes clear that outsourcing a regulatory function doesn’t outsource the responsibility — members need a written supervisory framework covering onboarding diligence, ongoing risk‑based review, and an exit plan.

FINRA has said the same for two decades. Notice to Members 05‑48 (2005) established that outsourcing never relieves supervisory responsibility. Regulatory Notice 21‑29 (2021) modernized that guidance for a vendor‑heavy industry: supervision, registration, cybersecurity, business continuity — plus a reminder that vendors holding books and records electronically still must meet Exchange Act recordkeeping rules. FINRA Rule 3110’s supervisory duty follows any activity a firm chooses to outsource, wherever it goes.

Where the chain actually breaks

SEC enforcement shows a pattern over time: breaches almost never start at the firm’s own front door.

  • In 2015, R.T. Jones Capital Equities paid $75,000 after hackers hit a thirdparty web server, not the firm’s system.[^12]
  • In August 2021, eight firms paid $200K–$300K each after contractors’ and employees’ cloud email accounts — not core infrastructure — were compromised.[^13]
  • In 2022, a $35 million penalty stemmed from data disposal failures, not collection: 15 million records mishandled during decommissioning.[^14]
  • In January 2025, Robinhood’s broker‑dealers paid $45 million combined, in part for Safeguards Rule failures.[^15]

Every case points to the same weak link: a contractor, a vendor, a disposal process, an integration point the firm didn’t fully control.

The takeaway

“Six degrees” isn’t just a clever hook. Clients, vendors, advisors, brokers, employees — it’s one network. And the amended Reg S‑P, layered on Rule 206(4)-7, NFA Rule 2‑9, and FINRA’s outsourcing guidance, makes managing that network a documented, ongoing obligation.

Map the network. Tier it by risk. Revisit it on a schedule. Firms that do this aren’t just examiner‑ready — they find the weak link before someone else does.

Managing that network by hand — spreadsheets, email chains, onetime PDFs — is exactly how firms lose track of the weak link. Leo RegTech is an all‑in‑one compliance platform built for this: centralized service provider due diligence, automated risk scoring and tiering, built‑in Reg S‑P incident response tracking (72‑hour vendor notice, 30‑day client notice, full audit trail), and automated reminders so due diligence never goes stale. It’s one system for vendor, employee, and client‑side compliance — instead of six degrees of spreadsheets.

Want to see it on your own vendor list? Reach out to Janice Kioko, Managing Director, at [email protected] or visit or book a demo below.

Navigating EMIR Refit 2024: changes, challenges, and an upcoming deadline

UK Crypto Rules Are Final: What Changed and What’s Next

If your firm has anything to do with cryptoassets, buying, selling, custody, staking, or simply marketing them to...

The FCA’s Consumer Duty: Implementation and What’s Next?

The FCA’s Consumer Duty comes into force this Monday, July 31st. The FCA will identify firms whose responses...
Leo RegTech
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.