Hungarian writer Frigyes Karinthy’s 1929 theory that any two people are connected by a short chain of acquaintances was tested by Stanley Milgram in 1967, who found the number hovered around five or six.
According to Leo RegTech, compliance teams at RIAs, CPOs/CTAs and broker-dealers are now discovering the same principle applies to their risk exposure. Vendor risk isn’t linear, it’s a web, and regulators expect firms to manage every strand of it.
Client data rarely stays put. It moves to a fund administrator, then to that administrator’s cloud host, then potentially to a subcontractor the firm never vetted. An employee’s personal brokerage account touches a clearing broker, while a marketing vendor’s CRM plugs directly into internal systems. Regulators have been explicit that no node in that chain is someone else’s problem.
RIAs already operate under Advisers Act Rule 206(4)-7, which requires written policies reasonably designed to prevent violations. In May 2024, the SEC sharpened that expectation with its first major overhaul of Regulation S-P since 2000.
Covered institutions, including broker-dealers, RIAs, funds, funding portals and transfer agents, must now maintain a written incident response programme, notify affected individuals within 30 days of a breach, and demonstrate ongoing vendor oversight rather than a one-off onboarding form. Large entities faced a December 2025 deadline, with smaller entities given until June 2026.
Other regulators have echoed the same demand. NFA Compliance Rule 2-9 requires CPOs and CTAs to diligently supervise their agents, while FINRA’s Notice to Members 05-48 and Regulatory Notice 21-29 have long established that outsourcing never removes supervisory responsibility.
Enforcement history shows breaches rarely start at a firm’s own front door. R.T. Jones Capital Equities paid $75,000 in 2015 after hackers hit a third-party web server. In 2021, eight firms paid between $200,000 and $300,000 each after contractors’ and employees’ cloud email accounts were compromised.
A 2022 case brought a $35m penalty over data disposal failures affecting 15 million records, and in January 2025 Robinhood’s broker-dealers paid $45m combined, partly for Safeguards Rule failures.
The message from regulators is consistent: map the network, tier it by risk, and revisit it on a schedule. Firms managing vendor risk through spreadsheets and email chains risk losing track of the weak link before an examiner, or an attacker, finds it first.
Read Leo RegTech’s full post here.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





