# Regulation S-P AI incident insert

Synthetic event, customers and roles. No actual investigation finding, notice, provider assurance or control result is represented.

A fictional covered institution investigates a spreadsheet of 40 invented customers sent through an unapproved AI feature. The count is deliberately below the separate FTC threshold.

| Response step | Worked insert for the fictional event | Owner and evidence |
| --- | --- | --- |
| Identify scope | Record the institution, AI account, feature, spreadsheet and potentially affected information. | Compliance and incident lead establish the actual rule and system scope. |
| Contain and preserve | Stop additional uploads and preserve relevant facts without spreading the spreadsheet. | Incident team records timing, payload evidence and completed actions. |
| Investigate sensitive information | Determine what was accessed or used and assess the substantial-harm-or-inconvenience standard. | Privacy/legal owner documents the reasonable investigation and any exception conclusion. |
| Assess individual notice | Do not treat 40 consumers as automatically below a Regulation S-P threshold. | Notice owner applies the actual rule and relevant 30-day outer limit. |
| Coordinate provider notice | Obtain the service-provider facts and assess the applicable 72-hour provider-notification requirement. | Vendor owner separates provider notice from notices to affected individuals. |
| Close and improve | Retain decisions, actual notices if any and the remediation record. | Response owner updates the plan; no live notice is generated by this exercise. |

## Review steps

- Verify the legal and data scope: Identify covered institution status, customer information and potentially affected individuals without borrowing another rule’s threshold.
- Track separate notice duties: Record provider awareness, institution awareness, responsible recipients and the applicable timing.
- Evidence any exception: A reasonable investigation must support the relevant conclusion; a lack of reported misuse alone is not the record.

## Fictional response-plan insert

Trigger: employee reports using an AI feature with a spreadsheet containing 40 invented customer records.
Immediate routing: incident lead, privacy/compliance owner and vendor owner.
Evidence questions: which account and feature; what information; what actually reached the provider; which recipients and copies; what access/use occurred; what mitigation is evidenced.
Notice analysis: apply Regulation S-P’s affected-individual and investigation conditions. Do not apply the FTC 500-consumer threshold.
Provider coordination: document the separate provider-to-institution notice and facts.
Final decision: no live determination or notice in this exercise.

This insert supplements an existing institution-specific plan; it does not replace its roles, legal assessment or notice procedures.

## Source and scope

Guide: https://aona.ai/resources/guides/regulation-sp-ai-incident-response/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- 17 CFR 248.30: Customer-information safeguards and response: https://www.law.cornell.edu/cfr/text/17/248.30
- SEC: Regulation S-P final rule, 3 June 2024: https://www.govinfo.gov/content/pkg/FR-2024-06-03/html/2024-11116.htm
