# Regulation S-P AI incident insert

A fictional covered institution investigates a spreadsheet of 40 invented customers sent through an unapproved AI feature. The count is deliberately below the separate FTC threshold.

Synthetic event, customers and roles. No actual investigation finding, notice, provider assurance or control result is represented.

Source: https://aona.ai/resources/guides/regulation-sp-ai-incident-response/
Sources checked: 2026-09-21

## Keep the notice paths distinct

### Service provider

Notify the institution under the applicable provider provision

Note: The described outer limit is 72 hours.

### Covered institution

Assess, contain and investigate

### Affected individual

Receive required notice from or on behalf of the institution

Note: Apply the separate notice conditions and timing.

| Response step | Worked insert for the fictional event | Owner and evidence |
| --- | --- | --- |
| Identify scope | Record the institution, AI account, feature, spreadsheet and potentially affected information. | Compliance and incident lead establish the actual rule and system scope. |
| Contain and preserve | Stop additional uploads and preserve relevant facts without spreading the spreadsheet. | Incident team records timing, payload evidence and completed actions. |
| Investigate sensitive information | Determine what was accessed or used and assess the substantial-harm-or-inconvenience standard. | Privacy/legal owner documents the reasonable investigation and any exception conclusion. |
| Assess individual notice | Do not treat 40 consumers as automatically below a Regulation S-P threshold. | Notice owner applies the actual rule and relevant 30-day outer limit. |
| Coordinate provider notice | Obtain the service-provider facts and assess the applicable 72-hour provider-notification requirement. | Vendor owner separates provider notice from notices to affected individuals. |
| Close and improve | Retain decisions, actual notices if any and the remediation record. | Response owner updates the plan; no live notice is generated by this exercise. |

## Review checklist

- [ ] Verify the legal and data scope
  Identify covered institution status, customer information and potentially affected individuals without borrowing another rule’s threshold.
- [ ] Track separate notice duties
  Record provider awareness, institution awareness, responsible recipients and the applicable timing.
- [ ] Evidence any exception
  A reasonable investigation must support the relevant conclusion; a lack of reported misuse alone is not the record.

## Included example files

- regulation-sp-ai-response-insert.md
- regulation-sp-ai-response-insert.csv

## Source references

- 17 CFR 248.30: Customer-information safeguards and response: https://www.law.cornell.edu/cfr/text/17/248.30 (2026-09-21)
- SEC: Regulation S-P final rule, 3 June 2024: https://www.govinfo.gov/content/pkg/FR-2024-06-03/html/2024-11116.htm (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
