Midyear IT Reality Check: What Salt Lake City Financial Advisors Need to Examine Before Q3

July 2026 | IT Support for Financial Advisors Salt Lake City | RIA Cybersecurity Services Utah | Midyear Security Review

Your Salt Lake City advisory firm hasn't stood still since January — and your IT systems haven't either.

You've added advisors to the team, adopted new tools, and made fast calls to keep client service moving. What's hard to track is the trail those decisions leave behind: who still has access to Redtail CRM or the Orion portfolio management system they no longer need, where client financial data ended up after a platform migration, and who's actually responsible for what when something goes wrong. For RIAs and wealth managers, these questions aren't just operational — they're tied directly to your SEC and FINRA compliance obligations.

By July, most advisory firms are running on assumptions about how their systems work. Here are four things every Salt Lake City financial advisor should examine before those assumptions become expensive — or become a finding during an SEC examination.

1. Access to Client Portfolios Was Expanded. Was It Ever Revisited?

A new advisor joined and needed access to Redtail and Orion right away. An operations staff member moved into a new role and picked up permissions along the way. Temporary access was granted to a compliance consultant to keep a project moving.

But access almost never gets revisited after it's no longer needed. Inside most advisory firms, the picture looks like this:

  • Advisors and staff have more privileges than their current role requires — including access to client financial data they no longer service
  • Former employees may still carry active permissions to Redtail, Black Diamond, Tamarac, or Schwab and Fidelity custodian portals
  • There's no clean view of who can actually reach client financial plans in eMoney, MoneyGuidePro, or RightCapital

Do the right people have the correct access to client financial data today? If that answer takes longer than a few seconds, it's worth a closer look. SEC cybersecurity rules expect firms to maintain documented access controls — and reviewing user access is one of the most impactful, and most overlooked, steps in both IT security and regulatory compliance for Salt Lake City financial advisors.

2. Your Compliance and Advisory Tools Solved Problems While Creating New Ones

Your advisory team needed a better way to track client relationships, so Redtail or Wealthbox CRM was added. Compliance brought on ComplySci to manage advisor certifications and disclosures. Operations adopted Docupace to streamline onboarding paperwork. The financial planning team expanded from one tool to three — MoneyGuidePro for some clients, eMoney for others, RightCapital for the newer advisors.

Every one of those was a reasonable decision. Collectively, they created something messier: client financial data now lives in more places, integrations between Orion and your CRM may not be working as intended, and visibility across systems has fragmented.

When systems coexist without anyone owning the full picture, risk doesn't announce itself. It shows up later in slower decisions, inconsistent client reporting, and data gaps that belong to nobody. An IT audit for your Salt Lake City advisory firm can map these integrations and flag where client data is flowing in ways that weren't planned — or that SEC examiners might flag.

3. Your Backup and Recovery Confidence for Client Financial Plans Is Probably Assumed

Most Salt Lake City advisory firms have backups in place and operate under a false sense of security about what those backups actually cover. Recovery is rarely tested, the realistic timeline to restore a client's financial plan in eMoney or eMoney archive is unclear, and ownership of the recovery process often isn't defined.

When something goes wrong — ransomware, a server failure, or an accidental deletion of a client document in ShareFile — the conversation too often starts with: 'Wait, who handles this?'

Having backups is not the same as being able to recover. The difference between them only becomes clear at the worst possible time — when a client is waiting on a plan update or an SEC examiner is asking about your data integrity controls. A midyear IT review is the right moment to test that process before you need it, and before someone asks for documentation that doesn't exist.

4. IT Responsibility Has Blurred as Your Firm Has Added Advisors and Tools

Early on, who owned what was clear. Your internal operations person handled certain systems, your broker-dealer or custodian handled others, and responsibilities were roughly defined — even if nobody had formally documented them.

Then you added advisors, brought on new compliance software, migrated to a new portfolio management platform, and somewhere in the middle of that growth, ownership got blurry. Now when something breaks across Orion and your CRM integration, or email archiving through Smarsh stops syncing correctly, the question of who takes the lead gets answered in real time. Issues bounce between your internal team, your software vendors, and whoever your previous IT contact was. Small problems sit unresolved longer than they should, and nobody's sure whose job it is.

Managed IT support for financial advisors in Salt Lake City can solve this by establishing clear ownership and documented escalation paths — so when something alarming happens to client financial data, everyone knows exactly what to do, and you have the documentation to show SEC examiners that your incident response plan is more than a PDF nobody has read.

Most Risk Comes From What's Changed, Not What's Broken

The vulnerabilities that hurt advisory firms most aren't usually dramatic system failures. They're the slow drift — access to client portfolios that was never revoked, integrations between compliance tools and CRMs that were never properly tested, financial plans in eMoney that were never confirmed to be backed up, and IT responsibilities that were never formally documented when your firm grew from 4 advisors to 12.

A midyear IT review with your Salt Lake City IT services team is the right time to close those gaps before Q3 opens new ones — and before the next SEC exam cycle finds them for you.

Frequently Asked Questions

Do you offer SEC and FINRA-compliant IT services for financial advisory firms in Salt Lake City?

Yes. Qual IT works with Salt Lake City RIAs and wealth management firms to align IT infrastructure and security practices with SEC and FINRA cybersecurity requirements — including access control documentation, backup verification, incident response planning, and vendor due diligence.

Why should Salt Lake City financial advisors do a midyear IT review?

By July, most advisory firms have made enough changes — new hires, new software, new custodian integrations — that their IT environment looks different than it did in January. A midyear review helps confirm that access to client financial data, backup coverage of financial plans, and security controls still match how the firm actually operates today — and what SEC examiners will expect to see.

What does a midyear IT security review cover for an RIA?

A thorough review for a financial advisory firm covers user access to CRM and portfolio management systems, backup and recovery testing of client financial data, software integrations between compliance and planning tools, custodian portal access, SEC/FINRA compliance alignment, email archiving integrity through Smarsh or Global Relay, and any new risks introduced by business changes in the first half of the year.

How long does a midyear IT assessment take for a Salt Lake City advisory firm?

For most small and mid-sized RIAs and wealth management firms in the Salt Lake Valley, a focused IT review can be completed within a few hours. Qual IT offers a free 10-minute discovery call to help identify where to start.

Ready to Clear the Assumptions Before They Cost You?

We work with Salt Lake City financial advisors to meet SEC/FINRA requirements and protect client data. Qual IT helps RIAs and wealth management firms identify where their systems have drifted, where access to client financial data needs to be reviewed, and what needs attention before Q3 — or before an SEC examiner asks the same questions.

Schedule your free discovery call today.