The Broker Protocol Does Not Cover Your RIA-to-RIA Move. Here Is What Governs It Instead

FastTrackr AI TeamJul 29, 202611 min read

The Protocol for Broker Recruiting is a voluntary agreement between signatory firms. If your current RIA never joined it, or your new firm has not, the Protocol simply does not apply to your move. What governs instead is your employment agreement, trade secret law, and Regulation S-P. Those rules are less predictable and less forgiving.

This is one of the most common and most expensive misunderstandings in the independent channel. An advisor reads a dozen articles about the five permitted data fields, builds their departure plan around them, and discovers after resigning that the framework they planned against was never available to them. The five-field rule was never a law. It is a term in a contract between firms, and if your firms are not parties to it, the term is not yours to use.

We have written separately about running a non-Protocol breakaway when a wirehouse has withdrawn from the agreement. This article covers a different and increasingly common situation: a move between two registered investment advisers, where the Protocol frequently was never in play at all.

Why RIA-to-RIA is different

The Protocol originated among brokerage firms and its signatory list, while it does include RIAs, covers a small fraction of the roughly fifteen thousand SEC-registered advisers. Most independent RIAs, especially firms under a few hundred million in AUM, have never signed it.

That produces three practical differences from the wirehouse breakaway most content describes.

Protocol move (both firms signatories) RIA-to-RIA move (typical)
What you may take Five specified client data fields, per the agreement Whatever your employment agreement and applicable law permit, which may be nothing
Litigation posture Signatories generally agree not to pursue claims when the Protocol is followed No agreed framework, standard contract and trade secret claims available
Predictability High, the rules are written and shared Low, depends on your contract and your state
What decides the outcome Compliance with the agreement Your specific restrictive covenants and how your state's courts treat them

The last row is the important one. In a Protocol move, following the procedure is close to a complete answer. In an RIA-to-RIA move, there is no procedure to follow. There is a contract you signed, possibly years ago, possibly without reading it closely, and a body of state law that varies enormously.

Step one: read your actual agreement

Before anything else, find and read every document you signed with your current firm. Not the offer letter you remember. All of them, including anything you signed when the firm was acquired, restructured, or updated its handbook.

You are looking for five specific things.

Non-solicitation of clients. The most commonly enforced provision. Read the scope carefully: does it cover all firm clients, or only clients you personally serviced? Does it prohibit soliciting, or also accepting unsolicited business? The distinction between those two is where most disputes live, and courts in many states treat a ban on accepting unsolicited business far less favorably than a targeted ban on active solicitation.

Non-solicitation of employees. Frequently overlooked and frequently violated by advisors who bring an assistant with them.

Non-compete. Enforceability varies dramatically by state, and the landscape has been moving. Some states prohibit them outright for most employees, some enforce them as written, and many apply a reasonableness test on duration, geography, and scope. Whatever the general rule in your state, the answer for your specific agreement is a question for a lawyer in that state, not for a blog post.

Confidentiality and trade secret provisions. These survive independently of the non-solicit and are often broader than advisors expect, covering client lists, financial information, and internal materials.

Notice and garden leave. Some agreements require weeks of notice, during which you may be restricted from preparing to compete.

The output of this reading should be a written list of what the contract actually says, taken to a securities attorney in your state before you take any other step. Our breakdown of what software can automate and what needs a securities attorney draws the line for a Protocol breakaway, and the line moves further toward counsel in a non-Protocol RIA move.

Step two: understand what trade secret law adds

Even if your agreement is silent or weak, trade secret law provides an independent basis for a claim.

The federal Defend Trade Secrets Act creates a private civil action for misappropriation of a trade secret related to a product or service used in interstate commerce. The statutory definition of a trade secret turns on two elements: the owner took reasonable measures to keep the information secret, and the information derives independent economic value from not being generally known or readily ascertainable.

Whether a client list qualifies is fact-specific and courts have come out both ways. A list that is essentially a compilation of names available in public directories is a weaker candidate than one containing account values, holdings, risk tolerances, and contact preferences accumulated over years. The second kind is what sits in most RIA CRMs.

The practical consequence is straightforward: the fact that your non-solicit may be unenforceable in your state does not mean you can take the client file. Those are separate questions with separate answers, and advisors routinely conflate them.

Step three: Regulation S-P, the constraint nobody plans for

This is the provision that catches even careful advisors, because it is not about your contract at all.

Client information held by a registered investment adviser is nonpublic personal information subject to Regulation S-P, which governs the privacy of consumer financial information and the safeguarding of customer information. The obligation belongs to the firm, and it constrains what can be shared with unaffiliated third parties.

Your new firm is an unaffiliated third party.

That means the analysis of whether you can bring client data is not only about what your contract permits and what trade secret law protects. It is also about whether the sending firm's privacy policy and the client's own choices permit that information to move. Even in a Protocol move, the Protocol does not waive privacy obligations, which is a point that gets lost in the focus on the five fields.

What advisors do in practice, on counsel's advice, is separate the two things: the information needed to contact a client and tell them where you went, versus the account information needed to open and fund accounts. The second category generally comes from the client, not from the old firm's systems. The client requests statements, or provides them, or authorizes the new firm to gather what it needs.

That is not a workaround. It is the actual mechanism, and it changes your operational plan significantly.

What this does to the operational timeline

Here is the part that matters for anyone actually running the transition rather than advising on it. A non-Protocol RIA move typically means you arrive at your new firm with less usable data than a Protocol move would provide, and you get it later.

Data source Protocol move Non-Protocol RIA move
Client contact details Permitted five fields, available at resignation Depends on contract and counsel, often limited
Account numbers and registrations Not covered by the five fields Not available from the old firm
Account values and holdings Not covered Not available from the old firm
Statements From the client From the client
When usable data arrives After client contact After client contact, and often later

Notice that the bottom rows are the same in both columns. Account-level detail comes from the client's own statements in either scenario. What differs is how quickly you can reach the client to ask.

This is why statement processing capacity, rather than data you brought with you, is the real determinant of repapering speed in a non-Protocol move. Every household arrives as a set of PDFs from a client who wants this over with, and the work of turning those into validated account forms is the whole job. Reading them at volume is what document intelligence does, and it matters more in a non-Protocol move precisely because you have nothing else to work from.

The sequence that keeps you out of trouble

Assuming counsel has reviewed your agreements, the general shape of a defensible non-Protocol RIA transition:

Before resignation. Do not take documents, files, exports, or screenshots. Do not email anything to a personal account. Do not have your new firm's paperwork pre-filled with client data. Advisors lose cases on the digital trail far more often than on the substance, because forensic evidence of a mass export at 11pm on a Friday is easy to produce and hard to explain. Preparing to compete and misappropriating are different things, and the record you leave should make that obvious.

At resignation. Resign in writing, return firm property, and follow the notice terms in your agreement. Keep a record of what you returned.

Client contact. What you may say, to whom, and when, is entirely governed by your agreement and your state's law here. There is no Protocol safe harbor. Announcement versus solicitation is a real legal line and our guide to what a breakaway advisor can legally tell clients and when covers the distinction, with the caveat that in a non-Protocol move you have less room and should be operating from counsel's specific advice rather than general guidance.

Data collection. Client-provided statements and client-authorized data gathering. Build the intake so a client can send everything once, in whatever format they have, rather than making them field repeated requests. Every additional round trip costs days and goodwill.

Repapering. Standard from here: extract, validate, stage, submit, work exceptions. This is the part that is identical regardless of Protocol status, and it is where the timeline is actually won or lost.

What firms on the hiring side should do

If you are the RIA recruiting the advisor, you have your own exposure, and it is larger than most independent firms assume.

Ask for the agreements before you make an offer, and have your own counsel read them. Do not accept an advisor's summary of what their contract says. Document that you instructed the incoming advisor not to bring firm property or client data, and keep that documentation. Do not accept data that arrives from the old firm's systems, regardless of how it gets to you. Build an intake process that starts from client-provided information by default, so the clean path is also the easy path.

Firms that recruit regularly should make this a standard onboarding artifact rather than an ad hoc conversation, which is one of the things transition consultants are typically brought in to systematize. Running it as a repeatable process on an advisor transition platform also produces the audit trail that becomes valuable if the old firm ever asks how the data got there. The advisor transition case study walks through the operational sequence on a real book.

The summary

The Protocol is a contract between firms, not a rule of law, and it does not travel with you. In an RIA-to-RIA move it frequently was never available in the first place.

What governs instead: the restrictive covenants you actually signed, trade secret law that operates independently of those covenants, and Regulation S-P obligations that belong to the firm rather than to you. None of those produce a clean five-field answer. All of them are fact-specific and state-specific enough that general guidance, including this article, is a starting point for a conversation with a securities attorney rather than a substitute for one.

The operational consequence is the one thing that generalizes: you will arrive with less data, later, and the transition will be decided by how fast you can turn client-provided statements into validated paperwork. Plan the intake accordingly, and start building that capability before you resign rather than after.

Frequently Asked Questions

Does the Broker Protocol apply when moving from one RIA to another?

Only if both firms are signatories to the agreement, which is uncommon among independent RIAs. The Protocol is a voluntary contract between the firms that joined it, not a regulation. If either firm has not signed, the Protocol's five-field allowance and its litigation truce are unavailable, and the move is governed by the advisor's employment agreement, trade secret law, and privacy rules instead.

If my non-compete is unenforceable in my state, can I take my client list?

No, those are separate questions. Non-compete enforceability is a matter of state contract law. Whether a client list is protectable is a matter of trade secret law, which turns on whether the firm took reasonable measures to keep the information secret and whether it derives value from not being generally known. A firm can lose on the non-compete and still prevail on a misappropriation claim.

Why does Regulation S-P matter in an advisor transition?

Because client information held by an adviser is nonpublic personal information, and the receiving firm is an unaffiliated third party. The obligation sits with the firm rather than the individual advisor, and it applies regardless of Protocol status. In practice this is why account-level data comes from the client's own statements rather than from the old firm's systems, in both Protocol and non-Protocol moves.

What is the most common mistake advisors make in a non-Protocol RIA move?

Creating a digital trail before resignation. Exporting a CRM, emailing files to a personal account, or having the new firm's paperwork pre-populated with client data are all easy to prove forensically and difficult to explain, and they convert a contract dispute into a misappropriation claim. Preparing to compete is generally permissible. Taking the firm's data is a different act.

How does a non-Protocol move change the repapering timeline?

You arrive with less usable data and receive it later, so the transition depends almost entirely on how quickly client-provided statements can be turned into validated account forms. Account numbers, registrations, and holdings come from the client in either scenario, but in a non-Protocol move you also have limited contact data to start from, which compresses the window and makes statement processing capacity the binding constraint.

See how FastTrackr fits your transition.

A 20-minute walkthrough is enough to show you whether this works for your book.

More from the blog