Legal

Business Continuity Notice

Our commitment to uninterrupted service delivery, our 24-hour recovery time objective, key continuity capabilities, contingency plan components, and alignment with FINRA 4370, SEC guidance, OCC, NYDFS 500, and the FFIEC BCM booklet.

Effective date: August 2026

1. Our Business Continuity Approach

International Compliance Solutions LLC ("ICS") maintains a comprehensive Business Continuity Plan ("BCP") designed to ensure the uninterrupted delivery of compliance consulting services. The plan addresses the full range of events that could disrupt operations — adverse weather, facility disruptions, technology failures, cybersecurity incidents, public health emergencies, and loss of key personnel — and is maintained in coordination with our IT vendor, Sinergy Systems. It is reviewed and updated at least annually.

2. Recovery Time Objective

ICS targets the resumption of all client services within 24 hours of any significant business disruption. For technology-related disruptions, ICS maintains redundant access to all critical systems and backup research methods to support uninterrupted service delivery.

3. Key Continuity Capabilities

  • ·Remote work capability: all ICS professional staff are equipped and trained to work remotely. In the event of a facility disruption, ICS can transition to fully remote operations without disruption to client services.
  • ·Cloud backup and storage: all client work product, files, and documentation are stored securely in cloud-based systems with regular backups, accessible by authorized staff from any location.
  • ·Personnel continuity: ICS maintains a succession plan and cross-training program. Identified backup personnel are prepared to assume responsibilities for principal compliance officers in the event of unavailability.
  • ·IT resilience: Sinergy Systems provides continuous monitoring, real-time vulnerability assessment, and rapid incident response. Regular testing and tabletop exercises validate recovery procedures.
  • ·Technology independence: ICS does not rely exclusively on any single technology platform. Backup research and drafting capabilities are maintained independently of any AI or specialized compliance technology tool.
  • ·Client communication: in the event of a significant disruption, ICS will promptly notify affected clients through established channels, providing status updates and expected resumption timelines.

4. Contingency Plan Components

  • ·Computer Emergency Response Plan: defines who is contacted, when, and how for technology emergencies, including cybersecurity incidents, system failures, and data loss events.
  • ·Succession Plan: describes the flow of responsibility and authority when key personnel are unavailable.
  • ·Data Backup and Restoration Plan: details what data is backed up, frequency, storage locations, and procedures for restoring data following a disruptive event.
  • ·Criticality of Service List: ranks all ICS services by business criticality and establishes the priority order for restoration.
  • ·Equipment Replacement Plan: identifies equipment required to restore service delivery, replacement priority, and sources for rapid procurement.
  • ·Communication and Media Management Plan: designates authorized spokespersons and establishes guidelines for communications with clients, regulators, and media.

5. Technology Continuity — Primary and Backup Systems

  • ·Compliance management: SMART-RIA (primary); manual procedures and document management (backup).
  • ·Email and archiving: cloud-based system with redundant archiving; accessible remotely from any authorized device.
  • ·Regulatory research: Thomson Reuters (primary); direct access to SEC EDGAR, FINRA, federal agency publications, and other public resources (backup).
  • ·AI research tools: Anthropic Claude (primary); direct manual regulatory research (backup). AI tools are non-critical — all services deliverable without AI.
  • ·Client records: secure cloud storage with automated, geographically redundant backup.
  • ·Communications: cloud-based email and video conferencing, accessible from any location.
  • ·Financial systems: QuickBooks Online (cloud-based) with backup data exports maintained.

6. Testing and Maintenance

  • ·Annual tabletop exercises: management and key personnel conduct annual simulations of realistic disruption scenarios to identify gaps and validate response procedures.
  • ·IT assessment: Sinergy Systems conducts periodic assessments across Technology, People, and Process, benchmarked against ISO 27001, NIST 800-53, and FFIEC standards.
  • ·Annual plan review: the BCP is reviewed and updated at minimum annually, or more frequently following any material change in operations, technology, or regulatory environment.
  • ·Vendor review: ICS monitors key technology vendors for continuity developments and obtains vendor BCP summaries as part of ongoing oversight.

7. Regulatory Alignment

ICS's Business Continuity Plan is designed to be consistent with FINRA Rule 4370, SEC business continuity guidance for investment advisers, OCC business continuity management guidance, NYDFS Cybersecurity Regulation (23 NYCRR 500), and the FFIEC Business Continuity Management booklet.

8. Client Notification Procedures

  • ·Assess the nature, scope, and expected duration of the disruption as quickly as possible.
  • ·Notify affected clients through established channels (email and telephone), describing the disruption, expected impact on service delivery, and anticipated timeline for resumption.
  • ·Provide regular status updates until normal operations are fully resumed.
  • ·Notify regulators as required under applicable law or regulatory obligation.
  • ·Document the disruption, the response, and lessons learned for incorporation into future BCP updates.
  • ·ICS maintains current emergency contact information for all active clients and confirms it at least annually.

9. Requesting Our Business Continuity Plan

Clients may request a summary of ICS's Business Continuity Plan for vendor due diligence purposes by submitting a written request. This summary may be provided to regulators, examiners, or internal risk and compliance functions as part of a client's third-party risk management program.

10. Contact

Questions about this Notice, or to request BCP documentation, may be directed to Juan Carlos Riera, President — International Compliance Solutions LLC, 2600 Douglas Rd. Suite 908, Coral Gables, FL 33134 · +1 (305) 448-0014 · info@ics-compliance.com.

Questions about this document may be directed to info@ics-compliance.com or in writing to International Compliance Solutions LLC, 2600 Douglas Rd. Suite 908, Coral Gables, FL 33134.