IndustriesIndependent analysis · Our policy

Client portal for financial advisors - a primer

Vlad Kuzin13 min read
A reinforced vault door with a simple keyhole beside a compliance seal, opening into a clean well-lit client reading room

A client portal for financial advisors must meet SEC Reg S-P and GLBA Safeguards expectations while staying simple enough that clients sign in instead of reverting to email. Most tools nail one and fail the other. The portals that pass a compliance review bury clients in MFA prompts and password resets. The portals clients love store tax returns in a way that would not survive an SEC examination. You end up choosing which failure you can live with.

Three things decide it: what the rules require, what clients will tolerate, and the seven configuration choices that leave a portal used or unused.

What the rules actually require

There is no SEC rule that says "use a portal." Four rules, taken together, make email the wrong tool and a portal the practical one.

SEC Reg S-P (17 CFR 248). The 2024 amendments require registered investment advisers and broker-dealers to keep written policies protecting customer information: encryption controls, access restrictions, an incident response program. The amendments also impose a 30-day customer notification requirement after a breach involving sensitive customer information. Email has no per-message access log and no per-recipient permissions. That makes compliance hard to demonstrate during an examination.

FTC GLBA Safeguards Rule (16 CFR 314). The 2023 update broadened coverage and added specific technical requirements. Multi-factor authentication on any system containing customer information. Encryption of customer information at rest and in transit. A written incident response plan. The rule reaches most non-bank financial institutions, including independent RIAs that are not SEC-registered and most financial planners.

SEC Rule 204-2 (Books and Records). Investment advisers must retain every communication sent or received about a recommendation, advice, or transaction. The clock runs five years from the end of the fiscal year. The first two years have to sit somewhere easily accessible. A portal with an audit log produces that evidence cleanly. A personal email account does not.

FINRA Rule 4511. Broker-dealers and dual-registered advisors must preserve written communications about securities business for at least three years, in WORM format or an equivalent. Most portals built for advisors offer WORM storage as a configuration option. Consumer file-sharing tools do not.

The practical translation: if you are an RIA or a broker-dealer, your file-sharing tool needs encryption, MFA, per-document access logs, retention policies, and a documented incident response plan. A consumer Dropbox account meets none of that. Google Workspace gets there, with significant DLP configuration behind it. Dedicated advisor portals arrive that way.

The adoption problem nobody writes about

The compliance side gets the attention. Usability is what kills portal projects.

Three failure modes show up in almost every RIA I have spoken with:

  1. The MFA cliff. A 72-year-old client gets the invitation and sets up an account. Then the SMS code never arrives, because the carrier filtered it. They give up. Within a week they are emailing you their tax return.
  2. The forgotten-password loop. Six months between portal sign-ins is enough for any client to forget the password. If your reset flow requires email verification, the client is already sitting in the inbox. The document goes out from there.
  3. The "where do I click" problem. Most advisor portals are advisor dashboards with a client view bolted on. The client needs to upload one document and lands on a screen with twelve menu items.

Portal projects fail at client adoption, not compliance. A 95% advisor adoption rate with 30% client adoption means clients are still emailing tax returns.

The result is a portal with 95 percent advisor adoption and 30 percent client adoption. Compliance is happy. The client experience is worse than email.

The fix is configuration, not vendor selection. Pick a portal that lets you set the friction per action. Low friction for one-off uploads: a magic-link sign-in, no MFA, one visible action. High friction for downloads of tax returns and estate documents: MFA required, session timeout 10 minutes.

What a financial advisor portal actually needs

Seven requirements separate a working portal from a tool that passes a checklist but fails in practice.

1. Encryption at rest (AES-256) and in transit (TLS 1.2+). This is table stakes. Verify it is enabled by default, not an upsell.

2. Per-document access controls. Scope access at the file level, not just the folder level. Client A's spouse may need the joint trust and not Client A's personal 1040.

3. Per-document audit log. Who viewed, downloaded, or uploaded what, when, from which IP. You hand this to compliance during an examination. You reach for it when a client claims they "never received" a document.

4. MFA configurable by action, not by account. The strongest configuration is contextual. Low friction for routine intake, a full MFA gate for sensitive downloads. A portal that forces MFA on every sign-in spends client patience on actions that never needed it.

Ask every portal vendor for a current SOC 2 Type II report. If they cannot produce one within a week, that tells you what you need to know about their security posture.

5. SOC 2 Type II report from the vendor, on request. Ask for the current report. If the vendor cannot produce one within a week, that is the answer.

6. Retention and WORM storage. Configurable retention policies that match Rule 204-2 (five years) and FINRA 4511 (three years, WORM equivalent) without manual cleanup.

7. Client-side simplicity. A first-time client should get a requested document uploaded in under 90 seconds from the email link. If the portal needs a tour or a how-to guide, it is broken.

For ongoing planning relationships, planning software with an integrated vault (eMoney, RightCapital, Black Diamond) covers requirements 1-6 and varies on 7. For intake, ad-hoc requests, and documents collected between planning meetings, a lighter portal usually beats the full planning suite on 7.

Comparison: 7 portals advisors actually use

ToolBuilt forSOC 2 Type IIMFA + per-file accessPricing model
eMoney AdvisorFull planning + vaultYesYesPer advisor, per month ($300+/advisor)
RightCapitalPlanning + vaultYesYesPer advisor, per month (~$150/advisor)
Black Diamond (SS&C)Portfolio reporting + portalYesYesPer AUM tier, enterprise
Citrix ShareFile (Financial)Document exchangeYesYesPer user, per month
Box for Financial ServicesDocument exchange + DLPYesYesPer user, per month
LiscioClient messaging + document exchangeYesYesPer user, per month
PorticoIntake forms + document collectionAligned (SOC 2 controls in place)YesPer client tier

Pricing and features reflect vendor websites and product pages as of June 2026. Verify current rates directly with the vendor.

The honest summary: if you are doing full financial planning and need account aggregation and plan visualizations inside the same tool, eMoney or RightCapital is the buy. If you need to send and receive documents securely and your planning lives elsewhere, ShareFile and Box for Financial Services are the heavyweights with deep configuration. If your bigger pain is the intake form and document checklist at the start of every engagement and you want something purpose-built for that workflow, lighter portals fill the niche.

Portico is one of those lighter options. It handles client onboarding, intake forms, and recurring document requests. Per-client access controls, AES-256 at rest, TLS 1.2+ in transit, MFA, and a per-document audit log. It is built around the intake and document-collection workflow, not around financial planning. For ongoing planning, you still use eMoney, RightCapital, or your portfolio reporting tool.

What documents go through the portal

The eight categories below cover most independent advisory relationships. The right portal lets you scope access per category.

CategoryExamplesTypical access scope
Account statementsCustodian statements, 401(k) statementsAdvisor, client, joint owner
Tax returns1040, supporting schedules, K-1sAdvisor, client (joint files visible to spouse)
Estate documentsWill, revocable trust, beneficiary formsAdvisor, client, estate attorney (read-only)
InsuranceLife, disability, LTC policiesAdvisor, client
IdentificationDriver's license, passport, SSN cardAdvisor only, encrypted-at-rest, time-limited
Income documentsW-2, 1099, K-1Advisor, client
Prior plan documentsPrior advisor's IPS, plan PDFsAdvisor, client
Engagement docsADV Part 2, signed agreements, disclosuresAdvisor, client, compliance team

Identification documents (driver's licenses, SSN cards) should be the most restricted category — advisor-only access, encrypted at rest, with download tracking and a documented retention schedule.

Default everyone to least privilege: each document is visible to the smallest set of people who need to see it. Identification documents (driver's licenses, SSNs) get the tightest scope, with download tracking and a documented retention schedule.

For the broader category of document collection workflows that apply outside advisory practice, collect documents from clients covers the design choices in more depth.

The "we will just use encrypted email" trap

Encrypted email (Virtru, Microsoft Purview, ProtonMail Business) solves the in-transit encryption problem and helps with the recipient-control problem. It does not solve the recordkeeping problem.

Three reasons this approach falls short past five clients:

  • No central audit log. Each encrypted email lives in a thread. Answering "who has touched the Smith family tax return in the last 18 months" means searching every inbox. A portal answers it with one log.
  • No structured intake. Encrypted email moves files. It does not collect a 20-field intake form, validate the SSN format, or remind a client that the trust document is still missing.
  • No per-document access control after delivery. Once the recipient decrypts an encrypted email, the file lives on their machine. A portal keeps the file on the server, with downloads tracked and access revocable.

Encrypted email is a reasonable supplement to a portal for one-off, time-sensitive communications. It is not a substitute for the system of record.

Migrating an existing book to a portal

The hard part is not the tool. It is the behavior change, especially for older clients who have decades of email habits with you.

Three rules from advisors I have spoken with who have moved 50+ client households over:

  1. Onboard new clients first, retrofit existing clients second. Every new prospect starts on the portal as part of the engagement workflow. After three months you have an operating procedure that works, and an existing book you can migrate in cohorts.
  2. Use the portal during the annual review meeting. In the in-person or video review, walk the client through their sign-in, set up MFA together, and watch them upload one document. Adoption rate triples versus a cold email invitation.
  3. Retire email submissions on a date, with a 90-day notice. Pick the date. Say it three times, at 90, 30, and 7 days out. On the date itself, reply to any document-bearing email with a portal link. Most clients adapt within 60 days of the cutoff.

For the one-time intake portion of a new engagement — the part where you collect the W-9, prior tax returns, account statements, and signed disclosure forms — the structure is similar to other professional services. Client portal for accountants and client portal for bookkeepers cover related workflows for adjacent professions, and best client portal software gives the broader comparison set.

What the portal does not do

A portal is a request, exchange, and recordkeeping system. It is not:

  • A planning engine. It does not run Monte Carlo simulations or build retirement projections. eMoney, MoneyGuide, and RightCapital do that.
  • A CRM. It does not log calls, manage pipelines, or send birthday cards. Wealthbox, Redtail, and Salesforce Financial Services Cloud do that.
  • A custodian. It does not hold assets or execute trades.
  • A compliance program. It is one control inside a written information security program. The program itself is your responsibility.

Treat the portal as the document and intake layer. Planning, CRM, custody, and compliance stay separate systems. The portal's job is narrow: documents arrive securely, get logged, and reach the right people for the right amount of time. The thinking, the planning, and the policies are still yours.

FAQs

Do financial advisors legally need a client portal? No specific rule requires a portal, but SEC Reg S-P (17 CFR 248), the FTC's GLBA Safeguards Rule (16 CFR 314, updated 2023), and SEC Rule 204-2 require RIAs to protect nonpublic personal information and retain client records. Email is technically permitted but fails the compliance expectations those rules now imply.

What security standard should a financial advisor portal meet? SOC 2 Type II is the practical floor, with AES-256 encryption at rest and TLS 1.2 or higher in transit. The 2023 Reg S-P amendments require written incident response procedures and customer notification within 30 days of a breach involving sensitive information, so the portal should also produce a complete per-document access log on demand.

Can I use Google Drive or Dropbox for financial advisor document sharing? Consumer Google Drive and personal Dropbox do not meet Reg S-P or GLBA Safeguards expectations because they lack per-document access logging, enforced MFA, and the configuration required for handling nonpublic personal information. Google Workspace with full DLP configuration, Box for Financial Services, and ShareFile do meet the bar when configured correctly. The configuration is where most small firms fall short during an audit.

What is the difference between a financial planning portal and a client portal? A financial planning portal like eMoney or RightCapital is built around planning software with a client-facing layer that includes account aggregation, plan visualization, and a document vault. A general client portal handles document exchange, intake forms, and messaging without the planning engine. Most firms over $100M AUM run both: planning software for ongoing work, a lighter portal for intake and document requests.

How do I get clients to actually use the portal? Adoption fails because clients hit a sign-in friction wall on the first try and revert to email. The fix is to send the portal invitation during a scheduled call so the client signs in while you watch, and to configure low-friction sign-in for routine uploads while reserving MFA for sensitive downloads. Adoption rates roughly triple when the first sign-in happens with the advisor on the line.

Is a portal worth it for a solo RIA with under 25 households? It depends on what you handle. If you take in tax returns, estate documents, and ongoing account statements, the answer is yes — Reg S-P expectations apply at one client, not just 100. If you run a very narrow service (one-time financial plans, no ongoing document exchange), a properly configured Box or ShareFile account may cover you without a dedicated portal. The break-even on a per-seat portal is usually around 10 to 15 active households exchanging documents quarterly or more frequently.

What about document collection without the portal — just better email? Encrypted email (Virtru, Microsoft Purview) covers in-transit encryption and basic recipient controls, but it does not produce a central access log, does not collect structured intake forms, and does not let you revoke access after delivery. It works as a supplement for time-sensitive one-offs. It does not work as the system of record for a Reg S-P-compliant book of business.

V

Vlad Kuzin

Founder of Portico. 15 years in UX, content design, and information architecture at SAP and Intel. Ran a content design practice onboarding clients with Google Sheets, DocuSign, and email — the stitched-together workflow Portico replaces. Has worked with agencies, bookkeeping firms, consultants, and legal practices.

Onboard your next client with one link

Intake forms, documents, e-signatures, and payments in a single guided flow.

Start Free

No credit card required. Cancel anytime.

Related Articles

A lobby splitting into three separate corridors — buyer, seller, and renter — each with its own doorway and distinct set of forms on the wall
IndustriesIndependent analysis

Client onboarding for real estate - 3 flows

Real estate onboarding splits into three flows — buyers, sellers, renters — each with different paperwork. One generic intake form costs 5-10 days per deal.

13 min read
A row of mailbox slots in a stone wall, each labeled by month, replacing a cluttered shared shelf of loose folders
IndustriesIndependent analysis

Client portal for bookkeepers (2026)

A client portal for bookkeepers should collect the same 12 monthly documents from every client on schedule, without anyone chasing. Shared drives fail that job.

11 min read
A gated archway with four checkpoints — conflict check, engagement letter, identity badge, and document vault — before a courthouse corridor opens
IndustriesIndependent analysis

Client intake software for law firms - SMB guide

Law firm client intake covers four compliance-bound steps: conflict checks, engagement letters, identity verification, and document collection under $150/mo.

13 min read