Kandji vs Rippling IT for an RIA's Advisor Laptops
For a registered investment advisor, device management decides whether a lost laptop is a contained incident or a reportable one, and regulators expect a written plan. Kandji suits Apple-based advisors in one office, while Rippling suits remote or branch advisors. Each laptop holds account balances, Social Security numbers, and estate planning details.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Why examiners care about laptop-level controls
A compliance exam will typically ask how the firm protects client data on devices that leave the office, and a vague answer is worse than no answer at all in that conversation. Full-disk encryption, enforced screen lock, and current patch levels are the baseline most firms should be able to demonstrate on every advisor's laptop without hesitation. Whichever platform you choose, the goal is being able to answer that question with evidence pulled from a dashboard, not with a promise about what the firm generally tries to do, since a promise is not evidence and examiners know the difference.
Kandji's case for advisors on Apple hardware
Many advisory firms run on Macs, and Kandji's pre-built compliance baselines make it straightforward to show that encryption and patch levels meet a defensible standard across every advisor, including remote and branch staff who rarely visit a home office. Its zero-touch enrollment also matters when onboarding a new advisor quickly, since a laptop can arrive already configured to the firm's standard rather than needing manual setup before it can be trusted with client data.
Rippling's case for firms with remote and branch advisors
Advisory firms with advisors working from home offices or small branch locations benefit from Rippling's tie between device access and the same employment record used for payroll, since a departing advisor's access can be revoked from one place regardless of where they were physically located. For a firm managing several remote or branch staff who rarely come into a central office, that single point of control reduces the chance that a departure in a satellite location gets handled less rigorously than one at headquarters, simply because nobody there happened to notice the gap.
What device policy doesn't cover in a compliance exam
Device encryption protects data at rest; it doesn't address how client data is transmitted, how records are retained, or how a departing advisor's client relationships and their associated data are handled during a transition. Those are separate compliance obligations that a firm's counsel or compliance officer should own directly, informed by the firm's own regulatory situation rather than general guidance, since retention and transfer rules vary by circumstance in ways worth confirming with a professional rather than assuming.
A gap that shows up during an advisor's departure
The riskiest moment at most advisory firms isn't day-to-day operations, it's an advisor's departure, when access to client data needs to be cut cleanly while client relationships are transitioned to remaining staff. A laptop that isn't wiped promptly, or credentials that aren't revoked the same day, is exactly the kind of gap an examiner or a departing advisor's next employer might notice. Build the device wipe into the same checklist as the broader departure and transition process, not as an afterthought handled separately once everyone has already moved on.
Choosing based on how your firm actually operates
A firm with advisors concentrated in one office and mostly on Macs gets a fast, demonstrable baseline from Kandji. A firm with remote or branch advisors, already tracked through Rippling for payroll, gets more value from keeping device access tied to that same employment record regardless of location. Either way, loop in your compliance officer on the decision, since the platform choice should support the firm's written data security plan, not be made independently of it.
Building the case file before the examiner asks for it
Rather than waiting for an exam to reveal a gap, build a simple internal file now: a list of every advisor laptop, its enrollment date, current patch status, and encryption status, refreshed on a regular schedule. That file is exactly what an examiner will ask to see, and having it ready, current, and accurate is a very different experience than scrambling to assemble it once a request lands with a deadline attached. Treat it as a living document your operations team owns, not a one-time project completed and forgotten.
Build the examiner file with these entries:
- List every advisor laptop with its enrollment date.
- Record current patch status and encryption status for each device, refreshed on a regular schedule.
- Enforce full-disk encryption, screen lock, and current patch levels as the baseline you can demonstrate on request.
- Wipe a departing advisor's laptop and revoke credentials the same day, while client relationships transition to remaining staff.
- Ask counsel or your compliance officer about data transmission, record retention, and transition handling, which device policy does not cover.
What Good Looks Like
Every advisor's laptop is encrypted and enrolled before they access client data, and their access is fully revoked the same day their departure or role change takes effect, regardless of location.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Rippling ties a departing advisor's device access to the same employment record that ends their pay, which helps a branch or remote departure get handled as rigorously as one at headquarters.
Gusto runs payroll for the firm's advisors and staff separately from device management, keeping the two systems distinct as the firm grows.
Frequently Asked Questions
Does encrypting advisor laptops satisfy an SEC or state examiner's data security expectations by itself?
No. Encryption is one control examiners typically expect to see, but a firm's written information security plan needs to cover data transmission, retention, vendor access, and incident response as well. Device management supports the plan; it isn't the whole plan, and a compliance officer or attorney should confirm what your specific plan needs to cover.
How should a firm handle a departing advisor's laptop and client access?
Wipe the device and revoke access to client records the same day the departure is effective, coordinated with however the firm is transitioning those client relationships. This should be part of a documented departure checklist rather than an ad hoc step someone remembers to do eventually.
Is Rippling worth it for a firm with advisors in multiple branch locations?
It can be, since its device management ties access to the same employment record regardless of where an advisor is physically located, which helps ensure a branch departure is handled as rigorously as one at headquarters. A firm with only one location and low advisor turnover may not need that specific advantage.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
Justworks vs Rippling for a Registered Investment Advisor
Three criteria for a registered investment advisory firm to weigh when choosing between Justworks and Rippling for payroll, benefits, and staffing.
Rippling vs Firstbase When an Advisor Leaves With a Client Book
For registered investment advisory firms: comparing Rippling and Firstbase for advisor laptops and what happens to client data when an advisor departs.
Rippling vs Gusto for RIAs Paying Revenue Share by Book Size
Advisor pay that shifts as a book of business grows, plus multi-state registration, makes an RIA's payroll different. Here's the Rippling vs Gusto view.
Make vs Zapier for RIAs: Onboarding and Custodian Data
Compare Make and Zapier for a registered investment advisory firm: client onboarding, custodian data sync and meeting scheduling, with compliance in mind.
Deel vs Remote for RIAs: Hiring Ops and Compliance Staff
Pitfalls registered investment advisors run into when using Deel or Remote to hire portfolio operations and compliance support staff internationally.
The Client Onboarding Checklist RIAs Can't Afford to Skip
An incomplete KYC file or an unreviewed marketing post is where RIAs create real regulatory exposure. Here's how to build the checklist that catches it first.