Compliance Policies & Procedures: What must an RIA include?

A well-written policies and procedures manual is the foundation of an investment adviser's compliance program. Yet many registered investment advisers treat it as a document they only update when preparing for an SEC examination.

Regulators expect much more.

Under Rule 206(4)-7 of the Investment Advisers Act of 1940, every registered investment adviser must adopt and implement written policies and procedures that are reasonably designed to prevent violations of the Advisers Act. Those policies should reflect your firm's actual business, not simply a generic template.

Whether you're launching a new advisory firm or reviewing your compliance program, here's what your policies and procedures manual should include.

Why Is an RIA Policies and Procedures Manual Required?

The SEC adopted Rule 206(4)-7 to require investment advisers to establish compliance programs tailored to their specific business.

Your policies and procedures manual should:

  • Address the risks associated with your business

  • Describe how your firm complies with applicable regulations

  • Assign responsibility for compliance activities

  • Provide procedures employees can actually follow

  • Serve as the basis for your annual compliance review

A manual that sits on a shelf and doesn't reflect your day-to-day operations offers little value and may even create unnecessary examination risk.

Your Manual Should Be Tailored to Your Firm

One of the most common deficiencies identified during regulatory examinations is the use of generic compliance manuals.

Simply purchasing a template isn't enough.

For example, if your manual discusses private fund valuation procedures but your firm only manages retail separately managed accounts, those policies may not be appropriate.

Likewise, if you:

  • Use social media

  • Outsource portfolio management

  • Use model portfolios

  • Recommend proprietary products

  • Have custody

  • Charge performance fees

your manual should specifically address those risks.

The SEC and state regulators expect your compliance program to reflect how your business actually operates.

Key Sections Every RIA Policies and Procedures Manual Should Include

While every firm's manual will differ, most should address the following areas.

Compliance Program Administration

Start by explaining how your compliance program operates.

Include:

  • Responsibilities of the Chief Compliance Officer and delegation

  • Supervision of employees

  • Escalation procedures

  • Documentation requirements

  • Annual review process

Fiduciary Duty and Conflicts of Interest

Investment advisers owe clients a fiduciary duty.

Your manual should explain procedures for identifying, mitigating, disclosing, and monitoring conflicts, including:

  • Outside business activities

  • Gifts and entertainment

  • Referral arrangements

  • Proprietary products

  • Revenue sharing

  • Personal relationships

Code of Ethics Administration

Although your Code of Ethics is typically a separate document, your manual should explain how it is administered.

Include procedures for:

  • Personal securities reporting

  • Initial and annual holdings reports

  • Quarterly transaction reporting

  • Pre-clearance requirements

  • Restricted lists

  • Employee certifications

Portfolio Management

Document how investment decisions are made.

Topics may include:

  • Investment objectives

  • Client suitability

  • Asset allocation

  • Model management

  • Investment restrictions

  • Proxy voting (if applicable)

  • Rebalancing procedures

  • Account monitoring

Trading Practices

Your manual should explain how your firm seeks best execution.

Include procedures regarding:

  • Trade allocation

  • Block trading

  • Best execution reviews

  • Error corrections

  • Soft dollars (if applicable)

  • Trade monitoring

Marketing Rule Compliance

The Marketing Rule continues to be a major examination focus.

Your policies should address:

  • Advertisement review and approval

  • Testimonials

  • Endorsements

  • Third-party ratings

  • Performance advertising

  • Hypothetical performance

  • Books and records requirements

Be sure to address how your firm handles these risks, not just what the rule permits and prohibits.

Form ADV Updates

Explain how your firm monitors changes that may require amendments to Form ADV.

Include procedures for:

  • Annual updating amendments

  • Other-than-annual amendments

  • Responsibility for filing

  • Internal review process

Cybersecurity

Every advisory firm should address cybersecurity.

Your manual should include policies regarding:

  • Password management

  • Multi-factor authentication

  • Remote work

  • Vendor management

  • Incident response

  • Data backups

  • Access controls

  • Employee training

Privacy

Address compliance with Regulation S-P.

Include procedures for:

  • Protecting client information

  • Privacy notices

  • Information sharing

  • Data disposal

  • Incident response

Books and Records

Describe how records are maintained.

Include:

  • Required record retention

  • Electronic storage

  • Email retention

  • Marketing records

  • Trade documentation

  • Accessibility during examinations

Review what records an RIA is required to keep.

Business Continuity

Describe how the firm will continue operations during disruptions.

Topics include:

  • Disaster recovery

  • Remote operations

  • Communication plans

  • Technology failures

  • Vendor disruptions

  • Key personnel succession

Vendor Oversight

Many advisers rely heavily on third-party vendors.

Your manual should describe how vendors are:

  • Selected

  • Reviewed

  • Monitored

  • Evaluated for cybersecurity risk

  • Documented

Compliance Testing

Policies should explain how compliance is monitored throughout the year.

Examples include:

  • Personal trading reviews

  • Advertising reviews

  • Best execution reviews

  • Fee testing

  • Email reviews

  • Branch reviews (if applicable)

Common Mistakes RIAs Make

Many compliance manuals become outdated because firms only review them before an examination.

Some of the most common mistakes include:

Using a generic template

Templates can provide a useful starting point, but they should never be adopted without customization.

If your manual references services your firm doesn't offer—or omits risks unique to your business—it may raise concerns during an examination.

Policies don't match actual practice

Regulators don’t just review your written policies.

Examiners compare them to what employees actually do.

For example:

  • Your manual requires quarterly advertising reviews—but none occur.

  • Employees are required to pre-clear trades—but no documentation exists.

  • Cybersecurity training is required annually—but it hasn't been conducted.

If your written policies promise procedures your firm isn't following, that inconsistency can be more problematic than having no written procedure at all.

Failing to update the manual

Your business evolves over time. Your compliance manual should evolve with it.

Common events that should trigger a review include:

  • Hiring employees in new roles

  • Launching new services

  • Using new technology

  • Outsourcing functions

  • Regulatory changes

  • Acquisitions

  • Changes in custody practices

Policies that are too vague

Statements such as "The firm complies with applicable regulations." don't tell employees what they should actually do.

Good policies explain:

  • Who performs the task

  • When it's completed

  • How it's documented

  • Who reviews it

Specific procedures are far more useful than broad statements of intent.

Forgetting operational areas

Many firms focus heavily on investment management but overlook areas such as:

  • Vendor oversight

  • Cybersecurity

  • Marketing reviews

  • Electronic communications

  • Business continuity

  • Third-party technology

Regulators are increasingly examining these operational controls as part of a firm's overall compliance program.

Review Your Manual at Least Annually

Rule 206(4)-7 requires advisers to review the adequacy of their policies and procedures and the effectiveness of their implementation at least annually.

An annual review should consider:

  • Regulatory changes

  • Business changes

  • Examination findings

  • Compliance testing results

  • Client complaints

  • Operational issues

  • Technology changes

Any necessary revisions should be documented and implemented promptly.

Check out our Annual Review Checklist!

Final Thoughts

Your policies and procedures manual should be more than a document created to satisfy a regulatory requirement. It should serve as a practical guide for how your firm manages compliance every day.

A manual that is tailored to your business, regularly updated, and consistently followed can help reduce compliance risk and better prepare your firm for an SEC examination.

Need Help Reviewing Your Compliance Manual?

Whether you're creating a new compliance manual, updating an existing one, or preparing for an SEC examination, RIA Compliance Desk offers practical guidance designed specifically for registered investment advisers.

Members receive ongoing compliance Q&A, practical resources, templates, monthly regulatory updates, and access to additional compliance review services when more in-depth assistance is needed.

Next
Next

What Records Must An RIA Keep?