Compliance Policies & Procedures: What must an RIA include?
A well-written policies and procedures manual is the foundation of an investment adviser's compliance program. Yet many registered investment advisers treat it as a document they only update when preparing for an SEC examination.
Regulators expect much more.
Under Rule 206(4)-7 of the Investment Advisers Act of 1940, every registered investment adviser must adopt and implement written policies and procedures that are reasonably designed to prevent violations of the Advisers Act. Those policies should reflect your firm's actual business, not simply a generic template.
Whether you're launching a new advisory firm or reviewing your compliance program, here's what your policies and procedures manual should include.
Why Is an RIA Policies and Procedures Manual Required?
The SEC adopted Rule 206(4)-7 to require investment advisers to establish compliance programs tailored to their specific business.
Your policies and procedures manual should:
Address the risks associated with your business
Describe how your firm complies with applicable regulations
Assign responsibility for compliance activities
Provide procedures employees can actually follow
Serve as the basis for your annual compliance review
A manual that sits on a shelf and doesn't reflect your day-to-day operations offers little value and may even create unnecessary examination risk.
Your Manual Should Be Tailored to Your Firm
One of the most common deficiencies identified during regulatory examinations is the use of generic compliance manuals.
Simply purchasing a template isn't enough.
For example, if your manual discusses private fund valuation procedures but your firm only manages retail separately managed accounts, those policies may not be appropriate.
Likewise, if you:
Use social media
Outsource portfolio management
Use model portfolios
Recommend proprietary products
Have custody
Charge performance fees
your manual should specifically address those risks.
The SEC and state regulators expect your compliance program to reflect how your business actually operates.
Key Sections Every RIA Policies and Procedures Manual Should Include
While every firm's manual will differ, most should address the following areas.
Compliance Program Administration
Start by explaining how your compliance program operates.
Include:
Responsibilities of the Chief Compliance Officer and delegation
Supervision of employees
Escalation procedures
Documentation requirements
Annual review process
Fiduciary Duty and Conflicts of Interest
Investment advisers owe clients a fiduciary duty.
Your manual should explain procedures for identifying, mitigating, disclosing, and monitoring conflicts, including:
Outside business activities
Gifts and entertainment
Referral arrangements
Proprietary products
Revenue sharing
Personal relationships
Code of Ethics Administration
Although your Code of Ethics is typically a separate document, your manual should explain how it is administered.
Include procedures for:
Personal securities reporting
Initial and annual holdings reports
Quarterly transaction reporting
Pre-clearance requirements
Restricted lists
Employee certifications
Portfolio Management
Document how investment decisions are made.
Topics may include:
Investment objectives
Client suitability
Asset allocation
Model management
Investment restrictions
Proxy voting (if applicable)
Rebalancing procedures
Account monitoring
Trading Practices
Your manual should explain how your firm seeks best execution.
Include procedures regarding:
Trade allocation
Block trading
Best execution reviews
Error corrections
Soft dollars (if applicable)
Trade monitoring
Marketing Rule Compliance
The Marketing Rule continues to be a major examination focus.
Your policies should address:
Advertisement review and approval
Testimonials
Endorsements
Third-party ratings
Performance advertising
Hypothetical performance
Books and records requirements
Be sure to address how your firm handles these risks, not just what the rule permits and prohibits.
Form ADV Updates
Explain how your firm monitors changes that may require amendments to Form ADV.
Include procedures for:
Annual updating amendments
Other-than-annual amendments
Responsibility for filing
Internal review process
Cybersecurity
Every advisory firm should address cybersecurity.
Your manual should include policies regarding:
Password management
Multi-factor authentication
Remote work
Vendor management
Incident response
Data backups
Access controls
Employee training
Privacy
Address compliance with Regulation S-P.
Include procedures for:
Protecting client information
Privacy notices
Information sharing
Data disposal
Incident response
Books and Records
Describe how records are maintained.
Include:
Required record retention
Electronic storage
Email retention
Marketing records
Trade documentation
Accessibility during examinations
Review what records an RIA is required to keep.
Business Continuity
Describe how the firm will continue operations during disruptions.
Topics include:
Disaster recovery
Remote operations
Communication plans
Technology failures
Vendor disruptions
Key personnel succession
Vendor Oversight
Many advisers rely heavily on third-party vendors.
Your manual should describe how vendors are:
Selected
Reviewed
Monitored
Evaluated for cybersecurity risk
Documented
Compliance Testing
Policies should explain how compliance is monitored throughout the year.
Examples include:
Personal trading reviews
Advertising reviews
Best execution reviews
Fee testing
Email reviews
Branch reviews (if applicable)
Common Mistakes RIAs Make
Many compliance manuals become outdated because firms only review them before an examination.
Some of the most common mistakes include:
Using a generic template
Templates can provide a useful starting point, but they should never be adopted without customization.
If your manual references services your firm doesn't offer—or omits risks unique to your business—it may raise concerns during an examination.
Policies don't match actual practice
Regulators don’t just review your written policies.
Examiners compare them to what employees actually do.
For example:
Your manual requires quarterly advertising reviews—but none occur.
Employees are required to pre-clear trades—but no documentation exists.
Cybersecurity training is required annually—but it hasn't been conducted.
If your written policies promise procedures your firm isn't following, that inconsistency can be more problematic than having no written procedure at all.
Failing to update the manual
Your business evolves over time. Your compliance manual should evolve with it.
Common events that should trigger a review include:
Hiring employees in new roles
Launching new services
Using new technology
Outsourcing functions
Regulatory changes
Acquisitions
Changes in custody practices
Policies that are too vague
Statements such as "The firm complies with applicable regulations." don't tell employees what they should actually do.
Good policies explain:
Who performs the task
When it's completed
How it's documented
Who reviews it
Specific procedures are far more useful than broad statements of intent.
Forgetting operational areas
Many firms focus heavily on investment management but overlook areas such as:
Vendor oversight
Cybersecurity
Marketing reviews
Electronic communications
Business continuity
Third-party technology
Regulators are increasingly examining these operational controls as part of a firm's overall compliance program.
Review Your Manual at Least Annually
Rule 206(4)-7 requires advisers to review the adequacy of their policies and procedures and the effectiveness of their implementation at least annually.
An annual review should consider:
Regulatory changes
Business changes
Examination findings
Compliance testing results
Client complaints
Operational issues
Technology changes
Any necessary revisions should be documented and implemented promptly.
Check out our Annual Review Checklist!
Final Thoughts
Your policies and procedures manual should be more than a document created to satisfy a regulatory requirement. It should serve as a practical guide for how your firm manages compliance every day.
A manual that is tailored to your business, regularly updated, and consistently followed can help reduce compliance risk and better prepare your firm for an SEC examination.
Need Help Reviewing Your Compliance Manual?
Whether you're creating a new compliance manual, updating an existing one, or preparing for an SEC examination, RIA Compliance Desk offers practical guidance designed specifically for registered investment advisers.
Members receive ongoing compliance Q&A, practical resources, templates, monthly regulatory updates, and access to additional compliance review services when more in-depth assistance is needed.