RIA Annual Review Checklist

Every SEC-registered investment adviser is required to review the adequacy of its compliance policies and procedures at least annually under Rule 206(4)-7 of the Investment Advisers Act of 1940. Yet one of the most common findings during SEC examinations is that annual reviews are poorly documented, incomplete, or fail to address the firm's actual risks.

A well-executed annual review should be more than a checklist exercise—it should demonstrate that your compliance program evolves alongside your business.

What Is an Annual Review?

The annual review is a documented assessment of whether your firm's compliance policies and procedures remain reasonably designed to prevent violations of the Advisers Act.

The SEC expects firms to evaluate both:

  • The effectiveness of existing policies

  • Whether changes to the business require updates to the compliance program

Annual Review Checklist

Your review should consider:

  • Changes in business operations

  • New advisory services

  • New personnel

  • Marketing practices

  • Cybersecurity controls

  • Vendor oversight

  • Code of Ethics compliance

  • Personal trading reviews

  • Form ADV accuracy

  • Books and records

  • Client complaints

  • Privacy policies

  • Business continuity planning

  • Regulatory developments

Common Mistakes RIAs Make During the Annual Review

The annual review is one of the SEC's most fundamental compliance requirements, yet it is also an area where firms frequently fall short. During examinations, the SEC doesn't just look for evidence that an annual review occurred—it evaluates whether the review was meaningful, risk-based, and appropriately documented. Below are several common mistakes and practical ways to avoid them.

Treating the Annual Review as a Checklist Exercise

Many firms approach the annual review by simply confirming that required topics were considered. While checklists are useful tools, they should not replace thoughtful analysis.

Your annual review should evaluate whether your compliance program continues to be reasonably designed based on your firm's current business. If your services, client base, technology, or personnel have changed over the past year, your compliance program should evolve accordingly.

Best practice: Document not only what was reviewed, but also your conclusions and any changes made as a result of the review.

Failing to Document Testing

One of the most common weaknesses is insufficient documentation. A report that merely states, "Marketing was reviewed," provides little evidence that meaningful testing occurred.

Instead, describe the procedures you performed. For example:

  • Reviewed a sample of advertisements published during the review period for compliance with the SEC Marketing Rule.

  • Verified that Form ADV disclosures remained consistent with current business practices.

  • Tested a sample of employee personal securities transactions for compliance with the firm's Code of Ethics.

Detailed documentation demonstrates that the review was substantive rather than a formality.

Ignoring Changes in the Business

Your compliance risks change as your business grows.

Examples include:

  • Hiring additional investment adviser representatives

  • Launching new advisory services

  • Beginning to use social media for marketing

  • Working with solicitors or promoters

  • Adopting new technology vendors

  • Expanding into additional states

Each of these developments may require updates to your policies, disclosures, testing procedures, or supervisory processes. The annual review is an ideal opportunity to determine whether your compliance program still reflects how your firm actually operates.

Overlooking Regulatory Developments

Regulations and SEC priorities continue to evolve. An annual review should include consideration of new rules, SEC Risk Alerts, enforcement actions, and examination priorities that may affect your firm.

For example, recent years have seen heightened regulatory attention on topics such as:

  • Marketing practices

  • Cybersecurity

  • Electronic communications

  • Off-channel messaging

  • Outsourced service providers

  • Artificial intelligence and predictive analytics

Even if a new rule does not directly apply to your firm, documenting that you considered its impact demonstrates a proactive compliance program.

Failing to Review Form ADV for Accuracy

Many firms only think about Form ADV during the annual amendment process. However, your annual review is an excellent opportunity to confirm that your disclosures continue to accurately describe your business.

Consider questions such as:

  • Are fee schedules still accurate?

  • Have services changed?

  • Have conflicts of interest evolved?

  • Are disciplinary disclosures still complete?

  • Do assets under management align with internal records?

  • Have personnel or ownership changed?

Remember that some changes require prompt amendments rather than waiting for the annual update.

Not Following Up on Prior Findings

The annual review should not exist in isolation. If deficiencies were identified during the previous year's review, the SEC expects firms to demonstrate that corrective actions were implemented and evaluated.

Examples include:

  • Updating policies and procedures

  • Conducting employee training

  • Revising supervisory processes

  • Enhancing recordkeeping

  • Implementing new compliance technology

Documenting these follow-up efforts helps demonstrate a culture of continuous improvement rather than a one-time compliance exercise.

Copying the Previous Year's Report

It may be tempting to reuse last year's report as a template, but simply changing the date without performing a fresh assessment can undermine the credibility of the review.

Each annual review should reflect the firm's current operations, risks, and regulatory environment. Examiners can often identify reports that have been recycled with minimal updates.

Using prior reports as a starting point is perfectly appropriate, but the analysis should be refreshed each year based on current facts and circumstances.

Missing the Opportunity to Improve the Compliance Program

Perhaps the biggest mistake is viewing the annual review as a regulatory obligation instead of a strategic exercise.

A thoughtful annual review can help identify inefficiencies, strengthen internal controls, improve employee training, and reduce regulatory risk before issues become examination findings.

Rather than asking, "Did we complete the annual review?" ask, "Did we learn anything that makes our compliance program stronger?"

Final Thoughts

A well-executed annual review is more than a requirement under Rule 206(4)-7. It's one of the most effective tools for evaluating whether your compliance program remains aligned with your firm's evolving risks and operations. Firms that invest the time to perform meaningful testing, document their analysis, and address identified gaps are often better prepared for regulatory examinations and better positioned to manage compliance risk throughout the year.

Need help reviewing your compliance program? Members of RIA Compliance Desk receive practical guidance, templates, and ongoing support for annual reviews.

Previous
Previous

When Does an RIA Need to Amend Form ADV?