SEC Issues New Risk Alert on RIA Annual Compliance Reviews: What Investment Advisers Should Know

On September 14, 2026, the SEC's Division of Examinations issued a new Risk Alert focused specifically on investment advisers' annual compliance reviews under Rule 206(4)-7 of the Investment Advisers Act.

For registered investment advisers, the message is important: simply completing an annual review is not necessarily enough.

Based on observations from recent examinations, SEC staff identified several areas where advisers' annual review processes fell short—including reviews that weren't performed on time, incomplete testing procedures, reviews that didn't follow the firm's own written policies, inadequate documentation, and corrective actions that were identified but never completed.

For RIAs approaching their next annual review, the Risk Alert provides a useful roadmap for evaluating whether their current process is sufficiently thorough and well documented.

What Does Rule 206(4)-7 Require?

Under Rule 206(4)-7, SEC-registered investment advisers are required to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and its rules.

Those policies and procedures must be reviewed no less frequently than annually to evaluate:

  • Whether the firm's policies and procedures remain adequate; and

  • Whether those policies and procedures are being effectively implemented.

The SEC has also previously stated that an annual review should consider compliance matters that arose during the previous year, changes in the adviser's or its affiliates' business activities, and regulatory developments that may require changes to the compliance program.

Importantly, the new Risk Alert also reminds advisers that significant compliance events, business changes, or regulatory developments may warrant an interim review rather than waiting for the next scheduled annual review.

What Is the SEC Finding During RIA Examinations?

The Risk Alert identifies several recurring issues observed by SEC staff during examinations.

These observations provide RIAs with a useful checklist of areas to consider when evaluating their own annual review processes.

1. Annual Reviews Were Not Conducted on Time

Perhaps the most fundamental issue identified by SEC staff was that some advisers simply weren't conducting annual reviews at least annually.

Examples included firms that skipped entire review years or conducted reviews covering periods longer than 12 months.

The SEC also observed advisers that treated employee compliance training or annual employee attestations as substitutes for an annual review.

They aren't.

Training and certifications can be important components of a compliance program, but they don't replace an assessment of whether the firm's policies and procedures remain adequate and are being effectively implemented.

Takeaway for RIAs: Establish a defined annual review cycle and document when each review begins and ends. Personnel changes, including the departure of a CCO, shouldn't cause the annual review requirement to fall through the cracks.

2. Annual Review Procedures Were Too Vague

Having a policy that says "the firm will conduct an annual review" may not be enough to create an effective process.

SEC staff observed firms whose policies required testing and validation but didn't provide sufficient procedures explaining:

  • What testing should be performed;

  • How testing should be conducted;

  • What factors should be evaluated;

  • How the results should be assessed; or

  • What documentation should be retained.

The staff also observed situations where other sections of a firm's compliance manual required certain areas to be reviewed annually, but those areas weren't incorporated into the firm's annual review process.

Takeaway for RIAs: Your compliance manual should do more than require an annual review. It should establish a repeatable process for conducting, evaluating, and documenting that review.

3. Firms Didn't Follow Their Own Annual Review Procedures

This is an important distinction.

Some advisers were conducting annual reviews—but weren't conducting them in accordance with their own policies.

SEC staff observed firms that failed to use required workpapers, didn't perform specified tests, reviewed the wrong period, or otherwise departed from the procedures outlined in their compliance manuals.

In some cases, firms even evaluated outdated versions of policies and procedures that had already been superseded.

Takeaway for RIAs: Before beginning your annual review, review the annual review section of your own compliance manual. If your policies say you will perform a particular test, maintain a particular workpaper, or review a particular area, make sure your actual review does it.

4. Annual Reviews Failed to Identify Gaps Between Policies and Actual Practices

This may be one of the most important observations in the Risk Alert.

An annual review shouldn't evaluate your compliance documents in a vacuum. It should determine whether those documents accurately reflect what your firm is actually doing.

SEC staff identified annual reviews that failed to detect significant inconsistencies involving areas such as:

Advisory Fees and Expenses

The SEC observed differences between actual billing practices and the methodologies described in policies, client agreements, or Form ADV.

Examples included:

  • Different fee calculation methodologies;

  • Failure to prorate fees;

  • Failure to apply applicable breakpoints; and

  • Failure to issue appropriate refunds for terminated accounts.

This is a good reminder that annual reviews should include testing, not merely reading policies.

Proxy Voting

Some firms' policies stated that they voted client proxies even though their disclosures and actual practices indicated otherwise.

Custody

SEC staff identified custody procedures that didn't adequately address all accounts subject to the firm's custody arrangements.

Marketing Rule Compliance

The staff observed firms whose marketing policies had not been updated to reflect the SEC Marketing Rule—even though its compliance date was in 2022.

Form CRS

Some firms' regulatory filing procedures didn't reflect applicable Form CRS requirements for advisers serving retail investors.

Outsourced Functions

The SEC also observed policies that delegated responsibilities to third parties without adequately addressing how the adviser would oversee those outsourced activities.

Takeaway for RIAs: One of the most valuable exercises during an annual review is comparing policy vs. disclosure vs. practice.

Ask: What does our policy say we do? What do our disclosures say we do? And what are we actually doing?

Those answers should align.

5. Firms Didn't Maintain Adequate Annual Review Documentation

Documentation was another significant theme.

SEC staff observed advisers that apparently performed testing and identified compliance issues but failed to retain the supporting documentation.

Other firms had policies requiring a written annual review report but didn't actually prepare one.

Still others required specific checklists or workpapers but maintained only incomplete versions.

The annual review report itself is important—but so are the records supporting the conclusions in that report.

Depending on the review performed, that could include testing documentation, samples reviewed, workpapers, findings, recommendations, and evidence of remediation.

Takeaway for RIAs: Your annual review file should allow someone unfamiliar with the process to understand what you reviewed, what testing you performed, what you found, and what you did about it.

6. Corrective Actions Were Identified—but Never Completed

Finding a compliance problem is only half the job.

SEC staff observed advisers whose annual reviews recommended corrective actions but who failed to implement those changes.

Examples involved areas such as:

  • Proxy voting disclosures;

  • Documentation of client risk tolerances;

  • Best execution analysis; and

  • Broker-dealer due diligence.

Perhaps more concerning, the SEC identified situations where annual review reports indicated that corrective actions had already been completed even though the underlying issue continued.

Takeaway for RIAs: Every finding should have an owner, an expected completion date, and a mechanism for confirming that remediation actually occurred.

Consider maintaining a simple remediation tracker containing:

  • Finding;

  • Recommended action;

  • Responsible person;

  • Target completion date;

  • Status; and

  • Evidence of completion.

What Should RIAs Do in Response to the New Risk Alert?

The Risk Alert doesn't create new legal obligations, but it gives advisers valuable insight into what SEC examination staff are seeing in practice.

If your firm has an annual review coming up, consider using this opportunity to evaluate the review process itself—not just your compliance manual.

Ask yourself:

  • Did we complete our last review within the required timeframe?

  • Do our written procedures explain how the annual review should actually be conducted?

  • Does our testing cover the areas required by our policies?

  • Are we following the testing procedures described in our compliance manual?

  • Are our policies based on our current business and operations?

  • Are we testing actual practices rather than simply reviewing documents?

  • Do our policies, Form ADV, agreements, and actual practices align?

  • Are we retaining adequate workpapers and supporting documentation?

  • Are findings clearly documented?

  • Can we demonstrate that prior findings were actually remediated?

If you're unsure where to begin, our RIA Annual Review Checklist provides a broader framework for evaluating your compliance program and identifying areas that may warrant additional testing.

Annual Reviews Should Be More Than a Compliance Checklist

One theme comes through clearly in the SEC's observations: an annual review shouldn't be a once-a-year paperwork exercise.

A meaningful annual review connects four things:

Policies → Testing → Findings → Remediation

Your policies establish what your firm should be doing.

Your testing determines whether that's actually happening.

Your findings identify where improvements may be necessary.

And your remediation process demonstrates that identified issues were addressed.

When one of those pieces is missing, the annual review becomes significantly less useful as a compliance tool.

Need Help With Your RIA Annual Compliance Review?

Conducting a meaningful annual review can be particularly challenging for small and mid-sized RIAs where the CCO is balancing compliance responsibilities with operations, client service, or other roles.

RIA Compliance Desk offers a comprehensive Annual Compliance Program Review designed to help RIAs evaluate the adequacy and effectiveness of their compliance program under Rule 206(4)-7.

Our review may include:

  • Policies & Procedures

  • Code of Ethics

  • Business Continuity Plan

  • Compliance calendar and required testing

  • Form ADV consistency

  • Firm-specific compliance risks

  • Written findings and recommendations

  • Identification of areas requiring remediation

Rather than simply confirming that an annual review occurred, the goal is to provide an independent, structured assessment of your compliance program and practical recommendations for strengthening it.

Annual Compliance Program Reviews start at $2,999.

Ready to Start Your Annual Review?

Learn more about RIA Compliance Desk's Annual Compliance Program Review and get a structured, practical assessment of your firm's compliance program.

→ Start Your Annual Compliance Review

RIA Compliance Desk provides compliance guidance and consulting services and does not provide legal advice. The scope of an annual review depends on the firm's business, operations, risks, and the materials provided for review.

Next
Next

Compliance Policies & Procedures: What must an RIA include?