The staff (Staff) of the Division of Examinations of the Securities and Exchange Commission (SEC) published a Risk Alert on Sept. 14, 2026, summarizing observations from recent examinations of SEC-registered investment advisers (Advisers) regarding their annual compliance obligations.
Rule 206(4)-7 (the RIA Compliance Rule) under the Investment Advisers Act of 1940, as amended (Advisers Act) requires Advisers to adopt and implement written compliance policies and procedures reasonably designed to prevent violations of the Advisers Act; review policies and procedures at least annually; and maintain true, accurate and timely records of that review. In their observations, the Staff identified deficiencies across five main areas: (i) the alignment of the compliance reviews performed in relation to Advisers’ actual policies and procedures, (ii) the resolution of corrective actions for concerns identified during compliance reviews, (iii) the completeness of Advisers’ policies and procedures for conducting compliance reviews, (iv) the timeliness of annual compliance reviews, and (v) the documentation of compliance reviews.
Key Takeaways
- The Compliance Rule continues to be a Staff focus. The Staff made observations regarding fundamental investment adviser compliance obligations such as robust and timely reviews, complete procedures and adequate documentation. Such deficiencies have been highlighted by Staff in the past and are likely to continue to be a subject of investigation and enforcement action by the SEC.
- The Staff highlighted various specific areas of noncompliance. These included examples of inadequate review, deficient policies and procedures and insufficient follow-up corrective actions. The Staff also noted several important overarching issues, including that compliance training and annual compliance attestations alone did not satisfy an Adviser’s annual compliance review requirement, and that some written annual review reports stated that corrective actions had already been implemented when the issues had never actually been addressed.
- The Risk Alert does not establish any new legal requirements and is intended to help Advisers address the adequacy of their compliance policies and procedures and the effectiveness of their implementation.
In brief, the Staff’s observations covered the following areas:
I. Conducting Reviews Aligned with Actual Practices
The Staff observed that while certain Advisers conducted timely reviews, the reviews were not implemented in accordance with their written procedures. To compound this, the Advisers did not recognize that their policies and procedures did not fully address or were not aligned with their actual practices.
The Staff also observed certain Advisers that (i) had not adopted policies and procedures to address risk and other core areas important to their advisory business, (ii) had not adequately addressed material changes in their business activities, including failing to inform the chief compliance officer of business changes that could impact the scope of the annual compliance review, and (iii) made fundamental errors such as assessing the effectiveness of incorrect or outdated documents.
Examples of compliance issues that annual reviews did not properly identify or address included:
- Fee and expense billing practices that deviated from policies and procedures and/or client disclosures, including using different fee-calculation methodologies. The Staff cross-referenced its June 9, 2026, Risk Alert on economic conflicts of interest in this regard. See our Client Alert on that Risk Alert HERE.
- Contradictions between proxy voting policies and procedures, client disclosures and actual voting.
- Custody policies and procedures that omitted steps to ensure custodial accounts were properly identified to the independent public accountants performing surprise examinations.
- Policies and procedures not updated to fully reflect Rule 206(4)-1 (Marketing Rule) or Form CRS (Client Relationship Summary).
- Policies that delegated execution of services and/or operations to third parties without identifying how the Adviser should oversee those delegated responsibilities.
- Incidents of noncompliance identified and reported during the review period that were not addressed in the annual reviews.
II. Taking Corrective Action
The Staff observed that certain Advisers did not take corrective action after their annual reviews identified compliance issues or recommended changes to compliance policies or procedures, disclosures and/or business practices. These included instances in which annual reviews identified the need to conduct more thorough analysis of best execution and third-party due diligence, as well as to better document client investment information, such as risk tolerances. In certain instances, the Advisers indicated that corrective actions were already implemented, but the issues identified in prior annual reviews persisted.
III. Adopting Complete Procedures for Conducting Annual Reviews
The Staff found that certain Advisers had policies requiring annual reviews, but such procedures did not adequately assess the completeness and effective implementation of their compliance programs. This included Advisers whose reviews omitted material topics or did not establish procedures that personnel should follow for the compliance tests, the factors to be used to evaluate effective implementation or the types of documentation to be kept.
IV. Conducting Timely Review
Although a fundamental requirement for annual reviews under the Compliance Rule, the Staff found instances where certain Advisers did not perform reviews at least annually. This included review gaps or reviews covering periods longer than 12 months or other extended intervals due to business, operational and personnel changes. As noted above, the Staff also identified Advisers that, instead of performing an annual review, stated that compliance training or annual personnel attestations of adherence to policies satisfied the Compliance Rule’s annual review requirement. The Staff also identified Advisers that had not taken corrective action after receiving prior deficiency letters for failing to perform annual reviews or failing to perform them in a timely manner.
V. Documenting and Maintaining Records of Annual Reviews
The Staff observed that certain Advisers created documentation during annual reviews, such as when performing testing and recommending corrective actions, but did not maintain it in their books and records. For example, certain Advisers’ written annual review reports discussed compliance violations identified during the review, but the Advisers did not maintain the underlying documentation addressing those issues, such as records of testing performed, issues identified and corrective actions recommended. The Staff also identified Advisers with policies requiring reviews to be memorialized in written reports covering specific topics, such as recommendations for improvement, material changes to policies and procedures, and material compliance issues requiring remedial action during the previous year, but for which no such written reports were prepared.
Read the Risk Alert HERE.
The Investment Management Practice Group at Haynes Boone regularly counsels SEC-registered investment advisers on Compliance Rule matters, annual compliance reviews, policies and procedures and other disclosure and compliance matters. Please contact Daren Domina or another member of the Investment Management Group.