CBIZ

Insights. Applied. Integrated solutions that turn strategy into action.

  • Article
September 25, 2026

SEC Risk Alert Highlights Gaps in Adviser Annual Compliance Reviews

SEC Risk Alert Highlights Gaps in Adviser Annual Compliance Reviews
Table of Contents

Recent examination observations offer a practical roadmap for assessing whether annual reviews are timely, complete, documented, and supported by follow-through.

The SEC Division of Examinations recently issued a Risk Alert on investment adviser annual compliance reviews. The Alert focuses on how registered investment advisers conduct and document the review required at least annually by Rule 206(4)-7 under the Investment Advisers Act of 1940. It does not create new obligations. Instead, it identifies recurring examination deficiencies and reminds advisers that an annual review must assess both the adequacy of their compliance policies and procedures and the effectiveness of their implementation.

The staff’s observations fall into six closely related areas: timeliness; complete review procedures; adherence to those procedures; alignment with the adviser’s actual business and regulatory obligations; retention of supporting documentation; and completion of corrective action. Together, these observations provide a useful framework for evaluating whether an annual review is substantive or merely procedural.

Six Areas Identified by the SEC

Conduct the review on time

Rule 206(4)-7 requires an adviser to review its compliance policies and procedures no less frequently than annually. The staff observed reviews that were skipped, covered periods longer than 12 months or were delayed because of operational or personnel changes, including a chief compliance officer departure. The Alert also notes that compliance training and annual employee attestations do not replace the required review. Advisers should establish a clear review cycle, preserve accountability during personnel transitions and avoid treating other compliance activities as substitutes for the annual assessment.

Establish complete procedures for conducting the review

Having a policy that calls for an annual review is not enough. The staff identified firms whose compliance manuals required testing, validation, and documentation but did not explain how those activities should be performed. In other cases, topics identified elsewhere in the compliance program as requiring annual testing were omitted from the annual review procedures. Written procedures should identify the scope of the review, the testing or validation to be performed, the factors used to assess adequacy and effectiveness, and the records that must be retained.

Follow the procedures that were adopted

The staff also observed advisers that completed timely reviews but did not conduct them in accordance with their own written procedures. Examples included using an incorrect review period, omitting required tasks or tests, failing to use specified workpapers and assessing outdated policies that had already been superseded. Before beginning the review, firms should confirm that the current procedures, templates and policy versions are being used and that any required steps are assigned and completed.

Align the compliance program with current practices

The annual review should address the adviser’s actual operations and current regulatory responsibilities. The Alert describes policies that did not cover risks central to the adviser’s business and reviews that did not consider relevant business or operational changes. It also identifies specific inconsistencies involving fee billing, proxy voting, custody, marketing, regulatory filings and oversight of delegated functions. For example, the staff observed billing practices that differed from policies or client disclosures, including fee methodologies, proration, breakpoints and refunds. The point is broader than any one compliance topic: the annual review should compare written requirements with current practices and account for changes in the adviser’s business, affiliates and applicable law.

Maintain documentation supporting the review

The books and records requirements include records documenting the annual review. The staff observed firms that prepared reports but did not retain the testing records, identified issues or recommended corrective actions supporting those reports. Other firms required a written report, checklist or workpaper package but did not prepare it or completed it only partially. A final report, standing alone, may not demonstrate the work performed. Advisers should retain the evidence supporting their scope, testing, conclusions, and recommendations in the manner required by their procedures.

Complete and verify corrective action

An annual review does not end when a recommendation is recorded. The staff identified advisers that failed to implement changes involving disclosures, client risk tolerances, best execution analysis and third-party due diligence. In some cases, reports stated that corrective action had been completed even though the problem persisted. Firms should assign responsibility, establish target dates, retain evidence of completion and verify that remediation is operating as intended. Open items should remain visible until they are resolved and validated.

Practical Considerations for Advisers

The Alert provides a direct basis for reassessing the annual review process. Advisers may want to consider whether:

  • The review is scheduled and completed at least annually, with continuity plans for personnel or operational changes;
  • the written review procedures specify scope, testing, evaluation criteria and documentation expectations;
  • the review follows the current procedures and evaluates the current versions of the firm’s policies;
  • the assessment reflects changes in business activities, affiliates, regulations and actual operating practices;
  • the firm retains the reports, testing records, workpapers and other support required by its policies and the books and records rules; and
  • corrective actions are assigned, tracked, completed, and independently verified where appropriate.

Bottom Line

The SEC’s observations are not a checklist of new requirements. They illustrate how an annual review can fall short when it is late, incompletely designed, inconsistently performed, disconnected from the adviser’s business, poorly documented or not followed by effective remediation. Advisers should use the Alert as a focused roadmap for evaluating both the design of the annual review process and the evidence showing that the process works in practice.

For more information about evaluating or strengthening an investment adviser’s annual compliance review process, contact CBIZ.

Disclaimer: This article was prepared by a CBIZ affiliate other than CBIZ Investment Advisory Services (CBIZ IAS) and does not necessarily reflect the views, guidance, or services of CBIZ IAS. This content is for informational purposes only and should not be considered investment advice or a recommendation from CBIZ IAS. Any investment decisions should be made only after consulting with a qualified investment advisor or financial professional.

© Copyright CBIZ, Inc. All rights reserved. Use of the material contained herein without the express written consent of the firms is prohibited by law. This publication is distributed with the understanding that CBIZ is not rendering legal, accounting or other professional advice. The reader is advised to contact a tax professional prior to taking any action based upon this information. CBIZ assumes no liability whatsoever in connection with the use of this information and assumes no obligation to inform the reader of any changes in tax laws or other factors that could affect the information contained herein. Material contained in this publication is informational and promotional in nature and not intended to be specific financial, tax or consulting advice. Readers are advised to seek professional consultation regarding circumstances affecting their organization.

“CBIZ” is the brand name under which CBIZ CPAs P.C. and CBIZ, Inc. and its subsidiaries, including CBIZ Advisors, LLC, provide professional services. CBIZ CPAs P.C. and CBIZ, Inc. (and its subsidiaries) practice as an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. CBIZ CPAs P.C. is a licensed independent CPA firm that provides attest services to its clients. CBIZ, Inc. and its subsidiary entities provide tax, advisory, and consulting services to their clients. CBIZ, Inc. and its subsidiary entities are not licensed CPA firms and, therefore, cannot provide attest services.

Let’s Connect

Our team is here to help. Whether you’re looking for business solutions, financial strategies, or industry insights, we’re ready to collaborate. Fill out the form, and we’ll be in touch soon.

This field is for validation purposes and should be left unchanged.