The SEC Just Put Annual Compliance Reviews Under the Microscope. Is Yours Ready?
On September 14, 2026, the SEC’s Division of Examinations released a new Risk Alert focused squarely on one of the most fundamental, and most frequently mishandled, obligations for registered investment advisers: the annual compliance review required under Rule 206(4)-7 of the Advisers Act, commonly known as the Compliance Rule.
For more than two decades, advisers have been required to adopt written compliance policies and procedures and, at least once a year, review both their adequacy and the effectiveness of their implementation. That review must account for compliance matters that arose during the year, changes to the firm’s business, and regulatory developments. It must also be documented in the firm’s books and records.
If that sounds routine, the exam staff’s observations suggest otherwise. The Risk Alert catalogs a long list of ways advisers are falling short, and it could be a preview of what examiners will be probing in upcoming exams.
Here’s what stood out to us, and what your firm should be doing about it.
What Examiners are Seeing
Reviews are late or never happen at all. Examiners found advisers that skipped years entirely, let more than 12 months lapse between reviews (often citing CCO turnover or operational disruption), or completed their first review long after the post-registration deadline. Some firms argued that annual compliance training or employee attestations satisfied the requirement; the staff was clear that they do not. Most concerning, the staff called out repeat offenders: firms that already received deficiency letters for missed or untimely reviews and still hadn’t fixed the problem. That kind of recidivism is a fast track to an enforcement referral. Policies that require a review, but no roadmap for doing one. Many firms have a policy that says, “we conduct an annual review,” but no actual procedures explaining how. Who performs the testing? What factors determine whether a policy is adequate? What documentation must be created and retained? Examiners also flagged firms whose compliance manuals mandated review of specific topics, such as identity theft procedures, that then never appeared in the annual review itself. Reviews that don’t follow the firm’s own playbook. Some advisers conducted timely reviews but ignored their own written procedures, such as skipping required workpapers, testing the wrong review period, or, remarkably, assessing outdated versions of policies that had already been superseded. Reviews that miss the gap between paper and practice. This is where the alert is most pointed. Examiners repeatedly identified problems in core business areas that the adviser’s own annual review never caught, including:- Fee billing that deviated from client agreements and Form ADV (e.g., missed breakpoints, unprorated fees, refunds never issued)
- Proxy voting policies that contradicted actual practice and client disclosures
- Custody procedures that failed to route all applicable accounts to the surprise examination
- Marketing policies never updated for the Marketing Rule
- Filing procedures that overlooked Form CRS obligations
- Delegated functions with no oversight framework
- Known compliance incidents that were reported during the year but never made it into the review
Why This Matters Now
Risk Alerts are how the Division of Examinations telegraphs its priorities. When the staff takes the time to publish detailed observations on a single rule, advisers should expect the topic to feature prominently in exam request lists and interviews going forward. In fact, the staff already routinely asks for annual review documentation as part of its standard exam scoping. The message behind these observations is simple: the annual review is not a box to check. It is the mechanism the SEC expects firms to use to find their own problems before examiners find them first. A review that’s late, thin, undocumented, or ignored signals a compliance program that exists only on paper, and that is precisely the conclusion exam staff will draw.Questions Every Adviser Should Be Asking
Before your next review cycle, we’d encourage every CCO and firm principal to honestly consider:- Has a review been completed for every calendar year since registration?
- Do written procedures actually describe how the review is performed, including the testing, the evaluation criteria, and the required documentation?
- Does the review’s scope match your current business, including new products, services, personnel, and regulatory changes?
- Are billing practices, proxy voting, custody, and marketing tested against what the firm actually does, not just what the manual says?
- Is every workpaper, test result, and recommendation retained in your books and records?
- Has every corrective action from prior reviews been genuinely implemented, and can you prove it?