Blog
The SEC Just Put Annual Compliance Reviews Under the Microscope. Is Yours Ready?
Brian MacKenzie | 14 September 2026
On September 14, 2026, the SEC's Division of Examinations released a new Risk Alert focused squarely on one of the most fundamental, and most frequently mishandled, obligations for registered investment advisers: the annual compliance review required under Rule 206(4)-7 of the Advisers Act, commonly known as the Compliance Rule.
For more than two decades, advisers have been required to adopt written compliance policies and procedures and, at least once a year, review both their adequacy and the effectiveness of their implementation. That review must account for compliance matters that arose during the year, changes to the firm's business, and regulatory developments. It must also be documented in the firm's books and records.
If that sounds routine, the exam staff's observations suggest otherwise. The Risk Alert catalogs a long list of ways advisers are falling short, and it could be a preview of what examiners will be probing in upcoming exams.
Here's what stood out to us, and what your firm should be doing about it.
Reviews are late or never happen at all. Examiners found advisers that skipped years entirely, let more than 12 months lapse between reviews (often citing CCO turnover or operational disruption), or completed their first review long after the post-registration deadline. Some firms argued that annual compliance training or employee attestations satisfied the requirement; the staff was clear that they do not. Most concerning, the staff called out repeat offenders: firms that already received deficiency letters for missed or untimely reviews and still hadn't fixed the problem. That kind of recidivism is a fast track to an enforcement referral.
Policies that require a review, but no roadmap for doing one. Many firms have a policy that says, "we conduct an annual review," but no actual procedures explaining how. Who performs the testing? What factors determine whether a policy is adequate? What documentation must be created and retained? Examiners also flagged firms whose compliance manuals mandated review of specific topics, such as identity theft procedures, that then never appeared in the annual review itself.
Reviews that don't follow the firm's own playbook. Some advisers conducted timely reviews but ignored their own written procedures, such as skipping required workpapers, testing the wrong review period, or, remarkably, assessing outdated versions of policies that had already been superseded.
Reviews that miss the gap between paper and practice. This is where the alert is most pointed. Examiners repeatedly identified problems in core business areas that the adviser's own annual review never caught, including:
Documentation that disappears. Some firms performed real testing and identified real issues, then failed to retain the underlying workpapers, testing records, or corrective action recommendations. Others had policies requiring a written annual review report and never produced one or left required checklists and templates half-finished. If it isn't in your books and records, from an examiner's perspective, it didn't happen.
Findings without follow-through. Finally, the staff observed advisers whose annual reviews recommended changes (e.g., better proxy disclosures, documented risk tolerances, and more rigorous best execution analysis) that were never implemented. In some cases, written reports claimed corrective actions were already complete while the underlying problems quietly persisted. Claiming you fixed something you didn't is worse than admitting you haven't fixed it.
Risk Alerts are how the Division of Examinations telegraphs its priorities. When the staff takes the time to publish detailed observations on a single rule, advisers should expect the topic to feature prominently in exam request lists and interviews going forward. In fact, the staff already routinely asks for annual review documentation as part of its standard exam scoping.
The message behind these observations is simple: the annual review is not a box to check. It is the mechanism the SEC expects firms to use to find their own problems before examiners find them first. A review that's late, thin, undocumented, or ignored signals a compliance program that exists only on paper, and that is precisely the conclusion exam staff will draw.
Before your next review cycle, we'd encourage every CCO and firm principal to honestly consider:
If any of those answers give you pause, you're not alone. That's exactly the pattern the staff described.
At PINE, annual compliance reviews are core to what we do for registered investment advisers, and the Risk Alert describes the same gaps we help firms close every day.
Our team of compliance experts conduct independent annual reviews on your behalf or alongside your CCO, bringing structured testing, defined evaluation criteria, and examiner-ready documentation to the process. We build out the procedures behind the policy, including the workplans, checklists, and testing protocols the staff expects to see, so your review is repeatable even through personnel transitions. We perform gap analyses that compare your written policies against your actual practices in the areas examiners highlighted: fees and billing, proxy voting, custody, marketing, Form CRS, and oversight of outsourced functions. We also track corrective actions from recommendation through verified implementation, so last year's findings don't become this year's deficiency letter.
Whether you need a full outsourced review, a second set of eyes on your existing process, or targeted remediation after an exam, PINE can help you build a review you'd be comfortable handing an examiner.
Ready to pressure-test your annual review before the SEC does? Contact PINE today to schedule a consultation.
For more than two decades, advisers have been required to adopt written compliance policies and procedures and, at least once a year, review both their adequacy and the effectiveness of their implementation. That review must account for compliance matters that arose during the year, changes to the firm's business, and regulatory developments. It must also be documented in the firm's books and records.
If that sounds routine, the exam staff's observations suggest otherwise. The Risk Alert catalogs a long list of ways advisers are falling short, and it could be a preview of what examiners will be probing in upcoming exams.
Here's what stood out to us, and what your firm should be doing about it.
What Examiners are Seeing
Reviews are late or never happen at all. Examiners found advisers that skipped years entirely, let more than 12 months lapse between reviews (often citing CCO turnover or operational disruption), or completed their first review long after the post-registration deadline. Some firms argued that annual compliance training or employee attestations satisfied the requirement; the staff was clear that they do not. Most concerning, the staff called out repeat offenders: firms that already received deficiency letters for missed or untimely reviews and still hadn't fixed the problem. That kind of recidivism is a fast track to an enforcement referral.
Policies that require a review, but no roadmap for doing one. Many firms have a policy that says, "we conduct an annual review," but no actual procedures explaining how. Who performs the testing? What factors determine whether a policy is adequate? What documentation must be created and retained? Examiners also flagged firms whose compliance manuals mandated review of specific topics, such as identity theft procedures, that then never appeared in the annual review itself.
Reviews that don't follow the firm's own playbook. Some advisers conducted timely reviews but ignored their own written procedures, such as skipping required workpapers, testing the wrong review period, or, remarkably, assessing outdated versions of policies that had already been superseded.
Reviews that miss the gap between paper and practice. This is where the alert is most pointed. Examiners repeatedly identified problems in core business areas that the adviser's own annual review never caught, including:
- Fee billing that deviated from client agreements and Form ADV (e.g., missed breakpoints, unprorated fees, refunds never issued)
- Proxy voting policies that contradicted actual practice and client disclosures
- Custody procedures that failed to route all applicable accounts to the surprise examination
- Marketing policies never updated for the Marketing Rule
- Filing procedures that overlooked Form CRS obligations
- Delegated functions with no oversight framework
- Known compliance incidents that were reported during the year but never made it into the review
Documentation that disappears. Some firms performed real testing and identified real issues, then failed to retain the underlying workpapers, testing records, or corrective action recommendations. Others had policies requiring a written annual review report and never produced one or left required checklists and templates half-finished. If it isn't in your books and records, from an examiner's perspective, it didn't happen.
Findings without follow-through. Finally, the staff observed advisers whose annual reviews recommended changes (e.g., better proxy disclosures, documented risk tolerances, and more rigorous best execution analysis) that were never implemented. In some cases, written reports claimed corrective actions were already complete while the underlying problems quietly persisted. Claiming you fixed something you didn't is worse than admitting you haven't fixed it.
Why This Matters Now
Risk Alerts are how the Division of Examinations telegraphs its priorities. When the staff takes the time to publish detailed observations on a single rule, advisers should expect the topic to feature prominently in exam request lists and interviews going forward. In fact, the staff already routinely asks for annual review documentation as part of its standard exam scoping.
The message behind these observations is simple: the annual review is not a box to check. It is the mechanism the SEC expects firms to use to find their own problems before examiners find them first. A review that's late, thin, undocumented, or ignored signals a compliance program that exists only on paper, and that is precisely the conclusion exam staff will draw.
Questions Every Adviser Should Be Asking
Before your next review cycle, we'd encourage every CCO and firm principal to honestly consider:
- Has a review been completed for every calendar year since registration?
- Do written procedures actually describe how the review is performed, including the testing, the evaluation criteria, and the required documentation?
- Does the review's scope match your current business, including new products, services, personnel, and regulatory changes?
- Are billing practices, proxy voting, custody, and marketing tested against what the firm actually does, not just what the manual says?
- Is every workpaper, test result, and recommendation retained in your books and records?
- Has every corrective action from prior reviews been genuinely implemented, and can you prove it?
If any of those answers give you pause, you're not alone. That's exactly the pattern the staff described.
How PINE Can Help
At PINE, annual compliance reviews are core to what we do for registered investment advisers, and the Risk Alert describes the same gaps we help firms close every day.
Our team of compliance experts conduct independent annual reviews on your behalf or alongside your CCO, bringing structured testing, defined evaluation criteria, and examiner-ready documentation to the process. We build out the procedures behind the policy, including the workplans, checklists, and testing protocols the staff expects to see, so your review is repeatable even through personnel transitions. We perform gap analyses that compare your written policies against your actual practices in the areas examiners highlighted: fees and billing, proxy voting, custody, marketing, Form CRS, and oversight of outsourced functions. We also track corrective actions from recommendation through verified implementation, so last year's findings don't become this year's deficiency letter.
Whether you need a full outsourced review, a second set of eyes on your existing process, or targeted remediation after an exam, PINE can help you build a review you'd be comfortable handing an examiner.
Ready to pressure-test your annual review before the SEC does? Contact PINE today to schedule a consultation.