Skip to Main Content
Publications

SEC Division of Examinations Issues Risk Alert on Investment Adviser Annual Compliance Reviews

The SEC's Division of Examinations (the Division) recently published a Risk Alert detailing certain deficiencies of investment advisers' annual compliance review processes that were observed during examinations. The Risk Alert focuses on advisers' obligations under Rule 206(4)-7 (the Compliance Rule) under the Investment Advisers Act of 1940, as amended (the Advisers Act), which requires registered investment advisers to:

  1. adopt and implement written compliance policies and procedures reasonably designed to prevent violations of the Advisers Act;
  2. review the adequacy of those policies and procedures and the effectiveness of their implementation no less frequently than annually; and
  3. designate a chief compliance officer (CCO) responsible for administering the compliance program.

Advisers are also required under Rule 204-2(a)(17)(ii) to maintain books and records documenting annual reviews. The Risk Alert identifies six recurring areas of deficiency observed by the Division, and serves as a clear signal of the Division's enforcement priorities. Advisers should treat this guidance as a roadmap for self-assessment.

Failure to comply with the Compliance Rule and related recordkeeping requirements can result in deficiency letters, referrals to the SEC's Division of Enforcement, and potential civil penalties. The Division's emphasis on recidivist conduct indicates heightened scrutiny for advisers with prior examination findings.

The Division organized its observations into six categories, summarized below.

1. Failure to Conduct Timely Annual Reviews

The Division observed advisers who failed to perform reviews on an annual basis. Deficiencies included gaps in review cycles (e.g., completing reviews for 2021 and 2023 but omitting 2022), conducting reviews covering periods exceeding 12 months, and failing to perform initial reviews until 18 months after registration. In some cases, advisers substituted compliance training sessions or employee attestations for the required annual review, neither of which satisfies the Compliance Rule. The Division also flagged recidivist conduct, noting instances where advisers failed to correct untimely reviews even after receiving prior deficiency letters.

2. Incomplete Policies and Procedures for Annual Reviews

While many advisers had policies requiring annual reviews, the Division found that some lacked corresponding procedures providing direction on how to conduct those reviews. For example, policies might require documentation and testing but contain no procedures specifying the types of tests to perform, the factors to consider, or the level of documentation expected. Additionally, the Division observed that certain required practices identified elsewhere in an adviser's compliance manual, such as identity theft prevention programs requiring annual testing, were omitted from the scope of the annual review.

3. Annual Reviews Inconsistent With Written Procedures

Even where advisers conducted timely reviews, the Division found that some reviews were inconsistent with the adviser's own written procedures. Examples included failing to follow policies regarding defined review periods, required work papers, or specified tasks and tests. In certain cases, annual reviews assessed outdated or superseded versions of the adviser's compliance policies rather than the current versions in effect.

4. Misalignment Between Policies and Actual Practices

The Division identified advisers that failed to recognize or address discrepancies between their written compliance policies and their actual business practices. Notable examples included:

  • Fee and expense billing practices that deviated from disclosed methodologies (e.g., failure to prorate fees, apply breakpoints, or issue refunds);
  • Proxy voting policies stating the adviser votes proxies when, in practice, the adviser did not;
  • Custody policies that omitted steps to ensure accounts were identified for surprise examinations;
  • Marketing policies not updated to reflect the Advisers Act marketing rule (compliance date November 4, 2022);
  • Regulatory filing procedures not updated to reflect Form CRS requirements for retail clients; and
  • Incidents of noncompliance identified during the review period but neither addressed nor recorded in annual reviews.

5. Failure to Maintain Adequate Documentation

The Division observed advisers who created annual review documentation but failed to maintain it as part of their books and records. Examples included written annual review reports referencing compliance violations without maintaining the underlying testing records, issues identified, or corrective actions recommended. In other cases, policies required written reports covering specific topics, such as recommendations for improvement, material changes, and material compliance matters, but no written report was actually prepared. The Division also noted instances where policies required specific documentation formats (checklists, work papers, or templates), but advisers failed to complete all required elements.

6. Failure to Implement Corrective Actions

Finally, the Division highlighted advisers who identified deficiencies in their annual reviews but failed to implement the recommended corrective actions. For example, reviews identified the need for improved proxy voting disclosures, better documentation of client risk tolerances, and more thorough best execution and third-party due diligence analysis, yet the recommended changes were never made. In some cases, advisers represented in written reports that corrective actions had already been implemented, but the same issues persisted in subsequent periods.

Recommended Actions for Advisers

In light of this Risk Alert, we recommend that investment adviser clients consider the following steps to strengthen their annual compliance review processes before their next SEC examination or annual review cycle:

  • Confirm Annual Review Timeliness and Cadence. Verify that annual reviews are conducted on a calendar year or other regular 12-month cycle, with no gaps. Ensure that the review cadence is not disrupted by personnel transitions (including CCO departures) or operational changes. Do not treat compliance training, employee certifications, or annual attestations as substitutes for the annual review.
  • Evaluate the Completeness of Review Procedures. Assess whether your compliance manual includes not only a policy requiring annual reviews, but also detailed procedures, which may specify the scope, methodology, testing protocols, documentation standards, and responsible personnel. Cross-reference all material compliance obligations identified elsewhere in your policies and procedures to confirm they are captured in the annual review scope.
  • Audit Adherence to Written Procedures. Confirm that annual reviews are conducted in accordance with your written procedures, including adherence to defined review periods, required work papers, and specified tests, as applicable. Ensure that reviews assess the current versions of all policies and procedures, not outdated iterations.
  • Conduct a Policy-to-Practice Gap Analysis. Compare your written compliance policies against actual business practices in key areas, such as fee billing, proxy voting, custody, marketing, and regulatory filings. Identify and remediate any misalignments. In particular, review whether policies have been updated to reflect the Advisers Act marketing rule and Form CRS filing requirements.
  • Strengthen Recordkeeping Practices. Ensure that all annual review documentation, including testing records, findings, recommendations, and corrective action plans, is maintained as part of the firm's books and records in compliance with Rule 204-2(a)(17)(ii). Consider developing standardized templates and checklists, and confirm that all required elements are completed for each review cycle.
  • Establish a Corrective Action Tracking Process. Implement a formal process for tracking and verifying the implementation of corrective actions identified in annual reviews. Assign responsibility, set deadlines, and document remediation efforts. Consider incorporating corrective action follow-up into subsequent annual reviews to prevent recurrence of identified issues.
  • Review Prior Deficiency Letters. If your firm has received prior deficiency letters or examination findings from the SEC, confirm that all identified deficiencies have been fully remediated. The Division's emphasis on recidivist conduct signals heightened scrutiny of repeat findings.

The Risk Alert underscores the Division's continued focus on the substance and rigor of investment advisers' compliance programs. Advisers should view this guidance as an opportunity to proactively assess and enhance their annual review processes before their next SEC examination.

Additional Information

For any questions regarding this or any other related topic, please contact Paul J. Foley, Cole Beaubouef, John M. Faust, and Kiki Scarff. Among other things, the Fund Formation and Investment Management Team is available to assist with compliance program assessments, policy reviews, and SEC examination preparation.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept