SEC Risk Alert: Annual Compliance Reviews

Published On:29 September 2026
Share:

SEC Risk Alert: Annual Compliance Reviews

Overview

SEC-registered investment advisers (“advisers”) are required to adopt and implement written compliance policies and procedures pursuant to the Compliance Rule (Rule 206(4)-7) under the Investment Advisers Act of 1940 (the “Act”)).A critical component of the Compliance Rule is the requirement that advisers conduct a review of their compliance policies and procedures at least annually to assess their adequacy and the effectiveness of their implementation.These reviews should consider compliance matters that arose during the previous year, changes in business activities, and any changes in the Act or regulations that might suggest a revision of their compliance policies or procedures. Advisers should also consider an interim review in response to significant legal, business and compliance events.

Also, advisers must maintain any books and records documenting the reviews in a true, accurate, and current manner in accordance with Rule 204-2(a)(17)(ii).

The SEC’s Division of Examinations (the “Division”) almost always requests information regarding advisers’ annual reviews as part of an examination initial document request.

The Division recently issued a risk alert (the “Alert”) that highlights staff observations and certain areas advisers should consider when conducting reviews of the adequacy of their compliance policies and procedures and the effectiveness of their implementation.

SEC Observations

Below is a summary of SEC observations from recent examinations related to annual reviews.

Conducting timely annual reviews. Advisers did not perform reviews of compliance policies and procedures, at least annually, to determine their adequacy and annual reviews (skipping or combining years for example).

• Performed annual reviews for periods of greater than 12 months, including first reviews at 18 months post-registration with the SEC.

• Instead of performing any annual review, stated that providing personnel with compliance training or obtaining annual attestations of personnel’s adherence to the advisers’ compliance policies and procedures satisfied the annual review requirement.

• Had not taken corrective action after receiving previous deficiency letters from the staff for not performing annual reviews or not performing them in a timely manner.

Adopting complete policies and procedures for conducting annual reviews.Advisers had compliance policies requiring annual reviews, but did not adopt procedures or had incomplete procedures for their personnel to use when assessing whether the advisers’ policies and procedures were adequate and effectively implemented. Examples include compliance policies that:

• Required advisers to document their annual reviews, and to include testing and validation of compliance policies and procedures as part of their review process. However, advisers did not document procedures providing direction and processes personnel should follow for the tests and validations, the factors personnel should consider when evaluating whether the policies and procedures were adequate and effectively implemented based on the testing and validation, or the types or level of documentation that should be made and kept in support of such reviews and assessments.

• Identified required practices, services, and/or operations to be assessed during the annual review in various sections of the advisers’ compliance policies and procedures but did not include these topics in their policies and procedures for annual review. Consequently, the annual reviews did not include these topics (e.g., adviser’s identity theft policies and procedures mandate annual review testing, but this topic was omitted from such annual review testing).

Conducting annual reviews consistent with written procedures. Advisers conducted timely annual reviews, but they were not conducted consistent with their written procedures. For example, advisers did not follow their own policies and procedures that required them to cover a defined review period or scope, utilize specified work papers or other documentation, and perform specific tasks and tests. In addition, annual reviews assessed the effectiveness of incorrect documents, such as outdated versions of policies and procedures.

Ensuring compliance policies and procedures fully address and align with practices. Advisers did not recognize, during their annual reviews, that their policies and procedures did not fully address or were not aligned with their practices. There were advisers that: (1) had not adopted policies and procedures to address risk areas that were pivotal to the advisers’ businesses; and (2) did not consider changes in their business activities that were relevant for their assessments of the adequacy of the adviser’s policies and procedures and effectiveness of their implementation (e.g., informing the CCO of certain business or operational changes that may impact the scope of the annual review). The staff identified these inconsistencies after observing issues in core areas of the adviser’s business, operations, and services, which were then compared to the adviser’s annual reviews and applicable written compliance policies and procedures. Examples include annual reviews that did not identify:

• Fee and expense billing practices that deviate from policies and procedures or client disclosures, such as using different fee calculation methodologies, not prorating fees, not applying breakpoints that reduced advisory fees, and not issuing refunds.

• Proxy voting policies that stated the advisers had a responsibility to vote proxies and would vote proxies in a manner consistent with the best economic interests of clients. However, advisers disclosed to clients they did not vote proxies for their clients, and did not vote proxies in practice.

• Custody policies and procedures that omitted steps to ensure that accounts over which the adviser had custody were identified to the independent public accountants performing surprise examinations.

• Marketing policies and procedures not updated to reflect the adoption of the revised marketing rule.

• Regulatory filing procedures not updated to reflect that, when advisers have retail clients, they need to file Form CRS.

• Policies that delegated the execution of services or operations to others, but did not identify how the adviser should oversee these delegated responsibilities to prevent violations of the Act.

• Incidents of non-compliance, identified and reported during the review period, but not addressed or recorded in the annual reviews as instances of noncompliance.

Maintaining documentation made regarding annual reviews.Advisers created documentation when conducting annual reviews, when performing testing and recommending corrective actions, but did not maintain the documentation in their books and records.For example, advisers:

• Included discussions in written annual review reports regarding compliance violations identified during the advisers’ annual reviews. However, the advisers did not maintain the documentation generated during the annual review addressing such compliance issues, such as records regarding the testing performed, issues identified, or corrective actions recommended.

• Adopted policies and procedures requiring annual reviews to be memorialized in written reports that covered specific topics (e.g., recommendations for improvement, material changes to be made to the policies and procedures, and material compliance issues that required remedial action during the previous year). However, no written annual review report was prepared.

• Adopted policies and procedures requiring the annual review to be documented in a specific manner (e.g., using a series of checklists, workpapers, or templates). However, the advisers did not satisfy all of these requirements or only partially completed them.

Taking corrective actions for issues identified in annual reviews.Advisers did not take corrective action after annual reviews recommended changes to the advisers’ compliance policies or procedures, disclosures, or business practices. For example, certain annual reviews identified improving proxy voting practice disclosures, documenting client risk tolerances, or conducting more thorough analysis of best execution and third-party due diligence on broker-dealers. However, the advisers did not make the recommended changes, including instances where the advisers indicated that corrective actions were already implemented but the issues identified persisted.

Conclusion

The Alert encourages advisers to reflect on their policies and procedures, and to implement any appropriate modifications to their annual review process.Orical LLC has significant experience in designing and implementing policies and procedures for registered investment advisers and would be happy to assist you with your next annual review.