Skip to main content

Author: James Smith

IA Annual Compliance Reviews – SEC Risk Alert

Business professionals review charts.

Is Your Annual Compliance Review Exam-Ready?

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Overview

The SEC’s Division of Examinations issued a Risk Alert on September 14, 2026, reminding advisers that the annual compliance review required by Advisers Act Rule 206(4)-7 must meaningfully assess both the adequacy of the firm’s policies and procedures and the effectiveness of their implementation. Examiners are focused on whether firms complete reviews timely, test current practices, preserve supporting documentation, identify deficiencies, and complete corrective actions.

While every SEC-registered adviser knows an annual review is required, the SEC’s message is clear: simply checking the box is not enough.

Where Examiners Found Weaknesses

• Timeliness of annual reviews

• Completeness of review procedures

• Alignment between policies and actual business practices

• Documentation and supporting records

• Follow-through on corrective actions

Perhaps the most significant takeaway is that the SEC expects firms to evaluate whether compliance programs actually work in practice. Policies that appear adequate on paper but do not reflect current operations, regulatory requirements, or business activities create examination risk.

Documentation Is Part of the Deliverable

The Risk Alert highlights a common weakness: firms may perform review activities but fail to preserve the supporting workpapers, testing records, findings, and recommendations needed to demonstrate the scope and quality of the review. Advisers should be prepared to show not only the final report, but also the evidence supporting their conclusions.

Findings Must Lead to Remediation

A finding is not resolved simply because it appears in an annual review report. Firms should assign responsibility, establish target dates, retain evidence of corrective action, and independently validate that the underlying condition has been corrected. Prior-year findings should be revisited to confirm that remediation remains effective.

Steps Advisers Should Consider

• Confirm that the review is completed no less frequently than annually.

• Ensure written procedures explain how testing and validation will be performed.

• Test current business practices against current policies and procedures.

• Maintain detailed workpapers and a centralized annual review file.

• Track regulatory, operational, personnel, and affiliate changes throughout the year.

• Use a corrective-action log and verify closure of prior findings.

• Evaluate whether significant events warrant an interim review.

Bottom line: An effective annual review should be timely, tailored to the adviser’s actual business, supported by evidence, and followed by verified corrective action.

Conclusion

As SEC examination activity continues, advisers should assess whether their annual review process would withstand examiner scrutiny today. A well-designed program should demonstrate what was reviewed, how it was tested, what issues were found, who was responsible for remediation, and how the firm confirmed that corrective action was effective.

Source

SEC Division of Examinations, Examinations Observations Regarding Investment Adviser Annual Compliance Review (Sept. 14, 2026).

Note: The Risk Alert reflects SEC staff views, has no legal force or effect, and does not create new obligations.

Regulation S-P: Next Steps for Investment Advisers

Business professionals looking at charts.

As the SEC’s amended Regulation S-P requirements become effective for all investment advisers, firms should now be focused on implementation of the requirements, including cybersecurity governance, vendor oversight, use of artificial intelligence (AI), and testing their ability to respond effectively to cyber incidents.

We outline key areas firms should prioritize over the balance of the year.

Implementation Readiness

The Regulation S-P requirements now place greater emphasis on incident response, customer notification, and protection of customer information.

Firms should ensure they have:

  • Written incident response procedures
  • Escalation and breach assessment protocols
  • Customer notification procedures
  • Vendor oversight programs
  • Information security controls
  • Documented employee training
  • Evidence of testing and governance

Recommended Action Items:

  • Conduct at least one tabletop cybersecurity exercise
  • Confirm client notification templates are prepared
  • Test escalation and communication workflows
  • Review vendor incident notification obligations

Key Risk: It is expected that the SEC will focus on firms that cannot demonstrate implementation and testing of their cybersecurity controls.

Artificial Intelligence (AI) Governance

AI usage has expanded rapidly, creating new regulatory and operational risks.

The SEC expects firms to maintain controls over customer information regardless of the technology platform being utilized.

Primary AI Risks:

  • Employees entering confidential client data into public AI systems
  • Unapproved “shadow AI” usage
  • AI-generated inaccuracies
  • Improper use of AI-generated marketing content
  • Vendor AI data retention concerns

Recommended Controls:

  • Establish an AI Governance Policy
  • Maintain an approved AI tools inventory
  • Prohibit entry of customer information into public AI platforms
  • Require human review of AI-generated content
  • Conduct employee AI usage training
  • Include AI vendors in vendor due diligence reviews

Best Practice: Treat AI access and governance similarly to email, cloud storage, and cybersecurity controls.

Cybersecurity & Threat Management

Cyber threats targeting financial services firms continue increasing in sophistication.

Key Threats Firms Should Monitor:

  • AI-powered phishing attacks
  • Business email compromise (BEC)
  • Remote Access Tool (RAT) attacks
  • Ransomware
  • Vendor and supply chain breaches
  • Credential theft and MFA bypass attacks

Recommended Controls:

  • Multi-factor authentication (MFA)
  • Endpoint Detection & Response (EDR)
  • Device encryption
  • Patch management
  • Privileged access restrictions
  • Secure backup testing
  • Employee phishing simulations
  • Wire transfer verification procedures

Best Practice: Cybersecurity should be treated as an enterprise risk management issue, not solely an IT function.

Vendor Oversight & Third-Party Risk Management

The SEC continues to increase focus on vendor oversight. Firms should identify all vendors with access to:

  • Customer information
  • Network infrastructure
  • Email systems
  • Portfolio or trading systems
  • AI or cloud environments

Recommended Vendor Reviews:

  • SOC 2 reports
  • Cybersecurity questionnaires
  • Incident notification obligations
  • Data encryption standards
  • Subcontractor usage
  • Business continuity capabilities
  • Cyber insurance coverage

Best Practice: Require contractual notification obligations for suspected breaches within 72 hours.

SEC Examination Preparedness

Regulators are increasingly requesting evidence of implementation rather than simply reviewing policies.

Firms should be prepared to provide:

  • Evidence of employee training
  • Incident response testing results
  • Vendor due diligence documentation
  • Access review records
  • Cybersecurity governance documentation
  • Risk assessments
  • AI governance documentation
  • Annual review and testing results

Likely SEC Examination Questions:

  • How does the firm identify and classify cyber incidents?
  • How are vendors monitored?
  • How does the firm govern AI usage?
  • What testing has been performed?
  • How would the firm notify clients after a breach?
  • What evidence exists that management reviewed cybersecurity risks?

Employee Training

Many cybersecurity incidents continue to originate from employee actions.

Training should include:

  • Phishing awareness
  • Password and MFA security
  • AI usage restrictions
  • Remote work security
  • Escalation procedures
  • Social engineering risks
  • Data handling procedures

Best Practice: Conduct periodic phishing simulations and maintain evidence of employee participation.

Governance & Documentation

One of the most important themes for 2026 is documentation.

If an action is not documented, regulators may assume it did not occur.

Firms should maintain documentation related to:

  • Testing activities
  • Vendor reviews
  • Employee training
  • Risk assessments
  • Incident response exercises
  • AI governance reviews
  • Cybersecurity committee or management discussions

Best Practice: Maintain centralized cybersecurity and compliance evidence repositories.

Final Takeaways

For the remainder of 2026, investment advisers should focus on five core themes:

  1. Implementation and Awareness
  2. Cybersecurity Governance
  3. AI Oversight and Controls
  4. Vendor Risk Management
  5. Testing and Documentation

The firms best positioned for SEC examinations will be those able to demonstrate that cybersecurity, AI governance, and operational controls are active, tested, and supported by management oversight.

Regulation S-P should now be viewed as a broader operational and cybersecurity framework rather than solely a privacy rule.