The SEC’s Division of Examinations issued a Risk Alert on September 14, 2026, reminding advisers that the annual compliance review required by Advisers Act Rule 206(4)-7 must meaningfully assess both the adequacy of the firm’s policies and procedures and the effectiveness of their implementation. Examiners are focused on whether firms complete reviews timely, test current practices, preserve supporting documentation, identify deficiencies, and complete corrective actions.
While every SEC-registered adviser knows an annual review is required, the SEC’s message is clear: simply checking the box is not enough.
Where Examiners Found Weaknesses
• Timeliness of annual reviews
• Completeness of review procedures
• Alignment between policies and actual business practices
• Documentation and supporting records
• Follow-through on corrective actions
Perhaps the most significant takeaway is that the SEC expects firms to evaluate whether compliance programs actually work in practice. Policies that appear adequate on paper but do not reflect current operations, regulatory requirements, or business activities create examination risk.
Documentation Is Part of the Deliverable
The Risk Alert highlights a common weakness: firms may perform review activities but fail to preserve the supporting workpapers, testing records, findings, and recommendations needed to demonstrate the scope and quality of the review. Advisers should be prepared to show not only the final report, but also the evidence supporting their conclusions.
Findings Must Lead to Remediation
A finding is not resolved simply because it appears in an annual review report. Firms should assign responsibility, establish target dates, retain evidence of corrective action, and independently validate that the underlying condition has been corrected. Prior-year findings should be revisited to confirm that remediation remains effective.
Steps Advisers Should Consider
• Confirm that the review is completed no less frequently than annually.
• Ensure written procedures explain how testing and validation will be performed.
• Test current business practices against current policies and procedures.
• Maintain detailed workpapers and a centralized annual review file.
• Track regulatory, operational, personnel, and affiliate changes throughout the year.
• Use a corrective-action log and verify closure of prior findings.
• Evaluate whether significant events warrant an interim review.
Bottom line: An effective annual review should be timely, tailored to the adviser’s actual business, supported by evidence, and followed by verified corrective action.
Conclusion
As SEC examination activity continues, advisers should assess whether their annual review process would withstand examiner scrutiny today. A well-designed program should demonstrate what was reviewed, how it was tested, what issues were found, who was responsible for remediation, and how the firm confirmed that corrective action was effective.
Pause, Think, Verify: Helping Clients Avoid Today’s Most Common Scams
Criminals are becoming increasingly sophisticated in their efforts to defraud investors. From impersonating government agencies and financial institutions to leveraging artificial intelligence to mimic voices, emails, and text messages, today’s scams are designed to create urgency, exploit vulnerabilities, and pressure individuals into making quick decisions.
While investor education remains a critical component of fraud prevention, investment advisers and broker-dealers are uniquely positioned to identify red flags, implement preventive measures, and help clients protect their assets before a scam succeeds.
Understanding Today’s Scam Environment
Scammers continually adapt their tactics to take advantage of current events, emerging technologies, and consumers’ trust in familiar institutions. While the methods vary, most scams are designed to create confusion, exploit emotions, and pressure victims into taking immediate action. By creating panic, scammers attempt to prevent victims from stopping to verify the legitimacy of the request. Understanding the most common scam types can help firms educate clients and recognize potential red flags.
Imposter Scams
Imposter scams occur when criminals pose as trusted organizations or individuals, such as government agencies, law enforcement officials, banks, credit card companies, or even family members. Fraudsters often use spoofed phone numbers, realistic emails, or text messages that appear legitimate. Their objective is typically to obtain sensitive personal information, gain access to financial accounts, or persuade victims to send money under false pretenses.
Investment and Affinity Scams
Investment scams frequently promise high returns with little or no risk, often involving products that are difficult to verify or understand. Fraudsters may use social media, online forums, or personal relationships to gain credibility before soliciting funds. Affinity scams are particularly effective because they target members of specific groups, communities, or organizations, leveraging existing trust to encourage participation.
Romance and Social Engineering Scams
Romance scams involve building an online relationship with a victim over weeks or months before requesting money for a fabricated emergency or investment opportunity. More broadly, social engineering scams manipulate victims through trust, fear, sympathy, or urgency. Rather than exploiting technological vulnerabilities, these scams exploit human behavior, making them especially difficult to detect.
Tech Support and Account Security Scams
In these schemes, individuals receive unsolicited calls, emails, or pop-up messages claiming that a computer, bank account, or financial account has been compromised. Victims are urged to provide login credentials, grant remote access to their devices, or transfer funds to supposedly “secure” accounts. In reality, the scammers are seeking direct access to the victim’s assets and information.
Payment and Cryptocurrency Scams
Many fraudsters instruct victims to use unusual payment methods such as gift cards, wire transfers, peer-to-peer payment applications, or cryptocurrency. These payment methods are difficult to reverse and can make recovery of lost funds nearly impossible. Requests for payment through non-traditional channels are often a significant warning sign that a scam may be underway.
What Advisory Firms and Broker-Dealers Can Do
Although firms cannot prevent every attempted fraud, there are several measures that can significantly reduce the risk of client harm.
Obtain Trusted Contact Information
One of the most effective tools available is obtaining a trusted contact person for client accounts. A trusted contact can serve as an important resource when there are concerns about possible financial exploitation, diminished capacity, or unusual account activity.
For broker-dealers, FINRA Rule 4512 requires firms to make reasonable efforts to obtain trusted contact information for retail customer accounts. Investment advisers are also increasingly adopting this practice as part of their overall client protection framework.
By proactively collecting and periodically updating trusted contact information, firms strengthen their ability to respond when suspicious situations arise.
Train Employees to Recognize Red Flags
Front-line personnel are often the first line of defense against fraud. Firms should provide ongoing training to help employees identify warning signs such as:
sudden requests for large or unusual disbursements;
wire transfers to unfamiliar third parties;
increased client anxiety or references to secretive situations;
requests involving cryptocurrency, gift cards, or other atypical payment methods;
clients acting under apparent pressure from an outside party; and
multiple failed attempts to verify account information or instructions.
An employee who recognizes these indicators may be able to intervene before fraudulent transactions occur.
Strengthening Verification Procedures
Verification procedures should be robust enough to address today’s evolving fraud tactics. Firms should consider implementing procedures that require additional verification for high-risk transactions, requests involving changes to account information, or instructions that deviate from established client behavior.
Encouraging clients to independently verify unsolicited requests through known telephone numbers or established communication channels can also help prevent successful impersonation attempts.
Educating Clients Regularly
Client awareness remains one of the strongest defenses against fraud. Regular communications, newsletters, seminars, and website resources can help clients understand current scam trends and recognize warning signs. Simple reminders can be highly effective:
pause before acting on urgent requests;
verify the identity of anyone requesting money or personal information;
be skeptical of unexpected communications; or
never assume an email, text message, or phone call is legitimate simply because it appears to come from a trusted source.
Conclusion
As fraud schemes continue to evolve, financial professionals must remain vigilant. A proactive approach that combines employee training, client education, trusted contact information, and strong supervisory controls can significantly reduce the likelihood that clients become victims of financial exploitation.
The most important message firms can share with clients is also the simplest: when faced with an urgent or unexpected request, pause, think, and verify before taking action. Those few moments of caution can make the difference between protecting a lifetime of savings and becoming the next victim of an increasingly sophisticated scam.
As the summer heat kicks in, while there is little indication that the regulatory “warming trend” will subside any time soon, the typical slowdown in business over the summer months provides opportunities to review your firm’s compliance program. Focusing on selected aspects of your compliance program may also reveal ways to cut costs associated with compliance in the long run. The secret to an efficient review is to focus on the regulatory target areas and not try to do too much.
The Regulatory Focus
The regulatory focus on the retail investor will continue. The SEC and FINRA have enhanced their practices to target the areas of the highest risk to the public. Novel new products such as digital assets, structured securities, and prediction markets are in focus. The updates to Regulation S-P brought renewed focus on firm’s due diligence practices for vendors that host systems and access or store customer data. Piling on all that is the increasing risk of cybercrime – both internal and external – and the increasing use of artificial intelligence tools. If that’s all buttoned up, then you don’t want to get caught off guard with “old school” compliance gaps such as inadequate policies and procedures, recordkeeping, or supervision. There are certainly a wide range of focus areas that can be addressed. Like many firms, the regulators are using AI to assist in their analysis, which provides the ability to cover a wider range of topics in exams.
Identifying the Areas to Review
With the above in mind, the review of your firm’s operations should focus on those areas most relevant to your business. First, assess your products and services from a financial perspective, identifying products and services that generate the most revenue. The compliance review should focus on those areas of your firm’s operations that generate the most business, i.e. revenue. Also, consider looking at the policies and procedures for supervising branch offices and remote locations. Additionally, if there is a product or service that you have not reviewed in some time, or that is new to your firm, the policies and procedures related to those areas should be included in your review. For example, if you’re selling more ETF’s or insurance securities, look at the supervisory and operational procedures for those products. If you recently added digital assets or prediction market access, look at the procedures governing those practices and the training programs in place for the public facing and supervisory personnel.
Second, consider any areas where you rely on third parties to provide a significant support function. The most common for broker-dealers is the clearing function, while RIAs may rely heavily on the custodian or a portfolio valuation service. Create a list of vendors that includes the services they provide, the contact people for the vendor, and the contract date. Larger firms should also add the person(s) internally who own the relationship, such as the financial officer for accounting software, the operations officer for clearing relationships, etc. Consider all services provided by third parties or affiliates (services provided by affiliates are typically considered outsourced) including surveillance and compliance management vendors. In addition to the clearing and custody relationships noted above, many firms use third party vendors to support internet access and email, storage of books and records, payroll processing, and accounting functions. Some other common areas that are often overlooked are the phone systems, technology support, law firms, and consultants.
Conducting the Review
For the areas you’ve selected to review, determine how the business is processed from start to finish. It may be helpful to create a flow diagram of the process that identifies “touch points” where a supervisory procedure or control would/should exist. A good example would be where the representative forwards completed paperwork for a variable annuity transaction to a principal for review. These points could include the representative assembling the paperwork, delivering it to a sales assistant, and the sales assistant forwarding it to the principal or a centralized operations department for review and approval. Your procedures should address a control or supervisory process for each time the paperwork changes hands. Perhaps the sales assistant does a check to ensure all the proper completed paperwork is included, and in the predetermined order, before forwarding to the principal. This simple control will reduce delays in processing paperwork and the time that the principal has to spend reviewing, and supervising, the transaction, thereby saving time and money. When reviewing processes, policies and procedures for new lines of business, be careful not to try to fit a square peg into a round hole. That is, don’t assume that the procedure for supervising an equity security transaction will fit the exchange traded note. You must consider the unique aspects of the product, related disclosures, and the customer’s objectives. This is a simple example and more complex operations require a more in-depth assessment even when processes are automated, we often find data breaks where two or more data feeds are required to complete a process. These need to be carefully mapped out.
If your firm relies on third party vendors and does not have a due diligence process for assessing them, develop one – you are late to the game. Start with the vendor contract to determine if the regulatory requirements are met. For example, Regulation S-P now formally requires notification of a breach within 72 hours. Also, if the vendor is deemed a “Service Bureau” for the purposes of the SEC’s Books and Records Rules, the vendor must agree to make the records available to the Regulators. Similarly consider any AML, business continuity, and privacy issues that may arise from the relationship. For FINRA members, these arrangements may also have to be disclosed before implementation. Depending on the nature of the vendor relationship, your due diligence process should include reviews of the vendor’s internal control reports, business continuity plans, information and technology security, and insurance coverage such as E&O, theft, and professional liability. Ongoing vendor monitoring is critical. While most services can be monitored on an ongoing basis – that is, if the service fails you know it and correct it with a backup plan – it’s a good practice to schedule a formal meeting at least annually with the vendors’ representatives to review the services and reassess the areas covered in the due diligence process.
Correction and Documentation
As you complete each review, create a short, written summary of the review and gap analysis performed, including the corrective steps to be taken, if any. For material deficiencies, consider reviewing with counsel to determine the potential regulatory impact. In addition to amending written policies and procedures, corrective actions should include training employees to ensure that proper procedures are implemented, and the new procedures are adequately communicated.
Conclusion
A compliance review provides a great opportunity to reassess your business operations, not only for compliance purposes, but to identify areas of efficiency and cost savings. This type of review can be incorporated into your annual review requirements and supervisory controls testing. Your review should be reasonable, and you should not try to do too much. Once you start digging, you may find that one issue will take longer than you anticipated completing. It’s better to do a portion at a time and complete a full review on an area than to take on too much and leave items undone.
So, what are your plans this summer? Awaiting the regulatory heat? Or sitting back and enjoying the compliance reliance?
As the SEC’s amended Regulation S-P requirements become effective for all investment advisers, firms should now be focused on implementation of the requirements, including cybersecurity governance, vendor oversight, use of artificial intelligence (AI), and testing their ability to respond effectively to cyber incidents.
We outline key areas firms should prioritize over the balance of the year.
Implementation Readiness
The Regulation S-P requirements now place greater emphasis on incident response, customer notification, and protection of customer information.
Firms should ensure they have:
Written incident response procedures
Escalation and breach assessment protocols
Customer notification procedures
Vendor oversight programs
Information security controls
Documented employee training
Evidence of testing and governance
Recommended Action Items:
Conduct at least one tabletop cybersecurity exercise
Confirm client notification templates are prepared
Test escalation and communication workflows
Review vendor incident notification obligations
Key Risk: It is expected that the SEC will focus on firms that cannot demonstrate implementation and testing of their cybersecurity controls.
Artificial Intelligence (AI) Governance
AI usage has expanded rapidly, creating new regulatory and operational risks.
The SEC expects firms to maintain controls over customer information regardless of the technology platform being utilized.
Primary AI Risks:
Employees entering confidential client data into public AI systems
Unapproved “shadow AI” usage
AI-generated inaccuracies
Improper use of AI-generated marketing content
Vendor AI data retention concerns
Recommended Controls:
Establish an AI Governance Policy
Maintain an approved AI tools inventory
Prohibit entry of customer information into public AI platforms
Require human review of AI-generated content
Conduct employee AI usage training
Include AI vendors in vendor due diligence reviews
Best Practice: Treat AI access and governance similarly to email, cloud storage, and cybersecurity controls.
Cybersecurity & Threat Management
Cyber threats targeting financial services firms continue increasing in sophistication.
Key Threats Firms Should Monitor:
AI-powered phishing attacks
Business email compromise (BEC)
Remote Access Tool (RAT) attacks
Ransomware
Vendor and supply chain breaches
Credential theft and MFA bypass attacks
Recommended Controls:
Multi-factor authentication (MFA)
Endpoint Detection & Response (EDR)
Device encryption
Patch management
Privileged access restrictions
Secure backup testing
Employee phishing simulations
Wire transfer verification procedures
Best Practice: Cybersecurity should be treated as an enterprise risk management issue, not solely an IT function.
Vendor Oversight & Third-Party Risk Management
The SEC continues to increase focus on vendor oversight. Firms should identify all vendors with access to:
Customer information
Network infrastructure
Email systems
Portfolio or trading systems
AI or cloud environments
Recommended Vendor Reviews:
SOC 2 reports
Cybersecurity questionnaires
Incident notification obligations
Data encryption standards
Subcontractor usage
Business continuity capabilities
Cyber insurance coverage
Best Practice: Require contractual notification obligations for suspected breaches within 72 hours.
SEC Examination Preparedness
Regulators are increasingly requesting evidence of implementation rather than simply reviewing policies.
Firms should be prepared to provide:
Evidence of employee training
Incident response testing results
Vendor due diligence documentation
Access review records
Cybersecurity governance documentation
Risk assessments
AI governance documentation
Annual review and testing results
Likely SEC Examination Questions:
How does the firm identify and classify cyber incidents?
How are vendors monitored?
How does the firm govern AI usage?
What testing has been performed?
How would the firm notify clients after a breach?
What evidence exists that management reviewed cybersecurity risks?
Employee Training
Many cybersecurity incidents continue to originate from employee actions.
Training should include:
Phishing awareness
Password and MFA security
AI usage restrictions
Remote work security
Escalation procedures
Social engineering risks
Data handling procedures
Best Practice: Conduct periodic phishing simulations and maintain evidence of employee participation.
Governance & Documentation
One of the most important themes for 2026 is documentation.
If an action is not documented, regulators may assume it did not occur.
Firms should maintain documentation related to:
Testing activities
Vendor reviews
Employee training
Risk assessments
Incident response exercises
AI governance reviews
Cybersecurity committee or management discussions
Best Practice: Maintain centralized cybersecurity and compliance evidence repositories.
Final Takeaways
For the remainder of 2026, investment advisers should focus on five core themes:
Implementation and Awareness
Cybersecurity Governance
AI Oversight and Controls
Vendor Risk Management
Testing and Documentation
The firms best positioned for SEC examinations will be those able to demonstrate that cybersecurity, AI governance, and operational controls are active, tested, and supported by management oversight.
Regulation S-P should now be viewed as a broader operational and cybersecurity framework rather than solely a privacy rule.
Broker-dealers operate in one of the most highly regulated areas of the financial services industry. Regulatory oversight from the SEC, FINRA, and other self-regulatory organizations requires firms to maintain strong compliance controls and supervisory systems. As a result, firms must implement a comprehensive broker dealer compliance program that addresses supervisory responsibilities, internal controls, regulatory reporting, and periodic compliance testing.
Investment advisers operate in a complex regulatory environment where maintaining a strong investment adviser compliance program is essential. The Securities and Exchange Commission (SEC) requires advisers to establish and maintain formal compliance systems designed to prevent regulatory violations and protect investors.