Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

Investment Adviser Compliance Programs in 2026: Why Technical Adequacy Is No Longer Enough Under SEC Rule 206(4)-7

The SEC's 2026 examination priorities put compliance program effectiveness at the center of investment adviser exams. Rule 206(4)-7 always required advisers to evaluate adequacy and effectiveness annually — but examiners are now testing that standard with specificity. Here's what a compliant annual review actually looks like.

Table of Contents

TL;DR

  • Rule 206(4)-7 requires SEC-registered investment advisers to review their compliance programs at least annually for adequacy and effectiveness — but the SEC’s 2026 examination priorities signal that the “effectiveness” half of that standard is now the examination focus
  • Common deficiencies: generic off-the-shelf policies, checklist reviews that confirm existence without testing function, compliance incidents not incorporated into the review, and identified weaknesses that persist across review cycles without remediation
  • The 2026 priorities explicitly call out annual reviews producing “just checklist completion or restated policies” as inadequate — examiners want root cause analysis and documented remediation
  • The right structure: inventory current-year compliance incidents → map root causes → identify control gaps → document remediation with owners and timelines → conclude on overall program adequacy with evidence citation

CCOs who run their Rule 206(4)-7 annual review as a certification exercise are the ones who get deficiency letters. The ones who run it as an effectiveness evaluation are the ones who walk away from exams without findings.

The distinction matters more in 2026 than it has in years. The SEC Division of Examinations’ 2026 priorities put compliance program quality directly in the center of investment adviser examination focus, with language that’s as close to instruction as exam priorities get: annual reviews should identify root causes of compliance issues and lead to meaningful program improvements — not just checklist completion or restated policies.

If your most recent annual review concluded that “policies are adequate and effective” without specifying what evidence supported that conclusion, an SEC examiner will ask the same question. Having the answer ready before they do is the difference between a clean exam and a deficiency letter.

What Rule 206(4)-7 Actually Requires

Rule 206(4)-7 was adopted in 2003. Its three core requirements have not changed:

  1. Adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and rules
  2. Review those policies and procedures, and their implementation, at least annually to assess adequacy and effectiveness
  3. Designate a Chief Compliance Officer to administer the compliance program

The rule is deliberately non-prescriptive about content. What constitutes “reasonably designed” policies depends on the adviser’s business model, client base, and risk profile. A large multi-strategy fund manager and a sole-practitioner RIA serving individuals in one state will have programs that look very different — both could be compliant.

What the rule is precise about is the review obligation. The review must assess both adequacy and effectiveness. These are different questions, and investment advisers who miss that distinction produce the annual reviews that generate examination findings.

Adequacy answers: Does the program cover the right areas? Are there policies for the firm’s specific business activities, regulatory obligations, and risk profile? A new service offering, a new compensation arrangement, or a new regulatory requirement not reflected in current policies is an adequacy gap.

Effectiveness answers: Do the controls actually work? Are employees following the policies? Are the controls catching the problems they’re designed to catch? A policy that says “all trades are reviewed for compliance before execution” is an adequacy statement. Whether the pre-trade reviews actually happened, whether they caught any issues, and whether caught issues were resolved — that’s effectiveness.

The recurring deficiency pattern is advisers who assess adequacy (do policies exist?) and treat that as the complete review.

The Five Deficiencies That Produce Examination Findings

SEC examination findings and risk alerts document a consistent pattern of Rule 206(4)-7 weaknesses. The five that appear most commonly:

1. Generic, off-the-shelf policies that don’t reflect actual business practices.

A policy library downloaded from a compliance consulting service or inherited from a predecessor firm is a starting point, not a compliant program. Examiners identify boilerplate quickly — policy language that doesn’t match the adviser’s service model, references to products or client types the firm doesn’t have, or controls that can’t possibly be implemented at the firm’s scale. Generic policies create a compounding problem: they don’t tell employees what to actually do, so they don’t prevent violations; and they don’t reflect the business, so they can’t be effectively supervised.

The fix isn’t a policy rewrite every year. It’s a review process that asks, for each major policy area: “Does this describe what we actually do? Would a new employee reading this know what to do?”

2. Annual reviews that confirm policy existence without testing whether policies are followed.

The most common deficiency pattern. The review produces a completed checklist: “Marketing policy — reviewed. Trading policy — reviewed. Code of ethics — reviewed.” No evaluation of whether the marketing team followed the marketing policy, whether trading controls caught any limit violations during the year, or whether code of ethics certifications were submitted on time. Adequacy is confirmed; effectiveness is not assessed.

Examiners know exactly what this review looks like. When the initial document request includes the most recent annual review and the CCO submits a checklist with “yes” in every box, the deficiency is visible before the first conversation.

3. Compliance incidents not incorporated into the annual review.

Every compliance incident during the review year — a late disclosure, a trading error, a customer complaint, a missed regulatory filing, a code of ethics exception — is evidence about whether the compliance program is working. An annual review that doesn’t address what went wrong during the review period is missing half the relevant input.

Examiners routinely ask: “Tell me about any compliance incidents from the past year.” If the annual review document doesn’t discuss them, the disconnect is immediate. If incidents happened but weren’t identified in the review, the question becomes whether any review actually occurred.

4. Identified weaknesses that persist across multiple review cycles.

An annual review that identifies a gap — “the onboarding disclosure checklist isn’t consistently completed” — but documents no remediation action, or documents a remediation action that wasn’t implemented by the next review cycle, creates compounding risk. By the second year the same issue appears, it’s a failure to address a known deficiency. By the third year, it starts to look like a systemic problem with the compliance program itself rather than an isolated gap.

The remediation table in the annual review document needs to carry forward. Items close when they’re confirmed remediated, not when they’re added to a list.

5. Policies last updated years before the current review without documented rationale.

The adequacy review requires asking whether policies cover current business practices. If the firm added a new advisory service two years ago, the policies should have been updated to cover it — and the annual review should either document the update or explain why existing policies adequately covered the new service without changes. Policies untouched for three or more years with no explanation in the review document suggest the adequacy analysis wasn’t conducted.

What a Compliant Annual Review Actually Looks Like

A Rule 206(4)-7 annual review that will hold up under examination scrutiny has four components, none of which require the review to be long:

1. Compliance incident inventory from the review period.

Start with a list of every compliance event during the year: customer complaints, trading errors, late filings, code of ethics violations, regulatory inquiries, audit findings. For each, document what happened, what the root cause was, and what the program response was. This is the effectiveness evidence — it shows the program identified problems, investigated them, and responded. An incident log with no entries doesn’t mean the firm is compliant; it means the CCO didn’t identify incidents, which is a different concern.

2. Policy and procedure adequacy assessment.

For each major compliance area (fiduciary duty, trading, marketing, portfolio management, recordkeeping, conflicts, privacy, AML if applicable), assess whether current policies cover the firm’s current business model. Flag areas where the program hasn’t kept pace with business changes, personnel changes, or regulatory developments. This produces an adequacy conclusion grounded in specific evidence rather than general assertion.

3. Root cause analysis for identified gaps and incidents.

For each gap or incident, document the root cause. Was it a policy gap — no policy covered this scenario? A control failure — the policy existed but wasn’t followed? A training gap — employees weren’t clear on the requirement? An oversight failure — the review process didn’t catch the deviation? The root cause determines the right remediation. A training gap can’t be fixed with a policy update. A control failure can’t be fixed with more training. Matching the remedy to the cause is what produces actual program improvement.

4. Documented remediation with owners and deadlines.

Every identified gap needs a remediation action, a named owner, and a target completion date. The annual review document should contain a remediation table that carries forward from prior reviews. Completed items are closed with evidence. Open items have current status. The CCO signing off on the review is accountable for the table — the items don’t disappear because the review period ended.

The conclusion — “the compliance program is adequate and effective for the firm’s current business” — should reference the evidence from the review process, not just state a conclusion. The examiner who reads that conclusion will ask what evidence supports it. That evidence needs to be in the same document.

The Format the Review Documentation Should Take

No prescribed format exists. A useful structure:

  • CCO cover memo summarizing review scope, methodology, the period covered, and the overall conclusion
  • Compliance incident log with root cause annotations for each entry
  • Policy review table listing each major policy area, the last update date, what (if anything) changed during the review period, and why
  • Gap analysis / remediation table with identified issues, root causes, remediation actions, responsible owners, target dates, and current status
  • Training review section documenting what training was delivered, who attended, and attestation process
  • Supporting evidence index referencing where code of ethics certifications, testing results, and control documentation are stored

The document doesn’t need to be long. A structured 10-to-15-page review with specific evidence citations is more defensible in an examination than a 50-page checklist that can’t be followed. If the reviewer can’t explain the methodology used to reach the adequacy and effectiveness conclusion, the review has a documentation problem regardless of how long it is.

The 2026 Examination Environment and What It Means for Your Next Review

The SEC’s 2026 examination priorities don’t change the substantive requirements of Rule 206(4)-7 — they signal how strictly the standard will be applied. The explicit identification of “checklist completion or restated policies” as the failure mode means examiners are walking into annual review requests with a specific hypothesis about what they’ll find.

Two additional factors make the 2026 review cycle particularly important:

The Reg S-P compliance deadline just passed. For smaller advisers (under $1.5 billion AUM), the June 3, 2026 Reg S-P compliance deadline means the new written incident response program is now an active obligation. The next annual review — and any examinations that follow — will assess whether the IRP is documented, tested, and operational. If the Reg S-P requirements aren’t reflected in your compliance policies yet, that’s an adequacy gap the current-cycle review needs to address.

AI governance is now an examination focus. If your firm uses AI tools in portfolio management, client communications, or compliance monitoring, the current-cycle annual review should specifically address AI governance: who owns it, what policies govern use, what testing was done before deployment. An annual review that doesn’t address AI if the firm uses it is an adequacy gap in an area examiners have explicitly flagged.

The firms that get the best examination outcomes on Rule 206(4)-7 are the ones that treat the annual review as the audit it’s designed to be — not a certification that the program exists, but an assessment of whether it works.


For registered investment advisers needing structured compliance documentation across key domains — data privacy, incident response, and business continuity — the Compliance Essentials bundle is built for multi-domain coverage that cross-references across your annual review evidence files.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does SEC Rule 206(4)-7 require from investment advisers?
Rule 206(4)-7, adopted in 2003, requires every SEC-registered investment adviser to: (1) adopt and implement written policies and procedures reasonably designed to prevent violations of the Investment Advisers Act and rules; (2) review those policies and procedures, and their implementation, at least annually to assess their adequacy and effectiveness; and (3) designate a Chief Compliance Officer responsible for administering the program. The rule does not prescribe specific policy content — it requires that policies be reasonably designed for the adviser's business and risk profile, and that they actually be reviewed for whether they work.
What does 'adequacy and effectiveness' actually mean under Rule 206(4)-7?
'Adequacy' means the compliance program covers the right areas — the firm's specific risks, business activities, and regulatory obligations. 'Effectiveness' means the policies and controls actually function as designed: employees follow them, the controls catch problems, and the program produces the outcomes it's supposed to produce. A checklist that confirms policies exist addresses adequacy. It says nothing about effectiveness. The SEC's 2026 examination priorities make clear that examiners are looking past policy existence to ask whether programs actually work.
What are the most common Rule 206(4)-7 deficiencies SEC examiners find?
Common deficiencies documented in SEC examinations include: generic or off-the-shelf policies that don't reflect the adviser's actual business practices; annual reviews that confirm policies are in place without assessing whether they were followed or whether controls functioned; compliance incidents or near-misses that were not incorporated into the annual review analysis; identified weaknesses that were documented in one review cycle but not remediated before the next; and policies last updated years before the current review without explanation for why no changes were needed.
Does Rule 206(4)-7 require a written annual review document?
While the original rule text requires advisers to 'review' their policies and procedures, the SEC has consistently expected that review to be documented in writing, and examiners routinely request the most recent annual review document as part of initial document requests. An adviser that conducted a review but cannot produce written documentation has effectively failed to demonstrate the review occurred. The SEC's examination approach treats the written record as the evidence that the review was actually conducted.
How does the SEC's 2026 examination emphasis change how investment advisers should approach the annual review?
The 2026 priorities explicitly state that annual reviews should identify root causes of compliance issues and produce meaningful program improvements — not just checklist completion or restated policies. This shifts the standard from a confirmation exercise ('we have policies, they haven't changed') to an effectiveness evaluation ('we identified these gaps, these controls failed, here is what we changed and why'). The output of the review should read more like an audit report than an attestation.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Compliance Essentials

Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.