Feature Regulatory Compliance
SEC 2026 Examination Priorities: What Investment Advisers, Broker-Dealers, and Compliance Teams Are Getting Tested On
The SEC Division of Examinations released its FY 2026 priorities on November 17, 2025. Here's what's new, what changed from 2025, and the specific controls investment advisers and broker-dealers need to document before examiners arrive.
Table of Contents
Every November, the SEC’s Division of Examinations publishes a letter that tells you, in plain language, what your next examination is going to focus on. Most compliance officers skim it. That’s a mistake.
The FY 2026 Examination Priorities, released November 17, 2025, aren’t just a policy statement. They’re a preview of where deficiency letters will come from. The Division doesn’t commit to examining only what’s in the priorities letter — examiners have full authority to test anything — but when they publish a focus area, they mean it.
TL;DR
- The SEC’s FY 2026 examination priorities focus on fiduciary duty, Regulation S-P compliance, cybersecurity, and AI governance
- Reg S-P amendments (adopted May 2024) required large firms to comply by December 3, 2025; the June 3, 2026 small-firm deadline has now passed — examiners will test both groups
- Crypto is off the priority list for the first time in eight years — a deliberate policy signal from the current SEC leadership
- Newly registered advisers and dual registrants (firms registered both as investment advisers and broker-dealers) face heightened examination scrutiny in 2026
What Changed From 2025 to 2026
Three things stand out comparing this year’s priorities to last year’s.
Crypto is gone. This is the first year since 2018 that digital assets don’t appear as an examination priority. The SEC under the current administration has pulled back on crypto enforcement, withdrew pending crypto-related rules, and signaled a policy reset. That doesn’t mean firms with crypto exposure are off the hook on custody, disclosures, and suitability — but it does mean exam resources are being directed elsewhere.
Reg S-P moved from “upcoming” to “tested.” In 2025, the Reg S-P amendments were future compliance. In 2026, they’re current obligations. Large firms hit their December 3, 2025 deadline months ago. Small firms hit their June 3, 2026 deadline. Examiners are now testing whether programs actually exist.
Tone shifted toward collaboration. The 2026 priorities explicitly frame examinations as collaborative — an opportunity to improve programs, not purely an enforcement mechanism. This is meaningfully different language than recent years. Read it as a signal, not a promise. The Division of Enforcement received a record 53,753 tips and complaints in FY 2025, nearly 19 percent more than the prior year.
Investment Adviser Priorities
Fiduciary Duty: Still the Anchor
The Division continues to prioritize fiduciary duty compliance for investment advisers — but “fiduciary duty” in examination context is specific. Examiners test:
- Whether advice given matches the client’s documented investment objectives and risk tolerance
- Whether conflicts of interest are disclosed in plain terms, not buried in Form ADV Part 2
- Whether compensation arrangements create undisclosed incentives that influence recommendations
- Whether material changes to the firm’s business, personnel, or conflicts are reflected in updated disclosures
The common failure pattern isn’t that advisers ignore fiduciary duty. It’s that documentation lags. An adviser changes a compensation arrangement, serves a new client type, or brings on a new product line — and the Form ADV doesn’t reflect it for a year.
Newly Registered Advisers
The Division explicitly prioritizes newly registered advisers and investment companies in 2026. If your firm registered with the SEC in the past two years, assume an examination is coming sooner rather than later. Examiners focus on:
- Whether written policies and procedures under Rule 206(4)-7 match how the firm actually operates
- Whether the Chief Compliance Officer has real authority — budget, access to senior management, and independence from the business lines they oversee
- Whether there’s documentation of the firm’s annual review of the compliance program’s adequacy and effectiveness
The Rule 206(4)-7 annual compliance review requirement isn’t a checkbox — examiners ask to see the review output, not just confirmation that a review happened.
Dual Registrants and Firms That Have Merged
Two categories get explicit mention as elevated-scrutiny targets:
Dually registered firms (registered as both an investment adviser and a broker-dealer): The priority is whether clients understand which hat the firm is wearing at each touchpoint — fiduciary standard vs. best interest standard. Examiners look at whether there’s role confusion in client communications and whether conflicts from the broker-dealer side are flowing through to advisory clients.
Recently merged advisory practices: Post-merger integration of compliance programs is consistently deficient. When two advisory firms merge, they often have inconsistent policies, different CCO structures, different fee schedules, and different client agreements. Examiners test whether the merged entity has actually reconciled those programs or is operating with two de facto compliance programs that conflict.
Broker-Dealer Priorities
Regulation S-P: Both Deadlines Are Now History
The SEC’s May 2024 amendments to Regulation S-P significantly expanded cybersecurity and data protection requirements for broker-dealers, investment advisers, investment companies, and transfer agents. What’s now required:
- Incident response program: Written policies and procedures for detecting, responding to, and recovering from unauthorized access to customer information
- 30-day customer notification: When customer information has been accessed without authorization, affected customers must be notified within 30 days
- Service provider oversight: Written procedures covering data sharing with third parties, contracts with vendors that access customer data, and oversight of those vendors’ data handling
- Recordkeeping: Documentation that demonstrates the incident response program is maintained and tested
With both deadlines (December 3, 2025 for large firms; June 3, 2026 for small firms) behind us, “we’re working on it” is no longer an acceptable exam response. Examiners will ask to see the written program, the vendor inventory, and evidence that the notification procedure has been tested.
Best Execution
Best execution remains a perennial broker-dealer priority. The 2026 examination focus is on whether firms have documented the best execution review process — specifically, whether the review is periodic (not just theoretical), whether order routing arrangements that create financial incentives are evaluated in that context, and whether clients receive the disclosures required under Rule 606.
Cybersecurity: What Examiners Are Actually Testing
The 2026 priorities identify specific cybersecurity areas for examination across all registrant types:
Policies and procedures: Written cybersecurity policies that match actual operational practice. A policy that says “we use MFA” when the trading desk runs on shared passwords is a deficiency.
Data loss prevention: Controls over where customer data goes, who can access it, and how exfiltration attempts are detected.
Access controls and account management: Privileged access management, access reviews, and what happens to access credentials when employees terminate.
Incident response: The ability to detect, contain, and recover from a cyber incident — and to notify regulators and customers within required timeframes. For the intersection of SEC and banking regulators on notification requirements, see When One Cyber Incident Triggers Four Notification Clocks.
AI and polymorphic malware: Examiners are explicitly testing for controls over AI-enhanced threats — specifically polymorphic malware, which uses AI to alter its signature and evade traditional endpoint detection. Firms should assess whether their EDR tools are updated for this threat class.
AI: What “Supervisory and Governance Protocols” Means in Practice
The Division will review “controls to mitigate new risks associated with artificial intelligence.” That’s deliberately broad, but based on examination findings from 2025, the practical scope includes:
AI use in client-facing recommendations: If your firm uses an algorithm or AI tool that influences portfolio decisions, client recommendations, or financial plans, examiners will ask about the supervisory process for reviewing those outputs. Is there human oversight? Is the oversight documented? Are disclosures to clients accurate about the role AI plays?
AI in compliance monitoring: Many firms use AI for surveillance, transaction monitoring, and risk flagging. Examiners will test whether those tools are validated, whether alerts are acted upon, and whether the AI is creating false confidence about the compliance program’s effectiveness.
AI vendor oversight: Using a third-party AI tool doesn’t insulate a firm from responsibility for AI-driven outputs. Vendor due diligence, contract provisions about data use, and documentation of the vendor’s governance practices are all fair game.
Trading algorithms: Algorithmic trading has been an examination priority for years. The 2026 addition is scrutiny of AI-enhanced trading tools — particularly whether supervisory controls keep pace with the algorithm’s capabilities.
A note on the SEC cybersecurity disclosure rule’s intersection with AI: if your firm has a material cybersecurity incident involving an AI system — whether a model failure, data exfiltration through an AI tool, or an AI-driven trade error — the Form 8-K materiality analysis applies. Build that scenario into your incident response tabletop exercises now.
So What? Five Things to Do Before Your Next Exam
If you read the SEC’s 2026 priorities and your immediate reaction is that you’re behind on one or more of these areas, you’re not alone — and the answer isn’t panic, it’s sequencing.
1. Confirm your Reg S-P incident response program is written, not just understood. The most common Reg S-P deficiency will be “we have a process, but it’s not documented.” Examiners want a written policy they can read. Start there.
2. Pull your Form ADV and run a conflict check. When did you last update Part 2? Have your compensation arrangements, fee schedules, or service offerings changed since then? If you received an MRA related to disclosures in 2024 or 2025, confirm remediation is complete.
3. Document your AI governance perimeter. Make a list of every AI tool your firm uses — in trading, compliance, research, and client service — and confirm you have supervisory procedures and vendor documentation for each one.
4. Run a vendor access inventory. Who has access to your customer data? Under what contract terms? Under what controls? The Reg S-P service provider oversight requirement is often the hardest part of compliance because it requires building an inventory most firms don’t have.
5. Build a deficiency letter tracking system. Exam findings require timely, documented remediation. If you’re managing that in email or a spreadsheet, consider a structured issues management tracker that captures each finding, owner, due date, and closure evidence — the format examiners expect when they follow up.
The SEC Division of Examinations examined roughly 15 percent of registered investment advisers and 40 percent of broker-dealers annually in recent years. That’s not a remote risk — it’s a planning assumption. The firms that come out of examinations with deficiency letters rather than enforcement referrals are the ones whose programs are documented, tested, and up to date.
Sources:
- SEC Division of Examinations — 2026 Examination Priorities (full document)
- SEC Press Release — Division of Examinations Announces 2026 Priorities
- FINRA Cybersecurity Advisory — SEC Amends Regulation S-P
- SEC Announces Enforcement Results for Fiscal Year 2025
- Harvard Law School Forum — 2026 SEC Division of Examinations Priorities
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are the most important areas in the SEC's 2026 examination priorities?
Why did crypto drop out of the SEC's 2026 exam priorities?
What does the Reg S-P compliance deadline mean for smaller broker-dealers and advisers?
What does 'AI governance' mean for purposes of a 2026 SEC examination?
What's the practical difference between a deficiency letter and an enforcement referral?
Are newly registered advisers examined differently than established firms?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
Effective Challenge in Model Risk Management: Document the Disagreement
Model risk management effective challenge needs a decision trail. Build a challenge memo that preserves evidence, responses, conditions, and escalation.
Jul 24, 2026
Regulatory Compliance
FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now
FinCEN's student aid fraud alert gives banks nine red flags, a SAR keyword, and a clear transaction-monitoring task for ACH refunds.
Jul 23, 2026
Regulatory Compliance
Magnolia Diagnostics False Claims Act Settlement: Why Investors Paid Part of the $24 Million
The Magnolia Diagnostics False Claims Act settlement reached investors, requisition controls, and $24M in payments. Here is what to fix.
Jul 23, 2026