Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Regulatory Compliance

SEC 2026 Examination Priorities: What Investment Advisers, Broker-Dealers, and Compliance Teams Are Getting Tested On

The SEC Division of Examinations released its FY 2026 priorities on November 17, 2025. Here's what's new, what changed from 2025, and the specific controls investment advisers and broker-dealers need to document before examiners arrive.

Table of Contents

Every November, the SEC’s Division of Examinations publishes a letter that tells you, in plain language, what your next examination is going to focus on. Most compliance officers skim it. That’s a mistake.

The FY 2026 Examination Priorities, released November 17, 2025, aren’t just a policy statement. They’re a preview of where deficiency letters will come from. The Division doesn’t commit to examining only what’s in the priorities letter — examiners have full authority to test anything — but when they publish a focus area, they mean it.

TL;DR

  • The SEC’s FY 2026 examination priorities focus on fiduciary duty, Regulation S-P compliance, cybersecurity, and AI governance
  • Reg S-P amendments (adopted May 2024) required large firms to comply by December 3, 2025; the June 3, 2026 small-firm deadline has now passed — examiners will test both groups
  • Crypto is off the priority list for the first time in eight years — a deliberate policy signal from the current SEC leadership
  • Newly registered advisers and dual registrants (firms registered both as investment advisers and broker-dealers) face heightened examination scrutiny in 2026

What Changed From 2025 to 2026

Three things stand out comparing this year’s priorities to last year’s.

Crypto is gone. This is the first year since 2018 that digital assets don’t appear as an examination priority. The SEC under the current administration has pulled back on crypto enforcement, withdrew pending crypto-related rules, and signaled a policy reset. That doesn’t mean firms with crypto exposure are off the hook on custody, disclosures, and suitability — but it does mean exam resources are being directed elsewhere.

Reg S-P moved from “upcoming” to “tested.” In 2025, the Reg S-P amendments were future compliance. In 2026, they’re current obligations. Large firms hit their December 3, 2025 deadline months ago. Small firms hit their June 3, 2026 deadline. Examiners are now testing whether programs actually exist.

Tone shifted toward collaboration. The 2026 priorities explicitly frame examinations as collaborative — an opportunity to improve programs, not purely an enforcement mechanism. This is meaningfully different language than recent years. Read it as a signal, not a promise. The Division of Enforcement received a record 53,753 tips and complaints in FY 2025, nearly 19 percent more than the prior year.

Investment Adviser Priorities

Fiduciary Duty: Still the Anchor

The Division continues to prioritize fiduciary duty compliance for investment advisers — but “fiduciary duty” in examination context is specific. Examiners test:

  • Whether advice given matches the client’s documented investment objectives and risk tolerance
  • Whether conflicts of interest are disclosed in plain terms, not buried in Form ADV Part 2
  • Whether compensation arrangements create undisclosed incentives that influence recommendations
  • Whether material changes to the firm’s business, personnel, or conflicts are reflected in updated disclosures

The common failure pattern isn’t that advisers ignore fiduciary duty. It’s that documentation lags. An adviser changes a compensation arrangement, serves a new client type, or brings on a new product line — and the Form ADV doesn’t reflect it for a year.

Newly Registered Advisers

The Division explicitly prioritizes newly registered advisers and investment companies in 2026. If your firm registered with the SEC in the past two years, assume an examination is coming sooner rather than later. Examiners focus on:

  • Whether written policies and procedures under Rule 206(4)-7 match how the firm actually operates
  • Whether the Chief Compliance Officer has real authority — budget, access to senior management, and independence from the business lines they oversee
  • Whether there’s documentation of the firm’s annual review of the compliance program’s adequacy and effectiveness

The Rule 206(4)-7 annual compliance review requirement isn’t a checkbox — examiners ask to see the review output, not just confirmation that a review happened.

Dual Registrants and Firms That Have Merged

Two categories get explicit mention as elevated-scrutiny targets:

Dually registered firms (registered as both an investment adviser and a broker-dealer): The priority is whether clients understand which hat the firm is wearing at each touchpoint — fiduciary standard vs. best interest standard. Examiners look at whether there’s role confusion in client communications and whether conflicts from the broker-dealer side are flowing through to advisory clients.

Recently merged advisory practices: Post-merger integration of compliance programs is consistently deficient. When two advisory firms merge, they often have inconsistent policies, different CCO structures, different fee schedules, and different client agreements. Examiners test whether the merged entity has actually reconciled those programs or is operating with two de facto compliance programs that conflict.

Broker-Dealer Priorities

Regulation S-P: Both Deadlines Are Now History

The SEC’s May 2024 amendments to Regulation S-P significantly expanded cybersecurity and data protection requirements for broker-dealers, investment advisers, investment companies, and transfer agents. What’s now required:

  • Incident response program: Written policies and procedures for detecting, responding to, and recovering from unauthorized access to customer information
  • 30-day customer notification: When customer information has been accessed without authorization, affected customers must be notified within 30 days
  • Service provider oversight: Written procedures covering data sharing with third parties, contracts with vendors that access customer data, and oversight of those vendors’ data handling
  • Recordkeeping: Documentation that demonstrates the incident response program is maintained and tested

With both deadlines (December 3, 2025 for large firms; June 3, 2026 for small firms) behind us, “we’re working on it” is no longer an acceptable exam response. Examiners will ask to see the written program, the vendor inventory, and evidence that the notification procedure has been tested.

Best Execution

Best execution remains a perennial broker-dealer priority. The 2026 examination focus is on whether firms have documented the best execution review process — specifically, whether the review is periodic (not just theoretical), whether order routing arrangements that create financial incentives are evaluated in that context, and whether clients receive the disclosures required under Rule 606.

Cybersecurity: What Examiners Are Actually Testing

The 2026 priorities identify specific cybersecurity areas for examination across all registrant types:

Policies and procedures: Written cybersecurity policies that match actual operational practice. A policy that says “we use MFA” when the trading desk runs on shared passwords is a deficiency.

Data loss prevention: Controls over where customer data goes, who can access it, and how exfiltration attempts are detected.

Access controls and account management: Privileged access management, access reviews, and what happens to access credentials when employees terminate.

Incident response: The ability to detect, contain, and recover from a cyber incident — and to notify regulators and customers within required timeframes. For the intersection of SEC and banking regulators on notification requirements, see When One Cyber Incident Triggers Four Notification Clocks.

AI and polymorphic malware: Examiners are explicitly testing for controls over AI-enhanced threats — specifically polymorphic malware, which uses AI to alter its signature and evade traditional endpoint detection. Firms should assess whether their EDR tools are updated for this threat class.

AI: What “Supervisory and Governance Protocols” Means in Practice

The Division will review “controls to mitigate new risks associated with artificial intelligence.” That’s deliberately broad, but based on examination findings from 2025, the practical scope includes:

AI use in client-facing recommendations: If your firm uses an algorithm or AI tool that influences portfolio decisions, client recommendations, or financial plans, examiners will ask about the supervisory process for reviewing those outputs. Is there human oversight? Is the oversight documented? Are disclosures to clients accurate about the role AI plays?

AI in compliance monitoring: Many firms use AI for surveillance, transaction monitoring, and risk flagging. Examiners will test whether those tools are validated, whether alerts are acted upon, and whether the AI is creating false confidence about the compliance program’s effectiveness.

AI vendor oversight: Using a third-party AI tool doesn’t insulate a firm from responsibility for AI-driven outputs. Vendor due diligence, contract provisions about data use, and documentation of the vendor’s governance practices are all fair game.

Trading algorithms: Algorithmic trading has been an examination priority for years. The 2026 addition is scrutiny of AI-enhanced trading tools — particularly whether supervisory controls keep pace with the algorithm’s capabilities.

A note on the SEC cybersecurity disclosure rule’s intersection with AI: if your firm has a material cybersecurity incident involving an AI system — whether a model failure, data exfiltration through an AI tool, or an AI-driven trade error — the Form 8-K materiality analysis applies. Build that scenario into your incident response tabletop exercises now.

So What? Five Things to Do Before Your Next Exam

If you read the SEC’s 2026 priorities and your immediate reaction is that you’re behind on one or more of these areas, you’re not alone — and the answer isn’t panic, it’s sequencing.

1. Confirm your Reg S-P incident response program is written, not just understood. The most common Reg S-P deficiency will be “we have a process, but it’s not documented.” Examiners want a written policy they can read. Start there.

2. Pull your Form ADV and run a conflict check. When did you last update Part 2? Have your compensation arrangements, fee schedules, or service offerings changed since then? If you received an MRA related to disclosures in 2024 or 2025, confirm remediation is complete.

3. Document your AI governance perimeter. Make a list of every AI tool your firm uses — in trading, compliance, research, and client service — and confirm you have supervisory procedures and vendor documentation for each one.

4. Run a vendor access inventory. Who has access to your customer data? Under what contract terms? Under what controls? The Reg S-P service provider oversight requirement is often the hardest part of compliance because it requires building an inventory most firms don’t have.

5. Build a deficiency letter tracking system. Exam findings require timely, documented remediation. If you’re managing that in email or a spreadsheet, consider a structured issues management tracker that captures each finding, owner, due date, and closure evidence — the format examiners expect when they follow up.

The SEC Division of Examinations examined roughly 15 percent of registered investment advisers and 40 percent of broker-dealers annually in recent years. That’s not a remote risk — it’s a planning assumption. The firms that come out of examinations with deficiency letters rather than enforcement referrals are the ones whose programs are documented, tested, and up to date.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are the most important areas in the SEC's 2026 examination priorities?
The top areas are fiduciary duty and conflicts of interest disclosure, Regulation S-P compliance (incident response programs, 30-day breach notification, vendor oversight), cybersecurity controls, and AI governance. Newly registered investment advisers and firms dually registered as broker-dealers face heightened examination scrutiny.
Why did crypto drop out of the SEC's 2026 exam priorities?
The SEC under the current administration has deprioritized crypto enforcement and withdrawn several crypto-related rulemaking efforts. The 2026 priorities are the first since 2018 to exclude crypto as a focus area — a significant policy signal. That said, examiners can still surface compliance failures in core areas like custody, suitability, and disclosures that happen to involve crypto assets.
What does the Reg S-P compliance deadline mean for smaller broker-dealers and advisers?
The SEC amended Reg S-P in May 2024. Large firms had to comply by December 3, 2025. Small firms had until June 3, 2026 — a deadline that has now passed. The amendments require written incident response programs, 30-day customer notification of unauthorized data access, oversight procedures for service providers with access to customer information, and enhanced recordkeeping. Examiners will be testing whether smaller firms have these programs in place.
What does 'AI governance' mean for purposes of a 2026 SEC examination?
Examiners will look for documented governance over AI tools used in portfolio management, trading, compliance monitoring, and client communications — including supervisory procedures, disclosures to clients about AI use, controls over AI-generated recommendations, and monitoring for model drift. The 2026 priorities also specifically call out polymorphic malware (malware that uses AI to evade detection) as a cybersecurity threat requiring controls.
What's the practical difference between a deficiency letter and an enforcement referral?
Most exams result in a deficiency letter — a written finding that requires a response within 30 days explaining corrective actions, typically to be completed within 180 days. An enforcement referral is reserved for more serious potential violations and opens a formal investigation by the SEC's Division of Enforcement. The goal is addressing deficiencies thoroughly so the exam closes without escalation.
Are newly registered advisers examined differently than established firms?
Yes. The Division of Examinations explicitly prioritizes newly registered advisers and investment companies in 2026. New registrants often face exams within the first year or two of registration — focused on whether policies match actual business practices, whether the Chief Compliance Officer has adequate authority and resources, and whether fiduciary duty documentation exists in practice, not just on paper.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.