Breaking Regulatory Compliance
SEC's Simplify Asset Management Order: Four ETF Controls That Failed at Once
The SEC Simplify Asset Management order ties a $400,000 penalty to affiliate trades, VaR escalation, Form N-RN delays, and distribution notices.
Table of Contents
TL;DR
- The SEC’s July 27 order requires Simplify Asset Management to pay $400,000 after findings involving affiliate transactions, derivatives leverage breaches, late board escalation and Form N-RN filings, and missing return-of-capital notices.
- One ETF’s relative VaR reached 291% against Rule 18f-4’s 200% threshold; the fund lost more than 8% of its value on May 2, 2024, primarily while reducing the position.
- The breakdown was not one bad trade. Legal analysis, risk escalation, filing, shareholder disclosure, custom-basket procedures, and board reporting failed to connect.
- ETF advisers should test the handoffs: affiliate memo to Legal, VaR breach to the derivatives risk manager, day-five trigger to the board, event to Form N-RN, and distribution data to Section 19(a) notices.
The SEC’s Simplify Asset Management order reads like four separate compliance cases packed into 13 pages.
There were two affiliate transactions that gave a trust tax benefits. Two extended derivatives-risk breaches with months-late board notification and regulatory filings. Seven ETFs that failed to send required return-of-capital notices. Written policies that did not cover important custom-basket deviations until June 2026.
On July 27, 2026, the SEC announced settled charges against Simplify Asset Management. Without admitting the findings, the Las Vegas-based registered investment adviser agreed to cease and desist and pay a $400,000 civil penalty.
The penalty is not the most useful number in the case. The useful numbers are one business day, five business days, 30 days, and 200%. Those are the deadlines and limit that should have turned portfolio risk into board reporting, SEC filing, root-cause analysis, and program changes. The controls did not make the handoff.
What the SEC’s Simplify Asset Management order found
The SEC’s administrative order, Investment Company Act Release No. 36269, covers conduct from July 2021 through June 2026. It identifies four connected control failures.
| Finding | Entities or funds affected | Rule or provision | Outcome |
|---|---|---|---|
| Prohibited affiliate transactions | Trust A and Simplify Propel Opportunities ETF (SURI) | Investment Company Act Section 17(a)(1) | Two in-kind subscriptions proceeded without Section 17(b) exemptive relief |
| Extended leverage-limit breaches and late reporting | Simplify Macro Strategy ETF (FIG) | Section 18(f)(1), Rule 18f-4 conditions, Rule 30b1-10 and Form N-RN | Board notified and forms filed in August 2024, months after April/May events |
| Missing return-of-capital notices | Seven Simplify ETFs | Section 19(a) and Rule 19a-1 | Shareholders did not receive contemporaneous source-of-distribution notices |
| Inadequate policies and procedures | SURI, FIG, and other Simplify ETFs | Rule 38a-1; custom-basket issues also implicated Rule 6c-11 procedures | Relevant notice procedures were absent; custom-basket deviation processes were incomplete |
The Commission said it considered Simplify’s remedial efforts and cooperation. The order still imposes a cease-and-desist requirement covering Sections 17(a)(1), 18(f)(1), and 19(a), plus Rules 19a-1, 30b1-10, and 38a-1.
Failure one: an affiliate determination without the analysis behind it
Simplify advised SURI, a biotechnology and healthcare-focused ETF. A domestic trust—called Trust A in the order—held about a 25% fully diluted stake in Simplify and had voting rights that let it select two of Simplify’s four directors. That made the trust an affiliate of Simplify and, through Simplify’s adviser relationship, a second-tier affiliate of SURI under the SEC’s analysis.
Trust A became a seed investor in SURI. A January 30, 2023 board memorandum described an approximately $71.5 million in-kind contribution of securities for SURI shares and called the exchange tax-free. It also said Trust A was not an affiliate or affiliate of an affiliate of the Simplify Trust, Simplify, the sub-adviser, or an underwriter. According to the order, the memo did not give the board the basis for that conclusion.
The transaction occurred on February 7, 2023. A second in-kind subscription, valued at about $35.7 million, was approved in June. The second basket introduced new securities and different position weights. The memorandum did not discuss Trust A’s affiliate status or the tax benefit. No application for exemptive relief under Section 17(b) was submitted for either transaction.
This is the first practical lesson: a conclusion in a board memo is not an affiliate analysis.
For every seed-capital, in-kind, principal, cross, or custom-basket transaction involving owners, directors, advisers, sub-advisers, portfolio managers, or their controlled entities, the file should show:
- the entity and individual relationship map;
- voting and ownership percentages, including indirect interests;
- the applicable first-tier and second-tier affiliate definitions;
- the transaction role of each party;
- whether Section 17(a) applies;
- whether an exemption or exemptive order is available;
- Legal’s approval and the facts presented to the board.
A better pre-clearance control
Create a mandatory affiliate-and-conflicts ticket for nonstandard in-kind subscriptions and custom baskets. Block release until Legal signs the analysis. The ticket should link the ownership table, basket contents, tax and economic effects, adviser and sub-adviser relationships, requested exemptions, and the precise board disclosure.
Failure two: VaR crossed the line, but escalation did not
The derivatives part of the order is more operational—and more uncomfortable.
FIG used a derivatives strategy. In April 2024, its portfolio manager established an options position in a single unnamed issuer, Company D, designed to profit if the share price declined. The order says the position’s risk exposure was $3.4 million, more than 13% of FIG’s portfolio value at the time.
The stock rose. FIG’s relative VaR exceeded Rule 18f-4’s 200% threshold from April 26 through May 2. On April 26, Simplify’s chief risk officer, who also served as derivatives risk manager, told the portfolio manager that relative VaR was about 253%, primarily due to Company D. The order says the CRO urged reductions daily, but VaR climbed as high as 291%.
On May 2, FIG lost more than 8% of its value, primarily because the portfolio manager partially unwound the position. The fund fell below 200% on May 3, then exceeded the threshold again from May 6 through May 16, ranging from about 224% to 251%.
Risk detection worked. The CRO knew. Daily conversations happened. Yet the board was not notified of either extended breach until August 8, and the required Forms N-RN were not filed until August 9.
That is a classic handoff failure: the control produces information but does not create the required governance event.
The Rule 18f-4 clock
The SEC order explains the core sequence:
| Trigger | Required response | Evidence artifact |
|---|---|---|
| Daily VaR test exceeds applicable threshold | Return to compliance promptly in shareholders’ best interests; risk manager informs portfolio management and escalates material risk as appropriate | Daily calculation, alert, position-reduction decision and rationale |
| Exceedance continues for five business days | Derivatives risk manager sends the board a written report explaining how and when compliance is expected | Dated board report and delivery confirmation |
| Within 30 calendar days | Second written board report explains how compliance was restored; if not restored, update progress; analyze causes and update program elements as appropriate | Root-cause analysis, second board report, approved control changes |
| Form N-RN reportable event occurs | File within one business day under the form’s instructions and Rule 30b1-10 | Filing confirmation and event-to-filing audit trail |
The limit-monitoring system should not depend on a human counting days in email. Configure a stateful breach record with:
- business-day counter;
- fund, strategy, portfolio manager, derivatives risk manager, and compliance owner;
- current and peak relative or absolute VaR;
- threshold and model version;
- position drivers and planned remediation;
- day-one, day-three, and day-five escalation milestones;
- board-report and Form N-RN tasks;
- immutable timestamps and proof of delivery or filing.
A starter control can alert Compliance and the derivatives risk manager on day one, escalate to the CCO and fund counsel by day three, and automatically create draft board and Form N-RN tasks before day five. Those are workflow choices, not regulatory thresholds. Calibrate earlier internal alerts to the fund’s operating model, then test them against reconstructed breaches so the day count cannot be reset by an overnight dip or a manually closed ticket.
Failure three: return of capital reached investors without the required notice
Section 19(a) and Rule 19a-1 require a contemporaneous written statement when a registered investment company pays a distribution from a source other than net income. The notice must distinguish net income, capital gains, and paid-in surplus or other capital sources. The purpose is straightforward: an investor should not mistake returned capital for income generated by the portfolio.
The order found that seven Simplify ETFs failed to provide the notices over various periods between July 2021 and June 2024. Audited financial statements later disclosed the distribution sources, but later annual or semiannual reporting did not replace the contemporaneous notice.
The percentages in the order show why the missed control mattered:
| ETF and period | Portion identified as return of capital |
|---|---|
| Simplify Volatility Premium ETF, July 2021–June 2022 | 98.80% |
| Simplify U.S. Equity PLUS GBTC ETF, July 2022–June 2023 | 88.78% |
| Simplify U.S. Equity PLUS GBTC ETF, July 2023–June 2024 | 70.00% |
| SURI, July 2022–June 2023 | 48.21% |
| Simplify Aggregate Bond PLUS Credit Hedge ETF, July 2022–June 2023 | 33.06% |
The SEC found that the Simplify U.S. Equity PLUS GBTC ETF did not provide contemporaneous notice that a majority—84%—of distributions across the cited fiscal period reflected return of capital.
Build a three-way reconciliation for every distribution:
- the accounting source classification;
- the approved Section 19(a) notice, when required;
- evidence that the notice accompanied the payment to shareholders.
Exceptions should stop distribution release or trigger a documented legal escalation. Monthly compliance testing should sample from the payment population, not from the smaller population of notices produced. Sampling only existing notices will never find a distribution for which no notice was generated.
Failure four: policies lagged the activity
The order says the ETFs had no policies or procedures concerning Section 19(a) and Rule 19a-1 notices before August 2024. It also says custom-basket policies lacked a process for revisions or deviations until June 2026.
For the June 2023 SURI transaction, the custom basket contained securities not held in the ETF’s portfolio. The order says the transaction was incorrectly documented as a “rebalance” basket. Other funds also used custom baskets that deviated from their written parameters while lacking a deviation process.
That is the distinction examiners care about: a policy may describe the standard process while the business operates exceptions. If the policy does not say who can approve a deviation, what facts must be documented, and how Compliance tests it, the exception process is whatever happened in email that day.
A workable custom-basket deviation record should contain the basket composition, difference from standard parameters, reason, shareholder-interest analysis, affiliate and conflicts check, pricing and liquidity review, approvers, and post-transaction review. Labeling must match the actual transaction type.
This is also why the SEC’s 2026 examination priorities for investment advisers and funds should be converted into sample-based testing rather than a policy inventory. The finding lives where the approved workflow and the actual transaction diverge.
Run this four-file review in 30 days
Instead of launching a broad “ETF compliance enhancement,” pull four evidence files.
File 1: Affiliate and basket approvals
Owner: Fund Counsel with the CCO.
Select all seed and nonstandard in-kind transactions from the last 24 months. Reperform affiliate status using current and transaction-date ownership and voting rights. Confirm that custom baskets were correctly classified, any deviations followed written procedures, and the board received the underlying rationale—not just the conclusion.
File 2: VaR breach chronology
Owner: Derivatives Risk Manager with Compliance Testing.
Export every daily threshold breach. Reconstruct consecutive business days, alerts, portfolio instructions, board reports, Form N-RN decisions, filings, and root-cause updates. Pay special attention to episodes that cross below and back above the limit; document how the system handles continuity and separate events.
File 3: Distribution-to-notice reconciliation
Owner: Fund Accounting with the fund CCO.
Start with all distributions, classify the source, identify those requiring notice, and match each to approved content and delivery evidence. Test service-provider files back to the shareholder distribution date. Record missing or late evidence as an issue even if annual financial statements later disclosed the source.
File 4: Rule 38a-1 operating evidence
Owner: Fund CCO.
For affiliate trades, derivatives risk, regulatory filing, shareholder notices, and custom baskets, compare written procedures to actual records. Identify controls that exist only as institutional knowledge, procedures added after the activity began, and workflows with no deviation path.
By day 30, the CCO should have a board-ready gap table:
| Gap | Risk | Interim control | Permanent owner | Validation evidence |
|---|---|---|---|---|
| Affiliate analysis lacks ownership support | Prohibited transaction | Legal pre-clearance for all nonstandard baskets | Fund Counsel | Reperformed sample and approved checklist |
| VaR day counter is manual | Missed board/Form N-RN deadline | Daily Compliance review | Derivatives Risk Technology | Trigger test with immutable timestamps |
| Notice population starts from notices produced | Missing Section 19(a) notice stays invisible | Distribution-to-notice daily reconciliation | Fund Accounting | Population completeness test |
| Custom-basket deviations lack workflow | Inconsistent approval and documentation | CCO approval pending system change | Capital Markets Compliance | Sampled deviations with complete evidence |
The issue-management closure framework is useful here because “procedure updated” is not sufficient closure. The validation has to show that an actual breach creates the board report and filing tasks, an actual distribution creates the required notice, and an actual custom basket receives the right classification and approvals.
The lesson behind the $400,000 penalty
The Simplify order shows a system failing to turn known facts into the legally required next action. Compliance programs usually break at interfaces:
- ownership facts do not reach the affiliate analysis;
- a CRO’s warning does not start the regulatory clock;
- accounting classification does not start shareholder disclosure;
- an operating exception does not update policy or create a documented deviation;
- a board memo states a conclusion without enough support to challenge it.
The SEC’s broader 2026 enforcement shift toward investor harm and fiduciary failures does not make these control obligations academic. This case links leverage, conflicted transactions, and opaque distributions directly to fund investors.
If your review produces missed handoffs across Legal, Risk, Fund Accounting, and Compliance, the Issues Management Tracker & Template keeps remediation owners, due dates, evidence, and independent validation in one place.
Sources
- SEC administrative proceeding summary: Simplify Asset Management, July 27, 2026
- SEC Order, Investment Company Act Release No. 36269, File No. 3-22662
- Investment Executive: “ETF advisor settles with SEC,” July 27, 2026
Related: How to prepare for SEC investment adviser examinations and how to run a defensible Rule 206(4)-7 annual compliance review.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the SEC charge Simplify Asset Management with?
How much did Simplify Asset Management agree to pay?
What happened with the Simplify Macro Strategy ETF's VaR limit?
What is the Form N-RN deadline after a qualifying VaR exceedance?
What should ETF compliance teams review after the Simplify order?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs
OFAC's December 2025 settlement with Exodus Movement — $3.1 million for 254 apparent violations of the Iranian Transactions and Sanctions Regulations — is the clearest statement yet that non-custodial crypto wallets are in scope for sanctions obligations. The finding that staff advised Iranian users to use VPNs is the detail that turns a compliance failure into an egregious one.
Jul 30, 2026
Regulatory Compliance
Iuka State Bank Written Agreement: The Fed's 30-Day Credit Risk and BSA/AML Remediation List
The Iuka State Bank written agreement maps Fed findings to 30- and 60-day fixes across credit, capital, liquidity, and BSA/AML.
Jul 30, 2026
Regulatory Compliance
OCC-FDIC CRA Proposal: The 2026 Changes Banks Need to Map Now
The OCC-FDIC CRA proposal changes bank thresholds, lending tests, grant eligibility, and reporting. Here is the control impact.
Jul 30, 2026