Feature Compliance Strategy
The SEC Just Published Your Annual Compliance Review Exam Checklist
The September 14, 2026 SEC risk alert on Rule 206(4)-7 annual compliance reviews names five deficiency categories with specific examples — every one is testable at your next exam.
Table of Contents
TL;DR
- On September 14, 2026, the SEC’s Division of Examinations published a risk alert on investment adviser annual compliance reviews under Rule 206(4)-7.
- Five deficiency categories: timeliness, incomplete policies, misalignment with actual business, documentation, and unresolved corrective actions.
- Specific findings include advisers who skipped entire years, ran 15-month “annual” reviews, used training as a substitute for substantive review, and let corrective actions from prior years rot unimplemented.
- A risk alert is the closest thing to a preview of your exam. Read it as a checklist before your next review cycle.
A risk alert from the SEC Division of Examinations isn’t guidance. It isn’t aspirational. It’s a memo from the people who just finished examining a cohort of firms, telling you exactly what they found wrong — and implicitly, exactly what they’ll look for when they show up at your door.
The September 14, 2026 risk alert on investment adviser annual compliance reviews is that kind of document. Five deficiency categories, specific examples, and zero ambiguity about what “at least annually” means. If you run a registered investment adviser, this is your pre-exam briefing.
What Rule 206(4)-7 Actually Requires
Rule 206(4)-7 under the Investment Advisers Act of 1940 has three core requirements:
- Written compliance policies and procedures reasonably designed to prevent violations of the Advisers Act.
- An annual review of those policies and procedures to assess their adequacy and effectiveness.
- A designated Chief Compliance Officer responsible for administering the compliance program.
The “adequacy and effectiveness” standard is the one practitioners routinely underestimate. It’s not enough to have a compliance manual that gets updated once in a while. The rule requires a documented, substantive evaluation that asks whether the current policies actually work for the current business — and whether they’re being followed.
The September 2026 SEC examination priorities flagged Rule 206(4)-7 compliance as an active focus area. The risk alert is the follow-up: here’s what examiners found when they looked.
The Five Deficiency Categories
1. Timeliness
“At least annually” means no more than 12 months between reviews. The SEC found advisers who:
- Conducted reviews for 2021 and 2023 but skipped 2022 entirely.
- Performed reviews that covered periods exceeding 12 months — technically completing a review, but not at the required frequency.
- Completed their initial registration review 18 months after registering, rather than within the first year.
- Deferred reviews citing business disruptions, personnel changes, and operational transitions.
That last category is worth slowing down on. The alert specifically says that “changes in an adviser’s business or personnel” are not a sufficient justification to defer the annual review. CCO departure doesn’t pause the clock. A merger doesn’t pause the clock. A systems migration doesn’t pause the clock.
This matters operationally because most compliance calendars build the annual review around CCO bandwidth. If the CCO role is vacant or in transition, the review still needs to happen — either by the interim CCO, outside counsel, or a third-party compliance consultant covering the gap.
2. Incomplete Policies and Procedures
The adequacy test requires that your policies actually cover your current business. The SEC found advisers whose:
- Policies hadn’t been updated as the adviser’s business changed — new investment strategies, new distribution channels, new technology tools, new personnel structures.
- Compliance manuals lacked sections covering key risk areas that were active in the business but unaddressed in writing.
- Written procedures were disconnected from actual practices — the policy described one process, the business ran a different one.
This is a structural failure that compounds over time. A compliance program written when an RIA managed $50M in separately managed accounts doesn’t automatically cover model portfolios, crypto allocations, or AI-generated investment signals added five years later. The annual review is specifically designed to catch this gap — but only if someone is actually reading both the current policy and the current business activity.
3. Misalignment Between Review Design and Business Practices
Related to incomplete procedures but distinct: the SEC identified advisers who had policies and procedures but whose annual review process didn’t actually test whether those policies matched what the firm was doing.
Common patterns included:
- Annual reviews that were checkbox exercises — confirming procedures existed, not assessing whether they were being followed.
- Review scope that excluded high-risk business lines or new activities from meaningful scrutiny.
- Reviews that didn’t test controls — they reviewed the policy without asking whether the control actually worked.
A compliance program review that tests paperwork instead of behavior isn’t an annual review under Rule 206(4)-7. The rule asks whether the policies and procedures are adequate and effective. “Effective” requires some evidence that the controls actually function.
4. Documentation
The documentation deficiency is straightforward: if the annual review happened but there’s no record, an examiner can’t verify it happened. The SEC found advisers who:
- Maintained no written record of the annual review — no memo, no report, no working papers.
- Kept incomplete records that couldn’t support the scope or conclusions of the review.
- Had documentation that predated the review or was clearly templated without specific evidence of work done.
A written record isn’t optional. In an exam, the annual review documentation is the starting point — it tells examiners what you covered, what you found, and what you decided to do about it. If that record doesn’t exist or doesn’t match what happened, the subsequent exam conversation gets difficult quickly.
5. Unresolved Corrective Actions
This is the category that creates the most trouble in practice — and it’s worth treating as a standalone compliance risk. The SEC found advisers who:
- Identified deficiencies in a prior annual review but never implemented the remediation steps.
- Told examiners corrective actions had been completed, then showed the same deficiency appearing again in the next year’s review.
- Maintained an open log of corrective actions with no owners, no due dates, and no closure evidence.
The implication is significant: an annual compliance review that finds problems and doesn’t fix them is worse than no review at all in one respect — it creates a documented record of known deficiencies that weren’t remediated. That evidence is in the file when the examiner arrives.
What This Looks Like in a CCO’s Work Queue
The risk alert isn’t addressed to the CCO’s team in abstract terms. It describes specific situations that real compliance programs run into:
The gap year. Business is busy in 2025. The CCO is transitioning out. The 2025 annual review slips into early 2026, and then nobody realizes the 2026 calendar review needs to start almost immediately to stay on cycle. Before long, there’s an 18-month gap and a 2025 review that technically covers 2025-2026. Neither is what Rule 206(4)-7 requires.
The training substitution. The CCO builds a compliance training calendar. Annual attestations go out in January. Everyone reads and certifies the compliance manual. The CCO interprets this as the annual review. Examiners disagree — attestations establish that employees read the policy, not that the policy itself was evaluated for adequacy and effectiveness.
The evergreen corrective action. The 2024 annual review found that trade allocations weren’t being documented in compliance with the allocation policy. The 2024 review report recommended updating the documentation template. In 2025, the same finding reappears. In 2026, same finding. The CCO checks “in progress” on the 2024 corrective action every year. An examiner reading three consecutive annual reviews will notice.
The CCO personal liability cases the SEC and FINRA have brought in the last two years underscore why this matters at an individual level — not just a firm level. CCO personal liability under SEC and FINRA enforcement increasingly turns on whether the CCO had documented evidence of knowing about a problem and failing to address it. An open corrective action log is exactly that kind of document.
What Examiners Will Ask
When an examiner opens a Rule 206(4)-7 inquiry, the first document request typically covers:
- Annual review reports or memoranda for the past three years.
- List of corrective actions identified in each annual review.
- Evidence of corrective action completion (policy updates, system changes, training records).
- Any CCO changes or transitions that affected the review schedule.
The five deficiency categories in the risk alert map directly to those requests. If your annual review for 2025 happened in March 2026, the examiner will ask why — and “we’ve been busy” is not a safe answer.
The parallel with OCC and FDIC enforcement standards for banks is instructive: regulators across the spectrum are moving toward documented materiality thresholds, requiring clear evidence that identified problems got resolved, not just logged.
So What?
If you run a registered investment adviser or work in its compliance function, the September 14 risk alert gives you a clean pre-exam to-do list. Before your next annual review cycle:
Check your schedule. When did you complete the last annual review? Is it in a 12-month window? Pull the report and confirm the date range it covered. If there’s a gap or an overlap, document the reason and note whether it affected substantive coverage.
Assess your scope. Does your annual review actually test the business you’re running in 2026? Have you added services, strategies, technology, or personnel since the last policy update? If the compliance manual doesn’t address those activities, the annual review that uses that manual as a scope document has the same gap.
Confirm training isn’t your review. Annual compliance training and employee attestations are part of a compliance program — but they’re not the annual review. The review is a substantive evaluation of whether the policies work, conducted by the CCO or a designee with appropriate knowledge and independence.
Build an open-items tracker. Every corrective action from this year’s annual review should have an owner, a due date, and evidence when it’s closed. A spreadsheet is fine. A dedicated issues management tracker is better. What’s not acceptable is a list of recurring findings that never move to resolution.
Plan for CCO transitions. If your CCO is departing or the role is in transition, establish in writing who is responsible for completing the annual review and on what timeline. Don’t let the question go unanswered until an examiner asks it.
The Division of Examinations publishes risk alerts when they’re seeing patterns. This one is a direct readout from recent examination cycles. Every firm that reads it and doesn’t adjust before their next exam has the same information the examiner does — and chose to leave the gap open.
The SEC’s Division of Examinations risk alert is available directly from the SEC. Analysis from Mayer Brown, Latham & Watkins, and ACA Group provided additional context on the specific deficiency findings.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does Rule 206(4)-7 require for annual compliance reviews?
What were the most common annual compliance review deficiencies the SEC found in 2026?
Can a CCO departure justify delaying the annual compliance review?
Does completing compliance training count as an annual review?
How long does an annual compliance review have to be?
What happens if corrective actions from a prior annual review aren't implemented?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Compliance Strategy
Stop Building for the October 1 Form PF Deadline. It Just Moved to July 2027 — for the Fourth Time.
The SEC and CFTC extended the Form PF compliance date to July 1, 2027 — the fourth extension of the February 2024 amendments. If your firm was building systems to meet October 2026, here's what changed and what to do instead.
Sep 27, 2026
Compliance Strategy
The SEC Proposed to Rescind the Pay-to-Play Rule. Your Compliance Program Shouldn't Change Yet.
On September 3, 2026, the SEC proposed rescinding Rule 206(4)-5 — the pay-to-play rule investment advisers have operated under since 2010. The rule is still fully in effect. Here's what advisers need to know about what survives even a final rescission.
Sep 26, 2026
Compliance Strategy
FinCEN Hit UBS with a $125 Million Record Fine for BSA Failures It Already Paid to Fix. Here's What Recidivist AML Enforcement Means for Your Program.
On August 3, 2026, FinCEN assessed a $125 million penalty against UBS Financial Services — the largest BSA fine ever against a broker-dealer, and a repeat action for failures the firm had already settled in 2018. The message from FinCEN is direct: a consent order that doesn't change the program will eventually cost you more than the first one.
Sep 24, 2026