Skip to content
RiskTemplates · The Daily Brief Sunday, September 27, 2026
Wire OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program. SEP 26

Feature Compliance Strategy

The SEC Just Published Your Annual Compliance Review Exam Checklist

The September 14, 2026 SEC risk alert on Rule 206(4)-7 annual compliance reviews names five deficiency categories with specific examples — every one is testable at your next exam.

By Rebecca Leung · September 25, 2026 ·
Table of Contents

TL;DR

  • On September 14, 2026, the SEC’s Division of Examinations published a risk alert on investment adviser annual compliance reviews under Rule 206(4)-7.
  • Five deficiency categories: timeliness, incomplete policies, misalignment with actual business, documentation, and unresolved corrective actions.
  • Specific findings include advisers who skipped entire years, ran 15-month “annual” reviews, used training as a substitute for substantive review, and let corrective actions from prior years rot unimplemented.
  • A risk alert is the closest thing to a preview of your exam. Read it as a checklist before your next review cycle.

A risk alert from the SEC Division of Examinations isn’t guidance. It isn’t aspirational. It’s a memo from the people who just finished examining a cohort of firms, telling you exactly what they found wrong — and implicitly, exactly what they’ll look for when they show up at your door.

The September 14, 2026 risk alert on investment adviser annual compliance reviews is that kind of document. Five deficiency categories, specific examples, and zero ambiguity about what “at least annually” means. If you run a registered investment adviser, this is your pre-exam briefing.

What Rule 206(4)-7 Actually Requires

Rule 206(4)-7 under the Investment Advisers Act of 1940 has three core requirements:

  1. Written compliance policies and procedures reasonably designed to prevent violations of the Advisers Act.
  2. An annual review of those policies and procedures to assess their adequacy and effectiveness.
  3. A designated Chief Compliance Officer responsible for administering the compliance program.

The “adequacy and effectiveness” standard is the one practitioners routinely underestimate. It’s not enough to have a compliance manual that gets updated once in a while. The rule requires a documented, substantive evaluation that asks whether the current policies actually work for the current business — and whether they’re being followed.

The September 2026 SEC examination priorities flagged Rule 206(4)-7 compliance as an active focus area. The risk alert is the follow-up: here’s what examiners found when they looked.

The Five Deficiency Categories

1. Timeliness

“At least annually” means no more than 12 months between reviews. The SEC found advisers who:

  • Conducted reviews for 2021 and 2023 but skipped 2022 entirely.
  • Performed reviews that covered periods exceeding 12 months — technically completing a review, but not at the required frequency.
  • Completed their initial registration review 18 months after registering, rather than within the first year.
  • Deferred reviews citing business disruptions, personnel changes, and operational transitions.

That last category is worth slowing down on. The alert specifically says that “changes in an adviser’s business or personnel” are not a sufficient justification to defer the annual review. CCO departure doesn’t pause the clock. A merger doesn’t pause the clock. A systems migration doesn’t pause the clock.

This matters operationally because most compliance calendars build the annual review around CCO bandwidth. If the CCO role is vacant or in transition, the review still needs to happen — either by the interim CCO, outside counsel, or a third-party compliance consultant covering the gap.

2. Incomplete Policies and Procedures

The adequacy test requires that your policies actually cover your current business. The SEC found advisers whose:

  • Policies hadn’t been updated as the adviser’s business changed — new investment strategies, new distribution channels, new technology tools, new personnel structures.
  • Compliance manuals lacked sections covering key risk areas that were active in the business but unaddressed in writing.
  • Written procedures were disconnected from actual practices — the policy described one process, the business ran a different one.

This is a structural failure that compounds over time. A compliance program written when an RIA managed $50M in separately managed accounts doesn’t automatically cover model portfolios, crypto allocations, or AI-generated investment signals added five years later. The annual review is specifically designed to catch this gap — but only if someone is actually reading both the current policy and the current business activity.

3. Misalignment Between Review Design and Business Practices

Related to incomplete procedures but distinct: the SEC identified advisers who had policies and procedures but whose annual review process didn’t actually test whether those policies matched what the firm was doing.

Common patterns included:

  • Annual reviews that were checkbox exercises — confirming procedures existed, not assessing whether they were being followed.
  • Review scope that excluded high-risk business lines or new activities from meaningful scrutiny.
  • Reviews that didn’t test controls — they reviewed the policy without asking whether the control actually worked.

A compliance program review that tests paperwork instead of behavior isn’t an annual review under Rule 206(4)-7. The rule asks whether the policies and procedures are adequate and effective. “Effective” requires some evidence that the controls actually function.

4. Documentation

The documentation deficiency is straightforward: if the annual review happened but there’s no record, an examiner can’t verify it happened. The SEC found advisers who:

  • Maintained no written record of the annual review — no memo, no report, no working papers.
  • Kept incomplete records that couldn’t support the scope or conclusions of the review.
  • Had documentation that predated the review or was clearly templated without specific evidence of work done.

A written record isn’t optional. In an exam, the annual review documentation is the starting point — it tells examiners what you covered, what you found, and what you decided to do about it. If that record doesn’t exist or doesn’t match what happened, the subsequent exam conversation gets difficult quickly.

5. Unresolved Corrective Actions

This is the category that creates the most trouble in practice — and it’s worth treating as a standalone compliance risk. The SEC found advisers who:

  • Identified deficiencies in a prior annual review but never implemented the remediation steps.
  • Told examiners corrective actions had been completed, then showed the same deficiency appearing again in the next year’s review.
  • Maintained an open log of corrective actions with no owners, no due dates, and no closure evidence.

The implication is significant: an annual compliance review that finds problems and doesn’t fix them is worse than no review at all in one respect — it creates a documented record of known deficiencies that weren’t remediated. That evidence is in the file when the examiner arrives.

What This Looks Like in a CCO’s Work Queue

The risk alert isn’t addressed to the CCO’s team in abstract terms. It describes specific situations that real compliance programs run into:

The gap year. Business is busy in 2025. The CCO is transitioning out. The 2025 annual review slips into early 2026, and then nobody realizes the 2026 calendar review needs to start almost immediately to stay on cycle. Before long, there’s an 18-month gap and a 2025 review that technically covers 2025-2026. Neither is what Rule 206(4)-7 requires.

The training substitution. The CCO builds a compliance training calendar. Annual attestations go out in January. Everyone reads and certifies the compliance manual. The CCO interprets this as the annual review. Examiners disagree — attestations establish that employees read the policy, not that the policy itself was evaluated for adequacy and effectiveness.

The evergreen corrective action. The 2024 annual review found that trade allocations weren’t being documented in compliance with the allocation policy. The 2024 review report recommended updating the documentation template. In 2025, the same finding reappears. In 2026, same finding. The CCO checks “in progress” on the 2024 corrective action every year. An examiner reading three consecutive annual reviews will notice.

The CCO personal liability cases the SEC and FINRA have brought in the last two years underscore why this matters at an individual level — not just a firm level. CCO personal liability under SEC and FINRA enforcement increasingly turns on whether the CCO had documented evidence of knowing about a problem and failing to address it. An open corrective action log is exactly that kind of document.

What Examiners Will Ask

When an examiner opens a Rule 206(4)-7 inquiry, the first document request typically covers:

  • Annual review reports or memoranda for the past three years.
  • List of corrective actions identified in each annual review.
  • Evidence of corrective action completion (policy updates, system changes, training records).
  • Any CCO changes or transitions that affected the review schedule.

The five deficiency categories in the risk alert map directly to those requests. If your annual review for 2025 happened in March 2026, the examiner will ask why — and “we’ve been busy” is not a safe answer.

The parallel with OCC and FDIC enforcement standards for banks is instructive: regulators across the spectrum are moving toward documented materiality thresholds, requiring clear evidence that identified problems got resolved, not just logged.

So What?

If you run a registered investment adviser or work in its compliance function, the September 14 risk alert gives you a clean pre-exam to-do list. Before your next annual review cycle:

Check your schedule. When did you complete the last annual review? Is it in a 12-month window? Pull the report and confirm the date range it covered. If there’s a gap or an overlap, document the reason and note whether it affected substantive coverage.

Assess your scope. Does your annual review actually test the business you’re running in 2026? Have you added services, strategies, technology, or personnel since the last policy update? If the compliance manual doesn’t address those activities, the annual review that uses that manual as a scope document has the same gap.

Confirm training isn’t your review. Annual compliance training and employee attestations are part of a compliance program — but they’re not the annual review. The review is a substantive evaluation of whether the policies work, conducted by the CCO or a designee with appropriate knowledge and independence.

Build an open-items tracker. Every corrective action from this year’s annual review should have an owner, a due date, and evidence when it’s closed. A spreadsheet is fine. A dedicated issues management tracker is better. What’s not acceptable is a list of recurring findings that never move to resolution.

Plan for CCO transitions. If your CCO is departing or the role is in transition, establish in writing who is responsible for completing the annual review and on what timeline. Don’t let the question go unanswered until an examiner asks it.

The Division of Examinations publishes risk alerts when they’re seeing patterns. This one is a direct readout from recent examination cycles. Every firm that reads it and doesn’t adjust before their next exam has the same information the examiner does — and chose to leave the gap open.


The SEC’s Division of Examinations risk alert is available directly from the SEC. Analysis from Mayer Brown, Latham & Watkins, and ACA Group provided additional context on the specific deficiency findings.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does Rule 206(4)-7 require for annual compliance reviews?
Rule 206(4)-7 under the Investment Advisers Act of 1940 requires registered investment advisers to adopt and implement written compliance policies and procedures reasonably designed to prevent violations of the Advisers Act, and to review those policies and procedures at least annually to assess their adequacy and effectiveness. The rule also requires a designated Chief Compliance Officer.
What were the most common annual compliance review deficiencies the SEC found in 2026?
The September 14, 2026 risk alert identified five areas: (1) timeliness — reviews not completed at least annually, including missing entire calendar years; (2) incomplete procedures — policies not updated to reflect current business activities; (3) misalignment between review design and actual business practices; (4) documentation gaps; and (5) failure to implement corrective actions from prior reviews.
Can a CCO departure justify delaying the annual compliance review?
No. The SEC specifically flagged CCO departures and other business or personnel changes as insufficient justification for deferring or skipping an annual review. The review requirement continues regardless of staffing transitions.
Does completing compliance training count as an annual review?
No. The SEC risk alert explicitly identified advisers who treated annual compliance training or personnel attestations as satisfying the annual review requirement. Training and attestations are not substitutes for a documented substantive review of policies and procedures.
How long does an annual compliance review have to be?
The rule requires a review at least annually — meaning no more than 12 months between reviews. The SEC flagged cases where advisers conducted reviews covering periods exceeding 12 months, or skipped a year entirely (e.g., performed reviews for 2021 and 2023 but not 2022). The review must cover the prior year's period.
What happens if corrective actions from a prior annual review aren't implemented?
This is a standalone deficiency. The SEC found instances where advisers indicated corrective actions had been implemented, yet the same deficiencies reappeared in subsequent annual reviews. Failure to follow through on remediation is independently enforceable under Rule 206(4)-7.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.