Feature Compliance Strategy
The SEC Just Charged 38 Entities for Using Form ADV as a Fraud Tool. Here's What Legitimate Advisers Need to Fix Now.
In August 2026, the SEC charged 38 entities with filing false Forms ADV to impersonate legitimate investment advisers. The scheme exploited IAPD directly. Here is what compliance teams at legitimate advisers need to audit in their own filings — and what due diligence now requires.
Table of Contents
TL;DR
- In August 2026, the SEC charged 38 entities with filing false Forms ADV as exempt reporting advisers — fake Colorado addresses, disconnected phones, identical ownership structures, nonexistent audit firms — to appear legitimate on IAPD and lure retail investors
- The scheme exploited a real registration system: the entities appeared on a government database alongside thousands of legitimate advisers
- Legitimate registered advisers and ERAs need to audit their own Form ADV now — investors and counterparties are doing more verification, not less, after this case
- Due diligence procedures that stop at an IAPD lookup are no longer sufficient; verifying auditor existence, physical address presence, and ownership consistency are now baseline steps
There is a specific kind of institutional trust that makes financial markets function. One component of it: if an entity appears in the SEC’s publicly searchable investment adviser database, it has filed with a federal regulator and is subject to oversight.
That trust is what 38 entities exploited in 2025 and 2026.
On August 27, 2026, the SEC filed 38 separate civil complaints in the U.S. District Court for the District of Colorado against entities it alleges made material misrepresentations in Forms ADV filed with the Commission. Each entity filed as an exempt reporting adviser. Each appeared in IAPD alongside tens of thousands of legitimate registered investment advisers. Each listed what looked like a legitimate Colorado business address, claimed audited financial statements, and presented ownership information consistent with a real private fund structure.
None of it was true.
What They Did
The SEC’s complaints describe a systematic abuse of the Commission’s own filing infrastructure.
Each of the 38 entities filed Form ADV as an exempt reporting adviser — the category available to private fund advisers that qualify for an exemption from full SEC registration. Filing as an ERA requires completing Form ADV and submitting it through the SEC’s EDGAR system. It does not require prior approval, examination, or verification of the information filed.
The specific misrepresentations in the 38 filings, according to the SEC’s complaints:
Fake business addresses. All 38 entities listed Colorado business addresses where they had no actual presence. Colorado was likely selected because it allows entity formation and address-of-record services that can make a non-presence look like a real location.
Non-functional phone numbers. The listed phone numbers were either disconnected or belonged to unrelated businesses — a detail that would become relevant when a prospective investor tried to call before investing.
Identical ownership structures. Multiple entities across the 38 filings disclosed ownership structures and numerical data that were identical or nearly identical to each other. A diligent reviewer looking across several ERAs would have found copy-pasted information, which is not a pattern that arises organically among unrelated advisers.
Nonexistent audit firms. Each entity claimed its private fund’s financial statements had been audited by one of two named accounting firms. Those accounting firms do not appear in any public registry of federal or state accountancy firms — not the PCAOB’s registered firm database, not state CPA board directories.
Foreign IP addresses. The SEC alleges that a number of the defendants used IP addresses tracked to foreign jurisdictions to access the Commission’s EDGAR filing system when submitting their Forms ADV.
The SEC asked the entities to produce records substantiating their ADV disclosures. None complied.
Why This Is Harder to Detect Than It Looks
The scheme worked because it mimicked the legitimate structure of a real exempt reporting adviser. A legitimate ERA files Form ADV, appears in IAPD, has an auditor, has a Colorado (or any other state) address, and has an ownership structure. The content that distinguishes a fraudulent filing from a real one — a real address, a working phone, a verifiable auditor, a non-copy-pasted ownership section — requires active verification to confirm.
Retail investors who used IAPD to look up an entity’s registration status would have found a result. The result would show the entity had filed with the SEC. Without verifying the auditor’s existence, calling the phone number, or checking the physical address, the IAPD entry could reasonably be mistaken for evidence of oversight.
The SEC issued a separate investor alert specifically about ERA filing scams alongside these charges, noting that appearing in IAPD as an ERA does not mean the SEC has vetted, approved, or overseen the entity.
The Compliance Program Implications
This case matters beyond the fraud itself. The 38 fake ERA filings illustrate two distinct compliance concerns for legitimate advisers.
Your Own Form ADV Is Now a Verification Target
Investors, counterparties, and due diligence teams conducting post-August-2026 reviews of investment advisers are going to cross-check the details that fraudulent filers faked. If your Form ADV shows a Colorado address you don’t actually occupy, a phone number that doesn’t route to your firm, an auditor whose name can’t be found in a public registry, or ownership information that hasn’t been updated since your fund restructured — you will fail that cross-check.
The SEC’s charges don’t create new obligations for legitimate advisers. Form ADV accuracy is already required. Section 207 of the Advisers Act prohibits making untrue statements of material fact in any filing under the Act. The amendment obligation under Rule 204-1 requires prompt filing when information in Form ADV becomes materially inaccurate.
What the 38 fake ERA cases do is make visible the specific things that distinguish a credible ADV from a fraudulent one. Those things — verifiable address, working phone, real auditor, non-copy-pasted ownership, accurate financials — are worth auditing now in your own filings.
A Form ADV audit checklist for legitimate advisers:
| Item | What to Verify |
|---|---|
| Business address | Does your firm have actual operations there? Does a Google Maps check, state corporate registry, or lease/property record confirm presence? |
| Phone number | Does it ring to your firm? Is it answered by someone who can discuss the business? |
| Principals and owners | Are all current principals listed? Has anyone joined or departed that requires an update? |
| Financial information | Is your reported AUM current within the required tolerance? Is your account count accurate? |
| Auditor | Does your stated auditor appear in the PCAOB registered firm database or the relevant state CPA board directory? |
| Private fund financials | If you report audited financials, can you produce documentation that an audit by that firm actually occurred? |
| Substantiation | For every material statement in the ADV, is there documentation you could produce to the SEC within days of a request? |
The Compliance Building coverage of this sweep makes an important practical observation: the 38 entities all failed to respond to SEC requests for records. A legitimate adviser responding to an SEC inquiry with documentation is a very different posture from one that goes silent. Your ability to produce substantiating records quickly is itself a compliance control.
Due Diligence Procedures Need to Go Beyond IAPD
If your compliance program includes reviewing investment advisers — whether you’re a fund-of-funds doing manager due diligence, an institutional investor evaluating allocations, a bank reviewing relationships with adviser counterparties, or a platform conducting onboarding — an IAPD lookup can no longer be the end of your process.
The Davis Polk September 2026 Investment Management Regulatory Update catalogues this case alongside other SEC enforcement developments, noting the pattern of fraudulent actors exploiting legitimate regulatory infrastructure to manufacture apparent legitimacy.
A diligence checklist post-August 2026:
-
IAPD lookup — necessary, not sufficient. Confirm the entity appears in IAPD, review the Form ADV, note the filing date and any amendments.
-
Verify the physical address. Call the address a “presence check”: Google Maps, state corporate registry, LinkedIn, any other source that confirms the entity actually operates from that location.
-
Verify the phone number. Call it. Note who answers and whether the response is consistent with a functioning advisory firm.
-
Verify the auditor. Look up the named auditor in the PCAOB registered firms database (pcaobus.org) and the relevant state CPA board directory. If the firm doesn’t appear in either, that is a significant red flag.
-
Check for duplicate ownership structures. If multiple entities you’re reviewing share identical or near-identical ownership disclosures, flag this for closer review.
-
Cross-check state registrations. Many advisers are also registered with state securities regulators. Consistent information across SEC and state filings is a positive signal; gaps or inconsistencies warrant more digging.
-
Request documentation. A legitimate adviser can produce partnership agreements, audited financial statements from the named auditor, proof of physical office, and key personnel verification. If an adviser resists producing these in response to a reasonable request, that is material information.
The Broader Pattern: Registration Infrastructure as a Fraud Vector
This case follows a familiar pattern. In late September, the SEC charged entities for using fake Form D filings and FinCEN MSB registrations to manufacture the appearance of regulatory legitimacy for AI trading scams. The 38 ERA case uses the same structural logic applied to Form ADV.
Regulatory infrastructure — Form D, MSB registration, Form ADV — creates an impression of oversight. For legitimate entities that use these systems, that impression is accurate. The problem is that the systems are generally open to filing without prior vetting. A Form D is a notice filing. An ERA Form ADV is a reporting obligation. FinCEN MSB registration is a self-registration. None of these trigger an examination before the registration is visible to the public.
Compliance programs that treat the existence of a registration as evidence of legitimacy are working with an assumption the SEC has now explicitly flagged as false.
The SEC’s annual compliance review risk alert from September 2026 noted that advisers with compliance deficiencies frequently lacked procedures responsive to current regulatory risks. Verification procedures for counterparty and manager due diligence are exactly the kind of area where a compliance program can lag behind the actual threat environment.
So What?
Two actions. Neither is complex.
For registered advisers and ERAs: Pull your Form ADV. Run the audit checklist above. If anything is materially inaccurate, file an amendment. Ensure that for every material statement in the ADV, you have documentation you could produce within days of an SEC request. This isn’t a new legal obligation — it’s meeting the obligation that already exists, now with visibility into how the SEC is looking at it.
For compliance teams doing counterparty or manager due diligence: Update your procedures to require verification of the auditor’s existence, the physical address, and the contact information listed in Form ADV. An IAPD lookup that stops at confirming the entity appears in the database is not due diligence in the current environment.
An Issues Management Tracker is useful for both: documenting the findings from a Form ADV self-audit, tracking remediation of any inaccuracies, and creating a record that shows your program responded to this enforcement signal with documented action — not a note to revisit later.
Registration is not legitimacy. But maintaining accurate registrations, and verifying them thoroughly before relying on them, is what competent compliance programs now require.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the 38 entities actually do?
What is an Exempt Reporting Adviser and why was this structure targeted?
What charges is the SEC pursuing and what penalties are at stake?
How should a firm verify whether an investment adviser is legitimate?
What do I need to check in my own Form ADV?
Does appearing in IAPD mean an investment adviser is regulated or legitimate?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Compliance Strategy
The New SEC Exam Handbook Turns Exam Readiness Into a Production-Control Test
The SEC Exam Handbook sets 24-hour record availability and 180/30/60-day milestones. Here is the evidence workflow CCOs should test.
Oct 1, 2026
Compliance Strategy
The DOJ Just Charged Two Engineers for Trading Crypto on a DEX With Listing MNPI. Your MNPI Policy Probably Doesn't Cover This.
DOJ charged two former Robinhood engineers in September 2026 for front-running crypto listing announcements using perpetual futures on Hyperliquid. The case reveals surveillance gaps in every crypto-adjacent MNPI policy.
Sep 29, 2026
Compliance Strategy
Stop Building for the October 1 Form PF Deadline. It Just Moved to July 2027 — for the Fourth Time.
The SEC and CFTC extended the Form PF compliance date to July 1, 2027 — the fourth extension of the February 2024 amendments. If your firm was building systems to meet October 2026, here's what changed and what to do instead.
Sep 27, 2026