Feature Compliance Strategy
Investment Adviser Compliance Programs in 2026: Why Technical Adequacy Is No Longer Enough Under SEC Rule 206(4)-7
The SEC's 2026 examination priorities put compliance program effectiveness at the center of investment adviser exams. Rule 206(4)-7 always required advisers to evaluate adequacy and effectiveness annually — but examiners are now testing that standard with specificity. Here's what a compliant annual review actually looks like.
Table of Contents
TL;DR
- Rule 206(4)-7 requires SEC-registered investment advisers to review their compliance programs at least annually for adequacy and effectiveness — but the SEC’s 2026 examination priorities signal that the “effectiveness” half of that standard is now the examination focus
- Common deficiencies: generic off-the-shelf policies, checklist reviews that confirm existence without testing function, compliance incidents not incorporated into the review, and identified weaknesses that persist across review cycles without remediation
- The 2026 priorities explicitly call out annual reviews producing “just checklist completion or restated policies” as inadequate — examiners want root cause analysis and documented remediation
- The right structure: inventory current-year compliance incidents → map root causes → identify control gaps → document remediation with owners and timelines → conclude on overall program adequacy with evidence citation
CCOs who run their Rule 206(4)-7 annual review as a certification exercise are the ones who get deficiency letters. The ones who run it as an effectiveness evaluation are the ones who walk away from exams without findings.
The distinction matters more in 2026 than it has in years. The SEC Division of Examinations’ 2026 priorities put compliance program quality directly in the center of investment adviser examination focus, with language that’s as close to instruction as exam priorities get: annual reviews should identify root causes of compliance issues and lead to meaningful program improvements — not just checklist completion or restated policies.
If your most recent annual review concluded that “policies are adequate and effective” without specifying what evidence supported that conclusion, an SEC examiner will ask the same question. Having the answer ready before they do is the difference between a clean exam and a deficiency letter.
What Rule 206(4)-7 Actually Requires
Rule 206(4)-7 was adopted in 2003. Its three core requirements have not changed:
- Adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and rules
- Review those policies and procedures, and their implementation, at least annually to assess adequacy and effectiveness
- Designate a Chief Compliance Officer to administer the compliance program
The rule is deliberately non-prescriptive about content. What constitutes “reasonably designed” policies depends on the adviser’s business model, client base, and risk profile. A large multi-strategy fund manager and a sole-practitioner RIA serving individuals in one state will have programs that look very different — both could be compliant.
What the rule is precise about is the review obligation. The review must assess both adequacy and effectiveness. These are different questions, and investment advisers who miss that distinction produce the annual reviews that generate examination findings.
Adequacy answers: Does the program cover the right areas? Are there policies for the firm’s specific business activities, regulatory obligations, and risk profile? A new service offering, a new compensation arrangement, or a new regulatory requirement not reflected in current policies is an adequacy gap.
Effectiveness answers: Do the controls actually work? Are employees following the policies? Are the controls catching the problems they’re designed to catch? A policy that says “all trades are reviewed for compliance before execution” is an adequacy statement. Whether the pre-trade reviews actually happened, whether they caught any issues, and whether caught issues were resolved — that’s effectiveness.
The recurring deficiency pattern is advisers who assess adequacy (do policies exist?) and treat that as the complete review.
The Five Deficiencies That Produce Examination Findings
SEC examination findings and risk alerts document a consistent pattern of Rule 206(4)-7 weaknesses. The five that appear most commonly:
1. Generic, off-the-shelf policies that don’t reflect actual business practices.
A policy library downloaded from a compliance consulting service or inherited from a predecessor firm is a starting point, not a compliant program. Examiners identify boilerplate quickly — policy language that doesn’t match the adviser’s service model, references to products or client types the firm doesn’t have, or controls that can’t possibly be implemented at the firm’s scale. Generic policies create a compounding problem: they don’t tell employees what to actually do, so they don’t prevent violations; and they don’t reflect the business, so they can’t be effectively supervised.
The fix isn’t a policy rewrite every year. It’s a review process that asks, for each major policy area: “Does this describe what we actually do? Would a new employee reading this know what to do?”
2. Annual reviews that confirm policy existence without testing whether policies are followed.
The most common deficiency pattern. The review produces a completed checklist: “Marketing policy — reviewed. Trading policy — reviewed. Code of ethics — reviewed.” No evaluation of whether the marketing team followed the marketing policy, whether trading controls caught any limit violations during the year, or whether code of ethics certifications were submitted on time. Adequacy is confirmed; effectiveness is not assessed.
Examiners know exactly what this review looks like. When the initial document request includes the most recent annual review and the CCO submits a checklist with “yes” in every box, the deficiency is visible before the first conversation.
3. Compliance incidents not incorporated into the annual review.
Every compliance incident during the review year — a late disclosure, a trading error, a customer complaint, a missed regulatory filing, a code of ethics exception — is evidence about whether the compliance program is working. An annual review that doesn’t address what went wrong during the review period is missing half the relevant input.
Examiners routinely ask: “Tell me about any compliance incidents from the past year.” If the annual review document doesn’t discuss them, the disconnect is immediate. If incidents happened but weren’t identified in the review, the question becomes whether any review actually occurred.
4. Identified weaknesses that persist across multiple review cycles.
An annual review that identifies a gap — “the onboarding disclosure checklist isn’t consistently completed” — but documents no remediation action, or documents a remediation action that wasn’t implemented by the next review cycle, creates compounding risk. By the second year the same issue appears, it’s a failure to address a known deficiency. By the third year, it starts to look like a systemic problem with the compliance program itself rather than an isolated gap.
The remediation table in the annual review document needs to carry forward. Items close when they’re confirmed remediated, not when they’re added to a list.
5. Policies last updated years before the current review without documented rationale.
The adequacy review requires asking whether policies cover current business practices. If the firm added a new advisory service two years ago, the policies should have been updated to cover it — and the annual review should either document the update or explain why existing policies adequately covered the new service without changes. Policies untouched for three or more years with no explanation in the review document suggest the adequacy analysis wasn’t conducted.
What a Compliant Annual Review Actually Looks Like
A Rule 206(4)-7 annual review that will hold up under examination scrutiny has four components, none of which require the review to be long:
1. Compliance incident inventory from the review period.
Start with a list of every compliance event during the year: customer complaints, trading errors, late filings, code of ethics violations, regulatory inquiries, audit findings. For each, document what happened, what the root cause was, and what the program response was. This is the effectiveness evidence — it shows the program identified problems, investigated them, and responded. An incident log with no entries doesn’t mean the firm is compliant; it means the CCO didn’t identify incidents, which is a different concern.
2. Policy and procedure adequacy assessment.
For each major compliance area (fiduciary duty, trading, marketing, portfolio management, recordkeeping, conflicts, privacy, AML if applicable), assess whether current policies cover the firm’s current business model. Flag areas where the program hasn’t kept pace with business changes, personnel changes, or regulatory developments. This produces an adequacy conclusion grounded in specific evidence rather than general assertion.
3. Root cause analysis for identified gaps and incidents.
For each gap or incident, document the root cause. Was it a policy gap — no policy covered this scenario? A control failure — the policy existed but wasn’t followed? A training gap — employees weren’t clear on the requirement? An oversight failure — the review process didn’t catch the deviation? The root cause determines the right remediation. A training gap can’t be fixed with a policy update. A control failure can’t be fixed with more training. Matching the remedy to the cause is what produces actual program improvement.
4. Documented remediation with owners and deadlines.
Every identified gap needs a remediation action, a named owner, and a target completion date. The annual review document should contain a remediation table that carries forward from prior reviews. Completed items are closed with evidence. Open items have current status. The CCO signing off on the review is accountable for the table — the items don’t disappear because the review period ended.
The conclusion — “the compliance program is adequate and effective for the firm’s current business” — should reference the evidence from the review process, not just state a conclusion. The examiner who reads that conclusion will ask what evidence supports it. That evidence needs to be in the same document.
The Format the Review Documentation Should Take
No prescribed format exists. A useful structure:
- CCO cover memo summarizing review scope, methodology, the period covered, and the overall conclusion
- Compliance incident log with root cause annotations for each entry
- Policy review table listing each major policy area, the last update date, what (if anything) changed during the review period, and why
- Gap analysis / remediation table with identified issues, root causes, remediation actions, responsible owners, target dates, and current status
- Training review section documenting what training was delivered, who attended, and attestation process
- Supporting evidence index referencing where code of ethics certifications, testing results, and control documentation are stored
The document doesn’t need to be long. A structured 10-to-15-page review with specific evidence citations is more defensible in an examination than a 50-page checklist that can’t be followed. If the reviewer can’t explain the methodology used to reach the adequacy and effectiveness conclusion, the review has a documentation problem regardless of how long it is.
The 2026 Examination Environment and What It Means for Your Next Review
The SEC’s 2026 examination priorities don’t change the substantive requirements of Rule 206(4)-7 — they signal how strictly the standard will be applied. The explicit identification of “checklist completion or restated policies” as the failure mode means examiners are walking into annual review requests with a specific hypothesis about what they’ll find.
Two additional factors make the 2026 review cycle particularly important:
The Reg S-P compliance deadline just passed. For smaller advisers (under $1.5 billion AUM), the June 3, 2026 Reg S-P compliance deadline means the new written incident response program is now an active obligation. The next annual review — and any examinations that follow — will assess whether the IRP is documented, tested, and operational. If the Reg S-P requirements aren’t reflected in your compliance policies yet, that’s an adequacy gap the current-cycle review needs to address.
AI governance is now an examination focus. If your firm uses AI tools in portfolio management, client communications, or compliance monitoring, the current-cycle annual review should specifically address AI governance: who owns it, what policies govern use, what testing was done before deployment. An annual review that doesn’t address AI if the firm uses it is an adequacy gap in an area examiners have explicitly flagged.
The firms that get the best examination outcomes on Rule 206(4)-7 are the ones that treat the annual review as the audit it’s designed to be — not a certification that the program exists, but an assessment of whether it works.
For registered investment advisers needing structured compliance documentation across key domains — data privacy, incident response, and business continuity — the Compliance Essentials bundle is built for multi-domain coverage that cross-references across your annual review evidence files.
Sources:
- SEC Rule 206(4)-7 — Compliance Programs of Investment Companies and Investment Advisers
- SEC Division of Examinations 2026 Priorities (November 2025)
- 2026 SEC Exam Priorities and Implications for Investment Advisers — Harvard Law School Blog (December 2025)
- Navigating SEC’s 2026 Examination Priorities for Investment Advisers — Plante Moran (January 2026)
- A Guide to Documenting the Annual Compliance Review — Kitces
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does SEC Rule 206(4)-7 require from investment advisers?
What does 'adequacy and effectiveness' actually mean under Rule 206(4)-7?
What are the most common Rule 206(4)-7 deficiencies SEC examiners find?
Does Rule 206(4)-7 require a written annual review document?
How does the SEC's 2026 examination emphasis change how investment advisers should approach the annual review?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Keep reading
Related posts.
Compliance Strategy
Policy Exception Management: Stop Temporary Waivers From Becoming the Real Policy
Add policy exception management to your policy management framework with approvals, compensating controls, expiry, and a waiver register.
Jul 25, 2026
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026