Scope
This guide examines the SEC Division of Examinations' September 14, 2026 Risk Alert on registered investment adviser annual compliance reviews. It's designed for compliance officers, CCOs, and operations managers at SEC-registered investment advisers responsible for conducting, documenting, and defending their Rule 206(4)-7 annual reviews.
You'll discover specific deficiencies identified by examiners, the regulatory requirements behind them, and a practical framework for building reviews that produce defensible evidence.
Key Concepts and Definitions
Annual Compliance Review: Required under Advisers Act Rule 206(4)-7, this assessment evaluates whether your compliance policies and procedures are adequate and effectively implemented. It's not optional and cannot be satisfied by training sessions or attestation forms.
Rule 204-2 Documentation Requirement: This is your recordkeeping obligation. The review must produce written records documenting what you tested, what you found, and what you recommended. If you can't produce these records during an exam, you haven't met the requirement.
Recidivist Conduct: The SEC's term for firms that receive deficiency letters for the same issues across multiple exam cycles. If you were cited for skipping a review in 2023 and skipped it again in 2025, that's recidivism, indicating a broken compliance program.
Policy-Practice Gap: The disconnect between what your compliance manual says you do and what actually happens in your operations. Your review exists to find and close these gaps before an examiner does.
Requirements Breakdown
Rule 206(4)-7: The Annual Review Mandate
You must review your compliance policies and procedures at least once every twelve months. The review evaluates two questions:
- Are your policies adequate for your current business?
- Are you actually following them?
Rule 204-2: The Documentation Standard
You must maintain records that document:
- The scope of the review
- Testing procedures performed
- Issues identified
- Corrective actions recommended
- Implementation status of prior recommendations
The Alert makes clear that "we conducted the review" isn't documentation. You need workpapers, test results, and a written report.
What "Adequate" Means
Your policies must address the risks present in your actual operations. If you've started offering new services, changed your fee structure, or delegated functions to third parties since your last policy update, your policies aren't adequate until they reflect those changes.
Implementation Guidance
Build Review Procedures That Explain the Work
Your compliance manual should require an annual review. Your procedures should explain how to conduct one. The difference matters.
Procedures should specify:
- Who performs each component of the review
- What testing methods to use for each policy area
- What constitutes evidence that a policy is working
- What documentation to retain
- How to escalate findings
If your procedures say "test proxy voting practices" without explaining what that test looks like, you haven't written procedures. You've written a to-do list.
Match the Review Period to Your Business Changes
Don't review 2023 policies against 2024 operations. The Alert cites firms that assessed superseded policies or reviewed the wrong period entirely. Your review should:
- Cover the twelve months just completed
- Assess the policies that were in effect during that period
- Account for any mid-year policy updates or business changes
If your CCO doesn't know about operational changes, your review will miss the gaps that matter most. Build a process that surfaces these changes before the review begins.
Test What Your Policies Require
The Alert identifies a pattern: firms had policies requiring specific practices, but the review never checked whether those practices happened. Examples include:
- Identity theft testing that was never performed
- Proxy voting requirements that weren't followed
- Marketing policies that predated the Marketing Rule
- Custody procedures missing required steps
Your review checklist should mirror your policy manual. If a policy says you'll do something annually, that item belongs on your review scope.
Document Issues and Track Remediation
A finding without follow-through becomes a repeat deficiency. The Alert describes firms that documented recommendations in their review reports but never implemented them. Recommendations included:
- Improving proxy voting disclosures
- Documenting client risk tolerances
- Conducting best execution analysis
- Performing broker-dealer due diligence
Each recommendation needs an owner, a deadline, and a status. If you're reporting an item as closed, you should have evidence that the underlying issue was resolved.
Common Pitfalls
Treating Training as a Review Substitute: Annual compliance training doesn't assess policy adequacy. Neither do signed attestations. These activities support your compliance program, but they don't satisfy Rule 206(4)-7.
Skipping Years Due to Transitions: CCO turnover doesn't pause the annual review clock. If you missed 2022 because your CCO left, you've missed a required review. Plan for continuity.
Reviewing Policies You Don't Follow: If your policy manual requires proxy voting but you don't vote proxies, your review should identify that gap. Instead, some firms reviewed the policy as if it were being followed.
Writing Reports Without Workpapers: A written report that discusses violations without supporting test documentation doesn't meet Rule 204-2. The examiner will ask for your testing records. If you don't have them, you've failed the documentation requirement.
Ignoring Fee and Billing Practices: The Alert specifically calls out advisers whose reviews missed fee calculation errors, unapplied breakpoints, and missing refunds. These aren't edge cases. They're core fiduciary obligations, and your review should test them.
Quick Reference Table
| Review Component | Regulatory Basis | What to Document | Common Gap |
|---|---|---|---|
| Timeliness | Rule 206(4)-7 | Review completion date, period covered | Skipping years, exceeding 12-month interval |
| Procedures | Rule 206(4)-7 | Testing methods, responsible parties, evaluation criteria | Policy requires review but no procedure explains how |
| Scope | Rule 206(4)-7 | Services assessed, operational changes considered | Reviewing old policies, missing new business lines |
| Testing | Rule 204-2 | Test workpapers, samples examined, results | Written report without supporting test records |
| Findings | Rule 204-2 | Issues identified, severity assessment | Fee errors, proxy voting gaps, custody oversights not surfaced |
| Remediation | Rule 204-2 | Recommendations, owners, deadlines, completion evidence | Recommendations documented but never implemented |
| Policy Updates | Rule 206(4)-7 | Changes made, approval dates, regulatory driver | Marketing Rule updates missing, Form CRS procedures absent |
If your last review produced a one-page summary and no workpapers, you're not ready for your next exam. The Division has shown you where they're looking. Build procedures that produce evidence, test what your policies require, and track recommendations until they're closed. That's the difference between a compliance review and a compliance program.




