The Securities and Exchange Commission charged 38 firms with filing false information in their Forms ADV, all following an identical playbook: claim the same auditor, report nearly identical asset values, and use SEC registration status as a trust signal to defraud investors. These cases are instructive not just for the fraud itself, but for how many compliance teams still treat regulatory filings as verification when they're actually just disclosure.
Your due diligence process probably has a gap here. Let's fix it.
Why These Mistakes Keep Happening
The Form ADV system operates on attestation, not validation. When a firm files Form ADV, the SEC doesn't verify the claims before publishing the filing. The form goes live in the Investment Adviser Public Disclosure database immediately, creating a window where fraudulent firms can point to their "SEC registration" before regulators catch the misrepresentation.
Compliance teams inherit this verification gap. You're trained to check whether a vendor is registered, not whether their registration is truthful. The cognitive shortcut, "they're in the SEC database, so they're legitimate," collapses when bad actors exploit the filing system itself.
Mistake 1: Treating Registration Status as Verification
Why it happens: Your vendor onboarding checklist asks, "Is the firm SEC-registered?" and stops there. Checking the IAPD database feels like due diligence because you're consulting an authoritative source.
Real consequence: The 38 firms in this sweep all appeared in the IAPD database with active registrations. One firm, Pinnacle Crypto, even created a certificate displaying its SEC registration status (riddled with typos, but visually convincing at a glance). If your process stops at "yes, they're registered," you've verified nothing about their actual operations.
The fix: Cross-reference Form ADV claims against independent sources. If a firm reports $78,960,522 in assets under management, ask for audited financials. If they claim 89 investors, request a client reference list. The specific figures from this case, either $78,960,522 or $48,960,522 in gross asset value, exactly 89 or 33 investors, and "Indicator Global" as their auditor, were red flags because they were identical across multiple supposedly independent firms.
Mistake 2: Ignoring Pattern Anomalies in Regulatory Data
Why it happens: You review each vendor in isolation. Your risk assessment compares the vendor against your criteria, not against peer firms in the same filing system.
Real consequence: The SEC identified these 38 firms because they shared identical data points: same auditor name, same asset values differing by only the first digit, same investor counts. If you're only looking at one Form ADV at a time, you won't spot the copy-paste pattern that signals coordinated fraud.
The fix: When onboarding financial services vendors, pull Form ADV data for comparable firms in the same state or service category. Look for statistical outliers: identical figures, suspiciously round numbers, or claims that don't align with the firm's stated inception date. If a firm founded six months ago claims the exact same AUM as three other recently-formed Colorado firms, escalate for additional verification.
Mistake 3: Skipping Physical Verification for Remote Vendors
Why it happens: Your vendor is remote-first or operates in a different geography. Requesting proof of physical presence feels intrusive or outdated in a distributed work environment.
Real consequence: In a prior case referenced by the SEC, investigators visited the address listed on a firm's Form ADV. The filing claimed the firm operated from the 52nd floor of a building. That floor was a mechanical floor with no tenants, the firm didn't exist at that location.
The fix: For vendors handling investor funds or sensitive financial data, verify the business address through third-party sources. Use commercial databases like Dun & Bradstreet or request a utility bill showing the business name at that address. If the vendor claims a prestigious office building, call the building's property management and confirm the tenant. This takes 15 minutes and eliminates ghost entities.
Mistake 4: Accepting Credentials Without Verifying Issuing Authority
Why it happens: A vendor provides a certificate, registration confirmation, or regulatory approval document. The document looks official, so you file it in your vendor documentation folder.
Real consequence: Pinnacle Crypto created a fake certificate displaying its SEC registration. The certificate contained multiple errors, but it served its purpose: giving non-expert investors a tangible "proof" of legitimacy. Your procurement team isn't trained to spot fraudulent regulatory certificates.
The fix: Never accept a vendor-provided certificate as sole proof of regulatory status. Go directly to the regulator's public database. For SEC-registered investment advisers, search the IAPD database yourself. For broker-dealers, check FINRA BrokerCheck. For insurance entities, verify through your state insurance department. The authoritative source is always the regulator's own system, not a PDF the vendor sent you.
Mistake 5: Failing to Escalate Low-Probability, High-Impact Risks
Why it happens: Your vendor risk assessment scores the likelihood of fraud as low because most vendors are legitimate. The risk matrix places it in the "accept" quadrant, and you move on.
Real consequence: A single fraudulent vendor in your investment supply chain can trigger regulatory scrutiny of your own due diligence processes. If you're a registered investment adviser and you refer clients to a firm later charged with Form ADV fraud, your own compliance program comes under examination. The SEC's recent investor alert specifically warns about this referral risk.
The fix: Separate likelihood from impact in your risk scoring. Even if fraud probability is low, the impact, regulatory penalties, reputational damage, investor losses, is severe enough to warrant enhanced controls. For vendors in financial services, legal, or audit roles, apply heightened due diligence regardless of the statistical likelihood of fraud. This means annual re-verification, not just onboarding checks.
Prevention Checklist
Use this checklist for onboarding any SEC-registered investment adviser or exempt reporting adviser:
- Verify registration status directly in the IAPD database, not from vendor-provided documents
- Review the firm's complete Form ADV, noting the date of initial filing and any amendments
- Cross-reference claimed AUM, investor count, and custodian information against audited financials or third-party data sources
- Search for the firm's claimed auditor in the PCAOB database (if they audit public companies) or verify the auditor exists as a registered entity
- Confirm the business address through property management, commercial databases, or public records
- Compare key Form ADV data points (AUM, investor count, auditor) against peer firms in the same geography or sector to identify anomalous patterns
- Request and verify at least two client references, confirming the reference contact works at the claimed organization
- Document your verification steps in your vendor risk file, not just the outcome
- Set a calendar reminder for annual re-verification, not just at contract renewal
- Escalate to your legal or compliance leadership if any verification step fails or produces inconsistent information
The SEC's enforcement sweep shows that regulatory registration is a disclosure mechanism, not a seal of approval. Your due diligence process needs to account for that distinction.





