Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
SEC Wants Written Reviews, Not Checkbox ExercisesInternal Controls & Audit
4 min readFor Compliance Officers

SEC Wants Written Reviews, Not Checkbox Exercises

The SEC's Division of Examinations has issued a warning to investment advisers: your annual compliance reviews aren't up to par. The division's latest risk alert highlights six specific failures across registered advisers, emphasizing that superficial documentation and procedural shortcuts won't withstand scrutiny.

This is critical because Rule 206(4)-7 under the Investment Advisers Act mandates annual reviews of your compliance policies and procedures. Since 2023, these reviews must be documented in writing. However, examiners are finding advisers who skip the review, fail to document it, or mistakenly believe that employee certifications suffice as a review.

They don't.

Checklist for Effective Compliance Reviews

Use this checklist to ensure your annual compliance review meets SEC expectations. Each item addresses a deficiency cited in the Division of Examinations' September 2026 risk alert. If you can't check every box, you're at regulatory risk.

Prerequisites

Before starting your annual review:

  • Confirm you have written procedures for the review. The SEC expects a documented methodology, not an ad hoc process.

  • Identify who owns the review. Typically, your Chief Compliance Officer leads it, but clear accountability is essential.

  • Gather last year's review documentation. Compare findings, track remediation, and demonstrate progress.

Annual Compliance Review Checklist

1. Complete the review within 12 months of your last review.

The Compliance Rule requires annual reviews. If your last review closed in March 2025, your next must be done by March 2026. Late reviews indicate weak governance.

Good looks like: A documented review schedule with completion dates for each phase and a final report signed within the 12-month window.

2. Document your review methodology in writing.

The SEC wants to see how you conduct reviews, not just that you did one. Your procedures should specify what you evaluate, who participates, and how you document findings.

Good looks like: A written procedure listing the policies under review, the testing approach (interviews, transaction sampling, control walkthroughs), and the format for documenting results. This procedure should exist before starting the review.

3. Follow your written procedures.

If your procedure says you'll interview portfolio managers about trade allocation policies, do it. If it says you'll sample 20 client communications, sample 20. Examiners compare what you said you'd do against what you actually did.

Good looks like: Review workpapers that map one-to-one to your documented procedures. If you deviated from the plan, document why and update the procedure for next year.

4. Verify your compliance policies fully address your operational practices.

This is where advisers often stumble. You might have a policy on personal trading, but does it cover your employees' use of separately managed accounts? You might have a gifts and entertainment policy, but does it address third-party marketing arrangements?

Good looks like: A gap analysis comparing each operational activity (client onboarding, performance reporting, fee billing, marketing, custody arrangements) against your written policies. Where you find gaps, update the policy or document why the activity falls outside scope.

5. Maintain complete documentation of the review.

The 2023 revision to the Compliance Rule made this explicit: your review must be written. That means workpapers, interview notes, testing results, and a final report. The SEC cited advisers who couldn't produce documentation when asked.

Good looks like: A review file that includes: (a) the scope and objectives, (b) testing workpapers, (c) findings and root cause analysis, (d) remediation plans with owners and deadlines, and (e) a final report approved by senior management or the board.

6. Implement corrective actions for identified deficiencies.

Finding problems isn't enough. The SEC expects you to fix them. If your review identifies a control weakness in fee calculation, document the remediation plan, assign an owner, set a deadline, and track completion.

Good looks like: A remediation tracker listing each deficiency, the corrective action, the responsible party, the target completion date, and evidence of closure. Include this tracker in next year's review to show follow-through.

Common Mistakes

Treating employee certifications as a substitute for the annual review. The Division of Examinations explicitly called this out. An annual certification where employees attest they've read the compliance manual doesn't meet the Compliance Rule's requirements. You need an independent evaluation of whether policies are adequate and effectively implemented.

Conducting reviews without written procedures. Some advisers treat the annual review as an informal check-in. The SEC expects a documented process that's repeatable and auditable.

Failing to align policies with actual practices. Your marketing policy might prohibit testimonials, but if your website features client quotes, you have a gap. Your review must surface these misalignments.

Incomplete documentation. If you can't show examiners what you reviewed, how you tested, and what you found, you haven't met the rule's requirements. "We did it but didn't write it down" won't work.

Next Steps

If your most recent annual review doesn't meet these standards, start remediation now:

  • Draft written procedures for your next review if you don't have them. Include scope, methodology, documentation requirements, and sign-off process.

  • Conduct a gap analysis comparing your current policies against your operational practices. Update policies where needed.

  • Build a remediation tracker for any deficiencies identified in your last review. If you found issues but didn't document corrective actions, do it now.

  • Schedule your next review to ensure it completes within 12 months of your last one. Block time for senior management or board review of findings.

The Division of Examinations doesn't issue risk alerts for theoretical concerns. These are the deficiencies examiners are seeing in the field, and they're tired of seeing them. Treat this checklist as your baseline, not your ceiling.

Promotional banner for the Penetration Report Template Kit

You Might Also Like