Nsight Blog | Ncontracts

RIA Annual Compliance Reviews Alert: What the SEC Found | Ncontracts

Written by Shannon Hull | Oct 8, 2026, 6:30:01 PM

Your policies require an annual review, but does anyone at your advisory firm know how to conduct one? 

The SEC Division of Examinations released a Risk Alert on September 14, 2026, covering what staff observed during examinations, and that question is a central point. Examiners came across firms whose policies required testing and validation, but they didn’t explain who was responsible, the procedures behind them, or what gets documented.  

These findings aren't independent problems; they feed each other. Missing documentation in one area turns into missed follow-through in another.  

Advisers who treat this alert as a preview of where examiners will look in the future will be better prepared ahead of their next exam. Here are the areas to review, and how compliance management software can help streamline and document your processes. 

Related: Top 5 Takeaways from the SEC’s 2026 Exam Priorities 

What Is an RIA Annual Compliance Review?

An annual compliance review is the assessment the SEC requires of every SEC-registered investment adviser at least once a year under Rule 206(4)-7. It evaluates whether a firm's compliance policies and procedures are adequate and if they're being implemented effectively.

What the SEC Risk Alert Covers

The Division organized its observations into a few key areas, moving from whether the review happened to what the firm did about what it found. 

Timeliness of the Review

Firms are treating the “annual” in annual compliance reviews as a suggestion. 

Examples cited in the alert include advisers who reviewed policies in 2021 and 2023 but skipped 2022 entirely. Some stretched the interval past twelve months due to organizational changes, such as a chief compliance officer leaving. Other advisers said their annual compliance trainings or signed personnel attestations had satisfied the requirement, though these items don’t assess whether a policy is adequate or working. 

The SEC staff also called out firms engaging in “recidivist conduct” for failing to make corrections after receiving previous deficiency letters for missed or poorly timed reviews. A deficiency can follow a firm, as examiners expect more than a one-time fix. Mitigation requires a dynamic, evolving, and documented compliance program. 

Related: How to Build Better Governance with Stronger Policies  

Procedures for Conducting the Review

A policy review only helps your firm if someone knows how to perform it.  

Advisers had compliance policies that required annual reviews, but they either didn’t adopt procedures or didn’t complete them. Nothing explained how the testing process worked, what factors determined whether a policy was adequate, or what documentation should support the conclusion. 

Some firms identified practices, services, and operations for annual assessment in their manuals, but never built those topics into the review procedures. For example, one adviser’s identity theft policies mandated annual review testing, but it never happened.  

Related: AI Compliance for Firms and RIAs in 2026 

Alignment Among Policy, Procedure, and Practice

A review is only as good as the information it’s based on. Some firms conducted timely reviews without following their own written procedures, covering the wrong period, or skipping required workpapers and tests. Others assessed policies that had been superseded before the review period began, evaluating documents the firm no longer followed. 

Staff also found advisers who never adopted risk policies for areas central to their business, and others whose reviews didn't account for changes in their firm’s operations. In one example, no one told the CCO about business or operational changes that would have altered the scope of the review. 

These areas came to light when staff compared issues in the advisers' business and operations against what the annual reviews had turned up. The reviews didn't identify:

  • Fee and billing practices that departed from advisory agreements and Form ADV, including fees that weren't prorated, breakpoints that weren't applied, and refunds that weren't issued on terminating accounts 
  • Proxy voting policies requiring the adviser to vote client proxies while the firm in practice didn’t vote them 
  • Custody policies and procedures that omitted steps to identify custody accounts to the accountant performing the surprise examination 
  • Marketing policies never updated for the Marketing Rule 
  • Regulatory filing procedures that didn't account for Form CRS for advisers with retail clients 
  • Policies that delegated services or operations to others without defining how the adviser oversaw that work 
  • Incidents of non-compliance identified during the review period that never appeared in the annual review 

Completing the review wasn't the problem. Reviewing the right things was. 

Related: Emerging Securities Risks: What Investment Advisers and Firms Need to Know in 2026 

Documentation and Recordkeeping

Advisers Act Rule 204-2 requires advisers to keep records documenting the annual review of their policies and procedures, but the Alert notes that many advisers failed in this area. 

Advisers produced written review reports that discussed compliance violations without keeping records of the testing performed, the issues identified, or the corrective actions recommended. Some never produced the written annual review report their own policies required. Others adopted detailed review procedures but didn't follow them. 

Corrective Action

The last observation results from firms failing to follow through in other areas.  

Some firms received specific recommendations from their annual reviews but never acted on them. The examples include improving proxy voting practice disclosures, documenting client risk tolerances, conducting more thorough analysis of best execution, and performing third-party due diligence on broker-dealers.  

Some firms even reported completed corrective action in their annual review reports while the underlying issue remained open. 

Related: Wealth Management Compliance: AI Governance, Vendor Risk, and the SEC and FINRA 

How Compliance Management Software Supports Reviews

Every finding in the alert describes information that must be documented, tracked, or produced on request, and that’s where compliance management software built specifically for financial institutions like RIAs can help carry the load.  

It tracks policy versions, approval dates, and the regulatory change behind each update, so you’re always looking at the most up-to-date information. A centralized repository with audit trails builds a record of past testing, cited issues, and recommended changes. 

When a review recommends a change and no one owns it, the item stays open until next year's review finds it again. Assigned owners and automated reminders keep it in front of the person responsible, and reporting tools put the trail in your hands when an examiner asks for it. 

While your team maintains oversight, the software makes sure you have current documents to assess, somewhere to record what you find, and a way to keep recommendations alive until they're resolved. 

Would Your RIA Annual Compliance Review Hold Up?

The Division ends the Alert by asking advisers to reflect on their own practices, policies, and procedures and make needed changes 

The first step is confirming your policies match your firm’s practices. Then review your procedures. They should explain how testing gets done, what determines whether a policy is adequate, what documentation to keep, and who owns what the review reveals. 

Get that right, and the review produces evidence you can give an examiner. Get it wrong and the same issues surface year after year until someone outside the firm finds them first. 

 Need a starting point? Our risk checklist for investment advisers helps you find where your compliance program no longer matches how your firm operates.