As SEC-registered firms plan for 2026, one message came through clearly during Comply’s recent webinar: a compliance calendar is no longer just a scheduling tool. It is a regulator-facing artifact that must reflect how a firm actually supervises risk, documents decisions, and adapts to change.
During the session, Comply consultants and legal experts walked through the areas most likely to define examination outcomes in the year ahead – policies and procedures, filings, marketing oversight, MNPI controls, and books and records – and shared how firms are operationalizing those requirements in practice.
What follows is a consolidated view of the most important themes, paired with real-time audience polling that shows where firms are confident – and where they are still catching up.
Policies & Procedures: “Living Documents” Are No Longer Optional
One of the strongest themes from the webinar was that inadequate or outdated manuals remain a root cause of violations. Regulators are not looking for annual refreshes alone, they’re looking for evidence that policies evolve alongside business practices and emerging risks.
As discussed during the session, firms should be asking:
- Do our policies reflect how we actually operate today?
- Are updates triggered by real events like new technologies, new risks, new client types?
- Are policy changes reinforced through training and testing, not just acknowledgments?
Both panelists emphasized that policy updates should be driven by compliance meetings, incidents, regulatory developments, and employee behavior. Bot an arbitrary calendar cadence.
Poll Insight: How Often Are Firms Updating Policies?
Poll Question:
How often are you updating your firm’s policies and procedures?

Key Takeaway:
A significant portion of respondents indicated they update policies only annually, despite acknowledging that policies should be “living, breathing documents.” This gap mirrors what regulators continue to cite during exams: static documentation that does not reflect day-to-day supervision.
AI Governance Has Officially Entered the Exam Room
AI was not treated as a future concern—it was discussed as a current supervisory obligation.
The panel highlighted that regulators are not expecting firms to build or understand AI models at a technical level. They are expecting firms to:
- Know where AI is being used (marketing, operations, surveillance, decision-support)
- Define what is permitted vs. prohibited use
- Address risks such as data leakage, bias, and so-called “AI hallucinations”
- Document controls and supervisory review
Importantly, the discussion drew a clear distinction between AI used for administrative support (e.g., drafting emails) and AI used in investment decision-making – a distinction regulators are increasingly focused on.
Filings: Timeliness Is Table Stakes–Accuracy Is the Differentiator
Form ADV updates, interim amendments, and Regulation S-P incident reporting were discussed as calendar anchors, not one-off tasks.
Panelists stressed three practical habits that reduce filing risk:
- Assigning ownership for data gathering, drafting, and review
- Building in review time well before deadlines
- Treating “trigger events” (growth, new services, new vendors) as filing prompts—not afterthoughts
As discussed during the session, recent amendments to Regulation S-P have raised the stakes around incident response and coordination with IT. Covered institutions must be prepared to notify affected individuals as soon as practicable, but no later than 30 days after becoming aware that unauthorized access to or use of sensitive customer information has occurred or is reasonably likely. For firms planning toward 2026, this makes clear ownership, escalation paths, and documentation essential parts of the compliance calendar.
Marketing Rule Oversight Remains an Enforcement Hotspot
Marketing compliance continues to generate deficiencies – not because firms lack policies, but because review processes are inconsistent.
The panel highlighted recurring risk areas cited by regulators:
- Unclear or missing disclosures
- Testimonials and endorsements without proper context
- Third-party ratings used incorrectly
- Inadequate supervision of social media and influencers
A key reminder from the discussion: everything is marketing – websites, LinkedIn posts, blogs, slide decks, even mobile app language – and review workflows must reflect that reality.
Poll Insight: Where Firms Struggle Most with Marketing Compliance
Poll Question:
Which area of the Marketing Rule is most challenging for your firm?

Key Takeaway:
Responses clustered around disclosures and social media oversight, reinforcing that decentralized content creation remains one of the hardest risks to supervise consistently.
MNPI Risk: Technology Helps, but Governance Leads
The MNPI discussion moved beyond theory into operational reality – remote work, increased data access, and faster deal cycles have widened exposure.
The panel outlined three pillars regulators expect to see:
- Access controls designed with IT, not assumed
- Pre-clearance and restricted list enforcement tied directly to policy
- Surveillance and analytics to identify unusual or “shadow” trading patterns
AI-driven analytics were positioned as a support tool (not a replacement) for supervision and escalation processes.
Books & Records: The Costliest “Basic” Deficiency
Books and records were described as one of the most preventable (and most penalized) areas of regulatory compliance.
Key reminders from the session:
- SEC Rule 204-2 requires firms to retain business communications for at least five years
- If a channel cannot be archived, it should not be used for business
- Policies must clearly define approved, monitored, and prohibited channels
- Escalation procedures must exist for violations
The panel also stressed that vendor relationships themselves are books and records and must be disclosed accurately in Form ADV – a point often missed during exams.
Compliance Calendars Must Reflect Risk, Not Just Rules
The webinar closed with a critical reframing: a compliance calendar is only credible if it mirrors the firm’s risk profile.
Best practices discussed included:
- Mapping calendar tasks directly to policies
- Adjusting frequency based on risk (not tradition)
- Removing tasks that no longer apply
- Aligning calendar evidence with annual review documentation
As one panelist noted, if your policies say reviews occur quarterly, regulators expect to see that reflected—clearly and consistently—in your calendar and supporting records .
Poll Insight: How Firms Are Managing Compliance Calendars
Poll Question:
How are you currently managing your compliance calendar?

Key Takeaway:
Many firms still rely on manual or hybrid approaches, underscoring why calendars often drift from policies – and why regulators increasingly ask how firms ensure obligations are actually completed.
Final Thought: 2026 Is About Defensibility
The most consistent message from the webinar was not about adding more tasks – it was about making compliance defensible.
For 2026, SEC-registered firms should view their compliance calendar as:
- A real-time reflection of supervisory intent
- A bridge between policies and practice
- A document regulators can follow without explanation
When calendars, policies, training, and evidence align, compliance becomes easier to explain and far harder to challenge.
Comply Launches Financial Services' First Agentic Compliance Platform MCP Server, Enabling Teams to Build Custom AI Agents Without Developers