Comply Launches Financial Services' First Agentic Compliance Platform MCP Server, Enabling Teams to Build Custom AI Agents Without Developers Learn More
Blog

The SEC Just Told You Exactly How It Will Grade Your Annual Compliance Review

Sep 18, 2026

A new Risk Alert from the SEC’s Division of Examinations lays out six recurring failures in adviser annual compliance reviews — and it lands right as most RIAs begin their Q4 review cycle. 

On September 14, 2026, the SEC’s Division of Examinations published a Risk Alert on examination observations regarding the investment adviser annual compliance review. The timing is hard to ignore: most RIAs plan and conduct their annual review under Rule 206(4)-7 in the fourth quarter or the first quarter that follows. That makes the observations in this alert immediately actionable — a scoring rubric for work many firms are starting this month. 

None of what the staff describes in the Risk Alert is new. The SEC has been consistent about what a defensible annual review looks like. What the alert makes clear is that firms aren’t failing on concept. They’re failing on execution — timing, methodology, documentation, and follow-through. 

What the SEC Risk Alert says about the RIA annual compliance review 

Rule 206(4)-7 requires an adviser to review, no less frequently than annually, the adequacy of its compliance policies and procedures and the effectiveness of their implementation. Two words carry the weight: adequacy and effectiveness. Adequacy asks whether the policies cover the firm’s actual business and risks. Effectiveness asks whether anyone is actually following them. The deficiencies in the alert cluster around those two questions. 

One clarification worth flagging: some firms told examiners their first review was due at 18 months. The staff corrected the record — the original 18-month window applied only to rule implementation back in 2004. Every review since then is annual. 

Six failures examiners found in adviser annual compliance reviews 

The Division grouped its findings into six categories, each seen at multiple firms. 

  1. Untimely or missing reviews. Advisers skipped years entirely — conducting reviews for 2021 and 2023 but omitting 2022, for example — or stretched review periods past 12 months. Some treated compliance training and employee attestations as a substitute for the review itself. Training and attestations are inputs to a review. They are not the review. The staff also flagged recidivist conduct: firms that had already received SEC deficiency letters for untimely or missing reviews and still hadn’t corrected the problem going into the next cycle. 
  2. Incomplete procedures. Policies called for testing and validation but gave staff no direction on what to test, how to evaluate results, or what to document. Some firms omitted topics their own compliance manuals flagged as required — identity theft testing was specifically called out. 
  3. Failure to follow written procedures. This is separate from having incomplete procedures. These firms had procedures and then didn’t follow them. Reviews failed to cover the required period or scope, skipped required workpapers, and in some cases tested outdated, superseded versions of the firm’s own policies. 
  4. Policies not aligned with actual practice. The longest list in the alert, and one worth slowing down on. Examiners found fee calculation errors where prorations, breakpoints, and refunds weren’t applied correctly. Proxy voting policies that didn’t match what the firm was actually doing. Custody accounts missing from surprise examination scope. Marketing Rule noncompliance, still surfacing years after the November 2022 compliance date. Missing Form CRS procedures at firms with retail clients. Failures to oversee delegated responsibilities. And in some cases, known incidents of noncompliance that were identified during the review period but never recorded in the annual review itself. 
  5. Documentation failures. Testing got done but records weren’t retained. Firms with policies requiring a written annual review report — covering recommendations for improvement, material policy changes, and material compliance issues — produced no written report at all. Others only partially completed the checklists, workpapers, or templates their own procedures required. 
  6. Corrective action failures. Some firms identified problems in their annual reviews and recommended changes to policies, disclosures, or business practices — and then never made them. In some cases, written review reports stated that corrective actions had already been implemented when the same issues persisted into the next cycle. 

The five-question test for your annual compliance review 

Those six categories reduce to five questions worth asking before your next annual review. If you can answer all five with evidence, you’re in good shape. 

  1. Was the review timely — completed within 12 months of the last one, every year, without gaps? 
  2. Did it actually follow your written procedures — the right period, the right scope, the current version of your policies, the workpapers your manual requires? 
  3. Did it compare your policies against what the firm is actually doing, rather than just confirming the policies exist? 
  4. Is it documented — testing records retained, and the written report your own policies promise actually produced? 
  5. Did it produce corrective actions that were implemented and verified, including anything raised in a prior deficiency letter? 

One reminder worth underlining: an annual review is not a document you produce once a year. It is a year-long discipline that produces a document. Firms that treat it as a Q4 writing exercise are the ones generating these findings. 

Annual compliance review services: where Comply fits 

Every deficiency in the alert traces back to capacity, method, or memory. Firms know what the review requires; they run short on time, on a repeatable methodology, or on a record they can hand an examiner 18 months later. That is the gap Comply is built to close — through technology, consulting services, or both. 

Timeliness that survives turnover. Purpose-built compliance calendars keep the review cycle on schedule regardless of who is in the CCO seat, and standing calls with a Comply consultant hold the firm to the timelines written into its own compliance documents. The Annual Review Tool in Comply Program Management and Comply for RIA walks the team through each required consideration so nothing drops between cycles. 

Procedures that tell your team what to do. Comply maintains a dedicated annual review section within its IA policies and procedures content, with prescriptive model language a firm can tailor to its actual practices — or have a Comply consultant tailor for them. Comply also offers consulting services that review and update a firm’s policies at the outset of the engagement and at least annually thereafter. 

A review that ties back to the policies you actually have. Comply’s platform connects the risk assessment, the policies and procedures, the compliance calendar, and the annual review so they stay in sync — no testing against a superseded version. Firms without the bandwidth or the in-house methodology can outsource the annual review entirely, either once to build internal capability or on a recurring basis. 

Testing that compares policy against practice. Comply’s annual review and mock audit services examine the policies top to bottom against what is actually happening, using documentary evidence and interviews with the C-suite and other key stakeholders. Beyond the 12-month lookback, the focus is on remediating the gaps found — so the same finding doesn’t reappear next cycle. 

Documentation you can produce on demand. Structured workflows, a centralized audit trail and books-and-records repository, and workpapers that assemble quickly — for internal review, investor due diligence, or an SEC exam. 

The window is now 

Advisers beginning their annual review this quarter have something they rarely get: the examiners’ own list of what they will be looking for, published before the work starts. The firms that read this alert as a checklist rather than a news item will be the ones with a clean answer when the exam letter arrives. 

If you’d like to talk through how your current annual review process maps against the SEC’s observations, Comply’s consultants and solutions team are available to walk through it with you. 

Source: SEC Division of Examinations, Risk Alert — Examinations Observations Regarding Investment Adviser Annual Compliance Review (September 14, 2026). 

Index