Investment Adviser Annual Compliance Reviews: Key Takeaways from the SEC's Risk Alert

Regulatory Updates

September 28, 2026

Investment Adviser Annual Compliance Reviews: Key Takeaways from the SEC's Risk Alert

On September 14, 2026, the SEC’s Division of Examinations issued a risk alert outlining observations from recent examinations of investment advisers’ annual compliance reviews under Rule 206(4)-7 of the Investment Advisers Act of 1940. While the Risk Alert does not create new legal obligations, it provides important insight into how SEC examination staff assess annual reviews and highlights deficiencies involving timeliness, review procedures, alignment with actual practices, documentation and remediation.

 

Bottom Line

The SEC is signaling that an annual review should be viewed as a substantive assessment of compliance program effectiveness, not a check-the-box exercise. Examiners appear focused not only on whether an annual review was completed, but also on whether it was sufficiently rigorous to identify compliance risks, evaluate the firm's actual practices, document findings and drive meaningful remediation.

Key Examination Findings

The SEC identified several recurring deficiencies:

 

1. The 12-Month Clock Matters

Examiners cited advisers that:

  • Failed to perform annual reviews every year
  • Allowed review periods to exceed 12 months
    • The 18-month review period many advisers may be familiar with was a one-time exception allowed only during the period following the rule’s original release in 2004 and is therefore no longer applicable
    • Business, operational and personnel changes (e.g., Chief Compliance Officer (CCO) departures) are not permissible reasons to extend the 12 month review period
  • Relied on compliance training or employee attestations as substitutes for the required annual review
  • Repeated previously identified deficiencies without remediation

The SEC reiterated that annual reviews must be conducted no less frequently than every 12 months.

 

2. Inadequate Review Methodology

Many firms had policies requiring annual reviews but lacked documented procedures explaining:

  • What testing should be performed
  • How effectiveness should be evaluated
  • What evidence should be retained
  • How conclusions should be supported

The observations underscore the importance of a defined, documented review methodology that addresses testing, validation, evaluation and recordkeeping.

 

3. Failure to Follow Written Procedures

Some advisers completed reviews but did not follow their own documented process, including:

  • Omitting required testing areas
  • Using outdated compliance manuals
  • Failing to complete required workpapers or review templates
  • Deviating from prescribed review scope

The message is clear firms must do what their policies say they will do.

 

4. Policies Did Not Reflect Actual Business Practices

A key theme of the alert was the gap between written policies and actual operations. Examiners identified deficiencies involving:

  • Fee billing and expense allocations
  • Proxy voting practices
  • Custody controls
  • Marketing Rule compliance
  • Form CRS requirements
  • Oversight of outsourced or delegated functions
  • Compliance incidents identified during the review period

In many cases, annual reviews failed to identify business changes, operational realities or critical risk areas that rendered policies inaccurate or incomplete.

 

5. Insufficient Documentation

The SEC found firms that performed testing and identified issues but failed to retain supporting documentation. Common deficiencies included:

  • Missing test workpapers
  • Incomplete review files
  • Failure to retain evidence supporting conclusions
  • Policies requiring written review reports where no report was prepared

Examiners continue to emphasize that documentation is critical to demonstrating compliance with Rule 206(4)-7 and Rule 204-2 recordkeeping requirements.

 

6. Remediation Was Identified but Not Implemented

The SEC also cited firms that documented compliance weaknesses and proposed corrective actions but never completed them. In some instances, annual review reports stated that remediation had occurred even though the underlying issue persisted.

Why This Matters for Investment Advisers

The Risk Alert reinforces the SEC staff’s expectation that an adviser’s compliance program be tailored to its business, tested for effective implementation and supported by appropriate documentation.

Advisers that have experienced growth, launched new products, changed service providers, expanded their operations or otherwise modified their business should assess whether their policies, controls and annual review procedures continue to reflect their current risk profile and actual practices.

The alert is also notable because many of the cited deficiencies relate to areas that have been SEC examination priorities in recent years, including fees and expenses, marketing compliance, vendor oversight, custody and disclosure accuracy.

Kroll's Recommendations

Investment advisers should consider the following actions before their next annual review:

  • Confirm annual reviews are completed within 12-month intervals
  • Document a formal annual review methodology, including testing procedures and documentation standards
  • Evaluate whether compliance policies reflect current business practices, risks, regulatory requirements, products and services
  • Retain evidence supporting conclusions, testing results, identified issues and management decisions
  • Establish a remediation-tracking process that assigns ownership, target dates and status updates for corrective actions
  • Review prior annual review findings and regulatory examinations to ensure identified issues have been fully addressed

How Kroll Can Help

Kroll's Financial Services Compliance and Regulation practice assists investment advisers, private fund managers, wealth managers, registered investment companies and other regulated entities with:

  • Annual compliance reviews under Rule 206(4)-7
  • Compliance program gap assessments
  • Risk-based compliance testing
  • SEC mock examination reviews
  • Marketing Rule assessments
  • Fee and expense testing
  • Third-party oversight and governance reviews
  • Remediation program design and implementation

Firms should use the risk alert as an opportunity to evaluate their annual review processes, strengthen supporting documentation and confirm that identified corrective actions are implemented and tracked to completion.

Trade and Customs

Strengthen Your Compliance Framework

Whether you are assessing your compliance program, enhancing annual review procedures or addressing gaps identified in the SEC's latest Risk Alert, Kroll can help strengthen your compliance framework and support regulatory readiness.

Stay Ahead with Kroll

Financial Services Compliance and Regulation

In the ever-evolving financial services landscape, Kroll's award-winning team offers comprehensive regulatory and compliance services, guiding clients through registration, licensing, and compliance support to minimize risks and enhance efficiency globally.

U.S. Financial Services Compliance and Regulation

Navigate the ever-changing U.S. financial regulatory environment with confidence. Kroll provides unparalleled expertise in SEC, FINRA, NFA and CFTC regulations, helping clients mitigate risks, maintain current compliance programs and confidently overcome regulatory challenges.