A lot of RIA compliance content describes specific deficiencies as things that “trigger” an SEC examination. That’s not quite how adviser selection works. The SEC’s Division of Examinations runs a risk-based process to decide which advisers to examine and what to look at, weighing the firm’s business, regulatory history, products and services, and other information available to the Commission. Its 2026 Examination Priorities, for instance, again flag never-examined advisers, particularly recently registered ones, as a priority.
A deficiency like that still matters once an exam is underway; it just isn’t usually what starts one.
Once an exam is underway, though, ordinary inconsistencies stop being ordinary.
We see this pattern often: the compliance manual describes a process the firm quietly stopped following; Form ADV and the advisory agreement describe the same fee two different ways; a disclosed conflict isn’t actually addressed in the firm’s procedures; a required review never happened, or nobody can prove it did; the billing system produces a number that doesn’t match the client’s agreement.
Over time, an adviser can end up with disclosures, agreements, written procedures and operating practices that no longer line up, plus thin evidence that the required controls were actually performed. Examiners will make that comparison directly, so it should happen first in the firm’s own compliance review.
The Compliance Program Has Not Kept Pace With the Business
Compliance programs rarely go stale all at once. They drift as the business changes around them: personnel are added, investment strategies evolve, custodians and vendors change, technology platforms get replaced, new services or client types are introduced, affiliates are formed, compensation arrangements shift, marketing expands, and an acquisition brings in another office or business line. Any one of those is manageable on its own. Add enough of them together and the risks the compliance program is supposed to cover have shifted underneath it.
Rule 206(4)-7 requires SEC-registered investment advisers to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act. The SEC deliberately didn’t prescribe a single compliance program for everyone, because advisory businesses vary too much in their activities and risk. Each adviser has to build policies and procedures that fit its own operations and risks.
The first thing we check in an annual review or compliance testing engagement is whether the written program still describes the firm that actually exists, beyond just citing the right rule or carrying a current revision date: what’s changed in the business, what risk that change may have created, whether the existing procedures still fit, and whether the people assigned to run them are actually running them.
Generic manuals, even well-written ones, have to be tailored to the adviser using them. A procedure that makes sense for one firm may be unnecessary for another, or may assume processes and infrastructure the second firm simply doesn’t have. Controls should be measured against that adviser’s own business, risk, and operating capacity, not the model manual’s.
Annual Compliance Reviews That Emphasize Completion Over Effectiveness
Rule 206(4)-7 requires an SEC-registered investment adviser to review, no less frequently than annually, the adequacy of its compliance policies and procedures and the effectiveness of their implementation. The SEC has also said the annual review should factor in compliance matters from the preceding year, changes in the business activities of the adviser or its affiliates, and regulatory developments that may call for changes to the program.
A review can confirm that the adviser has a Code of Ethics, a business continuity plan, cybersecurity policies, the required disclosures, and a current compliance manual, but that only shows the paperwork exists, not whether the controls it describes actually worked.
The testing is where the annual review earns its keep, and how much of it happens depends on the firm. That might mean recalculating advisory fees, sampling personal securities transactions, checking advertising against the Marketing Rule and the firm’s own procedures, testing required approvals, reviewing exception reports, or following up on last year’s findings. A firm running significant performance advertising needs a different level of attention than one with a basic website and a plain description of services; an adviser with affiliates, private funds, or unusual compensation arrangements likely has more conflicts to test than a straightforward advisory business.
In 2023, the SEC adopted an amendment that would have expressly required registered advisers to document their annual reviews in writing. That amendment was part of the private fund adviser rulemaking the Fifth Circuit vacated in 2024, and the SEC later confirmed the amendment to Rule 206(4)-7 was no longer in effect.
The separate written-documentation requirement may be gone, but advisers should still retain enough support to show what the firm considered during the annual review, what got tested, what exceptions turned up, and whether anyone did anything about them. Keeping those workpapers also gives the next review something to build on, without turning the paperwork itself into the point of the exercise.
Inconsistencies Among Form ADV, Agreements and Actual Practices
A compliance review that checks Form ADV, the advisory agreement, fee schedules, marketing materials, the website, and internal policies each in isolation will miss the gaps between them. We look at all of it side by side, against what the firm actually does.
These gaps tend to open in ordinary ways. A fee schedule changes while an older advisory agreement stays in use for certain clients. A new service reaches the website before the disclosure brochure is revised. An affiliated business creates a conflict that’s addressed in one document but not another. A description written years earlier survives in marketing materials long after the investment process has moved on. A compliance procedure still points to an approval process that operations abandoned when the firm’s systems changed.
Any one of those documents can look perfectly reasonable read on its own, while still conflicting with another disclosure, agreement, or business practice. Line them up next to each other and against what the firm is actually doing, and the discrepancies get much easier to spot.
Form ADV should get a second look whenever the business changes, not only during the annual amendment cycle. Some changes require an amendment outside that cycle; others don’t require one but should still prompt a hard look at whether the existing disclosure is still accurate and complete.
Conflicts Require More Than Disclosure Language
Advisers are fiduciaries, and disclosure is an important part of addressing a conflict. But the analysis has to start with the economic incentive or competing interest itself, not the language describing it. Depending on the firm’s business, that might involve compensation arrangements, affiliates, proprietary products, revenue sharing, cash-management practices, account recommendations, brokerage relationships, expense allocation, outside business activities, or other financial incentives touching the adviser or its people.
The SEC’s Division of Examinations went back to this exact subject in its June 2026 Risk Alert on economic conflicts of interest, covering incentives tied to recommendations of products, services and account types, along with the related disclosures, fees and expenses, advisory fee calculations, and the adequacy of compliance policies and procedures.
A conflicts review that starts with the disclosure document has it backwards. We start with the business: how the firm and its people are compensated, what affiliations exist, what economic benefits flow from particular recommendations or arrangements, and where the firm’s interests and the client’s start to diverge. That’s what actually tells you whether the disclosure and the controls built around it hold up.
A disclosure stating that a conflict “may” exist doesn’t tell you whether it actually exists, whether the disclosure describes it adequately, or whether the firm needs additional mitigation, supervision, or testing. Sometimes disclosure alone is enough; other times the firm needs more controls, or has to avoid the conflict altogether.
Advisory Fee Billing Deserves Independent Testing
Automation can make advisory fee billing far more consistent. The flip side: one misconfigured fee rate, valuation method, breakpoint, or billing convention gets applied flawlessly, and incorrectly, across a large population of accounts.
Fee testing should start with the governing agreement, not the billing report. We work out independently what the client should have been charged, then compare that figure to what was actually billed.
Depending on the adviser, that can mean digging into the contractual fee rate, valuation methodology, billing period, treatment of deposits and withdrawals, excluded assets, householding, breakpoints, negotiated or legacy rates, and how terminated accounts were handled. Firms that have gone through an acquisition, or that are running multiple generations of advisory agreements, add another layer of complexity: the billing system has to accommodate arrangements struck under different contracts at different times.
The SEC’s June 2026 Risk Alert again flagged inaccurate advisory fee and expense calculations, along with inconsistencies among agreements, disclosures and actual billing practices. Fee issues have shown up in SEC exam findings for years. Increasingly sophisticated billing technology hasn’t made the independent check any less necessary.
Marketing Compliance Should Reflect the Marketing the Adviser Actually Uses
The Marketing Rule wants a review process that actually reflects what the firm is publishing, not a generic approval stamp applied to every piece of content.
A basic description of advisory services doesn’t need the same scrutiny as performance advertising. Testimonials, endorsements, third-party ratings, hypothetical performance, social media, paid promoters, and discussions of specific investment advice can each bring their own additional requirements and risks. The SEC kept finding Marketing Rule deficiencies in its December 2025 Risk Alert: testimonials and endorsements, third-party ratings, disclosures, and adviser oversight all made the list. [5]
How we review a given piece of advertising depends on what’s actually in it: performance presentation, substantiation of factual statements, fair and balanced treatment of benefits and risks, testimonial or endorsement requirements, third-party ratings, or whatever else the content calls for.
Running every communication through every possible control mostly just generates paperwork, with no real gain in compliance.
Marketing procedures should scale the same way. An adviser publishing occasional commentary off a basic website isn’t facing the same supervisory problem as a firm running numerous social-media channels, paid promoters, testimonials, and heavy performance advertising.
Books and Records Must Be Retrievable
Books and records policies tend to focus on what has to be retained and for how long. An examination also tests something else entirely: whether the firm can actually retrieve and produce it.
Retrieval has gotten harder as advisers add email systems, text messaging, collaboration apps, CRM platforms, mobile devices, cloud services, and whatever comes next. An adviser can have a perfectly good email archive while real business communications happen somewhere that archive never reaches. A vendor may be contractually on the hook for records that nobody at the firm has ever actually tried to pull. Old advertising might sit in one system while the approvals for it live in another.
We test this the direct way: request specific records from whatever system or vendor is supposed to hold them, and confirm the firm can actually retrieve what its policies and regulatory obligations require.
Technology creates operational questions that go beyond books and records. A CRM affects recordkeeping. A portfolio-management or accounting system affects advisory billing. A vendor may have access to customer information. And AI tools now show up in research, drafting, analysis, and other functions that intersect with privacy, recordkeeping, cybersecurity, and supervisory procedures already on the books.
The amended Regulation S-P compliance dates were December 3, 2025 for larger covered institutions and June 3, 2026 for smaller ones. Among other things, the amendments require covered institutions to maintain written incident-response policies and procedures addressing unauthorized access to, or use of, customer information.
The SEC’s 2026 Examination Priorities also cover information security and operational resiliency, including controls meant to identify and mitigate the new risks that come with artificial intelligence. Advisers should ask whether recent technology changes have altered the risks, or the controls, the compliance program is already supposed to address.
Written Procedures Should Describe Controls the Firm Can Actually Perform
Detailed procedures can establish who’s responsible and spell out how an important control is supposed to work. That same detail becomes a liability the moment the procedure describes work the firm isn’t actually doing.
If the manual says the CCO conducts a quarterly review, an examiner can reasonably ask to see evidence of those quarterly reviews. If a procedure calls for approval, testing, or escalation of exceptions, the firm should expect to show that it happened.
This shows up most often when a procedure has outlived the business process it was built for, or when language lifted from a model manual never got checked against how the firm actually operates. The procedure can be perfectly sound in the abstract and still be the wrong fit for that adviser.
A procedure needs to be specific enough to explain the control, assign responsibility, and address the relevant risk, and realistic enough that the firm can actually perform it, consistently, every time.
Reviewing a policy on paper only gets you so far. We talk to the people who actually run the process and compare their account of what happens with the written procedure, the evidence it generates, and the risk it’s meant to address. That combination usually turns up more than another read-through of the manual would.
What Do SEC Examiners Look for in an RIA Compliance Program?
There’s no universal SEC examination checklist that applies to every investment adviser. The Division of Examinations runs a risk-based approach, and the scope of any given exam depends on the adviser and the issues involved. The SEC is explicit that its annual priorities aren’t an exhaustive list of what the Division might review.
For 2026, the Division describes evaluating the effectiveness of advisers’ compliance programs as a core part of the exam process, and points to marketing, valuation, trading, portfolio management, disclosures and filings, and custody as areas that assessment might touch.
For exam readiness purposes, we line up what the firm has disclosed to clients and regulators, what its written policies say should happen, how personnel describe the actual process, what the firm actually does, and what the underlying records show. Those sources serve different purposes and often use different language, but they should still be reconcilable.
A fee described one way in Form ADV and another way in the advisory agreement is worth a second look. So is a procedure requiring periodic testing with no supporting evidence anywhere, a real compensation conflict described only as something that “may” occur, or a manual that accurately describes the firm as it existed a few years ago but not as it operates today.
Preparing an RIA for an SEC Examination
Exam preparation that starts only after the SEC’s document request lands leaves very little runway to find and fix anything before the staff starts its review.
We treat a mock exam as a test of the compliance environment itself, not an interview rehearsal: if the procedures say fees get reviewed, we test fees. If Form ADV describes a particular practice, we check it against the agreement and what actually happens. If records are supposed to exist, we ask for them. If a compliance review reached a conclusion, we look at the work behind it.
Sometimes what testing turns up is that a procedure needs to change, not grow. A finding might call for clarifying an existing control, revising a disclosure or business practice, or cutting a procedure that no longer addresses a real risk. It’s rarely another certification, another committee review, or another line item on the compliance calendar.
Exam preparation should come down to one question: do the firm’s important disclosures, procedures, and controls still fit the business, and can the firm support the conclusions it has already reached about them?
Compliance Program Drift
Every mismatch this piece has covered traces back to the same cause: the manual that has fallen behind the business, the annual review that confirms paperwork instead of testing it, the ADV that doesn’t match the agreement, the conflict addressed on paper but not in practice, the fee formula nobody has re-verified, the procedure nobody actually performs. None of it happens all at once; it accumulates, one reasonable decision at a time, until the compliance program is quietly describing a business that no longer exists.
Firms should periodically reconcile the business, its regulatory obligations and conflicts, the disclosures, the written procedures, and the controls actually being performed. The annual review is a natural checkpoint for that, but it shouldn’t be the only one; a material shift in the business deserves attention closer to when it happens, not eleven months later. Staying aligned gives the firm a straightforward story to tell an examiner. Falling out of alignment means reconstructing that story after the fact, under more scrutiny than the firm would like.
Frequently Asked Questions About RIA Compliance and SEC Exams
What are the most common RIA compliance mistakes during an SEC examination?
Most trace back to the same root cause: something the firm says about itself, in Form ADV, an agreement, a procedure, or marketing material, no longer matches what it actually does. The recurring variants are annual reviews that confirm a policy exists without testing whether it works, fee calculations nobody has re-verified, inconsistent disclosures across documents, and procedures nobody can show were actually performed.
How much any one of those matters depends on the adviser and the specific facts. There’s no single checklist behind it: the SEC’s exam program is risk-based, not built around one universal list of RIA compliance mistakes.
Can an RIA compliance deficiency trigger an SEC examination?
Not directly. A deficiency that surfaces through a filing, a prior exam, or a complaint can feed into the SEC’s risk assessment, but the selection process itself is broader than any single issue: the Division of Examinations doesn’t work off a one-strike trigger. The 2026 priorities keep pointing to never-examined advisers, especially recently registered ones, as a bigger factor than any individual compliance gap.
How often must an RIA conduct an annual compliance review, and what should it cover?
At least annually. That’s the floor Rule 206(4)-7 sets, not a target. The rule requires reviewing the adequacy of the firm’s compliance policies and procedures and the effectiveness of their implementation. In the adopting release, the SEC also said advisers should consider interim reviews in response to significant compliance events, changes in business arrangements, and regulatory developments.
A material change shouldn’t sit and wait for the next annual cycle just because the calendar says so. The SEC built that flexibility in on purpose. As for scope, the review should reflect the adviser’s particular business and risks: changes during the year, prior findings, regulatory developments, and how well important controls actually worked. Substantive testing commonly touches advisory fees, personal trading, marketing, regulatory disclosures, books and records, conflicts of interest, privacy and cybersecurity, and custody, though which of those gets the most attention depends entirely on the firm.
How should an RIA prepare for an SEC examination?
By checking, before the SEC does, that its disclosures, agreements, procedures, and actual practices all tell the same story, and that it has the records to prove it. Periodic testing, annual reviews, and mock exams are how that gets checked in advance, instead of getting discovered live during the exam.
Assembling the right documents is the baseline, not the finish line. What actually gets tested is whether that story holds up once someone starts asking follow-up questions: why a number is what it is, who signed off, and what happened the one time a control didn’t work as designed.
How DFP Partners Works With Registered Investment Advisers
DFP Partners provides compliance support to registered investment advisers, from independent reviews of an established compliance program to more extensive outsourced and ongoing support. Our RIA services include Rule 206(4)-7 annual reviews, compliance testing, exam preparation, policies and procedures, regulatory filings, marketing and advertising review, ongoing compliance consulting, and outsourced Chief Compliance Officer services.
Whatever the scope of the engagement, we start in the same place: the business the adviser actually operates, the regulatory obligations and conflicts that business creates, and whether the compliance program is actually designed and actually functioning around them.