On September 14, 2026, the Securities and Exchange Commission’s (“SEC”) Division of Examinations published a Risk Alert entitled Examination Observations Regarding Investment Adviser Annual Compliance Reviews. The Alert addresses deficiencies observed in registered investment advisers’ annual compliance reviews under Rule 206(4)-7 of the Investment Advisers Act of 1940. Under that rule, an adviser must review its compliance policies and procedures at least annually to assess both their adequacy and the effectiveness of their implementation.
A Familiar Requirement That Remains Easy to Miss
There is nothing especially novel about the Alert. As the SEC notes, the requirement that advisers must adopt and implement written compliance policies and procedures has been in place for roughly two decades. For most advisers, the annual review of these policies and procedures is viewed as basic compliance housekeeping. But an aged compliance manual and a missing, late, incomplete, or poorly documented review is what we often describe to clients as “low-hanging fruit” in an SEC examination.
The SEC identified several straightforward gaps. Some advisers skipped a year or allowed more than 12 months to pass between reviews. Others treated employee training or annual compliance attestations as a substitute for the required review. Some advisers had policies requiring specific testing, checklists, or written reports, but did not actually complete those steps. In other cases, the adviser tested an outdated version of its compliance manual, failed to retain supporting documentation, or identified corrective actions that were never completed. Perhaps less straightforward, the Alert describes reviews that failed to identify inconsistencies with actual business practices or remediation concerns that occurred over the year. These are not abstract drafting issues. They are practical mismatches that examination staff often seek to identify.
The Manual Should Follow the Business, Not the Other Way Around
Many advisers adopt a compliance manual when they register and then treat it as a largely static document. Over time, however, the business changes and, in many cases, becomes more complex. The adviser may add new services, products, client types, affiliates, personnel, vendors, technology, fee structures, or marketing practices. Regulatory requirements also change. If the manual and annual review process do not keep pace, the firm may be following procedures that no longer fit the business, or the business may be operating in areas the manual never addresses.
Sometimes the mismatch exists from the start. An adviser may adopt an “off-the-shelf” manual without tailoring it to the firm’s actual risks, operations, or staffing model and trusting that their compliance team has done the job. That approach can create unnecessary obligations if the manual promises testing or documentation that the firm does not perform. It can also leave genuine risks uncovered. During an examination, both problems are visible: the adviser may not be following its own procedures, and its procedures may not adequately address the business it actually conducts.
More Than a Documentation Exercise
A strong annual review is not simply an exercise in updating policy language or producing a polished report. It is an opportunity to step back and ask whether the compliance program still fits the firm, whether the firm is following the program, and whether identified problems were actually corrected.
Done well, this process can also improve the business. Clear and current procedures can reduce uncertainty, create consistency, identify duplicative or outdated processes, clarify responsibility, and make growth easier to manage. In that sense, the annual review is not only a regulatory obligation, but it can also serve as a practical operating review that helps the adviser remain organized, efficient, and scalable. It is worthwhile to spend the time.
Consider Leveraging Technology to Help, Including AI
Advisers can approach the annual review in a way that fits how they work. For one firm, that may mean a hard-copy checklist and a well-organized review file. For another, it may involve a compliance consultant’s electronic platform, workflow software, or an internal tracking system – there are many third party resources out there.
Artificial intelligence can also play a useful supporting role. AI may assist with comparing documents for inconsistent language or stale regulatory references, summarizing documented business and regulatory changes, identifying open remediation items, and organizing the evidence supporting the review. All such outputs should be subject to human confirmation. AI may also make it easier to create a repeatable process so the adviser is not rebuilding the annual review from scratch each year. Of course, the adviser should have an adequate AI policy and procedure before it adopts AI as a useful tool. That’s a subject for another article.
If your firm has fallen behind on this obligation, or if you are uncertain whether your annual review process meets regulatory expectations, now is the time to act. Consistent with the SEC’s Examination Observations Regarding Investment Adviser Annual Compliance Reviews, advisers would be wise to take the following steps to ensure compliance : (1) confirm that an annual review has been completed within the past 12 months and that it is fully documented; (2) compare your current compliance manual against your actual business practices to identify gaps or outdated provisions; (3) verify that any corrective actions from prior reviews have been completed and documented; and (4) assess whether your compliance policies adequately address new services, products, affiliates, or regulatory developments.