On September 14, 2026, the SEC Division of Examinations (the “Division”) published a Risk Alert (the “Risk Alert”) summarizing Staff examination observations on compliance with the annual compliance review requirement under Rule 206(4)-7 (the “Compliance Rule”) of the Investment Advisers Act of 1940 (the “Advisers Act”), and highlights areas that advisers may wish to particularly consider in their reviews.
The Risk Alert signals the Division’s examination priorities and expectations and provides a practical roadmap for strengthening annual compliance review processes.
Examination Observations:
A core component of the Compliance Rule is the requirement that advisers conduct a review of their compliance policies and procedures at least annually to assess their adequacy and the effectiveness of their implementation. The Risk Alert identifies six categories of Staff observations from examinations:
- Timeliness gaps: Staff observed that some advisers skipped review years, conducted first reviews past 18 months after registration, or let reviews lapse after CCO departures. Some mistakenly treated compliance training sessions or personnel attestations as a substitute for the required annual review.
- Incomplete review procedures: Staff observed that some advisers had written policies calling for annual reviews but “did not document procedures providing direction and processes personnel should follow for the tests and validations, the factors personnel should consider when evaluating whether the policies and procedures were adequate and effectively implemented based on the testing and validation, or the types or level of documentation that should be made and kept in support of such reviews and assessments.”
- Reviews inconsistent with written procedures: Staff observed that some advisers conducted timely reviews but did not follow their written procedures, including with respect to review period, scope, required work papers, or specified tasks and tests.
- Reviews did not identify that compliance procedures misaligned with firm activities/risks: Staff observed that some advisers’ annual reviews did not identify that the firm had not adopted policies and procedures to address risk areas that were pivotal to the firm, or did not consider changes to the business that were relevant to assessment of the adequacy of the advisers’ policies and procedures. Specifically, Staff noted reviews missed gaps between written policies and real-world practices, including fee billing, proxy voting, custody procedures, and marketing disclosures that were never updated to reflect rule changes. This is discussed further below.
- Documentation and recordkeeping: Advisers generated testing records and corrective-action recommendations but did not maintain them, or failed to prepare the written annual review reports their own policies required.
- Taking corrective action: Staff observed advisers that did not take corrective action after the annual reviews identified recommended changes.
The Risk Alert also implicitly highlights that several areas are topics of continuing focus for Staff, through an annual compliance review lens:
- Fee and expense billing practices: The Division noted deviations from policies, procedures, and client disclosures, including undisclosed fee methodologies, failure to prorate fees or apply breakpoints, and failure to issue refunds for terminating accounts. See our June 2026 client alert for additional information on Division observations regarding fee billing.[SB1.1]
- Proxy voting policies: The Division noted inconsistencies between advisers’ stated proxy voting responsibilities and their actual client disclosures and practices.
- Custody policies: The Division observed custody procedures that omitted steps necessary to ensure accounts over which the adviser had custody were properly identified to independent public accountants performing required surprise examinations.
Key Takeaways:
Advisers may use the Division’s observations in their evaluation and enhancement of their own annual review processes:
- Review annual review processes: Evaluate existing annual compliance review policies and procedures to confirm they are sufficiently detailed and actionable, with clear testing protocols, defined review scopes, and documentation requirements.
- Ensure timeliness and thoroughness: Implement controls to ensure annual reviews are completed on schedule each year, cover all required compliance areas, and are consistent with the adviser’s own written procedures.
- Align policies with actual practices: Confirm that written compliance policies accurately reflect current business practices across fee billing, proxy voting, custody procedures, and regulatory filing obligations.
- Follow through on corrective actions: Establish processes to track and verify that corrective actions identified during annual reviews are fully implemented within defined timeframes.
The King & Spalding team would be glad to answer any questions about how these observations may affect your compliance programs or annual review processes.
The Best and Latest Insights
All in One Place.