SEC Warns Investment Advisers About Gaps in Annual Compliance Reviews

The SEC is putting investment advisers on notice that an annual compliance review cannot be treated as a box checking exercise.

On September 14, 2026, the Securities and Exchange Commission’s Division of Examinations published a new Risk Alert outlining common weaknesses examiners have identified when reviewing investment advisers’ annual compliance reviews under Rule 206(4)-7 of the Investment Advisers Act of 1940.

The alert does not create new regulatory obligations. Instead, it provides insight into how SEC examiners are evaluating whether advisers are actually reviewing the adequacy of their compliance policies and the effectiveness of how those policies are implemented.

For firms operating in highly regulated industries, the message is straightforward: having a compliance policy is not enough. Firms need to demonstrate that their policies are current, tested, documented and reflected in their day to day operations.

SEC Identifies Five Areas of Concern

The SEC's observations center on five areas: timeliness, completeness of review procedures, alignment between policies and actual practices, documentation, and corrective action.

Annual Reviews Must Actually Happen Every Year

Examiners found instances where advisers skipped an annual review altogether or allowed more than 12 months to pass between reviews.

The SEC also noted cases where firms treated compliance training or employee attestations as substitutes for an actual annual review. The Risk Alert makes clear that these activities do not replace the required review.

The SEC also cautioned against interpreting the 18 month period discussed when the Compliance Rule was originally adopted as a current grace period for newly registered advisers.

Compliance Procedures Need More Than a Requirement

Some firms had written procedures requiring annual testing but failed to explain how the testing should be conducted, what factors should be considered or what records should be retained.

In other cases, firms had procedures requiring specific areas to be tested, but those areas were never included in the actual annual review.

This creates a disconnect between what a compliance program says should happen and what actually happens.

Written Policies Must Match Real Business Practices

One of the clearest themes in the Risk Alert is the SEC's focus on whether written policies reflect how firms actually operate.

Examiners identified examples involving fee calculations, proxy voting, custody, marketing procedures and Form CRS filings where written policies did not align with business practices or regulatory requirements.

For marketing teams, this is particularly relevant. The SEC noted instances where marketing procedures had not been updated following the implementation of the Marketing Rule.

That means compliance teams need to consider not only whether marketing policies exist, but whether those policies accurately reflect the content creation, review, approval and distribution processes being used across the organization.

Documentation Is Part of the Compliance Record

The SEC also highlighted weaknesses in documentation.

Some advisers produced reports describing compliance issues without retaining the underlying testing records, issue logs or recommended corrective actions. Others failed to produce documentation required by their own procedures.

Under Rule 204-2, advisers are required to maintain true, accurate and current records documenting their annual compliance reviews.

For teams managing large volumes of marketing content, this reinforces the importance of maintaining a clear record of how compliance decisions were made, particularly when content moves through multiple reviewers or approval stages.

Corrective Actions Cannot Stop at the Recommendation

Identifying a compliance problem is only one part of the process.

The SEC found instances where annual reviews recommended changes but firms failed to implement them. In some cases, reports indicated that corrective action had been completed even though the underlying issue remained.

This makes remediation tracking an important part of an effective compliance program.

What This Means for Marketing Compliance Teams

The latest Risk Alert is aimed at investment advisers, but its lessons are relevant to any regulated organization managing marketing compliance.

A strong compliance process should make it possible to answer basic questions:

  • Are current policies aligned with actual marketing practices?

  • Are regulatory changes reflected in internal procedures?

  • Can teams demonstrate how marketing content was reviewed and approved?

  • Are compliance issues documented and tracked through resolution?

  • Can reviewers quickly identify which policy or regulatory requirement applies to a piece of content?

As financial services organizations increase their use of AI, social media and distributed content creation, maintaining this alignment becomes increasingly important.

The SEC's latest message is not that firms need more paperwork. It is that compliance programs need to work in practice, and firms need evidence showing that they do.

For marketing teams, that means compliance cannot remain a final checkpoint before publication. It needs to be integrated into the content workflow from creation through review, approval and distribution.