On September 14, 2026, the staff (the “Staff”) of the Securities and Exchange Commission’s (the “SEC”) Division of Examinations issued a Risk Alert (the “Risk Alert”) highlighting examination observations relating to investment advisers’ annual reviews of their compliance policies and procedures.1
Rule 206(4)-7 under the Investment Advisers Act of 1940, as amended (the “Advisers Act”), requires SEC-registered investment advisers (“Advisers”) to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and to review, at least annually, the adequacy of those policies and procedures and the effectiveness of their implementation. The Risk Alert highlights deficiencies identified by the Staff and provides insight into the Staff’s examination focus regarding the annual review process.
I. Conducting Timely and Substantive Annual Reviews
The Staff observed Advisers that failed to conduct annual compliance reviews as required by rule 206(4)-7, or that treated compliance training or annual employee compliance attestations as satisfying the annual review requirement.
The Staff identified deficiencies in compliance policies that did not provide sufficient direction regarding the testing to be performed, the factors personnel should consider in evaluating results, or the documentation that should be maintained. Certain Advisers also failed to follow their own review procedures, including by omitting required subject areas or testing, failing to use required workpapers or other documentation, or reviewing superseded versions of policies and procedures.
According to the Risk Alert, Advisers should consider whether their annual review procedures provide a sufficiently clear framework for the scope of the review, testing to be performed, documentation to be maintained, and should confirm that those procedures are followed in practice. Advisers should also consider whether significant compliance events, changes in business arrangements, or regulatory developments warrant an interim review before the next scheduled annual compliance review.
II. Assessing Whether the Compliance Program Reflects Current Practices
The Staff identified annual reviews that failed to detect inconsistencies between Advisers’ written compliance programs and their actual business practices. Examples include:
- fee and expense billing practices that differed from applicable policies, advisory agreements or Form ADV disclosures, including failures to apply fee breakpoints, prorate fees or issue required refunds;
- proxy voting practices that were inconsistent with Advisers’ written policies or client disclosures;
- custody procedures that did not adequately address accounts subject to surprise examination requirements;
- policies and procedures that had not been updated to reflect applicable marketing rule or Form CRS requirements;
- delegated services or operations for which policies did not adequately address the Adviser’s oversight responsibilities; and
- known incidents of non-compliance that were reported during the review period but were not addressed in the annual review.
These observations underscore the Staff’s examination focus on whether an Adviser’s annual review process identifies discrepancies between an Adviser’s written compliance policies and its actual business practices.
III. Documenting Reviews and Following Through on Corrective Action
The Staff also identified deficiencies involving the documentation and remediation of annual compliance reviews. Rule 204-2 under the Advisers Act requires Advisers to maintain records documenting their annual reviews. The Staff observed Advisers that failed to retain supporting documentation regarding testing performed, issues identified or corrective actions recommended.
The Staff identified Advisers that recommended corrective actions through the annual review process but failed to implement them. In certain cases, annual review reports indicated that corrective actions had been completed even though the underlying deficiencies persisted.
The Staff stated that Advisers should consider establishing a process for documenting findings and recommended corrective actions, assigning responsibility for remediation, and tracking identified items through completion. Supporting documentation should demonstrate not only that an annual review occurred, but also what was reviewed, what issues were identified, and how those issues were addressed.
Dorsey Observations
The Risk Alert reinforces that an annual review process should serve as a meaningful assessment of an Adviser’s current compliance risks. Advisers should view the annual review as an opportunity to identify and remediate deficiencies before they are identified during an SEC examination. Advisers would be well advised to consider the following:
- Tailor the review to current operations and risks. Assess whether policies and procedures continue to reflect the Adviser’s actual business practices, client agreements and disclosures, and account for material business and regulatory developments during the year;
- Test whether the compliance program is working in practice. Confirm that the review follows the scope and testing procedures established by the Adviser and addresses areas of compliance risk relevant to its current operations rather than relying solely on a static checklist or prior-year process;
- Document the review. Maintain sufficient records to demonstrate the scope of the review, testing performed, findings and recommended corrective actions, including documentation requirements established by the Adviser’s own policies; and
- Follow through on identified deficiencies (including any that were previously identified by the SEC during an examination). Assign responsibility for corrective actions and establish a process for tracking remediation.
The appropriate scope and methodology of an annual review will depend on each Adviser’s particular business, operations and risk profile. The Staff’s observations nevertheless provide a useful framework for evaluating whether an Adviser’s annual review is designed to identify and address changes, inconsistencies and compliance deficiencies.
1 SEC Division of Examinations, Examinations Observations Regarding Investment Adviser Annual Compliance Review (Sept. 14, 2026) (the “Risk Alert”).
