The SEC just gave examiners a checklist for your annual review
The annual compliance review now has a published yardstick — firms that treat it as paperwork will feel it first.
The SEC's Division of Examinations just turned the annual compliance review from a private memo into a record examiners will ask to see, publishing a Risk Alert on Sept. 14 that covers the assessment every advisory firm is required to conduct — whether its policies and procedures are adequate and whether their implementation worked in practice. The alert flags areas advisers may want to consider during those reviews and presses firms to reflect on their practices and then modify review processes where that reflection points.
The requirement has always had two halves, and the second is the harder; adequacy is largely a drafting question, answerable by rereading the manual, while effectiveness asks about the past twelve months of the actual business — who signed off on what, which exceptions reached a decision-maker, what got rewritten afterward. A review that produces a signed memo and no changes has answered the first question and skipped the second.
A risk alert changes no rule, and the annual-review requirement is not new; the document comes from the same division that conducts the examinations and shows where examiner attention is pointed, which suggests the file behind the review is something staff will want to see rather than something a firm keeps for its own comfort. In practice, the review has to exist as a record: what was examined, what was found, what changed, and when.
That bites hardest on firms that have grown since their last rewrite: a review process built for a practice with a few employees, one custodian, and a single investment model can remain adequate on paper while drifting further from the operating day with every hire, every new outside manager, every acquired book. The alert's encouragement to modify the review process is, in effect, a nudge to concede that an old process no longer describes the business it is supposed to police.
Compliance rarely makes it into the growth conversation, and that is a miscalculation for teams in motion. Recruiting a breakaway group, absorbing a book, or adding a product line stresses a review process under a deadline rather than on its own calendar, and those are the moments when the gap between policy and practice runs widest. For a firm on a calendar-year cycle, the alert arrives with this year's review already drafted or signed, leaving a narrow choice: rerun the parts the alert names, or start from the new list next cycle. Only one of those leaves a file that matches the process the Division of Examinations just described.