Grading Your Annual Review: The SEC’s Five Red Flags
Have you conducted and documented timely and adequate annual compliance reviews which would satisfy the SEC in accordance with Rule 206(4)-7?
Introduction
On September 14, 2026, the SEC's Division of Examinations issued a Risk Alert flagging recurring deficiencies in how advisers conduct the annual review required under Rule 206(4)-7, the “Compliance Rule.” Drawing on recent examinations, the Division organized its observations around five areas:
the timeliness of reviews;
the completeness of the procedures that govern them;
whether reviews actually test what a firm's policies and practices say (their alignment);
the documentation retained to support them;
and whether firms follow through on the corrective actions a review identifies.
The Division's message is straightforward: treating the annual review as a once-a-year formality, rather than a genuine test of whether a firm's compliance program is working, is itself a deficiency that examiners are prepared to cite.
Background
The annual review requirement comes from the Compliance Rule, adopted in 2003, which obligates every SEC-registered adviser to review its own policies and procedures at least annually for adequacy and effectiveness. The requirement exists because a compliance program that isn't periodically tested against a firm's actual business tends to drift out of date as personnel, products, and rules change. The Division's Risk Alert organizes its observations around five components of that review:
Timeliness of the review. Advisers must complete a review at least once every 12 months, with no gaps, and firms previously cited for late or missing reviews are expected to have fixed the problem.
Completeness of the underlying procedures. A firm's policies must spell out how personnel actually test and validate them, and must cover every topic the firm's own policies flag for annual review.
Alignment between the review and actual practice. The review has to catch mismatches between what a firm's policies say and what the firm actually does, not just confirm that the policies exist.
Documentation of the review. Firms must keep the records generated during the review, including testing results and recommended corrective actions, as part of their books and records.
Follow-through on corrective actions. Identifying a problem during a review is not enough; firms are expected to actually fix it.
Advisers whose compliance programs predate the Compliance Rule's October 5, 2004 effective date were permitted to complete their first annual review as late as 18 months after adopting the program; every review since, for every adviser, must occur no less frequently than annually.
What Advisers Need to Know
1. An annual review is not training, and it is not an attestation. Examiners found firms that substituted compliance training or personnel sign-offs for an actual assessment of whether their policies and procedures were adequate and effective, which does not satisfy the requirement.
2. Late is late, even by a little. Reviews that ran past 12 months, skipped a year entirely, or followed a delayed first review (particularly past the 18-month mark) all drew scrutiny, especially at firms already cited for the same issue.
3. A policy requiring a review is not the same as a procedure for conducting one. Firms whose written policies called for testing and validation, but never documented how personnel should actually perform it, or that omitted topics their own policies flagged for coverage, were cited for incomplete procedures.
4. The review has to catch what the firm is actually doing, not just what its policies say. Examiners pointed to fee billing errors, proxy voting policies that didn't match practice, custody procedures missing accountant notifications, and outdated marketing and Form CRS procedures as issues a genuine review should have surfaced.
5. Doing the review is not enough if you don't keep the paperwork, or act on it. Firms that performed testing but didn't retain the records, skipped a required written report, or identified corrective actions they never actually implemented were cited even though a review technically took place.
6. This is a Risk Alert, not a rule, but it previews what examiners will ask for. It carries no independent legal force, though it signals the specific records and follow-through the Division expects to see in upcoming exams.
Bottom Line
We read this Risk Alert as a clear statement that the Division intends to scrutinize the substance of annual reviews, not merely their existence, going forward. Firms should not wait for their next scheduled review to find out where they stand: pull your last review against these five areas now, confirm your procedures actually describe how testing gets done, and verify that any corrective actions from a prior review were completed and documented, not just recommended. We will continue monitoring for additional guidance from the Division and will flag anything that changes what advisers need to do.