What Happened
On September 14, 2026, the SEC's Division of Examinations published a Risk Alert highlighting widespread failures in how investment advisers conduct their annual compliance reviews under Rule 206(4)-7. This rule has required annual reviews since 2004, but the alert revealed a troubling pattern: firms skipping entire review years, testing outdated policies, documenting problems without resolving them, and missing operational failures their own review procedures were supposed to catch.
Examiners found advisers conducting reviews for 2021 and 2023 but skipping 2022 entirely. Some firms let review intervals extend beyond twelve months, especially during CCO departures. Newly registered firms sometimes waited 18 months for their first review, mistakenly citing a transitional allowance from 2004. Even firms that had received deficiency letters for untimely reviews hadn't corrected the issue.
The operational failures missed were significant: fee billing errors, unfulfilled proxy voting promises, custody procedures that didn't ensure proper account identification, and third-party functions lacking oversight.
Timeline
The compliance failures unfolded over several review cycles, offering valuable lessons:
2021-2023: Firms skipped entire review years, conducting reviews for 2021 and 2023 but not 2022.
Ongoing: Review intervals extended beyond twelve months during CCO transitions, with no system to maintain the review schedule when personnel changed.
Post-deficiency: Some firms received deficiency letters for failing to conduct timely reviews but didn't address the issue before the next examination cycle.
2023-2024: The SEC amended the Compliance Rule to require written annual reviews as part of the private fund adviser package. The Fifth Circuit vacated this amendment in June 2024, leading some advisers to mistakenly reduce documentation.
September 2026: The Division published the Risk Alert, clarifying that the documentation requirement under Rule 204-2(a)(17)(ii) remains in effect and that an undocumented review is considered nonexistent.
Which Controls Failed or Were Missing
The failures fell into five categories, each showing a lack of basic supervisory discipline:
Timeliness controls: No mechanism ensured annual reviews when CCOs departed or personnel changed. No triggers for interim reviews during significant compliance events or business changes.
Scope controls: Review procedures existed but didn't specify how to test, what to weigh, or what to document. Policies requiring annual testing of specific topics were often omitted from the review plan.
Execution controls: Reviews didn't follow the firm's written procedures on review period, scope, or workpapers. Some tested outdated versions of the firm's policies.
Validation controls: Reviews documented problems but didn't verify if remediation occurred. Fee calculations were tested against billing system outputs, not executed agreements. Proxy practice wasn't compared to disclosure. The custody account list wasn't reconciled with what the surprise-examination accountant received.
Follow-through controls: Documentation was created during reviews but not retained. Required written review reports were never prepared. Corrective actions were recommended but not taken. Review reports claimed remediation when issues persisted into the next cycle.
What the Relevant Standard Requires
Rule 206(4)-7 requires every SEC-registered adviser to annually review whether its policies and procedures are adequate and being followed. The rule doesn't specify a format, but it requires the review to be an assessment, not a formality.
Rule 204-2(a)(17)(ii) mandates advisers to keep records documenting their annual review. The 2023 amendment requiring written reviews was vacated, but the underlying recordkeeping requirement was not. For examination purposes, an undocumented review is considered nonexistent.
The Compliance Rule adopting release has encouraged interim reviews since 2003 for significant compliance events, business changes, and regulatory developments. The review should test actual practices, not just paperwork. It should reconcile what the firm claims to do with what it actually does.
The alert clarifies how examiners use the annual review. They don't start with it; they end there. An examiner finds a fee calculation error, a custody gap, or a proxy disclosure that contradicts practice, and then checks the annual review to see if the firm noticed. If the review is silent, an operational error becomes a compliance program failure.
Lessons and Action Items for Your Team
Anchor the calendar to the firm, not the person. Set a fixed review period that survives personnel changes. Define who owns the review when the CCO departs and how the review schedule transfers.
Derive scope from risk, not the table of contents. Cross-reference every policy requiring testing to the review plan. Ensure business changes reach the CCO before the review, not after the examination. If you add continuation vehicles, co-investment structures, tokenized products, or AI tools to client communications, update the review scope.
Test practice, not paper. Reconcile fee calculations against executed agreements. Compare proxy practice to disclosure. Confirm the custody account list matches what the surprise-examination accountant received. Test the current version of every policy, not an outdated one.
Close the loop, and verify it's closed. Track every recommendation with an owner, a deadline, and a validation step. Don't record a corrective action as complete until someone confirms the issue is resolved. Attestations and training are inputs to a review, but they aren't a review.
Retain what you create. If your policy requires a written review report, prepare it. If you document findings during the review, keep them. The evidentiary expectation didn't disappear with the vacated amendment.
The annual review is where you test and prove your regulatory self-awareness. Examiners are checking whether that account is true.





