HomeArticlesWhat to Cover in RIA Annual Compliance Review and How to Document It

What to Cover in RIA Annual Compliance Review and How to Document It

Published: September 21, 2026•5 min read•Compliance
Blake Bjordahl

Blake Bjordahl

Compliance Technology Expert & RIA Consultant

What to Cover in RIA Annual Compliance Review and How to Document It

You know the feeling of scrambling at the end of the year when your annual review is due. Chasing down code-of-ethics attestations, pulling trade blotters, confirming your ADV is accurate, and every other piece of data you need for regulators is the only thing standing between you and the holidays.

The good news is that the review itself doesn't have to feel like chaos. It's chaos because the underlying work has been scattered throughout the year rather than captured as it happened. Fix that, and the annual review becomes a formality: a summary of documentation you already have, not a scramble to produce it.

What Rule 206(4)-7 Actually Requires

SEC Rule 206(4)-7 requires every registered investment adviser to review, at least annually, the adequacy of its written compliance policies and procedures and the effectiveness of their implementation. The rule doesn't set a hard calendar deadline; however, at least annually is why most firms anchor the review to the calendar or fiscal year-end, and why examiners expect to see a completed, dated review covering the prior twelve months.

A defensible annual review generally needs to address:

  • Business and operational changes: new custodians, new share classes or fee structures, growth that pushes AUM across a registration threshold, new advisory services, branch openings, or changes in ownership and control persons — and whether your Form ADV and policies were updated to reflect them.
  • Marketing Rule compliance: advertisements, testimonials and endorsements, and performance presentations reviewed against the current Marketing Rule (17 CFR § 275.206(4)-1), with evidence of your pre-dissemination review process.
  • Reg S-P and vendor safeguards: for 2026, this carries extra weight. The amended Regulation S-P compliance dates have now passed, which means this is the first annual review cycle where firms need to demonstrate the full safeguarding and breach-notification framework is actually operating, not just documented on paper.
  • Employee attestations: annual code-of-ethics acknowledgments, outside business activity disclosures, political contribution certifications, and confirmation that personal trading was reviewed and reconciled throughout the year.
  • Books and records: required communications, advertising, and trading records were captured, retained, and are retrievable in the format examiners expect.

None of this is new to anyone reading this. What's changed is how much of it firms are still tracking through email threads, shared drives, and spreadsheets that live in one person's head. This is exactly what turns a routine annual review into a scramble.

Why the Review Gets Stressful (and Why It Doesn't Have To)

The annual review isn't hard because the requirements are unclear. It's hard because, by the time you sit down to write it, you're reconstructing a full year's worth of activity from scratch.

The firms that complete their review with ease, and no delays, are doing all the same work as others; they’re simply doing it continuously, in the background, all year long. Meaning, by end-of-year, the review has completed itself, it just needs to be summarized and packaged with a neat bow for regulators.

This is the entire premise behind our compliance technology: build the documentation as the year happens, so the annual review (and any other reporting throughout the year) is a simple data pull rather than a research project.

  • Simple Compliance Portal is where the year-round tracking lives. A single calendar for every compliance deadline and task, a place for submissions and approvals to route through with a timestamped trail, and a home for ADV updates. When it's time for the annual review, the record of what changed and when it was addressed is already sitting there, audit-ready.
  • Simple Email Archive automatically captures and retains email, text, SMS, website, and social media communications as they occur — which means when your annual review needs to confirm advertising and correspondence were properly retained and supervised under the Marketing Rule and Reg S-P, you're searching an archive instead of reconstructing one from memory and inboxes.
  • Simple Trade Monitor links employee brokerage accounts electronically so personal trading gets reviewed in one digital workflow throughout the year. No chasing paper statements, no manual reconciliation, and a clean, continuous record to cite when the annual review addresses code-of-ethics compliance.

Put together, these three tools cover the parts of the annual review that consume the most last-minute hours: proving business changes were tracked, proving communications were retained and supervised, and proving personal trading was actually reviewed.

An End-of-Year Compliance Review Checklist

Whether or not you're using compliance technology yet, this is the core list worth working through before you get swamped with end-of-year requirements:

  • Confirm all business, ownership, and personnel changes from the year are reflected in your Form ADV and internal policies
  • Review this year's advertisements, testimonials, and performance materials against the Marketing Rule
  • Verify Reg S-P vendor safeguards
  • Collect annual code-of-ethics acknowledgments, outside business activity disclosures, and political contribution certifications from every access person
  • Confirm personal trading was reviewed and reconciled for the full year
  • Confirm required electronic communications were retained, are searchable, and supervisory review occurred on schedule
  • Deliver your annual privacy notice.
  • Document the review itself

Frequently Asked Questions

When should RIAs complete their annual compliance review?

Rule 206(4)-7 requires the review at least annually but doesn't set a fixed date. Most firms target calendar year-end so the review lines up with their Form ADV annual updating amendment, which is due within 90 days of fiscal year-end (March 31 for most calendar-year firms).

What happens if an RIA doesn't complete its annual review, or completes it late?

A missed or superficial annual review is a recurring SEC examination finding and can itself constitute a compliance violation independent of any underlying substantive issue, since the rule requires the review to occur and be documented.

Does Reg S-P affect the annual compliance review?

Yes. With the amended Reg S-P compliance dates now in effect for SEC registered RIA firms, annual reviews should confirm that vendor safeguarding documentation, breach-notification procedures, and incident-response readiness are current and operating — not just filed away from when they were first drafted.

Do employee attestations need to be collected every year?

Yes — code-of-ethics acknowledgments and related disclosures (outside business activities, political contributions) are generally collected annually and are among the records examiners ask for first.

Tags

Compliance TechnologyCompliance ReviewRule 206(4)-7RIARIA Rules
Blake Bjordahl

Blake Bjordahl

Compliance Technology Expert & RIA Consultant

Blake specializes in helping RIAs implement cost-effective compliance solutions. With extensive experience in regulatory technology, he focuses on making compliance simple and automated for investment advisory firms.

Ready to Simplify Your Compliance Management?

Stop worrying about compliance tasks and start focusing on what matters most - your clients. Get organized with our compliance calendar solution.

Ready To Get Compliance
Done Fast And Off Your Plate?

Learn More