Most compliance officers step into their first 90 days without a map. Nobody hands you a list of what was decided, what was deferred, or what the previous CCO left unfinished.
Nobody hands it to you — and you don’t need them to. More of this job is available to you on day zero than anyone will tell you. Your firm has a public record. You can read all of it before you accept the offer, and a great deal of what a new CCO spends their first month asking for is already sitting on a website, free, waiting.
That’s where this guide starts. Read the public record first. Then spend your first 30 days finding out where the inside of the firm disagrees with the outside.
It’s written specifically for compliance officers at registered investment advisers — not big bank compliance teams, not broker-dealers, not insurance companies. RIA compliance has its own rhythm, its own regulatory pressure points, and its own version of “the stuff nobody tells you.” That’s what this covers.
Use it. Edit it. Make it yours. The goal is to get you operational, oriented, and leading — and to help you document the work as you do it. The firms that get in trouble during SEC examinations aren’t always the ones who broke rules. More often, they’re the ones who did the work but couldn’t show it.
Everything in this section is public. None of it requires the job, a login, or anyone’s permission. Do it before you accept the offer if you can — and certainly before Day 1. Most CCOs waste this window waiting to be onboarded. Don’t.
Read the Firm’s Own Filings
Pull the firm’s record from IAPD and read everything published there — the Form ADV and the firm brochure. You will understand the business, the services, the conflicts, and the disclosures before you have met anyone, and you will immediately know whether what’s on paper matches what you find on the ground. Note what is not there: an SEC-registered adviser is not required to file its brochure supplements, so those are an internal ask rather than a download.
- ►Read the ADV as a diff, not a document. IAPD carries prior filings. Compare the last three years side by side. What changed in AUM, in the fee schedule, in the disclosure items? What got added tells you what the firm started doing. What got removed tells you what it stopped disclosing. This is real forensic work, it is free, and nobody will ever hand it to you.
- ►Read all the parts in sequence and cross-check them for consistency — the Form ADV, the brochure, the brochure supplements, and Form CRS if applicable. Anything that appears in two places and doesn’t match — AUM figures, advisory fee disclosures, conflicts of interest described differently between sections — is a question you do not want to be answering for the first time during an examination. It is entirely within your control to find first.
- ►The ADV names the chief compliance officer of record. You don’t need to ask HR who your predecessor was — you already know. Ask for time with them by name.
- ►The ADV discloses the firm’s custodians. You know who they are before Day 1.
- ►Check the firm’s disciplinary and regulatory disclosure on IAPD, and check BrokerCheck for every registered person. Do this now, not in month two.
If the Firm Advises Private Funds
Skip this if it doesn’t apply. If it does, it is a second regulatory surface, and it leaves a public trail most new CCOs never think to follow.
- ►Search EDGAR for the firm and its funds. Under both Rule 506(b) and Rule 506(c) of Regulation D, an issuer must file Form D electronically with the SEC after it first sells securities. The offerings are there.
- ►Find out which exemption each fund relies on — it governs what your marketing team is allowed to do. A Rule 506(b) offering cannot use general solicitation or advertising to market the securities. A Rule 506(c) offering may, but every purchaser must be an accredited investor and the issuer must take reasonable steps to verify it. A CCO who doesn’t know which is which cannot police the firm’s marketing.
- ►The exemption does not exempt the marketing. Marketing materials used in a Rule 506(b) or 506(c) offering must comply with the Marketing Rule if they are issued by a registered investment adviser — even though the offering itself is exempt from registration.
- ►Search EDGAR for the firm’s name generally and find out which filings it makes. If you don’t know what your firm files, you own an obligation you can’t see.
Inventory the Firm’s Marketing From the Outside
Before Day 1, with access to nothing, you can see most of what the firm says about itself: the website, social profiles, fact sheets, any performance presentation, testimonials, endorsements, third-party ratings. That is an advertisement inventory built entirely from outside the firm.
This is the fastest way to find live exposure, and the one area where you can form a real opinion before anyone briefs you. Write down what you find and date it. That list is the beginning of your baseline — and if something on it becomes a problem later, you will want the record showing you flagged it in week zero.
Then Ask for What Isn’t Public
A much shorter list than most new CCOs assume — which is the point. Now that you have read everything published, the asks get specific, and specific asks get answered.
- ►The most recent regulatory examination report, deficiency letter, or SEC/state correspondence. None of this is public. If they’re reluctant to share it, that’s a signal.
- ►Working drafts of the ADV, the filing history, and who actually owns the filing internally.
- ►The brochure supplements. They are delivered to clients and kept in the firm’s records rather than filed, so IAPD will not have them.
- ►Thirty minutes with your predecessor, by name. If there is one, a conversation is worth a week of archaeology.
- ►Where you are in the compliance calendar. Ask: “When is our ADV filing due? Have we completed our annual review? When does our next marketing review cycle start?”
- ►Whether the firm has ever been examined, and when. Never-examined firms and recently registered advisers are an explicit 2025–2026 SEC exam priority. If the firm has never been examined — or not in more than five years — plan your 90 days with exam readiness as a first-tier priority, not a second-tier one.
What you should be able to produce before Day 1
- □A dated outside-in summary of the firm as the public record describes it — services, conflicts, disclosures, custodians, funds.
- □A three-year ADV comparison noting every material change.
- □A list of the firm’s public marketing, as it stood the week you arrived.
- □A short written list of the questions the public record could not answer.
Your only job in the first 30 days is to get fully operational and to find out where the inside of the firm disagrees with the outside view you built in week zero. Resist the urge to fix things. Resist the urge to prove yourself. Learn the terrain before you start moving furniture.
Tools and Logins
You already know the firm’s custodians from the ADV. This exercise is reconciling the real operating stack against the disclosed one — and noting anything that appears in practice but not on paper.
- ►CRM (Salesforce, Wealthbox, Redtail) — do you have access?
- ►Portfolio management system (Orion, Black Diamond, Tamarac) — read-only at minimum
- ►Email and document archiving (Smarsh, Global Relay) — who administers this?
- ►Marketing review system — is there one?
- ►File storage (SharePoint, Google Drive) — where does compliance documentation live?
- ►Custodian portals — confirm the list matches what the ADV discloses
- ►State/SEC IARD — confirm your access credentials
Don’t assume you have access. Confirm it. Missing a login on Day 45 because nobody thought to set it up is a tax on your time you don’t need.
Your Own Obligations Start Immediately
Two obligations land on you personally in your first days. Both are easy to miss while you are still finding the coffee machine, and neither waits for you to settle in.
- ►You are almost certainly an access person under the firm’s own Code of Ethics. Rule 204A-1 requires an access person to submit an initial holdings report no later than 10 days after becoming one, current as of a date no more than 45 days before. Find out who administers the code and file yours on time. A compliance officer who is late on their own report starts from a weak position.
- ►Your prior political contributions came with you. Under the pay-to-play rule, an adviser may not provide advisory services for compensation to a government entity within two years of a contribution to an official of that entity by the adviser or a covered associate — and that expressly includes someone who becomes a covered associate within two years after the contribution was made. If the firm advises public plans or other government entities, your own giving history over the past two years is a live question. Raise it yourself, early, rather than having someone else find it.
Ask for the Code of Ethics and the firm’s political-contribution pre-clearance procedure in your first week, not your first month. Both create obligations for you personally, and the clock on the holdings report is already running.
Timing Orientation
The compliance calendar runs your year. Where you are in it when you start determines what’s urgent.
| Filing / Event | Typical Deadline |
|---|---|
| Form ADV Annual Amendment | Within 90 days of fiscal year-end (most firms: March 31) |
| Brochure Delivery | Within 120 days of fiscal year-end, or within 30 days of material change |
| Annual Compliance Review | No less frequently than annually — and the records documenting it must be kept |
| Annual Privacy Notice | Annually, or upon material change |
| Code of Ethics Annual Certification | Annually — varies by firm |
| Marketing Material Review | Ongoing — know your firm’s cadence |
| Regulation S‑P Incident Response Program | Compliance dates have passed — verify status now |
A note for December/January starters: ADV preparation is your first test. The marketing materials section (Part 2A, Section 5L) is where most firms have the most exposure.
Stakeholder Mapping
Compliance doesn’t operate in a silo. You work with almost every department in the firm, and your relationships with those people determine whether your program works or just exists on paper. Come to these conversations with hypotheses from the ADV, not a blank page — you already know what the firm claims to do.
Schedule 20-minute introductions with each of these in your first two weeks. Not to accomplish anything. Just to listen.
Cybersecurity Is a Compliance Obligation
Cybersecurity is not the IT department’s responsibility alone. It is a standing examination priority in its own right — it carries its own section in both the FY2025 and FY2026 examination priorities, and the stated focus is on firms’ policies and procedures for governance, data loss prevention, access controls, account management, and response to and recovery from cyber incidents. Those are compliance artifacts, which makes them yours. In your first 30 days, confirm:
- ►The firm has a written cybersecurity policy — who owns it, and when was it last updated?
- ►Someone owns the incident response program. Regulation S‑P requires written policies and procedures that include a program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. Know who owns it and whether it exists in writing.
- ►The firm has identified what customer data it holds, where it lives, and who has access. Examiners ask specifically about data loss prevention and access controls.
Know both clocks, because they are different lengths and you only control one. Under Regulation S‑P, you must notify each affected individual as soon as practicable, but not later than 30 days after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred. Your service providers owe you notice as soon as possible and no later than 72 hours after becoming aware of a breach of a customer information system they maintain — and your written vendor oversight policies are what make that notice arrive. The compliance dates for the incident response program requirements have already passed. If your firm hasn’t done this, it is not an upcoming deadline. It is an open item.
You don’t need to be a cybersecurity expert. You need to know who is responsible and whether the required documentation exists. If the answer to either question is “I’m not sure,” that’s your first cybersecurity finding.
What you should be able to produce at Day 30
- □A reconciled systems and vendor inventory, with every gap between practice and disclosure noted.
- □A compliance calendar for the next 12 months showing exactly where you are in it.
- □Notes from every stakeholder conversation, with the disagreements flagged.
- □A named owner for the cybersecurity policy and the incident response program — or a written finding that there isn’t one.
You know who everyone is and where everything lives. Now you need to understand the actual state of the program. This is the phase where you find out what’s real.
Service Provider Outreach
The firm has a set of vendors that compliance either owns, co-owns, or depends on. Some haven’t been reviewed in years.
- ►Outside Counsel — Introduce yourself. Ask: “Is there any open legal matter or regulatory correspondence I should know about?”
- ►Compliance Consultants — If the firm uses one, schedule a handoff call. They know where the bodies are buried.
- ►Technology Vendors — Every compliance-adjacent vendor (archiving, marketing review, trading compliance). Ask: “What’s the contract term? When is renewal?”
- ►Custodians — Know your liaison contacts at each custodian. Build the relationship now, before you need something urgently.
Vendor due diligence is also compliance. If the firm doesn’t have documented assessments of its key vendors, that’s a gap. Regulation S‑P requires written policies and procedures reasonably designed to require oversight of service providers — including through due diligence and monitoring — for vendors that handle customer information.
Policy and Procedure Review
Pull every compliance policy and procedure document the firm has. Read them. You’re looking for three things:
- 1.Currency — When was this last updated? Does it reflect current rules, current technology, and current operations?
- 2.Accuracy — Does it describe what people actually do, or what someone thought they’d do when they wrote it in 2019?
- 3.Coverage — Are there areas of the firm’s business that aren’t covered? Gaps are exam risk.
The most common gap right now: Marketing Rule policies were adopted and then never implemented. The SEC’s December 2025 Risk Alert, looking at testimonials, endorsements, and third-party ratings, observed advisers that had updated their compliance policies and procedures but had not implemented them — and that disseminated advertisements which did not appear to comply. The SEC’s FY2026 examination priorities say the same thing from the other direction: examinations focus on whether policies and procedures are implemented and enforced. So the question to ask isn’t “do we have a Marketing Rule policy?” It’s “can we show it was followed?” Other common gaps: vendor oversight policies that exist on paper but have never been implemented; Code of Ethics last updated before the Marketing Rule.
Inherited Open Projects
Every predecessor leaves something undone. You already pulled the public record in week zero — the firm’s IAPD disclosures, its BrokerCheck entries, its EDGAR filings. What’s left is the part that isn’t published anywhere, and the only way to get it is to ask.
- ►Ask stakeholders: “Is there anything compliance-related that’s been sitting on the back burner?”
- ►Reconcile what people tell you against what the public record already showed you. A disclosure on IAPD that nobody mentions internally is worth understanding.
- ►Confirm state registration status and any open correspondence with state regulators.
The honest version of this conversation is: “What’s embarrassing? What would you not want an examiner to see?” You’d be surprised how often people will tell you if you ask directly.
Exam Readiness Baseline
Before you can remediate anything, you need a baseline of where you actually stand from an exam perspective. Not where you think you stand — where the evidence shows you stand.
- ►Pull the last three years of SEC or state exam correspondence. Read every deficiency letter in full.
- ►Map each deficiency or observation to a current control. Is it fixed? Documented? Or just verbally addressed?
- ►Check your current marketing materials against the Performance Advertising and Marketing Rule requirements, starting from the inventory you built in week zero. Pay particular attention to testimonials, endorsements, and third-party ratings — that is where the December 2025 Risk Alert found the policy-versus-practice gap.
- ►Review your most recent Form ADV against what you observe on the ground. Every discrepancy is an exam risk.
- ►Confirm that the most recent annual compliance review was documented in writing, and that the documentation reflects what actually happened rather than what was planned. Rule 206(4)-7(b) requires the review itself; Rule 204-2(a)(17)(ii) requires the firm to keep any records documenting it. Both have been in force since the 2003 compliance-programs rulemaking took effect in 2004 — so a firm that has been running thorough but undocumented reviews is not newly exposed, it has been exposed for two decades. A review you cannot evidence is a review you cannot defend.
Examiners look for patterns, not incidents. A single outdated policy is a finding. A pattern of outdated policies suggests systemic compliance failure. Document your baseline assessment before you start fixing things — so you can show progress.
Inherited Risk Conversation
There’s a conversation most new CCOs avoid because it’s uncomfortable. You need to have it in the first 60 days.
What did the previous CCO know about, decide not to fix, and leave for me?
❞This isn’t about blame. It’s about risk transfer. When you accepted this role, you accepted the firm’s compliance history. You need to understand what’s in that history before you own it.
- ►Review any documented compliance incidents or client complaints from the prior 24 months.
- ►Ask outside counsel directly: “Is there any matter you’re aware of that the compliance program is carrying that I should know about?”
- ►Review the prior CCO’s correspondence files for anything that looks like an unresolved regulatory question.
- ►If the predecessor is reachable, have the direct conversation: “What were you working on? What worried you most?”
If you discover inherited risk after the fact — especially during an exam — your ability to explain your own remediation program depends on whether you have a documented assessment from when you arrived.
What you should be able to produce at Day 60
- □A written exam readiness baseline, dated, mapping every past deficiency to a current control.
- □A gap inventory covering policy currency, accuracy, and coverage.
- □A documented inherited-risk assessment naming what you found and what remains open.
- □A vendor list showing which relationships have documented assessments and which do not.
By now you understand the firm, you know the gaps, and you’ve built enough relationships to start moving things. Days 61–90 are when you shift from orientation to ownership.
What an Exam Actually Looks Like
If your firm has never been examined, understand the sequence before it arrives. The SEC typically provides two weeks or less notice. They will issue a formal document request covering your compliance manual, Form ADV, trade records, marketing materials, client agreements, and custodian records. The examination generally runs one to three days — on-site or as a structured document review. Afterward, you will receive either a deficiency letter requiring a written response, or an examination report with no significant findings.
Never-examined firms and recently registered advisers are an explicit SEC exam priority for 2025 and 2026. If the firm has no examination history, build your program as though the document request could arrive before the end of your first year.
The firms that perform best in examinations aren’t necessarily the ones with the most perfect compliance programs. They’re the ones that can produce documentation showing the program was followed — promptly, completely, and without gaps.
Set Your Compliance Calendar
Map every recurring compliance obligation for the next 12 months. Build it into your calendar and share it with the team. This single act does more for compliance culture than any policy document.
Your calendar should include: ADV annual amendment, annual review (with written documentation), annual certifications, quarterly portfolio review checkpoints, marketing review cadence, vendor reassessment schedule, and Regulation S‑P incident response program review.
Identify Your Priority One Remediation
From your gap inventory, identify the single highest-risk item — the one that, if an examiner walked in tomorrow, would be the first thing you’d need to explain. That’s your Priority 1.
Don’t try to fix everything at once. Fix the most important thing first, document the remediation, and move to Priority 2. A compliance program that shows documented improvement is more defensible than one that appears perfect on paper but can’t demonstrate how it got there.
Deliver a 90-Day Assessment to Leadership
Somewhere between Day 75 and Day 90, schedule 30 minutes with your CEO or Managing Partner and deliver a plain-language assessment:
- 1.Here’s the state of the program when I arrived
- 2.Here’s what I’ve fixed or started fixing
- 3.Here’s my priority list for the next 90 days
- 4.Here’s what I need from you to be effective
This conversation creates an alignment record. Leadership knows what compliance is doing and has approved the direction. That matters when an examiner asks whether the CCO has the authority and resources to do the job.
Regulatory Filing Check
Before you close out your first 90 days, run a complete audit of the firm’s regulatory filing status. Verify from the outside first — most of this is visible on IAPD and EDGAR without asking anyone — and escalate only what you cannot confirm yourself. This is non-negotiable.
| Filing / Registration | What to Verify |
|---|---|
| Form ADV — current annual amendment on file | Date filed, next due date — visible on IAPD |
| Form CRS (if applicable) | Current version, delivery documentation, consistent with the brochure |
| State registrations | All states where required, any pending renewals |
| Exempt reporting adviser status (if applicable) | Annual filing current |
| Form D for each private fund (if applicable) | Filed after first sale, exemption relied upon, amendments current |
| IARD / FINRA registration status for all IARs | Current, no lapses |
| U4/U5 filings for registered personnel | No outstanding amendments required |
Any gap here is an immediate remediation item — not a 90-day-plan item. Regulatory filing failures are strict liability in most contexts.
Budget and Authority
One of the most important — and least discussed — conversations of your first 90 days is about money and authority.
You cannot run a compliance program you aren’t empowered to run. And you cannot be empowered without an explicit conversation about what you control. A CCO who lacks access to business lines, is excluded from management decisions, or cannot independently engage outside counsel is carrying the responsibility without the means to discharge it — and that gap tends to become visible at exactly the wrong moment.
Questions to get answered in writing (or at minimum, in a documented meeting):
- ►What is the compliance budget for the current fiscal year? What does it cover?
- ►What spending decisions can you make without escalation? What requires CEO or CFO approval?
- ►Do you have independent authority to engage outside counsel on compliance matters, or does that require approval?
- ►If you identify a compliance failure that requires remediation spending, what is the authorization path?
- ►Does the firm have errors and omissions (E&O) or cyber liability insurance? What does it cover? Who manages renewals? For cyber liability specifically: many policies require the insurer to be notified within 24–72 hours of discovering a breach — a timeline shorter than the Regulation S‑P 30-day customer notification requirement. Know your policy’s trigger conditions before you need them.
These aren’t bureaucratic questions. They’re the architecture of your authority. A CCO who can’t answer them is a CCO who will eventually be blamed for something they weren’t empowered to prevent.
What you should be able to produce at Day 90
- □A 12-month compliance calendar, shared with the team.
- □A Priority 1 remediation, initiated and documented, with the reasoning recorded.
- □A completed regulatory filing audit with next due dates calendared.
- □A written record of the budget and authority conversation.
- □The 90-day assessment you delivered to leadership.
Nov–Jan Start
ADV season is on top of you. Make the ADV your first priority after getting operational. Review the draft, verify every disclosure, and make sure your marketing materials are consistent with what the brochure says. This is the most common source of Marketing Rule citations.
Mar–May Start
ADV is just behind you. Use this window — it’s the longest runway you’ll have until next year. This is the time for deep program work: comprehensive annual review, vendor assessments, policy rewrites.
Jun–Sep Start
You’re in the middle of the annual review cycle at most firms. Focus on understanding whatever review process was set in motion before you arrived and either completing it or documenting why it needs to restart.
October Start
A quieter operational window, but ADV season arrives faster than it appears from here. Use the remaining months to understand what you’ve inherited before the filing pressure starts.
A Few Things Nobody Tells You
The Risk You Can’t See
Your biggest risk isn’t the SEC. It’s the thing you didn’t know to look for. Build a culture of disclosure inside the firm — people tell compliance about problems early, not after they’ve festered.
The Predecessor’s Ledger
The previous CCO’s relationships are now yours — and so are their enemies. Find out who had friction with compliance and why. Sometimes the friction was the previous CCO’s style. Sometimes compliance was doing its job and someone didn’t like it. These are very different situations.
The Documentation Doctrine
Documentation protects you personally. In a regulatory context, if it isn’t written down, it didn’t happen. Your own notes, your own assessment records, your own emails confirming decisions — this is your record. Keep it.
The Ruthless Priority
You can’t do everything at once, and you shouldn’t try. A compliance program that prioritizes ruthlessly and executes consistently is more defensible than one that attempts everything and completes nothing.
The Certification You Didn’t Earn
Somewhere in your first 90 days you will be asked to sign or certify something covering a period you weren’t there for — an annual review, a code of ethics attestation, a filing. It is entirely predictable and almost nobody warns you about it. The answer is not to refuse. The answer is to sign what you verified, describe in writing what you inherited, and date both. A signature with a documented scope is defensible. A signature that silently adopts someone else’s year is not.
The Title and the Power
The role comes with personal exposure that is rarely explained when the offer is made. You are a named individual in the firm’s filings, and the compliance program is the thing you administer. That is not a reason to decline the job — it is a reason to be deliberate about two things. Document your work as you do it. And make sure the authority and the resources you are actually given match the responsibility you are accepting. Keep your own records: a CCO who can show what they did, what they escalated, and what they were told in response is in a very different position from one who cannot.
- ☐Firm’s IAPD record pulled and read in full — before Day 1
- ☐Three-year ADV comparison completed; every material change noted
- ☐All published parts cross-checked for consistency
- ☐Predecessor identified by name from the filing
- ☐Disciplinary and regulatory disclosure reviewed; BrokerCheck run on registered personnel
- ☐EDGAR searched — Form D and any other filings identified (if applicable)
- ☐Exemption relied upon by each private fund identified (if applicable)
- ☐Public marketing inventoried and dated
- ☐Written list of questions the public record could not answer
- ☐Systems and vendor inventory reconciled against what the ADV discloses
- ☐All system logins confirmed and documented
- ☐Compliance calendar mapped — know where you are in the year
- ☐Key stakeholder introductions complete (CEO, PM team, marketing, operations, outside counsel)
- ☐Exam correspondence requested; firm’s examination history confirmed
- ☐Predecessor handoff completed (if applicable)
- ☐Own Code of Ethics obligations met — initial holdings report filed within 10 days of becoming an access person
- ☐Prior political contributions raised and checked against the pay-to-play two-year look-back
- ☐Cybersecurity policy reviewed — ownership identified, last update date confirmed
- ☐Regulation S‑P incident response program status confirmed
- ☐All compliance-related vendor contracts reviewed (term, renewal date, usage)
- ☐Vendor due diligence status assessed — documented assessments on file?
- ☐All policies and procedures reviewed — currency, accuracy, coverage gaps documented
- ☐Marketing Rule implementation reviewed — not just policy, but evidence it was followed for each piece of content
- ☐Annual review documentation verified — most recent review in writing?
- ☐Open projects and unfinished items inventoried
- ☐Exam readiness baseline completed and documented
- ☐Inherited risk conversation completed — known open items documented
- ☐Gap inventory created and prioritized by risk
- ☐Annual compliance calendar built and shared with team
- ☐Priority 1 remediation identified, initiated, and documented
- ☐Regulatory filing audit complete — all filings current, next due dates calendared
- ☐Budget and authority conversation completed — documented
- ☐90-day assessment delivered to leadership
- ☐Upcoming ADV amendment preparation started (if applicable)
- ☐Vendor oversight program confirmed adequate or added to remediation list
- ☐Exam document production workflow understood — know what you’d produce and how fast
- ☐Cyber liability insurance notification requirements confirmed
Your first 90 days get you oriented. The harder problem starts on Day 91.
Compliance at an RIA isn’t a project you complete — it’s a program you run continuously. The risk that follows you isn’t usually whether you did the work. It’s whether you can show you did it.
“The compliance officers who do this job well aren’t the ones who know every rule cold. They’re the ones who build programs that work when they’re not in the room.”
If you’d like to see how Redan approaches the documentation side of compliance — specifically building the marketing review evidence trail as you go, so it’s ready when an examiner asks — we’d be glad to show you. Book a demo at redancompliance.com, or reach us at jason@redancompliance.com.
This guide is published by Redan Compliance. It does not constitute legal advice. Your firm’s specific circumstances, regulatory history, and applicable state and federal requirements will vary. Consult qualified securities counsel for legal guidance.