Insights

Marketing review

  1. Marketing Rule review: net of fees, hypothetical performance, and testimonials

    What the SEC Marketing Rule requires of net-of-fees performance, hypothetical performance, and testimonials and endorsements, and how a review of adviser marketing should run and what it should leave on file.

The annual compliance review

  1. The annual compliance review: what Rule 206(4)-7 requires, and a checklist

    Annual compliance reviews are mandatory for SEC-registered advisers. What the rule asks, what the SEC’s September 14, 2026 risk alert found firms getting wrong, and a checklist built from both.

What an SEC exam asks for

  1. SEC exams: the document request, the deficiency letter, and the 2026 priorities

    What an SEC exam of an investment adviser asks for, what happens during one, how a deficiency letter works, and what the Division of Examinations’ fiscal year 2026 priorities say it will look at.

Building the program, and who can be CCO

  1. Can an outsourced chief compliance officer be your CCO?

    Yes, an outsourced CCO can be an adviser’s chief compliance officer, and the firm still owns the program. What Rule 206(4)-7 asks, and what examiners found.

Off-channel messaging

  1. Off-channel communications: what counts, and what to do when a client texts

    Off-channel communications are business messages on a channel the firm doesn’t capture. What Rule 204-2 makes a record, and what to do when a client texts.

Books and records

  1. Investment adviser books and records: what to keep, how long

    Most investment adviser records are kept at least five years, the first two in an office. The Rule 204-2 list, the records on their own clocks, and e-storage.

Regulation S-P

  1. Regulation S-P amendments: requirements for investment advisers

    What the 2024 Regulation S-P amendments require of SEC-registered advisers: an incident response program, customer notice and service provider oversight.

Vendor oversight

  1. Vendor due diligence for RIAs and third-party vendor oversight

    What vendor due diligence an RIA owes under Regulation S-P, Regulation S-ID and the compliance rule, how deep to go by risk, and how to document it.

Training

  1. Compliance training requirements for RIAs, and proving it worked

    What compliance training an RIA owes: code of ethics acknowledgment, identity theft program training, what examiners may request, and showing it worked.