The annual compliance review: what Rule 206(4)-7 requires, and a checklist

Annual compliance reviews are mandatory for SEC-registered advisers. What the rule asks, what the SEC’s September 14, 2026 risk alert found firms getting wrong, and a checklist built from both.

An annual compliance review is mandatory for an adviser registered, or required to be registered, with the SEC. Rule 206(4)-7 under the Investment Advisers Act requires the adviser to review, “no less frequently than annually, the adequacy of the policies and procedures established pursuant to this section and the effectiveness of their implementation” (206(4)-7(b)). On September 14, 2026 the SEC’s Division of Examinations published a risk alert on what examiners found when they looked at those reviews.

This answer runs in seven parts:

  • What the rule asks: the three things Rule 206(4)-7 requires, the two records the books and records rule adds, and what the review should consider.
  • What the September 14, 2026 risk alert found, in five areas: timeliness, the procedures for the review, the fit between the review and the firm’s actual practices, documentation, and corrective action.
  • An annual compliance review checklist, opening with the year’s developments, then each line traced to the rule or to the risk alert.
  • Redan’s positions on a documented one-off, the marketing review, and the smaller firm.
  • How it’s actually done, from the year’s developments that start the review to the quarterly look at what could work better.
  • The record it should leave.
  • Frequently asked questions, then the sources.

What the rule asks

Rule 206(4)-7 makes it unlawful for a registered adviser to provide investment advice unless it does three things:

  • Adopts and implements written policies and procedures “reasonably designed to prevent violation, by you and your supervised persons, of the Act and the rules that the Commission has adopted under the Act” (206(4)-7(a)).
  • Reviews them at least annually, for the adequacy of the policies and the effectiveness of their implementation (206(4)-7(b)).
  • Designates a chief compliance officer, an individual who is a supervised person, responsible for administering them (206(4)-7(c)).

The books and records rule adds two records. The adviser keeps a copy of its policies and procedures in effect now or at any time in the past five years (204-2(a)(17)(i)), and “any records documenting the investment adviser’s annual review of those policies and procedures” (204-2(a)(17)(ii)). The review records are kept for five years from the end of the fiscal year of the last entry, the first two in an appropriate office of the adviser (204-2(e)(1)).

The rule text does not use the word “report”. It requires the review and records documenting it, and it sets no format, template or checklist. Any report or format requirement comes from the firm’s own policies, and the risk alert shows that once a firm’s policy says “written report”, the staff tests the firm against that.

What the review should consider. The Commission’s release adopting the rule said the review “should consider any compliance matters that arose during the previous year, any changes in the business activities of the adviser or its affiliates, and any changes in the Advisers Act or applicable regulations that might suggest a need to revise the policies or procedures,” and that advisers should “consider the need for interim reviews in response to significant compliance events, changes in business arrangements, and regulatory developments.” Both passages are quoted here as the September 14, 2026 risk alert quotes them.

What the September 14, 2026 risk alert found

The Division of Examinations reported problems in five areas: timeliness, the procedures for conducting the review, the fit between the review and the firm’s actual practices, documentation, and corrective action. The third comes below in two parts: following the firm’s own procedures, and policies that do not match practice. A risk alert is the staff’s view and has no legal force, but it is a direct account of what examiners ask for and what they found.

Timeliness. Advisers:

  • skipped a year, for example reviewing 2021 and 2023 but not 2022;
  • ran reviews more than 12 months apart, including after a chief compliance officer left;
  • treated compliance training or annual attestations from staff as the review; and
  • received deficiency letters for missing or late reviews and still did not correct it.

The alert also notes that the 18-month window for a first review, in the adopting release, applied only to advisers when the rule took effect in 2004. Every review since has to be at least annual.

Procedures for the review. Advisers had policies requiring an annual review, with testing, but no procedures telling staff how to test, what to weigh in judging adequacy and effectiveness, or what documentation to keep. Others named topics for annual testing elsewhere in their manual, such as identity theft, and left them out of the review.

Following the firm’s own procedures. Reviews did not cover the period or scope the firm’s own procedures required, did not use the specified workpapers or tests, or assessed an outdated version of the policies.

Policies that do not match practice. Reviews missed gaps between what the policies said and what the firm did. The examples the staff gives:

  • fee billing that departed from the policies, the advisory agreement or Form ADV, such as a different calculation method, no proration for large mid-period deposits, missed breakpoints and unpaid refunds on terminated accounts;
  • proxy voting policies saying the adviser votes, when it disclosed that it did not and did not in practice;
  • custody procedures that left out identifying accounts to the independent accountant for the surprise examination;
  • marketing policies never updated for the Marketing Rule;
  • filing procedures never updated for Form CRS;
  • policies delegating work to others with no procedure for overseeing it; and
  • incidents of non-compliance reported during the year that the review never recorded.

Documentation. Advisers created workpapers during the review and did not keep them. Written reports discussed violations with none of the testing, issues or recommendations behind them. Some firms’ policies required a written report and none was prepared. Others required checklists or templates that were only partly completed.

Corrective action. Reviews recommended changes, such as better proxy voting disclosure, documented client risk tolerances, or more thorough best execution analysis and broker-dealer due diligence, and the changes were never made. In some cases the report said they had been made, and the same issues appeared again in the next review.

An annual compliance review checklist

The first group is practice, the way the work is done. Every line after it traces to the rule or to the risk alert. A firm’s own policies may require more, and whatever they require is then part of the test.

The year’s developments

  • The year’s risk alerts and enforcement actions that bear on the firm’s business are listed, each with whether it reaches the firm and why.
  • Internal events are listed with the gap each one exposed, including issues raised for the first time.
  • Where a development reaches the firm, the drafted policy change or new language is in the file.
  • This year’s testing is chosen from that list, and the file says why each test was chosen.
  • Each gap from earlier reviews shows its status: closed with evidence, or open with an owner, a date and a reason.
  • For each area tested, the file pairs the issue addressed and the change made with the updated output, so both go out together on a request for that area.

Timing and scope

  • The review period runs from the end of the last review, with no gap and no stretch longer than 12 months (206(4)-7(b); risk alert, timeliness).
  • The review covers every policy in the current manual, and every topic the manual elsewhere says will be tested annually (risk alert, procedures for the review).
  • The version of each policy reviewed is the version in effect during the period (risk alert, following the firm’s own procedures).
  • Interim reviews have been considered after any significant compliance event, business change or regulatory change during the year (adopting release, as quoted in the risk alert).

What was tested

  • For each policy, both questions are answered: is it adequate, and was it implemented effectively (206(4)-7(b)).
  • Practice has been tested against policy and disclosure, not only the policy read: fee billing against the agreement and Form ADV; proxy voting; custody; marketing under the Marketing Rule; Form CRS; oversight of delegated work (risk alert, policies that do not match practice).
  • Every compliance matter from the year is in the review, including incidents already handled (adopting release; risk alert, policies that do not match practice).
  • Changes in the business, and in the rules, are listed with what each one changed in the policies (adopting release).
  • Training and staff attestations are treated as evidence the review considers, not as the review (risk alert, timeliness).

Documentation

  • The workpapers for each test are kept with the review: what was tested, the sample, what was found (204-2(a)(17)(ii); risk alert, documentation).
  • If the firm’s policy requires a written report, the report exists and covers what the policy says it covers (risk alert, documentation).
  • Any required checklist or template is complete (risk alert, documentation).
  • The policies in effect during the period are kept, as well as the current ones (204-2(a)(17)(i)).

Corrective action

  • Each finding has an owner, a due date and a recorded outcome (risk alert, corrective action).
  • Each corrective action from the last review is confirmed done by evidence, not by a statement in the report (risk alert, corrective action).
  • Any finding from a prior deficiency letter is traced to its fix (risk alert, timeliness).

Redan’s positions

A documented one-off is still a violation. A books-and-records failure is still a finding after the firm writes it down. The documentation shows the compliance program working as designed: a policy the firm can test, people it can train and a failure it can remediate. The same breach happening again moves the question off the person and onto the program.

A marketing review feeds the annual review. A marketing review checks whether the firm has a policy covering the claim, and a missing policy is written up as a finding rather than fixed with a copy edit. That finding belongs in the annual review file, because the same gap will produce the next piece.

No weaker answer for a smaller firm. Size does not predict whether a firm can implement a policy or test it. Where a control is right, it is the answer for every firm. A firm that cannot meet it has a problem worth naming. The rule makes no allowance for headcount: 206(4)-7(a) asks for policies “reasonably designed to prevent violation” at every firm.

How it’s actually done

The review starts from the year: what the staff published in risk alerts, which enforcement actions touched the firm’s kind of business, and what happened inside the firm, such as a complaint, an error or a gap someone raised for the first time. For each one, the file records whether it reaches the firm and, where it does, the policy language drafted in response. That list then decides the testing, so the review samples where the year says risk moved instead of rerunning last year’s request list.

Read across years, the reviews should show progression. A gap found in one review is closed in the next, with the evidence, or still open with an owner and a reason. An examiner reading three reviews in a row should see a program that kept up with the guidance and with its own events, and is more complete each year.

The review can be selective. A few enhancements each year, tied to what the year raised, show more than a review that touches every policy lightly. And when an examiner asks for one area, say the fee and expense review for a set of investments, the firm hands over two things together: a short account of the issue that bears on it and what the firm changed, and the updated output showing the change in practice.

Reviews from different years will look different, and that’s expected. In 2024 the firm built its program on the best information it had at the time. When new guidance, a new workflow or a newly identified risk came along in 2025 or 2026, it built further. The difference is defensible because the file shows why: the guidance or event, the policy change it prompted, and when. The reasoning stays consistent from year to year, and the outputs can change.

The firm hands over what was asked for, and where that area’s output changed between years, it includes the short record of why, so the change reads as an improvement.

A good program finds its problems and can show what it did about them. That means the file exists before the review starts: each review during the year, who approved it, the reasoning in their own words and the date, kept where the work happened rather than assembled afterward.

Anything reported to compliance during the year creates a duty to act and to record what was done. Every item gets an owner, a date, an outcome and a reason. “We looked and there was nothing here” is an outcome and is written like one. An intake log with no outcomes is worse evidence than no log, because it proves the firm knew.

Most programs only step back once a year, at the annual review, and by then the findings take the attention away from the improvements. A short quarterly look at what could work better is a different exercise from testing whether policies work, and the two are kept apart so the improvement list does not turn into a findings list.

The record it should leave

The file for each annual review should show:

  • The review period, the dates the review started and finished, and who conducted it.
  • The list of policies reviewed, with the version of each.
  • For each policy, the test performed, the sample, the result, and the judgment on adequacy and effectiveness.
  • The year’s compliance matters, business changes and rule changes, each with what it changed.
  • The findings, each with an owner, a due date and a recorded outcome.
  • Evidence that last year’s corrective actions were completed.
  • The written report, where the firm’s policy calls for one.

Most of what an annual review tests is made during the year: marketing approvals, vendor due diligence decisions, training completions. Where those are kept as dated records when the work happens, the review tests records that already exist instead of reconstructing them.

Frequently asked questions

Are annual compliance reviews mandatory? Yes, for an adviser registered or required to be registered with the SEC. Rule 206(4)-7(b) requires a review “no less frequently than annually.”

Does the rule require a written annual compliance report? The rule requires the review (206(4)-7(b)), and the books and records rule requires “any records documenting” it (204-2(a)(17)(ii)). Neither uses the word “report.” If the firm’s own policy requires a written report, the staff treats a missing report as a failure to follow the firm’s procedures.

Can compliance training or staff attestations count as the annual review? No. The September 14, 2026 risk alert lists advisers that relied on training or attestations instead of a review among the timeliness failures.

When is the first annual review due for a newly registered adviser? Redan’s position is within 12 months of registration, covering the whole period from registration to the review: an adviser registered on October 1, 2026 completes its first review by about October 1, 2027. The rule says “no less frequently than annually” (206(4)-7(b)) and names no start date for a new adviser. The September 14, 2026 risk alert lists “first reviews at 18 months post-registration” among annual reviews performed for periods of greater than 12 months, and notes that the 18-month period in the adopting release applied only to advisers when the rule took effect in 2004.

What happens to the annual review when the chief compliance officer leaves? It stays due. The risk alert lists review intervals stretched past 12 months by a chief compliance officer’s departure among the timeliness failures.

Is there an annual compliance review template? The rule sets none. The checklist above is built from the rule and the September 14, 2026 risk alert, and a firm’s own policies may add to it.

Sources

SourceWhat it supports here
Rule 206(4)-7 and (a), (b), (c), 17 CFR 275.206(4)-7What the rule requires
Rule 204-2(a)(17)(i), (a)(17)(ii) and (e)(1), 17 CFR 275.204-2The records of the review, and how long they are kept
Division of Examinations risk alert, “Examinations Observations Regarding Investment Adviser Annual Compliance Reviews,” September 14, 2026Every observation and the checklist lines citing it
Release IA-2204, “Compliance Programs of Investment Companies and Investment Advisers,” December 17, 2003What the review should consider, and interim reviews. Quoted here only as the September 14, 2026 risk alert quotes it
Redan’s positionsThe passages marked “Redan’s position”. Redan’s recommendations, labeled as such in the text