Compliance training requirements for RIAs, and proving it worked
What compliance training an RIA owes: code of ethics acknowledgment, identity theft program training, what examiners may request, and showing it worked.
The rules cited here require two things of an SEC-registered adviser’s training. Every supervised person must receive the code of ethics and give a written acknowledgment, and a firm running an identity theft program must train staff as necessary to implement it. None of them sets a general training requirement or a frequency. When it adopted the code of ethics rule, the Commission said it did not believe it necessary to require employee education, but that “we expect most advisory firms will ensure that their employees have received adequate training on the principles and procedures of their codes.” In an examination, staff may request the training given and documentation of attendance.
This answer runs in six parts:
- What the rules require: the code of ethics, identity theft programs, the compliance rule, and what an examination may ask for.
- Redan’s position on what each person should take.
- Showing that it worked: what a completion certificate cannot prove, and what can.
- How it’s actually done: who takes what, how often, and for how long.
- The record it should leave.
- Frequently asked questions, then the sources.
What the rules require
The code of ethics. Rule 204A-1(a)(5) requires an adviser’s code of ethics to include provisions “requiring you to provide each of your supervised persons with a copy of your code of ethics and any amendments, and requiring your supervised persons to provide you with a written acknowledgment of their receipt of the code and any amendments.” Rule 204-2(a)(12)(iii) requires the adviser to keep a record of all those acknowledgments for each person who is, or within the past five years was, a supervised person.
The rule stops at delivery and acknowledgment, and the adopting release (Release No. IA-2256, 2004) says why. The Commission called an adviser’s procedures for informing its employees about the code “critical to obtaining good compliance and avoiding inadvertent violations of the code,” and wrote: “Although we do not believe it is necessary to require employee education as an element of codes of ethics, we expect most advisory firms will ensure that their employees have received adequate training on the principles and procedures of their codes.”
The code also sets the first deadline a new hire meets. An access person must submit an initial holdings report no later than 10 days after becoming an access person (Rule 204A-1(b)(1)(ii)(A)).
Identity theft programs. Regulation S-ID applies to a registered adviser that is a financial institution or creditor as the Fair Credit Reporting Act defines those terms (Rule 248.201(a)(3)). Each such firm must periodically determine whether it offers or maintains covered accounts (248.201(c)), and one that does must run a written Identity Theft Prevention Program (248.201(d)(1)). Administering it includes the requirement to “train staff, as necessary, to effectively implement the Program” (248.201(e)(3)). In its December 2022 observations on those programs, the Division of Examinations reported firms that “did not have robust processes to assess which employees should be trained,” and training that “was limited to a single sentence telling employees to be aware of identity theft.” Its fiscal year 2026 priorities say it will assess whether firms’ programs “include firm training on identity theft prevention.”
The compliance rule. Rule 206(4)-7(a) requires written policies and procedures reasonably designed to prevent violations, and Rule 206(4)-7(b) requires an annual review of their adequacy “and the effectiveness of their implementation.” The rule does not mention training. A policy staff have never been taught is hard to show as implemented, and a manual that promises training commits the firm to delivering it.
OCIE (now the Division of Examinations) made the second point in its November 2020 observations on adviser compliance programs. Among advisers that “did not implement or perform actions required by their written policies and procedures,” the first example it gave was advisers that did not “Train their employees.” The same observations list inadequate resources for the compliance function, “such as information technology, staff and training,” among the deficiencies found, and “employee training” among the cybersecurity areas where advisers’ written policies had deficiencies or weaknesses.
What an examination may ask for. The Division of Examinations’ September 2023 risk alert on how it scopes adviser examinations lists documents staff may request, including “Written guidance and training provided to employees regarding compliance program and documentation of attendance.”
Redan’s position: a composition, not a count
- What each person takes is a composition. That means the annual firm-wide course, one or two courses for their department chosen by what that department does, and a small number of topical courses where they apply, such as off-channel communications, gifts and entertainment, or political contributions. A marketing or investor relations team, for instance, takes marketing fundamentals, then off-channel communications, then the annual course.
- Compare the two programs. Set an annual policy and an annual course beside a program that spreads the work across the year, with quarterly touchpoints, training triggered by a rule change or an incident, and a manual amended when something changes. Then ask which of the two you would rather defend in an examination.
- New hires start on day one. They begin training that day, and finish code of ethics and personal trading training inside their first ten days. The ten days come from the rule’s reporting deadline: an access person’s initial holdings report is due no later than 10 days after the person becomes an access person (204A-1(b)(1)(ii)(A)). Training that comes later means the report may already have gone in incomplete, and for the rest of a thirty-day window the new hire may be trading in ways the training would have caught. Thirty days is a common window at small firms, but the deadline is the same at every size of firm.
- Write to the most junior person. Write each course for the most junior person who will take it, and say so in the course. Senior readers read past material pitched below them, and junior readers do not read up. The junior person is also usually the one sending the message on someone else’s behalf, which is where the exposure sits.
- Budget the annual course in minutes. Start from the length of the session, decide how long each topic deserves, and weight the time toward last year’s violations.
Showing that it worked
A completion certificate proves that a person finished. Showing that training worked takes three more things.
- The version. Which version of which course each named person took, and when. A course that changed after a rule change, taken before the change, is not evidence of training on the new rule.
- The follow-up. Who was chased when they did not finish, and what happened to the people who never did.
- The link to the work. When something goes wrong, what the training record shows about the people involved, and what changed afterwards. Rule 204-2(a)(12)(ii) already requires a record of any code of ethics violation and of any action taken as a result.
Redan’s position on that third point is that a violation followed by a documented response is still a violation, and it is evidence of a program working as designed: a policy the firm can test, people it can train, and a failure it can remediate. When the same breach happens twice, the question moves off the person and onto the program, and the fix moves with it, to the policy, the training or the control that let it through.
Some training can be measured directly. Security awareness is the clearest case, because a phishing simulation measures what a module on phishing only teaches. For most compliance subjects the measure is slower, and it lives in the work the person does afterwards.
How it’s actually done
- Who takes what runs off role and access, not seniority. Everybody takes the firm-wide course and the code of ethics, and access persons take personal trading. Anyone who touches marketing takes the Marketing Rule, and anyone who touches client data takes security awareness.
- New hires inside ten days. Code of ethics and personal trading are done within the first ten days, before the initial holdings report is due.
- The rhythm across the year. One firm-wide course a year, topic sessions when a rule changes or something goes wrong, and short touchpoints through the year so the annual course isn’t the only time anyone hears from compliance. The same rhythm applies at every firm, whatever its size.
- Where the annual course sits. The fourth quarter puts it next to the code acknowledgment and the manual attestation. The first quarter puts it next to the annual review, but people are harder to find during year-end filings and audits.
- Length. About an hour of material for the annual course: the firm’s own risks, what changed since last year, the incidents worth naming, and the parts of the manual people get wrong. An annual deck nobody finishes is worse evidence than a short one everybody did.
- Security awareness. Annual training plus phishing simulations through the year, because people forget the training.
The record it should leave
For each person, the record should answer, without anybody reconstructing it: what they were assigned and why, which version of which course they took, when they started and finished, how they did on the assessment, and who chased them if they were late. For the program, it should answer what the firm trained on this year, who was covered, and who was not.
Frequently asked questions
Is compliance training required for investment advisers? The rules cited here require two things close to it. Every supervised person must receive the code of ethics and any amendments and give a written acknowledgment (Rule 204A-1(a)(5)). An adviser running an identity theft program must train staff as necessary to implement it (Rule 248.201(e)(3)). None of them sets a general training requirement. The Commission said in 2004 that it expects most advisory firms to ensure their employees have received adequate training on their codes of ethics, and in an examination staff may request the training given and documentation of attendance.
Is code of ethics training required? The rule requires delivery and acknowledgment, not training: each supervised person receives the code and any amendments and gives a written acknowledgment (Rule 204A-1(a)(5)). In adopting the rule, the Commission said it did not believe it necessary to require employee education, but expects “most advisory firms will ensure that their employees have received adequate training on the principles and procedures of their codes” (Release No. IA-2256).
How often do advisers have to do compliance training? The rules cited here set no frequency. The common practice is one firm-wide course a year plus new-hire training, with topic sessions when a rule changes or something goes wrong. Redan’s position is that each person’s training is a composition chosen by role.
What training records should an adviser keep? The written acknowledgments of the code of ethics for each current and former supervised person within the past five years (Rule 204-2(a)(12)(iii)), and the training given with documentation of attendance, which examinations request. A useful record also shows which version of each course a person took, when, and who followed up on anyone who did not finish.
What do examiners ask for on training? The Division’s September 2023 risk alert lists “Written guidance and training provided to employees regarding compliance program and documentation of attendance” among the documents it may request.
How do you show compliance training worked? By connecting the training record to what happened afterwards: the version each person took, the follow-up on those who did not finish, and, when something goes wrong, what the record shows and what changed in the policy, the training or the control as a result. Where a direct measure exists, such as a phishing simulation, use it.
Sources
| Source | What it supports here |
|---|---|
| 17 CFR 275.204A-1(a)(5) and (b)(1)(ii)(A) | Code delivery and acknowledgment; the ten-day initial holdings report |
| Release No. IA-2256, Investment Adviser Codes of Ethics, published in the Federal Register on July 9, 2004 (the passage quoted is at 69 FR 41700) | The Commission’s expectation of training on the code |
| 17 CFR 275.204-2(a)(12)(ii) and (iii) | Records of code violations and of acknowledgments |
| 17 CFR 248.201(a)(3), (d)(1) and (e)(3) | Staff training for identity theft programs |
| 17 CFR 275.206(4)-7(a) and (b) | The compliance rule and annual review. The rule does not mention training. |
| Risk alert, “OCIE Observations: Investment Adviser Compliance Programs,” November 19, 2020 | Advisers that did not train their employees as their policies required; training as a compliance-function resource; employee training in cybersecurity policies |
| Risk alert on identity theft prevention programs (Regulation S-ID), December 5, 2022 | The observation on inadequate training |
| Risk alert, “Investment Advisers: Assessing Risks, Scoping Examinations, and Requesting Documents,” September 6, 2023 | The document request for training and attendance |
| SEC Division of Examinations, Fiscal Year 2026 Examination Priorities | Training on identity theft prevention |
| FINRA continuing education and state investment adviser representative continuing education | Not addressed on this page |
| Redan’s positions | The passages marked “Redan’s position”. Redan’s recommendations, labeled as such in the text |