Can an outsourced chief compliance officer be your CCO?

Yes, an outsourced CCO can be an adviser’s chief compliance officer, and the firm still owns the program. What Rule 206(4)-7 asks, and what examiners found.

Yes, an outsourced chief compliance officer can be an adviser’s CCO. The rule’s condition is that the CCO is a named individual, not a consulting firm, who is a “supervised person” of the adviser, and the firm should be able to show how its CCO fits that definition. Separately, the arrangement goes on Form ADV, which asks who pays or employs a CCO the adviser doesn’t employ itself. Outsourcing moves the work, and the responsibility stays with the firm: in the SEC staff’s words, “each registrant is ultimately responsible for adopting and implementing an effective compliance program and is accountable for its own deficiencies.”

This answer runs in ten parts:

  • What the rule asks for: policies, an annual review and a CCO, and the 2023 amendment that no longer applies.
  • Who can be CCO, and how an outside individual fits the definition.
  • What goes on Form ADV when someone else pays or employs the CCO.
  • What examiners found at firms with outsourced CCOs.
  • When the CCO has another job at the firm.
  • What a small adviser’s program must contain: the ten core areas, the code of ethics and the insider-information policies.
  • Redan’s position: the standard doesn’t scale down, the route does.
  • How it’s actually done.
  • The record it should leave.
  • Frequently asked questions, then the sources.

What the rule asks for

Rule 206(4)-7 makes it unlawful for a registered adviser to give advice unless it has done three things:

  • Written policies and procedures. “Adopt and implement written policies and procedures reasonably designed to prevent violation, by you and your supervised persons, of the Act and the rules that the Commission has adopted under the Act” (206(4)-7(a)).
  • An annual review. “Review, no less frequently than annually, the adequacy of the policies and procedures … and the effectiveness of their implementation” (206(4)-7(b)).
  • A chief compliance officer. “Designate an individual (who is a supervised person) responsible for administering the policies and procedures” (206(4)-7(c)).

The Commission said when it adopted the rule that failing to have adequate policies and procedures in place is a violation on its own, independent of any other securities law violation (Release IA-2204).

One amendment to the rule no longer applies. In 2023 the Commission amended 206(4)-7(b) to require every adviser to document its annual review in writing. A federal court vacated that amendment effective June 5, 2024, and the Commission restored the earlier text (Release IA-6773). The separate records requirement for the annual review, in 204-2(a)(17)(ii), was not part of that amendment and still applies.

Who can be CCO

The rule names one condition: the CCO is an individual who is a supervised person. The Advisers Act defines a supervised person as “any partner, officer, director (or other person occupying a similar status or performing similar functions), or employee of an investment adviser, or other person who provides investment advice on behalf of the investment adviser and is subject to the supervision and control of the investment adviser” (section 202(a)(25)).

An outside consultant is none of those by default. Neither the rule nor the staff guidance cited here says how an outside individual comes within the definition, so the firm should record the basis on which its CCO does: the title or role the firm has given that person, and the supervision and control the engagement gives the firm over their work for it.

The appointment is made like any professional engagement, and the engagement letter carries it. The letter names the individual, not only their firm. It sets out the scope of the work, the term and how it ends, where and how the work is done, and the authority the CCO has to administer the program. It also states that the CCO’s work for the adviser is subject to the adviser’s supervision and control, with access to the records the work needs and a named person at the adviser the CCO reports to. The firm records the designation on its side as well, and the Form ADV Item 1.J entry matches it.

The Commission’s guidance adds what the person has to be able to do. As the staff has restated it from the adopting release, a CCO “should be competent and knowledgeable regarding the Advisers Act and should be empowered with full responsibility and authority to develop and enforce appropriate policies and procedures for the firm,” with “a position of sufficient seniority and authority within the organization to compel others to adhere to the compliance policies and procedures” (2020 risk alert, citing IA-2204). The staff’s 2015 alert applies that to a CCO who is “a direct employee of a registrant or … a contractor or consultant”: either way, the CCO “must be empowered with sufficient knowledge and authority to be effective.”

What goes on Form ADV

Form ADV Part 1A, Item 1.J, asks for the name and contact information of the CCO. Item 1.J(2) adds: if the CCO “is compensated or employed by any person other than you, a related person or an investment company registered under the Investment Company Act of 1940 that you advise for providing chief compliance officer services to you,” the adviser gives that person’s name and IRS Employer Identification Number. An outsourced CCO arrangement normally means filling in 1.J(2) with the consulting firm’s details.

What examiners found at firms with outsourced CCOs

The SEC’s examination staff looked specifically at advisers and funds that outsource the CCO role and published what it saw in November 2015. Where the outsourced CCO was effective, the staff saw regular, often in-person, communication with the firm, access to the firm’s documents, enough support from the firm, and knowledge of both the rules and the firm’s business.

Where it wasn’t, the staff saw a consistent set of problems:

  • Too many firms, too few resources. “More significant compliance-related issues were identified at registrants with an outsourced CCO that served as the CCO for numerous unaffiliated firms and that did not appear to have sufficient resources.”
  • The firm chose what the CCO saw. Annual reviews by CCOs who could “independently obtain the records they deemed necessary” matched the firm’s actual practices more closely than reviews where the CCO “relied wholly on the firm to select the records.”
  • Generic checklists and templates. Standardized risk checklists that “did not appear to fully capture the business models, practices, strategies, and compliance risks” of the firm, and manuals built from templates that described practices the firm didn’t follow, such as billing in advance when clients were billed in arrears, or naming departed employees as the people responsible for reviews.
  • No evidence of testing. The staff “observed a general lack of documentation evidencing the testing” in annual reviews the outsourced CCOs were responsible for.
  • Little presence, little authority. CCOs who rarely visited had “limited visibility and prominence,” which appeared to limit their authority to improve adherence or to change key disclosures.

The staff’s 2020 alert on compliance programs found the same two failures across advisers generally: CCOs with “numerous other professional responsibilities, either elsewhere with the adviser or with outside firms,” who “did not appear to have time to develop their knowledge of the Advisers Act,” and CCOs who lacked authority, including at firms that “restricted their CCOs from accessing critical compliance information, such as trading exception reports.”

When the CCO has another job at the firm

At many small advisers the CCO isn’t outsourced at all. A principal or the chief operating officer holds the title alongside their main job. Nothing in the rule forbids it, and the same standard applies: the time, knowledge and authority to administer the program. The 2020 alert’s finding about CCOs with “numerous other professional responsibilities” is written for this setup.

The code of ethics recognizes the smallest case. An adviser whose only access person is the adviser itself doesn’t have to report to itself or pre-approve its own IPO and limited-offering purchases, as long as it keeps records of all its holdings and transactions (204A-1(d)).

The CCO doesn’t review their own personal trading or approve their own marketing. That review goes to the next person in the compliance chain, usually whoever handles pre-approvals for everyone else. Where there’s no one else in compliance, it goes to another principal of the firm. Either way, the reviewer and their decision are recorded the same as for any other access person.

What a small adviser’s program must contain

The rule doesn’t list required elements. The Commission said investment advisers are too varied for a single set, and that each adviser should “first identify conflicts and other compliance factors creating risk exposure for the firm and its clients in light of the firm’s particular operations, and then design policies and procedures that address those risks” (as quoted in the 2015 risk alert).

It did say it expects policies, at a minimum, to address ten core areas to the extent they’re relevant to the adviser:

  1. Portfolio management processes
  2. Accuracy of disclosures made to investors, clients and regulators
  3. Proprietary trading of the adviser and personal trading activities of supervised persons
  4. Safeguarding client assets from conversion or inappropriate use by advisory personnel
  5. Accurate creation and retention of required records
  6. Privacy protection of client records and information
  7. Trading practices
  8. Marketing advisory services
  9. Valuing client holdings and assessing fees based on those valuations
  10. Business continuity plans

Beside the compliance rule sit two more requirements a small firm can’t skip. Rule 204A-1 requires a written code of ethics that at minimum:

  • sets a standard of business conduct that reflects the fiduciary obligations of the adviser and its supervised persons (204A-1(a)(1))
  • requires supervised persons to comply with the federal securities laws (204A-1(a)(2))
  • requires access persons to report, and the adviser to review, their personal securities transactions and holdings (204A-1(a)(3))
  • requires prompt reporting of code violations to the CCO (204A-1(a)(4))
  • gives each supervised person the code and any amendments, and gets their written acknowledgment of the code and any amendments (204A-1(a)(5))
  • requires access persons to get approval before acquiring any security in an initial public offering or a limited offering (204A-1(c))

Section 204A requires written policies to prevent the misuse of material nonpublic information, taking into consideration the nature of the adviser’s business.

On what examiners test, the Division of Examinations’ priorities for fiscal year 2026 say examinations of compliance programs typically evaluate the core areas, “as applicable and appropriate,” of “marketing, valuation, trading, portfolio management, disclosure and filings, and custody,” and typically include “an analysis of advisers’ annual reviews.”

Redan’s position: the standard doesn’t scale down, the route does

A smaller firm may reach a control by a different route, and the control it reaches is the same one. The right control is the answer for every firm, because size doesn’t decide whether a firm can implement a policy or test it. Where a firm can’t meet a control, name the gap.

The rule text points the same way. 206(4)-7(a) makes no allowance for headcount, and the staff lists inadequate compliance resources as a deficiency in its own right. Tailoring decides which risks a program addresses, and the standard for addressing them is the same at every firm.

How it’s actually done

The practice below is professional practice, not a rule requirement.

The CCO’s own trail. The protection for a CCO is a written trail showing they found the issue, told someone with the authority to fix it, asked for what they needed, and recorded the answer they got. The CCO keeps the things asked for and not given in writing and dated, because nobody else in the firm is keeping those.

Acting on what’s reported. A report to compliance creates a duty to do something and to record what was done. Every item needs an owner, a date, an outcome and a reason. “We looked and there was nothing here” counts as an outcome and is recorded the same way.

Stepping back between annual reviews. Most programs step back only at the annual review. A short quarterly look at what could work better is a good habit, and it’s a different exercise from testing whether the policies work. Keeping the two apart stops the improvement list turning into a findings list.

What a program needs from the start, in the order a working CCO builds it. Each step leans on the one before.

  1. The CCO’s authority, in writing. The designation, the engagement or role description, the budget, and the CCO’s right to engage outside counsel and reach any part of the business. Form ADV Item 1.J matches it. Everything after this depends on someone having the standing to require it.
  2. An inventory of the firm’s risks and conflicts. What the firm does, for whom, and where it could go wrong, read against its Form ADV and brochure. The Commission said policies start here: identify the risks first, then design the policies that address them.
  3. The compliance manual, written to that inventory. Policies and procedures (206(4)-7(a)) covering the areas that apply to the firm, the ones the Commission listed when it adopted the rule, from portfolio management and trading to marketing, valuation and fees, safeguarding client assets, privacy, records and business continuity. It says what each policy requires and how it is tested.
  4. The code of ethics and the insider-information policies. Personal trading reporting and pre-approval, the list of access persons, and acknowledgments from every supervised person (204A-1), with the material nonpublic information policies (section 204A). The ten-day clock on an initial holdings report starts when a person becomes an access person.
  5. The records system (204-2). Where each required record lives, how long it’s kept, and the archive for email and every approved messaging channel. The approved-channel list goes in the governance document.
  6. Client data and the vendors that hold it. The Regulation S-P safeguards, the incident response program, disposal procedures and a list of every service provider with access to customer information, each with a tier and a diligence record. Also the Regulation S-ID determination of whether the firm has covered accounts.
  7. Disclosure that matches practice. Form ADV Parts 1 and 2, brochure supplements, Form CRS if the firm has retail investors, the privacy notice, and a record of what was delivered to whom and when.
  8. Marketing review. Who approves what before it goes out, what evidence backs each claim, and where the approval record is kept, before the first piece is published.
  9. Training. The code of ethics and personal trading inside each person’s first ten days, the firm-wide course, and role-based courses, with completion recorded by person and date.
  10. The calendar, the issues log and the first annual review. Every filing and recurring deadline mapped for twelve months. An intake log from day one, where every matter reported to compliance gets an owner, a date and an outcome. The first annual review is scheduled within twelve months of registration, covering everything from registration onward.

Where they apply, add them in the same pass: custody procedures and the surprise examination, proxy voting, pay-to-play controls for government clients, and, for private funds, each fund’s offering exemption and what it allows the marketing to do.

When outsourcing works, and what to insist on. Outsourcing works when the CCO has what the staff saw at the firms where it worked: regular contact with the firm, access to its records, support from inside the firm, and knowledge of both the rules and the firm’s business. It fails in the ways the 2015 alert lists: a CCO serving numerous firms without the resources to do it, a firm that chooses what the CCO sees, a manual built from templates that were never tailored to the firm, and annual reviews with no evidence of testing.

So the engagement letter carries the protections, alongside the basics of who, scope and term:

  • Access the CCO controls. The CCO can obtain any record they consider necessary, without the firm choosing what they see.
  • Presence. How often the CCO is in contact with the firm and on site, written down.
  • A reporting line. A named principal the CCO reports to, with the authority to act on what the CCO raises.
  • Capacity. How many other firms the CCO serves, and who supports them.
  • A program built for this firm. Policies written to the firm’s own risks.
  • Evidence of testing. Each annual review comes with the testing behind it: what was tested, the sample and the result.

The firm stays responsible for the program whoever runs it, and the engagement letter is how the firm shows it gave the CCO what the job needs.

What the CCO owns. The firm owns the compliance program and answers for its deficiencies. In the staff’s words, “each registrant is ultimately responsible.” The CCO owns administering it: running the program, testing it, raising what they find, and keeping the record of what they did.

A CCO shows their own part with the trail described above: the issue found, who it was raised with, what was asked for, and the answer, all in writing and dated. That trail is credible when the CCO’s authority and resources are written down at the start, in the engagement letter or role description, and when the CCO signs only what they verified and describes in writing anything inherited from before their time.

The record it should leave

The rule’s record requirements for the program are specific. An adviser keeps a copy of the policies and procedures “that are in effect, or at any time within the past five years were in effect” (204-2(a)(17)(i)), and “any records documenting the investment adviser’s annual review” (204-2(a)(17)(ii)). The code of ethics carries its own records: the code in effect, any violation and the action taken, and every supervised person’s written acknowledgment (204-2(a)(12)).

For an outsourced CCO, three more things belong in the file: the basis on which the CCO is a supervised person, the Form ADV Item 1.J entry that matches it, and evidence of the testing behind each annual review. The evidence of testing answers the 2015 alert’s finding of a “general lack of documentation evidencing the testing.”

Frequently asked questions

Can an outsourced chief compliance officer be an adviser’s CCO? Yes. The rule requires an individual who is a supervised person, and the staff has addressed CCOs who are contractors or consultants as well as employees. The firm stays responsible for the program, reports an outside CCO’s employer on Form ADV Item 1.J(2), and should record how the CCO fits the supervised-person definition.

Can the CCO be a consulting firm rather than a person? No. Rule 206(4)-7(c) requires the adviser to designate an individual. A consulting firm can employ that individual, and Form ADV asks for the firm’s name and EIN when it does.

Does the CCO have to work full time? The rule doesn’t say so. The staff has cited as a deficiency CCOs with numerous other responsibilities who didn’t appear to have time to develop their knowledge of the Advisers Act or fulfill their responsibilities as CCO.

Can one outsourced CCO serve many firms? Nothing in the rule forbids it. The staff found more significant compliance issues where an outsourced CCO served numerous unaffiliated firms without sufficient resources.

Is a template compliance manual enough? Not on its own. The staff has repeatedly flagged manuals built from templates or off-the-shelf policies that weren’t tailored to the firm, including policies describing practices the firm didn’t follow.

What are the requirements for an RIA’s compliance program? Written policies and procedures reasonably designed to prevent violations, a review at least annually, and a designated CCO under Rule 206(4)-7; a code of ethics under Rule 204A-1; policies on material nonpublic information under section 204A; and the records under Rule 204-2 that show each of them.

Sources

Rule text, forms and staff guidance below are quoted from the source documents. The 2003 adopting release is quoted as the staff restated it in its 2015 and 2020 risk alerts. Redan’s positions and the professional practice described above are labeled as such in the text.

SourceWhat it supports here
17 CFR 275.206(4)-7(a), (b), (c)Compliance procedures and practices: policies, annual review, designated CCO who is a supervised person
Advisers Act section 202(a)(25), 15 U.S.C. 80b-2(a)(25)Definition of supervised person
Release IA-2204 (December 17, 2003)Compliance rule adopting release: failure to have adequate policies is a violation on its own; CCO qualities and the ten core areas, as restated by the staff
Release IA-6383 (August 23, 2023)The 2023 written annual review amendment, which required every adviser to document the annual review in writing; vacated
Release IA-6773 (November 8, 2024)Vacatur of the 2023 amendments: restores the earlier text of 206(4)-7(b) after the court’s vacatur, effective June 5, 2024
Form ADV Part 1A, Item 1.JCCO disclosure: name of the CCO, and of any outside person who pays or employs the CCO
SEC OCIE risk alert, November 9, 2015Outsourced CCO examinations: staff observations, not a rule
SEC OCIE risk alert, November 19, 2020Compliance program deficiencies: resources, authority, annual review evidence; staff observations, not a rule
SEC Division of ExaminationsFiscal year 2026 examination priorities: core areas examined; annual review analysis
17 CFR 275.204A-1(a)(1)–(5), (c), (d)Code of ethics: minimum contents, pre-approval, the one-access-person case
Advisers Act section 204AMaterial nonpublic information policies
17 CFR 275.204-2(a)(17)(i), (ii)Compliance program records: policies in effect within five years; annual review records
17 CFR 275.204-2(a)(12)Code of ethics records: code, violations and actions taken, acknowledgments
Redan’s positionsThe passages marked “Redan’s position”. Redan’s recommendations, labeled as such in the text