An RIA annual compliance review is the yearly assessment Rule 206(4)-7 requires. Every SEC-registered adviser must review the adequacy of its written policies and procedures and how effectively they were implemented, no less frequently than annually. In practice that means a risk assessment, testing of what the firm actually did against what its manual says, a findings log, remediation tracking, and retained records an examiner will ask to see.
This guide walks through how to run and document that review as a distinct annual project. It sits under our pillar guide to RIA compliance and is the process companion to our RIA compliance checklist. One quick distinction before we start. The general checklist is the standing list of everything your program owes across the year (Code of Ethics deadlines, Form ADV, custody, recordkeeping, and the rest). This page is different. It is how you audit that whole program once a year and write up what you found.
What is an RIA annual compliance review?
An RIA annual compliance review is the adviser's own examination of its compliance program: whether the written policies are still adequate for the business, and whether the firm actually followed them over the past year. It is required by Rule 206(4)-7(b) under the Investment Advisers Act of 1940. This guide covers SEC-registered advisers; state-registered advisers face state analogues that often track the SEC rule but differ in the specifics.
The SEC's adopting release for the rule frames the standard plainly: advisers should review the "adequacy of the policies and procedures ... and the effectiveness of their implementation" (Release No. IA-2204). Two words carry the weight. Adequacy asks whether your policies still fit the firm you have become. Effectiveness asks whether they were followed in practice, not just whether they exist on paper.
That second half is where thin reviews fail. Confirming a policy is in the manual proves nothing about whether personal-trading reports arrived on time or whether marketing pieces were approved before they went out. The review has to test practice.
On June 8, 2026, the SEC announced a settled order against Arizona-based Foundations Investment Advisors and its former CEO, finding among other things that the firm failed to properly implement its compliance policies, including provisions relating to conducting annual reviews, in violation of Rule 206(4)-7. The firm consented to a censure and a $1,200,000 civil penalty plus disgorgement (SEC administrative proceeding, June 8, 2026).
Is a written annual compliance review required?
No, the current rule text does not require a written annual review, though the answer has a recent history worth stating precisely because much of the web still gets it wrong.
A 2023 amendment would have required every adviser to document the annual review in writing, but the Fifth Circuit vacated that amendment in June 2024 along with the broader Private Fund Adviser Rules. The current rule text does not mandate written documentation. That said, the SEC's Division of Examinations has long expected advisers to be able to demonstrate that a review actually occurred, and a written memo or report memorializing the review remains a strong examination and risk-management practice (17 CFR 275.206(4)-7; SEC announcement regarding the vacated Private Fund Advisers Rules).
Read that carefully, because it is easy to over-correct. The vacatur removed a writing mandate. It did not remove the review itself, which Rule 206(4)-7(b) still requires no less frequently than annually. And "we did it, we just did not write it down" is a difficult position at exam, where the first request is often evidence the review happened. The safe posture is to keep running the review, keep documenting it, and understand that a formal report is now best practice, not a line-item requirement, even as the recordkeeping duty to retain what the review produces remains in force (more on that below). Some older guidance still states that written documentation is mandatory, much of it predating the June 2024 decision. It is not.
When is the annual compliance review due?
Rule 206(4)-7(b) requires the review "no less frequently than annually." It sets no fixed calendar date and prescribes no format. You choose the cadence; the rule only sets the floor.
Many firms choose to anchor the review to their fiscal year-end, which pairs it naturally with the Form ADV annual updating amendment due within 90 days of fiscal year-end. Anchoring the two together means the review can feed the ADV update. If the review surfaces a changed business line or a new conflict, that belongs in the amended brochure. Whatever schedule you pick, write it into your policies so the review runs on a defined date rather than whenever someone remembers.
Do not treat "annually" as a ceiling. When the business materially changes, a new service, an acquisition, a custody change, or a deficiency letter from an examiner, run an interim review rather than waiting up to eleven months for the next annual cycle.
How do you conduct the annual review?
One defensible framework organizes the review into five stages. Treat each as a step that produces a work product, not a box to tick. The rule does not prescribe by whom the work is done: the adviser must ensure the review occurs, the CCO normally coordinates and administers it, and the actual testing may be carried out by compliance staff, business personnel, internal audit, or an outside consultant. SEC examination staff have noted that the rules do not specify the time at which the review is conducted or by whom the work is done (Examiner Oversight of "Annual" Reviews).
The testing itself does not have to happen in one week. Many firms run it on a rolling basis through the year, testing one functional area at a time and aggregating the results into a single annual assessment, an approach SEC examiners have described observing in practice. Spreading the work out is also how the evidence stays current: the review reflects what the firm actually did, captured as it happened, rather than reconstructed at year-end.
- Build a risk assessment (risk inventory). Map the firm's conflicts and risk areas: portfolio management, trading and best execution, disclosure, custody, marketing, recordkeeping, privacy and cybersecurity, valuation, and business continuity. The inventory is what scopes the rest of the review, so a bigger or more complex firm should produce a bigger inventory. Carry forward the prior year's risks and add anything new.
- Review regulatory developments since the last review. Note new or amended rules, SEC examination priorities, and enforcement themes that touch your risk areas. If a rule changed, your policies and your testing plan may need to change with it.
- Test policies against practice. This is the core of the review and the part checklists cannot do for you. Pull samples and see what actually happened: personal-trading reports against the Code of Ethics cadence, a sample of marketing pieces against the approval workflow, books-and-records retention against Rule 204-2, fee calculations, and any area your risk inventory flagged as high. You are looking for the gap between the manual and the month.
- Log findings and deficiencies. Record gaps, exceptions, and near-misses as you find them, with enough detail that a reader a year later understands what happened. Examiners fault the gap you never wrote down far more than the one you found and fixed.
- Track remediation. Assign an owner and a due date to every finding, and carry open items forward from the prior review so nothing quietly disappears. The most common exam criticism is not that a firm found an issue, but that it found the same issue two years running and never closed it.
The output of these five stages is the documented record of the review, which the next section covers.
The annual review checklist
Condensed to a working list, a complete annual review produces evidence of each of these:
- A dated risk inventory covering every material business area, carried forward from last year with new risks added
- A note of regulatory developments since the last review and what they change
- Testing workpapers for each high-risk area, with sample sizes and methods recorded
- Personal-trading reports checked against the Code of Ethics deadlines
- A sample of marketing pieces checked against the approval workflow
- Books-and-records spot checks, including off-channel communications
- A findings and deficiencies log, including near-misses
- A remediation plan with an owner and due date per finding, plus last year's open items
- Senior-management sign-off on material findings and committed resources
- Everything above retained per Rule 204-2(a)(17)(ii)
If you can produce each item on request, the review is defensible in an examination. If one is missing, that gap is next year's first agenda item.
What should the annual review cover?
The review should touch every program area where the firm faces real risk, and test each against the rule that governs it. Keep the scope tight and tie each area back to a rule and a piece of evidence. The table below is a compact map; for the full obligations under each rule, work our RIA compliance checklist or the interactive checklist tool; this page does not re-derive them.
| Program area | Governing rule | What the review tests |
|---|---|---|
| Compliance program and CCO | Rule 206(4)-7 | Policies still fit the business; the review ran; the CCO has real authority |
| Code of Ethics and personal trading | Rule 204A-1 | Access-person reports arrived on the fixed deadlines; conflicts were reviewed |
| Books and records | Rule 204-2 | Records retained and accessible; off-channel communications captured |
| Marketing | Rule 206(4)-1 | Advertisements complied with the Marketing Rule and the firm's review-and-approval policy; material claims and performance were substantiated |
| Custody | Rule 206(4)-2 | Custody determination is current; surprise-exam and statement conditions met |
| Privacy and cybersecurity (Reg S-P) | Regulation S-P | Incident-response program in place; vendor oversight documented |
| Form ADV and Form CRS | Form ADV instructions | Disclosures accurate; annual amendment filed on time |
The table maps the core rule-anchored areas; your risk inventory adds the firm-specific ones, such as valuation and business continuity, that have no single rule row. The point of the table is not to re-explain each rule. It is to force a yes-or-no answer for each area: did we test it, and where is the evidence? Marketing-file testing in particular is a growing exam focus; our SEC Marketing Rule guide covers what examiners are currently citing.
How should you document the annual review?
Three obligations sit close together here, and keeping them separate is what the post-2024 landscape rewards:
- Conducting the review is mandatory. Rule 206(4)-7(b) requires it no less frequently than annually. That has not changed.
- A standalone written report is not forced. The 2023 amendment that would have compelled a written review was vacated, so nothing in Rule 206(4)-7 now dictates that you produce a formal report in any set form.
- Records documenting the review must be retained. Rule 204-2(a)(17)(ii) requires advisers to keep "any records documenting the investment adviser's annual review" conducted under Rule 206(4)-7(b) (17 CFR 275.204-2). This provision is part of the base books-and-records rule; it predates the vacated amendment and survives it. So while no rule forces you to create a standalone report, any records you do create documenting the review must be preserved.
Put plainly, the writing mandate is gone, but the recordkeeping obligation is not. If your review generates a risk assessment, testing workpapers, a findings log, or a memo, those are records documenting the review and fall within Rule 204-2. Records must be preserved in an easily accessible place for at least five years from the end of the fiscal year during which the last entry was made, with the first two years in an appropriate office of the adviser (Rule 204-2(e)(1)).
A written report remains the clearest way to demonstrate the review's scope, testing, findings, and remediation in one place, which is why it stays best practice even without a rule compelling it. There is no prescribed template, but a report that holds up at exam generally covers: the review's scope and period, who coordinated it and who performed the testing, the risk areas assessed, what was tested and how (sample sizes and methods), the findings, the remediation plan with owners and dates, and a sign-off. Store it where you can produce it promptly, because "we did the review verbally" is one of the weakest answers a CCO can give when an examiner asks for evidence.
Report and escalate. Close the loop by presenting the material findings, your recommendations, and any unresolved remediation to senior management or the firm's principals, and record their acknowledgment, decisions, and the resources they commit. This is a routine examination question. Examiners want to see that leadership saw the results and owned the response, not that the findings stopped at the CCO's desk.
Annual review vs. mock exam and independent review
The annual review is the adviser's own required self-assessment under Rule 206(4)-7(b). A mock exam is an optional, usually third-party, dry run that simulates an SEC examination, and an independent compliance review is a similar outside look often used by firms that want a second set of eyes.
These are complementary, not interchangeable. A mock exam or an outside review can feed your annual review with findings and a fresh perspective, and a firm without in-house depth may lean on one. A generic mock exam does not automatically satisfy Rule 206(4)-7(b). Its scope is the examiner's likely questions, not the full adequacy-and-effectiveness assessment the rule demands. An outside review that is appropriately scoped to your risk areas, by contrast, can perform or support substantial portions of the annual review. Either way, the adviser remains responsible for meeting the adequacy-and-effectiveness standard and for acting on what the review finds. When you use an outside party, own the scope, the findings, the conclusions, and the remediation; their work should inform your review, not stand in for your responsibility for it.
Turning the review into a program that documents itself
The annual review is only as strong as the evidence behind it, and the evidence is built the other 364 days of the year. The firms that dread the review are usually the ones reconstructing a year of activity from memory in a single week. The firms that do not are the ones whose personal-trading reports, marketing approvals, filings, and records were captured as they happened.
That is the gap RegFin is built to close. The platform tracks each obligation against its rule and deadline, routes Code of Ethics and preclearance workflows, archives the records your testing depends on, and surfaces what is due before it is late. When the annual review comes around, the evidence package and draft report assemble from a real audit trail instead of being reconstructed from memory. RegFin augments a CCO's judgment; it does not replace the review or the person accountable for it.
See how RegFin builds the evidence trail your annual review assumes. Book a demo.
Keep reading: RIA Compliance: The Complete Guide (our pillar overview) · The RIA Compliance Checklist · RIA Compliance Requirements · What Is RIA Compliance?.
This article is general information for compliance professionals, not legal or compliance advice. Rules change and firm facts differ, so verify every item against the linked primary sources (eCFR, SEC.gov) and consult qualified counsel for your firm's specific circumstances.
Frequently asked questions
Is a written annual compliance review required for RIAs?
How often must an RIA conduct a compliance review?
When is the RIA annual compliance review due?
What should an annual compliance review include?
Who is responsible for the RIA annual compliance review?
What is the difference between the annual review and a mock SEC exam?
Sources
- 17 CFR 275.206(4)-7 — Compliance procedures and practices — eCFR
- Compliance Programs of Investment Companies and Investment Advisers (Release No. IA-2204) — U.S. SEC
- Announcement Regarding Private Fund Advisers Rules (Fifth Circuit vacatur) — U.S. SEC
- 17 CFR 275.204-2 — Books and records to be maintained by investment advisers — eCFR
- 17 CFR 275.204-2(a)(17)(ii) — Records documenting the annual review — eCFR
- Examiner Oversight of "Annual" Reviews Conducted by Advisers and Funds — U.S. SEC
- 17 CFR 275.204A-1 — Investment adviser codes of ethics — eCFR
- 17 CFR 275.206(4)-1 — Investment adviser marketing — eCFR
- SEC Institutes Settled Order as to Arizona-Based Investment Adviser and Former CEO for Breaches of Fiduciary Duty — U.S. SEC