Home Features RIA Compliance Software Archiving iMessage Archiving Trade Monitoring Vendor Due Diligence Marketing Reviews Content Library Form ADV Forms & Tasks AI Consultant Reporting Documents For Consultants Pricing Blog About Sign in Request demo

RIA Compliance: A Complete Guide for 2026

RegFin Team June 16, 2026 20 min read

RIA compliance is the system of written policies, controls, and recordkeeping a registered investment adviser (RIA) uses to meet its fiduciary duty and comply with the Investment Advisers Act of 1940 and the rules of the SEC or its state regulator. It comes down to three things: a written compliance program, an annual review, and a designated Chief Compliance Officer.

If you run compliance at an advisory firm, you already know the rules are not the hard part. Operating them every day, and proving you did, is. This guide walks the full landscape a Chief Compliance Officer (CCO) is accountable for, links each obligation to its primary source, and points to where software and AI now carry real weight. It is written for the person who actually answers the examiner's questions.

A note before the details. This is educational, not legal or compliance advice. The rules below are SEC rules that bind SEC-registered advisers. State-registered firms answer to their home-state securities act and the NASAA model rules, which usually mirror the SEC's requirements but are not identical, so confirm each item against your state's version rather than assuming the federal rule applies.

What is RIA compliance?

RIA compliance is the ongoing practice of keeping a registered investment adviser within the law that governs it: the Investment Advisers Act of 1940, the rules the SEC has adopted under it, and the parallel state securities acts. It is the operational expression of one underlying obligation: the adviser's fiduciary duty to act in the best interest of its clients.

Unlike broker-dealers, who answer primarily to FINRA, RIAs are fiduciaries. That single distinction shapes everything: disclosure has to be full and fair, conflicts must be eliminated or clearly disclosed and managed, and the firm has to be able to demonstrate, on demand, that its conduct matched its disclosures.

In practice, "compliance" is not a document. It is a program: policies, the people who run them, the controls that enforce them, and the records that prove all three were working. For a deeper primer, see What is RIA compliance?.

What changed for RIA compliance in 2026?

A handful of recent shifts are why the "2026" in the title matters. If your program was calibrated to older guidance, start by checking these:

  • Regulation S-P is now live for smaller SEC-registered advisers. The 2024 amendments added a written incident-response program and a 30-day breach-notification duty. They took effect December 3, 2025 for larger covered entities and June 3, 2026 for smaller ones, so by mid-2026 they apply to covered SEC-registered advisers of all sizes. (State-registered advisers generally look to state privacy requirements and, where applicable, the FTC's GLBA safeguards.) (SEC Press Release 2024-58)
  • The custody "safeguarding" overhaul is off the table. The SEC withdrew its 2023 Safeguarding proposal in June 2025, so the existing Custody Rule (206(4)-2) remains the operative rule.
  • The mandatory written annual review was vacated. A 2023 amendment that would have required the Rule 206(4)-7 annual review to be documented in writing was struck down by the Fifth Circuit in 2024. Written documentation is no longer required by rule text, though examiners still expect a written record (see below).
  • The Marketing Rule is a mature enforcement area. In force since November 4, 2022, it is well past its transition period; testimonial disclosures, performance substantiation, and the supporting records are now active exam targets.

Each of these is covered in context below.

The foundational statute is the Investment Advisers Act of 1940. It defines who is an "investment adviser," establishes the fiduciary standard, and authorizes the SEC to write the detailed rules (found in Title 17, Part 275 of the Code of Federal Regulations) that fill in the day-to-day obligations.

A few structural points matter for a CCO:

  • The Act's antifraud provisions (Section 206) apply to every adviser, whether SEC-registered, state-registered, or exempt. You do not escape the fiduciary standard by staying small.
  • Most of the operational rules a CCO lives by (the compliance program rule, the marketing rule, the code of ethics rule, the recordkeeping rule) are SEC rules adopted under the Act, each carrying a 206(4), 204A, or 204 citation.
  • State-registered advisers are governed by their state securities act and the model rules of the North American Securities Administrators Association (NASAA), which closely track the federal rules but are not identical. Always check your home state.

What is the Compliance Program Rule 206(4)-7?

Rule 206(4)-7, the "Compliance Rule," is the spine of every adviser's program. It requires each registered adviser to do three things: (1) adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act; (2) review those policies at least annually for adequacy and effectiveness; and (3) designate a Chief Compliance Officer to administer them. (17 CFR § 275.206(4)-7)

This is the rule examiners build their visit around, so each piece matters.

Written policies and procedures. They must be reasonably designed and, above all, tailored to your firm. In the 2003 adopting release, the SEC was explicit that an adviser cannot satisfy the rule with a generic, off-the-shelf manual; the policies have to reflect the firm's actual conflicts, business lines, and operations. (SEC adopting release) A 60-page manual describing a business you do not run is worse than useless. It is evidence against you.

The annual review. At least once a year, the adviser must review whether its policies are adequate and whether they are actually being followed. The review should account for compliance issues that arose during the year, changes in the firm's business, and changes in the law. In 2023 the SEC adopted an amendment that would have required the annual review to be documented in writing, but the U.S. Court of Appeals for the Fifth Circuit vacated that amendment in June 2024 as part of its ruling in National Association of Private Fund Managers v. SEC. The rule text has reverted: written documentation is not formally required. In practice, however, SEC examiners continue to expect advisers to maintain a written record of the annual review, and an undocumented review may be treated by examiners as though it never happened.

The designated CCO. More on the role below, but note the rule does not let you appoint a name on paper. The SEC expects the CCO to have real competence, authority, and independence.

What does a Chief Compliance Officer do?

The CCO administers the compliance program: they own the written policies, run the annual review, train staff, monitor for violations, and serve as the firm's primary point of contact with regulators. In a small RIA, the CCO is frequently also the owner or an investment adviser representative wearing a second hat.

The SEC's expectation, stated in the adopting release, is that the CCO be "competent and knowledgeable regarding the Advisers Act" and "empowered with full responsibility and authority to develop and enforce appropriate policies and procedures." Read plainly, that means three things:

  • Competence: a working command of the rules and of how the firm actually operates.
  • Authority: the standing to change behavior, not merely document it, including access to senior management.
  • Independence: enough distance from the revenue side to flag problems without being overruled by the people who created them.

During an SEC exam, the CCO is typically the person asked to produce the compliance manual, the most recent annual review, the code of ethics and personal trading records, the marketing files, and the books and records, and to explain, on the spot, how each control works in practice. Day to day, the role is less about writing policy and more about evidence: can you show the work was done?

Many smaller firms address the bandwidth problem by using an outsourced or co-sourced CCO, or increasingly by using RIA compliance software to carry the monitoring and recordkeeping load so a single in-house CCO can actually keep up.

Should an RIA register with the SEC or the state?

It depends primarily on regulatory assets under management (RAUM). Advisers with $100 million or more in RAUM generally register with the SEC; advisers below that register with the state securities regulator in each state where they have a place of business or enough clients to trigger registration. The thresholds were reshaped by the Dodd-Frank Act in 2010-2011.

The "mid-sized adviser" band, roughly $25 million to $100 million in RAUM, generally registers with the states, not the SEC, unless an exception applies (for example, the adviser is not subject to examination by its home-state regulator, or it would have to register in 15 or more states). There are also buffers so firms are not forced to switch the moment they cross a line.

Factor State registration SEC registration
Typical RAUM Under $100M (mid-sized advisers $25M–$100M generally register with states) $100M or more (must register at $110M; need not withdraw until below $90M)
Primary regulator State securities administrator(s) U.S. Securities and Exchange Commission
Governing rules State securities act + NASAA model rules Investment Advisers Act + SEC rules (17 CFR Part 275)
Multi-state burden Register in each state where required Single federal registration covers all states
Where eligibility is declared Form ADV, Item 2 Form ADV, Item 2

The numeric buffers above (register at $110M; withdraw below $90M) come from the SEC's Dodd-Frank implementing rules. An adviser may voluntarily register at $100M, must register at $110M, and need not withdraw until it falls below $90M.

Two practical notes. First, the exact rules for when and whether you must register, including de minimis client counts, vary by state, so a multi-state firm near the line should map every state individually. Second, eligibility is reported and updated on Form ADV, Item 2, which is the bridge to the next section.

What are Form ADV and Form CRS?

Form ADV is the uniform registration and disclosure form every RIA files. Form CRS (Form ADV Part 3) is a short, plain-English relationship summary that retail-facing advisers must deliver to clients. Together they are the public, regulator-facing face of the firm.

Form ADV has distinct parts, and a CCO should keep all of them current and consistent:

  • Part 1A: the check-the-box regulatory data (assets, employees, disciplinary history, custody, affiliations) filed electronically through the IARD system. This is the part regulators query against.
  • Part 2A: the "brochure," a narrative, plain-English disclosure of the firm's services, fees, conflicts, and disciplinary history, delivered to clients.
  • Part 2B: the "brochure supplement," covering the individuals who provide advice.
  • Part 3 / Form CRS: a relationship summary of no more than two pages (four pages for dual registrants) for retail investors, covering required headings on the relationship, fees, conflicts, standard of conduct, and disciplinary history.

Form ADV is not file-and-forget. Advisers must file an annual updating amendment within 90 days of fiscal year-end, and file other-than-annual amendments promptly when certain information becomes materially inaccurate. The recurring exam finding here is simple and avoidable. The brochure says one thing, the firm does another. Keeping Form ADV synchronized with actual practice is a core compliance control, not an administrative chore.

What is the Marketing Rule 206(4)-1?

The Marketing Rule, Rule 206(4)-1, has been in force since the November 4, 2022 compliance date and governs how RIAs advertise. It replaced the decades-old advertising and cash-solicitation rules with a single, principles-based framework and specific conditions for testimonials, endorsements, third-party ratings, and performance figures. (17 CFR § 275.206(4)-1; SEC small-entity compliance guide)

What changed, and what a CCO has to police:

  • A broad definition of "advertisement." It captures most communications to more than one person (and certain one-on-one communications) that offer the adviser's services, plus most compensated testimonials and endorsements.
  • General prohibitions. No untrue or misleading statements, no unsubstantiated claims, no cherry-picked or one-sided presentations, no material omissions.
  • Testimonials and endorsements are now permitted, but only with clear and prominent disclosure of (a) whether the speaker is a client, (b) whether they were compensated, and (c) any material conflicts of interest, plus a written agreement and oversight where compensation is involved.
  • Performance advertising carries detailed conditions, including showing net-of-fees performance alongside gross, and presenting prescribed time periods.

The Marketing Rule has been an active enforcement area since the transition period ended, so testimonial disclosures, performance substantiation, and the supporting recordkeeping deserve close, ongoing review. Our SEC Marketing Rule guide walks through the testimonial, performance, and third-party-rating conditions in depth. For the full requirements list a CCO should track, see RIA compliance requirements.

What is the Code of Ethics and personal trading rule (204A-1)?

Rule 204A-1 requires every SEC-registered adviser to adopt a written code of ethics that sets a standard of business conduct, requires compliance with the federal securities laws, and, most importantly for day-to-day operations, requires the firm's access persons to report their personal securities holdings and transactions. (17 CFR § 275.204A-1)

The mechanics a CCO administers:

  • Access persons are supervised persons who have access to nonpublic information about client transactions or holdings, or who are involved in making recommendations. At many small advisers, that is effectively everyone.
  • Initial and annual holdings reports. Each access person reports their securities holdings when they join and at least once a year, current within a defined window.
  • Quarterly transaction reports. Access persons report personal securities transactions each quarter, due no later than 30 days after quarter-end.
  • Code acknowledgments. Supervised persons must acknowledge in writing that they received the code and any amendments.

Personal trading surveillance (reconciling broker statements against reported transactions, screening for front-running or conflicts, and managing any preclearance and restricted-list process) is one of the most labor-intensive parts of the role, and one of the most natural fits for automation.

The evidence standard is the same here as everywhere else. If an access person reports a quarterly transaction late, a strong process preserves the report, the exception it triggered, the CCO's review, and how it was resolved, not just the final attestation. That trail is what turns a late filing into a documented, handled exception rather than an exam finding.

What are the books and records requirements (Rule 204-2)?

Rule 204-2, the "Books and Records Rule," specifies the records an adviser must make and keep and how long to keep them. The default retention is not less than five years from the end of the fiscal year during which the last entry was made on such record, with the first two years in an appropriate office of the investment adviser. (17 CFR § 275.204-2)

The required records are extensive, but the categories a CCO is asked for most often are:

  • Financial and accounting records (journals, ledgers, trial balances).
  • Order memoranda and records of advisory transactions.
  • Advertising and performance records, including the substantiation for performance claims and the materials supporting testimonials and endorsements (tightened by the Marketing Rule amendments).
  • Code of ethics records: the code itself, acknowledgments, personal trading reports, and any violations and their disposition.
  • Client agreements, written communications sent and received, and the compliance policies and the annual review documentation.

The exam-day failure here is rarely "we destroyed records." It is "we cannot find them quickly, in a complete and reliable form." Electronic recordkeeping, including capturing off-channel communications (text, chat, social), is where many firms are exposed today. Regulators have pursued advisers and broker-dealers aggressively for unpreserved business communications on personal devices.

What are the custody requirements for RIAs?

Custody means having access to, or authority over, client cash or securities, and it triggers heightened safeguards under the Custody Rule (Rule 206(4)-2). Many advisers assume they do not have custody and are wrong. Deducting fees directly from client accounts, serving as trustee, or holding client login credentials can all constitute custody.

Where an adviser has custody, the rule generally requires client assets to be held with a qualified custodian, clients to receive account statements from that custodian, and, depending on the form of custody, an annual surprise examination by an independent accountant. The single most common custody pitfall is failing to recognize that an arrangement (standing letters of authorization, for instance) created custody in the first place.

Note: In February 2023 the SEC proposed a broader "Safeguarding Advisory Client Assets" rule that would have replaced Rule 206(4)-2. The SEC withdrew that proposal in June 2025. Rule 206(4)-2 remains the operative custody rule.

What does Reg S-P and cybersecurity require?

Regulation S-P governs how advisers protect and handle nonpublic personal information about clients. In May 2024 the SEC adopted amendments that, for the first time, require advisers to maintain a written incident response program and to notify affected individuals of a data breach involving their sensitive information, generally as soon as practicable, and no later than 30 days after the firm becomes aware that the information was, or is reasonably likely to have been, accessed without authorization. (SEC Press Release 2024-58)

For a CCO, the amended Reg S-P now means maintaining:

  • A written incident response program covering assessment, containment, and client notification.
  • A breach-notification process built to meet the 30-day clock.
  • Service-provider oversight: diligence and controls to ensure third parties that receive client information protect it.
  • Expanded recordkeeping to evidence the above.

The compliance dates were staggered by firm size: December 3, 2025 for larger entities (investment advisers with $1.5 billion or more in AUM; fund complexes with $1 billion or more in net assets) and June 3, 2026 for smaller entities. By mid-2026 these obligations are live for nearly all advisers. Beyond Reg S-P, cybersecurity broadly (access controls, vendor risk, business continuity) is a standing exam priority even where no single rule prescribes every control.

What happens during an SEC examination?

An SEC examination is a review, usually conducted by the Division of Examinations, of whether an adviser is doing what its disclosures and the rules require. Most begin with a document request letter, proceed through interviews (the CCO is central), and end with a closing call and, frequently, a deficiency letter listing findings the firm must address.

What examiners reliably ask to see maps directly to the rules above:

  • The current compliance manual and the most recent written annual review.
  • Form ADV (all parts) and Form CRS, tested against actual practice.
  • Code of ethics records and personal trading reports.
  • Marketing/advertising files and performance substantiation.
  • Books and records, including electronic communications.
  • Evidence of custody safeguards and Reg S-P controls.

The through-line is evidence. Examiners want proof the policy operated, not just confirmation that you have one. A firm with modest but faithfully-followed procedures and clean records fares far better than one with an elaborate manual and nothing to show it was used.

For example, an examiner asks for every testimonial the firm used in the last twelve months. A firm with a real process produces, for each one, the advertisement itself, the disclosures shown, the substantiation, the written compensation agreement, and the supervisory sign-off, as a single package. A firm without one spends the next two weeks reconstructing what it should have kept all along, and the gaps become the deficiency.

That kind of evidence trail is exactly what modern compliance software should preserve automatically, so the package is one export away instead of a two-week scramble.

What are the most common RIA compliance pitfalls?

The recurring deficiencies are strikingly consistent year to year, and almost all are about operation, not knowledge:

  • The off-the-shelf manual. Generic policies the firm never tailored and never actually followed. This is the original sin Rule 206(4)-7 was written to prevent.
  • The skipped or undocumented annual review. It happened in someone's head, or not at all, and there is no written record.
  • Stale Form ADV. Fees, services, or conflicts changed; the brochure and Form CRS did not.
  • Marketing Rule missteps. Testimonials without required disclosures, unsubstantiated performance, cherry-picked results.
  • Personal trading gaps. Late or missing access-person reports; no real reconciliation against broker statements.
  • Off-channel communications. Business conducted by text or chat on personal devices, never captured or retained.
  • Unrecognized custody. Fee deduction or standing authorizations that created custody obligations the firm never met.

Notice the pattern: the firm usually knows the rule. What breaks is the day-to-day discipline of doing the work and keeping the proof. Our RIA compliance checklist turns this list into a working set of controls. Nearly every item on that list is a step that was missed or never written down, which is what a system of recurring tasks and attestations is built to prevent. RegFin forces each review, update, and sign-off onto a schedule and captures the record when it happens, so the gap closes before an examiner finds it.

How do software and AI help with RIA compliance?

Compliance software and, increasingly, AI reduce the gap between having a program and operating one by automating the monitoring, recordkeeping, and review tasks that overwhelm a small compliance team. The rules still require human judgment. Technology removes the manual drudgery and the silent failures.

Concretely, modern tooling helps a CCO:

  • Maintain a living manual and the annual review. Versioned policies, a documented review workflow, and an audit trail of who changed what and when.
  • Automate personal trading surveillance. Ingest broker feeds, reconcile against reported transactions, and flag conflicts and preclearance breaches.
  • Capture and retain communications, including off-channel messages, mapped to Rule 204-2 retention requirements.
  • Review marketing materials against Marketing Rule conditions before they go out.
  • Keep Form ADV and Form CRS synchronized with the firm's actual practices and flag amendment triggers.
  • Track service-provider due diligence and access-person attestations. These are the vendor-oversight records Reg S-P now expects and the code-of-ethics acknowledgments Rule 204A-1 requires.
  • Stay exam-ready. Produce the document set examiners request, with evidence that controls operated, on demand.

Software does not replace the CCO's judgment, but it can make the evidence trail much harder to miss. That is where it changes the economics. A small compliance team can maintain the kind of evidence trail that used to take far more manual work. Not every tool that claims this delivers it, so our guide to evaluating AI compliance software lays out the tests that separate a useful tool from a demo. RegFin's AI compliance consultant lets a CCO ask plain-English questions grounded in current regulations and the firm's own records, surfaces what needs attention, and keeps the evidentiary trail an examiner will ask for. Book a demo →


This guide is for general educational purposes and is not legal or compliance advice. Verify all requirements against current SEC, state, and NASAA rules and consult qualified counsel for your firm's specific situation.

Frequently asked questions

What is RIA compliance?
RIA compliance is the system of written policies, controls, and recordkeeping a registered investment adviser uses to meet its fiduciary duty and comply with the Investment Advisers Act of 1940 and SEC or state rules. It centers on a written compliance program, an annual review, and a designated Chief Compliance Officer.
Does an RIA register with the SEC or the state?
SEC registration is mandatory at $110 million or more in regulatory assets under management and optional starting at $100 million. Below that, advisers register with the states where they do business. Mid-sized advisers ($25M–$100M) usually register at the state level, with specific buffers and exceptions in the rules.
Is a Chief Compliance Officer required for an RIA?
Yes. SEC Rule 206(4)-7 requires every SEC-registered adviser to designate a Chief Compliance Officer to administer its compliance policies and procedures. The CCO should have the competence, authority, and independence to make the program effective. Most state rules impose a parallel requirement.
How often must an RIA review its compliance program?
At least annually. Rule 206(4)-7 requires advisers to review the adequacy and effectiveness of their policies and procedures no less frequently than once a year. A 2023 amendment that would have required written documentation was vacated by the Fifth Circuit in 2024, but SEC examiners continue to expect a written record of the review in practice.

Sources

  1. 17 CFR § 275.206(4)-7 — Compliance procedures and practices — eCFR
  2. Compliance Programs of Investment Companies and Investment Advisers (Adopting Release) — U.S. SEC
  3. 17 CFR § 275.206(4)-1 — Investment adviser marketing — eCFR
  4. 17 CFR § 275.204A-1 — Investment adviser codes of ethics — eCFR
  5. 17 CFR § 275.204-2 — Books and records to be maintained by investment advisers — eCFR
  6. SEC Adopts Rule Amendments to Regulation S-P (Press Release 2024-58) — U.S. SEC
  7. Investment Adviser Marketing — Small Entity Compliance Guide — U.S. SEC
Share this article

Ready to simplify your compliance?

See what RegFin can do for your RIA's compliance program.