Home Features RIA Compliance Software Archiving iMessage Archiving Trade Monitoring Vendor Due Diligence Marketing Reviews Content Library Form ADV Forms & Tasks AI Consultant Reporting Documents For Consultants Pricing Blog About Sign in Request demo

The RIA Compliance Checklist (2026)

RegFin Team June 16, 2026 12 min read

An RIA compliance checklist is a structured list of an investment adviser's recurring regulatory obligations: compliance-program review, Code of Ethics reporting, books and records, Form ADV, marketing, custody, and cybersecurity. Each item is tied to the SEC rule and deadline that governs it. A working CCO uses it to track what's done, what's due, and where the documentation lives.

Below is the checklist we'd hand a new Chief Compliance Officer, grouped by area. It's written for an SEC-registered adviser under the Investment Advisers Act of 1940; state-registered advisers should map each item to their state's analog (most states mirror the federal framework). Treat it as a working document, not legal advice. Confirm specifics against your firm's facts and the primary sources linked throughout. The broader program these items sit within is mapped in our complete guide to RIA compliance.

Compliance program & annual review (Rule 206(4)-7)

Everything else on this checklist hangs from this rule. Rule 206(4)-7 requires every adviser registered or required to be registered with the SEC to adopt and implement written policies and procedures, designate a CCO, and review the program "no less frequently than annually."

  • [ ] Maintain written compliance policies and procedures reasonably designed to prevent violations of the Advisers Act. Make sure they describe what your firm actually does, not a generic template.
  • [ ] Conduct the annual compliance program review assessing the adequacy of your policies and how well they're actually being followed (Rule 206(4)-7(b)). Frequency: at least annually; many CCOs run interim reviews after material changes (new service line, M&A, a deficiency letter).
  • [ ] Write an annual review report (or memo) and retain it. A written record is no longer required by the rule text (the 2023 documentation amendment was vacated in 2024), but examiners commonly expect evidence that the review occurred, so it remains best practice and one of the first things they request.
  • [ ] Track and fix findings from the prior review; carry open items forward so they don't disappear.
  • [ ] Review and update the program when the business changes. Don't wait for the annual cycle if a material risk emerges.

CCO designation (Rule 206(4)-7(c))

  • [ ] Designate a Chief Compliance Officer who is a supervised person and is responsible for administering the compliance program (Rule 206(4)-7(c)).
  • [ ] Confirm the CCO has the authority, seniority, and resources to enforce the program. The SEC has repeatedly signaled, including in its framework for CCO liability, that the role must carry real authority, not just a title.
  • [ ] Document the CCO's responsibilities, reporting line, and any outsourced-CCO arrangements.

Code of Ethics & personal trading (Rule 204A-1)

Rule 204A-1 requires a written code of ethics setting a standard of business conduct and governing personal securities transactions by access persons. The reporting cadence is fixed, so calendar these.

  • [ ] Adopt and maintain a written Code of Ethics that includes a standard of business conduct and provisions for personal trading.
  • [ ] Identify and maintain a current list of access persons (and which employees are also "supervised persons").
  • [ ] Collect initial holdings reports from each access person no later than 10 days after the person becomes an access person, with information current as of a date no more than 45 days prior (Rule 204A-1(b)(1)).
  • [ ] Collect quarterly transaction reports no later than 30 days after the end of each calendar quarter (Rule 204A-1(b)(2)). Deadline: 30 days post quarter-end.
  • [ ] Collect annual holdings reports at least once each 12-month period, current as of a date no more than 45 days before submission (Rule 204A-1(b)(1)(ii)).
  • [ ] Require pre-approval (preclearance) before access persons acquire beneficial ownership in any IPO or limited offering (Rule 204A-1(c)).
  • [ ] Provide the Code to every supervised person, obtain a written acknowledgment of receipt, and refresh acknowledgments after amendments.
  • [ ] Apply the reportable securities exclusions correctly (e.g., direct obligations of the U.S. government, money-market funds, certain open-end fund shares). Over-collecting creates noise; under-collecting creates gaps.

Books & records (Rule 204-2)

Rule 204-2 is the recordkeeping rule. It enumerates what you must keep and for how long.

  • [ ] Maintain the required books and records (financials, order memoranda, client agreements, advertisements, communications, and more) listed in Rule 204-2(a).
  • [ ] Retention period: preserve records for at least five years from the end of the fiscal year in which the last entry was made, the first two years in an appropriate office of the adviser (Rule 204-2(e)(1)).
  • [ ] Preserve records in an easily accessible format; if maintained electronically, meet the rule's storage, indexing, and reproduction conditions.
  • [ ] Capture and archive electronic communications and off-channel messaging used for business (text, chat, social DMs). Off-channel communications have been a recurring SEC enforcement theme.
  • [ ] Retain records that support performance claims in advertisements (now tied to the Marketing Rule; see below).

Form ADV annual amendment + Form CRS

  • [ ] File the Form ADV annual updating amendment through IARD within 90 days after the end of your fiscal year (Rule 204-1). Deadline: 90 days post fiscal year-end.
  • [ ] File other-than-annual (interim) amendments promptly when required by the Form ADV instructions (e.g., certain Item 1 changes, disciplinary events).
  • [ ] If there are material changes to the brochure since the last annual updating amendment, deliver the updated brochure (Form ADV Part 2A), or a summary of material changes plus an offer to provide the full brochure, to each client within 120 days after fiscal year-end (Rule 204-3). Deadline: 120 days post fiscal year-end. (No annual delivery is required in years with no material changes.)
  • [ ] Deliver brochure supplements (Part 2B) for relevant supervised persons and keep them current.
  • [ ] Maintain and deliver Form CRS / Form ADV Part 3 (the relationship summary) to retail investors: before or at the time of entering into an advisory contract, within 30 days of a request, and communicate changes to existing retail clients within 60 days of an update (SEC Form CRS guide). (Applies to advisers with retail-investor clients.)

Marketing (Rule 206(4)-1)

The Marketing Rule governs advertisements and compensated testimonials/endorsements. Our SEC Marketing Rule guide walks through each of these conditions in depth.

  • [ ] Maintain policies for reviewing and approving advertisements against the rule's general prohibitions (no untrue or misleading statements; no unsubstantiated claims).
  • [ ] Ensure any performance advertising that shows gross performance also shows net performance with equal prominence and includes the required time periods.
  • [ ] For testimonials and endorsements, provide the required disclosures (client/non-client status, compensation, material conflicts), oversee compliance, check the disqualification provisions, and use written agreements where required. The written-agreement requirement has exceptions for certain affiliates and de minimis (≤ $1,000 over 12 months) compensation arrangements.
  • [ ] Substantiate factual claims and retain the supporting records. This ties back to Rule 204-2.
  • [ ] Confirm third-party ratings used in advertising meet the rule's conditions.

Custody (Rule 206(4)-2)

If your firm has custody of client assets, Rule 206(4)-2 adds significant obligations.

  • [ ] First, determine whether you have custody (e.g., direct fee deduction, trustee/POA authority, access to client funds). Many advisers have custody solely through fee deduction.
  • [ ] Maintain client funds and securities with a qualified custodian.
  • [ ] Ensure the custodian sends account statements to clients at least quarterly, and verify clients are actually receiving them.
  • [ ] Unless an exception applies, undergo an annual surprise examination by an independent public accountant; the accountant files Form ADV-E within 120 days of the exam.
  • [ ] Check whether the independent verification or audited-financials exceptions (e.g., audited pooled vehicles, fee-deduction-only relief) apply to your situation.

Cybersecurity / Reg S-P

The SEC's 2024 amendments to Regulation S-P (Release No. 34-100155) added incident-response and customer-notification obligations.

  • [ ] Maintain written policies to safeguard customer records and information (the longstanding safeguards and disposal rules).
  • [ ] Adopt an incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information (2024 Reg S-P amendments).
  • [ ] Implement customer notification procedures. Notify affected individuals whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, as soon as practicable, and not later than 30 days after becoming aware that the incident has occurred or is reasonably likely to have occurred. (Note: the incident-response program covers all customer information, but the notification obligation is triggered only when sensitive customer information is involved.)
  • [ ] Oversee service providers that receive customer information, with contractual safeguards and breach-notification expectations.
  • [ ] Confirm compliance with the compliance dates that are now in effect. Larger entities (advisers with $1.5 billion or more in AUM) were required to comply by December 3, 2025; smaller entities by June 3, 2026. Both deadlines have passed. If your firm has not yet implemented these requirements, treat this as an urgent gap.

Business continuity

For SEC-registered advisers, business continuity is generally treated as part of your reasonably designed policies and procedures under Rule 206(4)-7, not a separate standalone rule. Examiners still expect a workable plan.

  • [ ] Maintain a written business continuity and transition plan as part of your Rule 206(4)-7 compliance program, addressing operational disruptions, data recovery, key-person risk, and the orderly transition of client accounts if the firm winds down.
  • [ ] Test the plan periodically and update it after material changes (key-person, vendor, or location changes).
  • [ ] Address key-person and succession risk and document data backup and recovery procedures.

State notice filings

  • [ ] File and renew notice filings (and pay state fees) in every state where notice filing is required based on your client locations and assets.
  • [ ] Confirm investment adviser representative (IAR) registration and any IAR continuing education obligations in applicable states.
  • [ ] Track renewals through the IARD/CRD renewal program so registrations don't lapse at year-end.

Key annual deadlines

Obligation Rule Deadline / frequency
Form ADV annual updating amendment Rule 204-1 Within 90 days after fiscal year-end
Brochure (Part 2A) delivery to clients (if material changes) Rule 204-3 Within 120 days after fiscal year-end (only when material changes exist)
Compliance program review Rule 206(4)-7 No less frequently than annually
Code of Ethics: initial holdings report Rule 204A-1 Within 10 days of becoming an access person
Code of Ethics: quarterly transaction report Rule 204A-1 Within 30 days after each calendar quarter-end
Code of Ethics: annual holdings report Rule 204A-1 At least once each 12-month period
Custody: surprise exam & Form ADV-E Rule 206(4)-2 Annual exam; ADV-E filed within 120 days of exam
Books & records retention Rule 204-2 5 years (first 2 in an office of the adviser)
Reg S-P incident response program Release 34-100155 Larger entities 12/3/2025; smaller 6/3/2026 (both now in effect)
State notice filing renewals State law / IARD Annual (year-end renewal program)

Deadlines above are anchored to your firm's fiscal year-end unless otherwise noted. Verify each against the linked primary source and your specific facts.

Turning the checklist into a living program

A checklist is only as good as the system that runs it. The failure mode we see most often isn't ignorance of the rules. It's a quarterly transaction report that arrives on day 35, a brochure-delivery log nobody kept, or an annual review that got verbally "done" but never written up. When an examiner asks for evidence, "we do that" isn't an answer; the documentation is.

RegFin is built to close that gap. The platform tracks each obligation on this checklist against its rule and deadline, routes Code of Ethics and preclearance workflows, archives the records that back up your Marketing Rule and books-and-records duties, and surfaces what's due before it's late. The annual review writes itself from a real audit trail instead of from memory. If you're comparing platforms to run this checklist, our guide to evaluating AI compliance software lays out the tests to apply before you buy.

See how RegFin automates and tracks this checklist for your firm. Book a demo.

Prefer to work through this checklist as an interactive, saved-progress tool? Use our interactive RIA compliance checklist, which cites every item to the rules above and can be downloaded as a PDF. Running down your Regulation S-P obligations in more depth? Work through our interactive Reg S-P compliance checklist, a free tool that saves your progress in your browser and cites each item to 17 CFR Part 248.


Keep reading: RIA Compliance: The Complete Guide (our pillar overview) · What Is RIA Compliance? · RIA Compliance Requirements.

This article is general information for compliance professionals, not legal advice. Rules change and firm facts differ, so verify every item against the linked primary sources (eCFR, SEC.gov) and consult qualified counsel for your situation.

Frequently asked questions

What is an RIA compliance checklist?
It is a structured list of an investment adviser's recurring regulatory obligations (compliance program review, Code of Ethics reporting, books and records, Form ADV, marketing, custody, and cybersecurity), each tied to the SEC rule and deadline that governs it, so a CCO can track and document completion.
What are the most important RIA compliance deadlines?
The Form ADV annual updating amendment is due within 90 days after fiscal year-end (Rule 204-1). In years with material changes, the updated brochure (or summary of material changes) must reach clients within 120 days (Rule 204-3). Code of Ethics quarterly transaction reports are due within 30 days of quarter-end (Rule 204A-1).
Does every RIA need a written compliance program?
Yes. Rule 206(4)-7 under the Advisers Act requires every SEC-registered adviser to adopt and implement written policies and procedures, designate a Chief Compliance Officer, and review the program no less frequently than annually. Most state-registered advisers face equivalent state requirements.
How long must an RIA keep its books and records?
Under Rule 204-2(e), most required records must be preserved for at least five years from the end of the fiscal year in which the last entry was made, with the first two years kept in an appropriate office of the adviser.

Sources

  1. 17 CFR 275.206(4)-7 — Compliance procedures and practices — eCFR
  2. 17 CFR 275.204A-1 — Investment adviser codes of ethics — eCFR
  3. 17 CFR 275.204-2 — Books and records to be maintained by investment advisers — eCFR
  4. 17 CFR 275.204-1 — Amendments to Form ADV — eCFR
  5. 17 CFR 275.204-3 — Delivery of brochures and brochure supplements — eCFR
  6. 17 CFR 275.206(4)-1 — Investment adviser marketing — eCFR
  7. 17 CFR 275.206(4)-2 — Custody of funds or securities of clients by investment advisers — eCFR
  8. Form CRS Relationship Summary; Amendments to Form ADV — Small Entity Compliance Guide — U.S. SEC
  9. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information (Release No. 34-100155) — U.S. SEC
Share this article

Ready to simplify your compliance?

See what RegFin can do for your RIA's compliance program.