Home Features RIA Compliance Software Archiving iMessage Archiving Trade Monitoring Vendor Due Diligence Marketing Reviews Content Library Form ADV Forms & Tasks AI Consultant Reporting Documents For Consultants Pricing Blog About Sign in Request demo

RIA Compliance Requirements: What Firms Must Do

RegFin Team June 16, 2026 11 min read

For an SEC-registered investment adviser, the core compliance requirements generally include: maintain written compliance policies and procedures, review them at least annually, designate someone to administer them, adopt a Code of Ethics with personal-trading reporting, keep prescribed books and records, file and update Form ADV and Form CRS, and follow the Marketing, Custody, and privacy (Reg S-P) rules.

The phrase "RIA compliance requirements" can feel like a moving target, but most of it traces back to a handful of rules under the Investment Advisers Act of 1940. Below is a practical rundown of each obligation: what the rule actually says and what it means for the way your firm operates day to day. For the bigger picture, start with our pillar guide on RIA compliance, and if you're new to the topic see what RIA compliance is.

The requirements at a glance

Here are the rules that drive most of an adviser's compliance calendar:

Rule What it requires Frequency / deadline
Rule 206(4)-7 Written policies and procedures; annual review; designate a compliance officer Review at least annually
Rule 204A-1 Code of Ethics; personal-trading reports from access persons Holdings within 10 days of becoming an access person, then annually; transactions quarterly
Rule 204-2 Make and keep prescribed books and records Generally 5 years; first 2 years easily accessible
Form ADV (incl. Form CRS) Disclosure documents filed via IARD Annual updating amendment within 90 days of fiscal year-end; prompt amendments when materially inaccurate
Rule 206(4)-1 Marketing Rule governing advertisements Ongoing
Rule 206(4)-2 Custody Rule safeguards for client assets Ongoing; annual surprise exam if applicable
Regulation S-P Privacy notices, a written incident-response program, and service-provider oversight Ongoing; notify affected individuals within 30 days

Each is unpacked below. Citations point to the exact section in the eCFR.

What does Rule 206(4)-7 require?

Rule 206(4)-7 is the foundation. It makes it unlawful for a registered adviser to provide advice unless it (a) adopts and implements written policies and procedures reasonably designed to prevent violations of the Act, (b) reviews their adequacy and the effectiveness of their implementation no less frequently than annually, and (c) designates an individual responsible for administering them (17 CFR 275.206(4)-7).

In practice, this is your compliance manual. It should be tailored to your firm's actual business and conflicts. A generic, off-the-shelf template is a common examination finding. The policies have to address the areas where you face real risk: portfolio management, trading, disclosure, custody, marketing, recordkeeping, privacy, and business continuity, among others.

Who has to be the Chief Compliance Officer?

Rule 206(4)-7(c) requires you to designate a supervised person responsible for administering your policies and procedures, the role almost everyone calls the Chief Compliance Officer (CCO). The rule does not require a separate hire; at a small firm, the owner or principal frequently wears the CCO hat, though a firm can also bring in an RIA compliance consultant or an outsourced CCO to carry the role. What matters is that the person is competent, knowledgeable about the Advisers Act, and empowered with the authority and resources to enforce the program.

The annual review under 206(4)-7(b) belongs to this person. A 2023 amendment would have required every adviser to document the annual review in writing, but the Fifth Circuit vacated that amendment in June 2024 along with the broader Private Fund Adviser Rules. The current rule text does not mandate written documentation. That said, the SEC's Division of Examinations has long expected advisers to be able to demonstrate that a review actually occurred, and a written memo or report memorializing the review remains a strong examination and risk-management practice (17 CFR 275.206(4)-7).

What goes in a Code of Ethics? (Rule 204A-1)

Rule 204A-1 requires every registered adviser to adopt a written Code of Ethics that sets a standard of business conduct, requires compliance with the federal securities laws, and requires access persons to report their personal securities holdings and transactions (17 CFR 275.204A-1).

The reporting deadlines are specific. Worth committing to memory:

  • Initial holdings report: within 10 days of becoming an access person, with information current as of a date no more than 45 days prior.
  • Annual holdings report: at least once every 12-month period, current as of a date no more than 45 days prior to submission.
  • Quarterly transaction reports: submitted to the CCO covering each calendar quarter. The report can be satisfied by broker confirmations or statements the adviser already holds, provided those are received no later than 30 days after quarter-end.

Defining who counts as an "access person," collecting these reports on time, and reviewing them for conflicts (front-running, undisclosed holdings) is one of the more administratively demanding obligations, and a frequent source of exam deficiencies. It is also exactly the kind of recurring, deadline-driven work that compliance software is built to track.

What records must an RIA keep? (Rule 204-2)

Rule 204-2 requires advisers to make and keep true, accurate, and current books and records relating to the advisory business. The list is long: financial journals and ledgers, order memoranda, advisory contracts, written communications relating to recommendations and advice, advertising records, and copies of all compliance policies and procedures, among others (17 CFR 275.204-2).

The default retention period is five years from the end of the fiscal year during which the last entry was made, with the first two years kept in an easily accessible place at an appropriate office of the adviser. Records of access persons and approvals of their securities acquisitions must also be kept for five years, and copies of policies and procedures in effect within the last five years must be retained. Certain corporate and formation records carry longer retention. If you store records electronically, you must be able to produce them promptly and protect them against alteration or loss, an obligation that increasingly sweeps in email and off-channel communications. Our RIA compliance checklist breaks the recordkeeping categories into a working list.

What are the Form ADV and Form CRS requirements?

Form ADV is your primary registration and disclosure document, filed electronically through the IARD system. Part 1 captures structured data about the firm; Part 2 (the "brochure") is the plain-English narrative delivered to clients; and Part 3, the Form CRS relationship summary, is the short client-facing document required of advisers that serve retail investors.

You must file an annual updating amendment within 90 days of your fiscal year-end. Beyond that, you must amend Form ADV promptly whenever certain information becomes materially inaccurate. You cannot wait for the annual cycle to fix a material change. Because the annual amendment is also the moment many advisers reassess their registration eligibility, it tends to anchor the entire compliance calendar.

What is the Marketing Rule? (Rule 206(4)-1)

Rule 206(4)-1, the modernized Marketing Rule, governs adviser advertisements and replaced the old advertising and cash-solicitation rules. It prohibits a set of misleading practices (untrue statements, unsubstantiated claims, misleading presentations of performance, and similar conduct) and sets conditions for using testimonials and endorsements (17 CFR 275.206(4)-1).

Per the SEC's own compliance guide, an advertisement may not include a testimonial or endorsement unless the adviser provides clear and prominent disclosures (including whether the promoter is a client and whether they are compensated), oversees compliance, and enters a written agreement with the promoter. The written-agreement requirement has exceptions for certain affiliates and for promoters receiving de minimis compensation of $1,000 or less over the prior 12 months, but the disclosure and oversight conditions still apply. The adviser also may not compensate a promoter it knows is subject to certain disqualifying events within the prior 10 years (SEC, Investment Adviser Marketing). If you show performance, the substantiation and presentation requirements are detailed. Build a review-and-approval workflow before anything goes out the door. The full set of conditions, and what examiners are currently citing, is in our SEC Marketing Rule guide.

What does the Custody Rule require? (Rule 206(4)-2)

If your firm has custody of client funds or securities (which can include something as simple as the authority to deduct advisory fees, or acting as trustee), Rule 206(4)-2 imposes safeguards. Client assets generally must be held by a qualified custodian; clients must receive account statements at least quarterly; and, where applicable, the adviser must arrange an annual surprise examination by an independent public accountant (SEC, Custody Rule Small Entity Compliance Guide).

A common relief applies. If the qualified custodian sends account statements directly to clients, the adviser may be relieved of sending its own statements, and certain fee-deduction-only arrangements have tailored treatment. Determining whether you have custody at all is the first step, and the most commonly misjudged one, so document your analysis. Note: the SEC proposed a broader "safeguarding" rule in 2023 that would have replaced Rule 206(4)-2, but it was withdrawn; the current custody rule remains in effect.

What are the cybersecurity and privacy requirements (Reg S-P)?

Regulation S-P has long required advisers to deliver privacy notices and adopt written safeguard policies for customer records. The SEC's 2024 amendments raised the bar. Covered advisers must maintain a written incident-response program to detect, respond to, and recover from unauthorized access to customer information, and must notify affected individuals as soon as practicable, and no later than 30 days, after becoming aware that an incident has occurred or is reasonably likely to have occurred (SEC Press Release 2024-58).

The amendments carry tiered compliance dates: larger entities by December 3, 2025, and smaller entities by June 3, 2026. Both dates have now passed. Every covered adviser should have an incident-response program and breach-notification process in place. A separate proposed cybersecurity risk-management rule for advisers and funds was withdrawn by the SEC in June 2025 along with the safeguarding rule; Reg S-P remains the governing framework for incident response and breach notification.

SEC vs. state: which rules apply to your firm?

Not every adviser answers to the SEC. Jurisdiction turns largely on regulatory assets under management (RAUM):

  • $110 million or more in RAUM: you generally must register with the SEC. If your annual updating amendment shows RAUM at or above $110 million, you must apply for SEC registration within 90 days of filing it.
  • $100 million to $110 million: a discretionary "buffer" band where you may register with the SEC.
  • $25 million to $100 million (mid-sized advisers): generally regulated by your home state, unless an exception applies (for example, the state doesn't examine advisers).
  • An SEC-registered adviser may remain registered while RAUM stays at $90 million or more (17 CFR 275.203A-1).

State-registered advisers primarily follow their state's registration and compliance rules, many of which are modeled on NASAA frameworks, while federal anti-fraud principles may still apply. Net-worth or bonding requirements, recordkeeping, and the Code of Ethics expectations can differ by state. The throughline, regardless of regulator, is the fiduciary duty of care and loyalty you owe every client.

Bringing it together

These obligations are interlocking: the compliance manual (206(4)-7) documents how you'll satisfy the others; the Code of Ethics (204A-1) and Marketing Rule (206(4)-1) generate records that 204-2 requires you to keep; and Form ADV discloses much of it to clients and regulators. Managing them as a connected calendar, not a stack of one-off tasks, is what separates a defensible program from a reactive one.

A defensible program is not just a list of obligations. It is a calendar, an evidence trail, and a review process that keeps each requirement connected to the others. That is the problem RegFin was built to solve: annual reviews, personal-trading reports, recordkeeping retention, filing deadlines, marketing approvals, and incident-response obligations tracked in one place, so your CCO spends time on judgment, not chasing forms. Book a demo →

This article is for general informational purposes and is not legal or compliance advice. Confirm every requirement against the current regulation and consult qualified counsel for your firm's specific circumstances.

Frequently asked questions

What are the main RIA compliance requirements?
Written policies and procedures, an annual compliance review, a designated compliance officer, a Code of Ethics with personal-trading reporting, books and records, accurate Form ADV and Form CRS filings, compliance with the Marketing and Custody rules, and a written cybersecurity/incident-response program under Reg S-P.
Does every RIA need a Chief Compliance Officer?
Rule 206(4)-7 requires every SEC-registered adviser to designate an individual (commonly titled Chief Compliance Officer) responsible for administering its compliance policies and procedures. Most state rules impose an equivalent requirement. The role can be held by an existing employee.
How long must an RIA keep its books and records?
Rule 204-2 generally requires records to be preserved for at least five years from the end of the relevant fiscal year, with the first two years kept in an easily accessible place at an appropriate office of the adviser. Some records, such as formation documents, must be kept longer.
Are RIAs regulated by the SEC or the states?
It depends on regulatory assets under management. Advisers with $110 million or more generally must register with the SEC; mid-sized advisers between $25 million and $100 million generally register with the states. The core fiduciary duty applies either way.

Sources

  1. 17 CFR 275.206(4)-7 — Compliance procedures and practices — eCFR
  2. 17 CFR 275.204A-1 — Investment adviser codes of ethics — eCFR
  3. 17 CFR 275.204-2 — Books and records to be maintained by investment advisers — eCFR
  4. 17 CFR 275.206(4)-1 — Investment adviser marketing — eCFR
  5. Investment Adviser Marketing — Small Entity Compliance Guide — U.S. SEC
  6. Custody of Funds or Securities of Clients by Investment Advisers — Small Entity Compliance Guide — U.S. SEC
  7. 17 CFR 275.203A-1 — Eligibility for SEC registration; switching to or from SEC registration — eCFR
  8. SEC Adopts Rule Amendments to Regulation S-P (Press Release 2024-58) — U.S. SEC
Share this article

Ready to simplify your compliance?

See what RegFin can do for your RIA's compliance program.