If you run or advise a registered investment adviser (RIA), "compliance" is the word that shows up in almost every exam letter, annual review, and regulator conversation. But what does RIA compliance actually mean, and what does it require? Here is the plain-English version.
RIA compliance is how a registered investment adviser meets its legal and fiduciary obligations under the Investment Advisers Act of 1940 and the rules of its regulator, whether that is the U.S. Securities and Exchange Commission (SEC) or a state securities authority. In practice, it means adopting written policies and procedures, following them, keeping records that prove you followed them, and reviewing the whole program at least once a year.
This primer defines the term and walks through who must comply, what the law requires, and what a compliance program contains. It focuses mainly on the SEC framework; state-registered advisers should confirm the parallel requirements under their state's rules, which usually mirror the SEC's but are not always identical. For the full treatment, see our pillar guide, RIA Compliance: The Complete Guide.
What is RIA compliance?
RIA compliance is the ongoing process by which a registered investment adviser demonstrates that it is meeting its duties as a fiduciary and following the federal and state securities laws that govern investment advice. It is both a legal obligation and a day-to-day operating discipline.
An investment adviser is, under Section 202(a)(11) of the Investment Advisers Act of 1940, "any person who, for compensation, engages in the business of advising others … as to the value of securities or as to the advisability of investing in, purchasing, or selling securities." When that person or firm registers with a regulator, it becomes a registered investment adviser (an RIA), and its conduct becomes subject to a defined body of rules. Compliance is how the firm puts those rules into practice.
Because an adviser is a fiduciary, it must act in its clients' best interests, disclose conflicts of interest, and avoid misleading them. RIA compliance is the system that makes those duties real: the written procedures, the supervision, the recordkeeping, and the annual review that together show a regulator the firm is doing what the law requires.
Who has to comply (SEC vs. state-registered advisers)?
Every registered investment adviser must comply. But who you answer to depends mainly on how much money you manage. Larger advisers register with and are examined by the SEC; smaller advisers register with their state securities regulator.
The dividing line comes from Section 203A of the Advisers Act and Rule 275.203A-1. In general:
- SEC-registered advisers: generally those with $110 million or more in regulatory assets under management (RAUM). Advisers with RAUM between $100 million and $110 million may, but are not required to, register with the SEC. Once SEC-registered, an adviser need not withdraw its registration until RAUM falls below $90 million.
- State-registered advisers: generally those below $100 million, who register with the securities regulator in the state(s) where they do business. "Mid-sized advisers" (RAUM between $25 million and $100 million) typically register with their state unless that state does not require it or does not examine advisers, in which case they register with the SEC.
Many state requirements are influenced by the North American Securities Administrators Association (NASAA) model rules, though each state adopts and enforces its own. The substance of a compliance program is similar at both levels, but the regulator, the registration mechanics, and some specific rules differ. Confirm your firm's status before building your program.
What does the Investment Advisers Act of 1940 require?
The Investment Advisers Act of 1940 is the federal statute that defines who is an investment adviser, requires registration (subject to exemptions), and imposes the core fiduciary and anti-fraud duties RIA compliance is built around.
The Act's central obligation is the fiduciary duty an adviser owes its clients: a duty of care and a duty of loyalty. Flowing from that are concrete rules, including the duty to make full and fair disclosure of material conflicts of interest (largely through Form ADV), restrictions on advertising and marketing, requirements to keep specified books and records, and rules governing custody of client assets. The SEC has adopted these as rules under Part 275 of Title 17 of the Code of Federal Regulations.
The Act also makes it unlawful for an adviser to "engage in any act, practice, or course of business which is fraudulent, deceptive, or manipulative." That anti-fraud authority is the legal hook for the Compliance Program Rule discussed next.
What is Rule 206(4)-7 (the Compliance Program Rule)?
Rule 206(4)-7, adopted by the SEC in 2003 in Release No. IA-2204, is the rule that requires every adviser registered or required to be registered with the SEC to actually have a compliance program. It sets out three obligations.
- Adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and its rules by the adviser and its supervised persons.
- Review those policies and procedures at least annually for adequacy and for the effectiveness of their implementation.
- Designate a Chief Compliance Officer (CCO), a supervised person responsible for administering the policies and procedures.
The SEC stated that an adviser's failure to have adequate compliance policies and procedures is itself a violation of the rule, independent of any other securities-law violation. You can be cited for a weak compliance program even if no client was harmed. A documented, regularly reviewed program is the foundation of RIA compliance. Good intentions alone will not satisfy an examiner.
One nuance is worth knowing. A 2023 amendment that would have required the annual review to be documented in writing was vacated by the courts in 2024, so a written record is no longer required by the rule text. Examiners still expect one in practice, which is why most firms keep documenting the review.
What does a Chief Compliance Officer do?
The Chief Compliance Officer (CCO) is the individual a firm designates under Rule 206(4)-7 to administer its compliance program. The CCO is responsible for making the policies and procedures work in practice, not just exist on paper.
On a daily basis, the CCO owns the compliance manual and code of ethics, conducts the annual review, monitors employee personal trading and conflicts, reviews marketing and advertising, maintains required books and records, and serves as the firm's primary point of contact during an SEC or state examination. During an exam, the CCO is typically the person asked to produce the policies, the review documentation, and the evidence that the firm followed its own procedures.
At smaller RIAs the CCO is often a principal who wears several hats; larger firms may have a dedicated compliance team or an outsourced CCO. Either way, the role and its accountability are required. Increasingly, technology handles the monitoring, recordkeeping, and review workflows that once consumed most of a CCO's time.
What are the core areas of an RIA compliance program?
A compliance program is the set of policies and procedures that cover each area of regulatory risk an adviser faces. While the Compliance Program Rule does not dictate a checklist, SEC guidance and examination practice point to a consistent set of core areas.
| Compliance area | What it covers | Primary rule |
|---|---|---|
| Code of ethics & personal trading | Standards of conduct, personal securities transaction reporting, preclearance, access persons | Rule 204A-1 |
| Advertising & marketing | Testimonials, endorsements, performance advertising, social media | Rule 206(4)-1 (Marketing Rule) |
| Books & records | Required records and retention periods; electronic communications | Rule 204-2 |
| Custody of client assets | Safeguarding client funds and securities; surprise exams; account statements | Rule 206(4)-2 (Custody Rule) |
| Disclosure (Form ADV) | Firm brochure, conflicts of interest, annual updating amendment, Form CRS | Form ADV / Advisers Act |
| Privacy & cybersecurity | Safeguarding client information, incident response, breach notification, and service-provider oversight | Regulation S-P |
Most programs also address business continuity, valuation, proxy voting, and oversight of any third-party service providers. For a step-by-step build-out, see RIA Compliance Requirements and the practical RIA Compliance Checklist.
The verification points across all of these areas are the same three Rule 206(4)-7 obligations: write it down, follow it, and review it annually. Build the program around those three requirements, document everything, and an examination becomes a matter of producing evidence you already have.
RIA compliance is repetitive, evidence-heavy work, and that is exactly what software is good at. It does not replace the CCO's judgment, but it can make the operating rhythm easier to maintain: reminders, approvals, records, annual-review evidence, and examiner-ready exports. If you're weighing tools for that work, our guide to evaluating AI compliance software covers the tests to run before you buy. RegFin's AI compliance consultant brings those together for registered investment advisers, so your program runs as an always-ready, documented system instead of a once-a-year scramble. Book a demo →
Start with the basics here, then go deeper with RIA Compliance: The Complete Guide and review your firm's specific obligations in RIA Compliance Requirements.
Frequently asked questions
What is RIA compliance in simple terms?
Is RIA compliance required by law?
Who regulates RIA compliance?
What is the difference between an RIA and a Chief Compliance Officer?
Sources
- Investment Advisers Act of 1940, Section 202(a)(11) (definition of investment adviser) — U.S. Government Publishing Office (govinfo)
- 17 CFR 275.206(4)-7 — Compliance procedures and practices — eCFR
- Compliance Programs of Investment Companies and Investment Advisers (Release No. IA-2204, adopting Rule 206(4)-7) — U.S. SEC
- 17 CFR 275.203A-1 — Eligibility for SEC registration; switching to or from SEC registration — eCFR
- Investment Adviser (Investor.gov glossary) — U.S. SEC (Investor.gov)