ARTICLE
6 October 2026

Showing Your Work: How SEC Examiners Review The Annual Review

PR
Proskauer Rose LLP

Contributor

The world’s leading organizations and global players choose Proskauer to represent them when they need it the most. Our top tier team of star trial attorneys, acclaimed transactional lawyers and exceptionally talented partners and associates have earned a reputation for the relentless pursuit of perfection and a dauntless pursuit of success.
The SEC's Division of Examinations has released new guidance highlighting common deficiencies in investment advisers' annual compliance reviews, revealing critical gaps in documentation, testing procedures, and policy alignment. With examination coverage rates declining and enforcement actions targeting compliance failures, advisers face heightened scrutiny over their ability to demonstrate thorough, timely, and accurate annual reviews that catch policy-practice drift before regulators do.
United States Corporate/Commercial Law

On October 1, 2026, the Securities and Exchange Commission’s Division of Examinations released The SEC Exam Handbook: A Practical Guide on Process and Engagement (the “Handbook”), replacing its examination brochure. On September 14, the Division published a Risk Alert describing recurring deficiencies in the annual compliance reviews required under Rule 206(4)-7 under the Investment Advisers Act (the “Compliance Rule”).

Neither document breaks new legal ground. What they do supply is practical detail: the Handbook explains how the staff conducts an examination and what it leaves to the adviser; the Risk Alert gives a direct account of the questions that SEC examiners ask about an adviser’s annual review, and of certain answers that the staff has found wanting.

This is particularly useful at a time when fewer advisers will hear those questions in person, a result of recent and projected drops in the SEC’s exam coverage. The SEC’s Fiscal Year 2027 Congressional Budget Justification estimates the share of advisers examined at 9% for FY 2026 and 11% for FY 2027, against 13% in FY 2025 and 14-15% or higher from FY 2017-2024. Although the Division’s examination priorities have regularly highlighted that examinations include an analysis of the annual review, and questions regarding an adviser’s annual review are frequently part of the initial request list delivered by SEC staff, the Risk Alert now provides more detail on how advisers can expect to be tested.

The deficiencies cited by the Risk Alert, and described below, are all process failures. Consequently, most of the work to avoid them can be done now, before the next exam. The Handbook describes the recordkeeping requirements as “foundational to the work of the Division.” The Handbook is also clear that the staff will identify problems but will not prescribe the fix, and generally will not comment on whether a proposed fix is adequate. The annual review is therefore the place where an adviser identifies those problems first, designs and implements its own fixes, and shows its work, both to the staff and to itself.

The following companion to this post also sets out a set of questions that an adviser can use to assess its existing annual review checklist before it is used again. 

Deficiencies in the Review Period

The Risk Alert cites timeliness as a failing. Its examples include advisers that conducted reviews for 2021 and 2023 but omitted 2022, and review periods that stretched beyond twelve months, including first reviews at eighteen months post-registration and intervals extended by business, operational or personnel changes such as a CCO departure. Some advisers offered compliance training or annual personnel attestations in place of a review. Others had taken no corrective action after earlier deficiency letters on this same point, which the staff describes as recidivist conduct.

As explained in the Risk Alert, the annual review requirement refers to the twelve-month period the review covers. The staff treats a review stretched to “periods of greater than 12 months” as a failure, just like a missed year, and exam staff expects registered advisers to show an unbroken series of review periods, none longer than twelve months. The 2003 adopting release had previously allowed an eighteen-month first review period, and exam staff observed that some advisers were reading that as still available. As the Risk Alert notes, however, that accommodation ran only from the Compliance Rule’s October 5, 2004 effective date, and all subsequent reviews must be performed “no less frequently than annually.”

The staff also repeated the 2003 adopting release’s statement that advisers should “consider the need for interim reviews in response to significant compliance events, changes in business arrangements, and regulatory developments.” That statement is guidance rather than a requirement of the rule. The staff did not cite any specific deficiencies involving interim reviews, nor have we historically seen significant focus on this topic during examinations. Nonetheless, an adviser that experiences one of these events may wish to consider whether an interim review is needed.

What advisers can do now. Check the last several annual reviews and confirm that they covered consecutive periods of no more than twelve months each. State the review period expressly in future reports.

Deficiencies in the Review Procedures

Two categories of deficiencies stemmed from internal inconsistencies. In some instances, the staff observed policies that called for testing, validation and documentation without specifying any tests, evaluation criteria or documentation standards. There, the failure was that the procedures were not specific enough to be followed consistently. In other instances, the staff observed policies that were sufficiently specific to be followed, such as a requirement to test a specific process, but they simply were not followed in practice. The staff also criticized reviews that were conducted against a superseded version of the policies, testing the wrong things.

On the one hand, advisers should avoid creating procedural requirements for themselves that they will not be able to follow. Detailed procedures do create commitments an examiner will test. On the other hand, thinner procedures also risk deficiencies if they do not provide enough detail to be executable. Vague policies were treated as a deficiency in their own right.

What advisers can do now. Start by reading the most recent annual review to see whether the testing it describes was enough to show that the procedures being tested were in fact implemented, and whether the firm can sustain it every year. Where the answer to both is yes but the policies describe different testing, amend the policies to match. Where either answer is no, decide what testing would meet both, and name its tests, criteria and documentation in the policies.

Deficiencies Where Policies and Practices Had Drifted

The most instructive deficiency examples cited by the staff all share a similar cause: the written policy and the adviser’s actual practice had drifted, in some cases also drifting from investor-facing disclosures on the same topic, and the annual review did not catch it. On two of these topics, the staff cited its own earlier Risk Alerts (a June 2026 alert on economic conflicts of interest and a December 2025 alert on Marketing Rule compliance), suggesting that the staff considers its expectations on these topics to already be on the record.

 

Topic

What the policy or disclosure covered

What the review did not catch

 

Fee and expense billing

Fees calculated on a disclosed methodology

No proration for large intra-period deposits, breakpoints not applied, no refunds on termination

 

Proxy voting

A stated voting policy

A policy that contradicted both the disclosure and the practice

 

Custody

Custody policies and procedures requiring surprise examinations

No steps for identifying custodial accounts to the surprise-examination accountant

 

Marketing

Marketing policies and procedures

Never updated for the Marketing Rule

 

Regulatory filings

Regulatory filing procedures

Never updated for Form CRS

 

Delegated functions

Functions performed by others

No mechanism for overseeing them

 

Incidents of non-compliance

Reporting incidents of non-compliance

Reported incidents were not addressed or recorded in the annual review


What advisers can do now. Align the policy requirements with any investor-facing disclosure that makes a specific operational commitment, then test whether actual practice matches both the disclosure and the policy. This is hardest on topics where the adviser has given investors detailed disclosure about how it operates. Fee and expense billing, frequently a focus during examinations, is the main example cited in the Risk Alert, but that is not the only place this issue arises, so the investor-facing disclosures are worth reviewing with this question in mind.

Deficiencies in Document Retention

The Risk Alert also cited a number of recordkeeping failures relating to advisers’ annual reviews. All of them were anchored on Rule 204-2(a)(17)(ii), which requires an adviser to make and keep “any records documenting the investment adviser’s annual review.” The staff described advisers whose written annual review reports discussed the compliance violations identified during the review, but who did not retain the underlying documentation of the testing performed, the issues identified or the corrective actions recommended. It also described advisers whose own policies required the review to be memorialized in a written report, where no report was ever prepared.

It is worth bearing in mind that Rule 204-2(a)(17)(ii) is primarily a document retention obligation, not a document creation obligation, although the Risk Alert does not highlight this distinction. The Commission highlighted this distinction when it adopted the now-vacated private fund adviser rules, amending the Compliance Rule to “establish[] a written documentation requirement” of the annual review. The Fifth Circuit’s vacatur of those rules removed that requirement, leaving only Rule 204-2(a)(17)(ii). The advisers described in the Risk Alert were cited for failures to keep documents that they had created, or failures to create documents that their own policies had required them to produce.

In practice, however, that distinction may not be very meaningful. An adviser that tells the staff it performed a review but cannot produce anything evidencing it is likely to find that the assertion is given little weight. The Handbook makes the same point from the staff’s point of view: “Our findings are based on the best information available to us at the time, including the materials that you provided.” Documenting aspects of the annual review can help build credibility with future SEC examiners.

What advisers can do now. Treat the annual review file as the record establishing that credibility, and then create and keep enough documentation to show the work actually done each year, including the testing performed and the issues it surfaced.

Deficiencies in Document Accuracy

The accuracy of what an adviser documents is a separate matter from keeping documents that have been created. The Risk Alert’s most pointed example of such a deficiency is a review report stating that remediation had occurred while the underlying issues persisted. The staff did not indicate whether the inaccuracies were intentional or inadvertent, but it is worth noting that intentional misstatements by an adviser’s compliance staff in the adviser’s records can have very serious consequences for the adviser as well as for the compliance staff. This was illustrated as recently as last year, in two SEC settled-order enforcement actions against chief compliance officers in their personal capacities, finding that they had backdated or fabricated annual review documents.

What advisers can do now. Inaccuracies of this kind are avoidable with a methodical check of the prior review before the current report is finalized. Take each corrective action identified in the prior review, confirm whether it was in fact implemented, and record in the current report what was checked and what was found.

Ensuring the Exam Staff Gives Credit Where Credit Is Due

Many of the Risk Alert’s observations turn on whether a particular procedure, workpaper or testing file was produced and understood. Details do get missed in an examination, sometimes details that bear directly on the staff’s deficiency findings, and advisers are often unsure how to correct the record. The Risk Alert does not address this. However, it was addressed by the Division’s Director, Keith Cassidy, in published remarks two days after the Risk Alert was issued, saying that if “you believe an observation or deficiency is unwarranted, the exit conference is an excellent occasion to raise your concerns,” because “it is possible that something was overlooked or that a procedure or policy was not produced which could affect a finding.”

The Handbook now puts this in writing, asking advisers who think the staff has “misunderstood your policies or practices” to say so “as soon as possible.” The Handbook is just as clear that the fix for a finding is up to the adviser. Deficiency letters “purposely do not mandate a particular corrective action beyond complying with applicable law.” It adds that prompt and appropriate corrective action, while not dispositive, “may be a mitigating factor” when the staff considers whether to refer a finding to the Division of Enforcement.

Confirming that each corrective action was in fact taken therefore falls to the adviser. As the Risk Alert notes, the annual review should “consider any compliance matters that arose during the previous year,” and a deficiency letter is one of them. The recidivist conduct and inaccurate reports described above show what happens when no one checks.

What advisers can do now. Advisers whose annual review documentation is sufficiently detailed, well-organized and retrievable are likely to be in a good position to make their case, and to receive credit where credit is due. After an exam, the next annual review is the natural place to confirm, with evidence, that each step promised in response to a deficiency letter was taken.

Neither the Handbook nor the Risk Alert has any legal force or effect, and the Risk Alert simply closes by encouraging advisers “to reflect upon their own practices, policies, and procedures.” The following steps would answer most of what the Risk Alert describes, and each of them can be taken now:

  • Reconstruct the prior review periods and confirm that no period was missed or ran long.
  • Confirm that the review file can be retrieved quickly by someone who did not assemble it. The Handbook says the Commission expects records to be available within 24 hours in most circumstances, although the staff usually allows two weeks for an initial request.
  • Inventory every commitment in the compliance policies to review or test something periodically, and check that the review covers each one.
  • Name the tests and criteria that each of the review procedures calls for.
  • Compare any disclosure making a specific operational commitment against actual practice.
  • Confirm that prior corrective actions, including any promised in response to a deficiency letter, are in fact completed before the next report describes them as complete.

As noted above, the following companion to this post also sets out a set of questions that an adviser can use to assess its existing annual review checklist before it is used again. 

Showing Your Work: How SEC Examiners Review The Annual Review

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More