Investment Adviser Annual Compliance Review Checklist Template

Rule 206(4)-7 asks for one review a year, and examiners ask to see it. A review that lives in the CCO’s inbox and a spreadsheet of ticks is hard to evidence when the request list arrives.

Every SEC-registered investment adviser must review its compliance policies and procedures at least once a year, checking both whether they are adequate and whether they work in practice. This free checklist is for chief compliance officers and compliance consultants at registered investment advisers (RIAs). It runs the annual review from planning to a signed report: fiduciary and operations testing, the code of ethics, marketing, books and records, cybersecurity under the amended Regulation S-P, custody, and the Form ADV annual updating amendment. Three scope questions decide what you see: SEC or state registration, whether the firm has custody, and whether it has retail clients who receive Form CRS.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

The Annual Review, the ADV Update and the Exam: Three Different Jobs

Rule 206(4)-7 under the Investment Advisers Act, often called the compliance programme rule, has three parts. An SEC-registered adviser must adopt written policies and procedures reasonably designed to prevent violations, review them no less often than annually, and designate a chief compliance officer to run them. The rule does not prescribe a format for the review. The SEC’s adopting release expects it to consider compliance matters that arose during the year, changes in the business and changes in the law.

Two neighbouring jobs are often confused with it. The Form ADV annual updating amendment is a filing with its own deadline. A regulatory exam is the SEC testing your programme from the outside. A good annual review feeds both: it finds the disclosure changes the ADV needs and produces the document examiners ask for first.

Annual compliance review

Rule 206(4)-7(b)

When: at least once every year, plus interim reviews when something changes.

Work: test whether each policy is adequate and effective, find gaps, assign fixes.

Output: a written report and remediation plan.

ADV annual amendment

Rule 204-1

When: within 90 days of the fiscal year end.

Work: update Part 1A and the Part 2 brochure, then deliver within 120 days.

Output: an accepted IARD filing and delivery records.

Regulatory exam

Opened by the SEC or a state

When: on the regulator’s schedule, usually with a short request deadline.

Work: produce records, including the last annual review, and answer questions.

Output: a closing letter or deficiency findings to remediate.

What the RIA Annual Compliance Review Checklist Covers

Six phases run on every review. The custody phase appears only when the firm has custody, and tasks inside the cybersecurity and Form ADV phases switch with the registration and retail client answers.

Phase 1

Phase 1: Plan the Review

Assigned to the CCO. The scope answers recorded here decide which later phases and tasks appear.

  • Record the review period and the fiscal year end — the ADV and brochure deadlines are offset from it
  • Answer the scope questions — SEC or state registered, custody Yes or No, retail clients receiving Form CRS Yes or No
  • Update the compliance risk inventory — new products, strategies, custodians, staff, offices and conflicts since the last review
  • Collect the year’s inputs — last year’s findings, exam deficiency letters, interim testing, complaints, trade errors and regulatory changes
  • Assign an owner to each test area — the person who runs a process should not be the only one who tests it
  • Confirm the CCO designation — that the CCO is knowledgeable about the Advisers Act and has the authority and resources to run the programme
Phase 2

Phase 2: Fiduciary Duty & Operations Testing

  • Test fee billing against advisory agreements and the brochure — sample invoices for rate, breakpoints, household aggregation and billing on cash
  • Review the conflicts inventory against disclosure — every material conflict is eliminated or fully and fairly disclosed
  • Test portfolio management against client objectives and restrictions — sample accounts for drift and breached restrictions
  • Review trading, allocation and best execution — aggregation and allocation records, the trade error log and the best execution review
  • Review valuation of hard-to-value holdings — pricing sources, overrides and who approved them
  • Test the business continuity and succession plan — contact lists, backups and who acts if a key person is unavailable
Phase 3

Phase 3: Code of Ethics, Marketing & Books and Records

  • Reconcile the access person list and personal trading reports — initial holdings within 10 days of becoming an access person, annual holdings and quarterly transaction reports within 30 days of quarter end (Rule 204A-1)
  • Check pre-approval of IPO and limited offering purchases by access persons — and test personal trades against the restricted list
  • Collect each supervised person’s written acknowledgement of the code of ethics — and log any code violations and the action taken
  • Review a sample of advertisements against the marketing rule — net with gross performance, testimonial and endorsement disclosures, third-party ratings and hypothetical performance controls
  • Check the Form ADV Part 1A Item 5.L marketing answers — they must match what the firm actually does
  • Test books and records under Rule 204-2 — required records exist, are retrievable, and electronic communications are captured on approved channels
Phase 4

Phase 4: Cybersecurity, Privacy & Regulation S-P

SEC-registered advisers test against amended Regulation S-P. For state-registered advisers the task list switches to the FTC Safeguards Rule and state rules.

  • Review the written incident response programme — it must cover detecting, assessing, containing and controlling unauthorised access to customer information
  • Test the customer notification procedure — affected individuals notified as soon as practicable and no later than 30 days after the firm becomes aware
  • Review service provider oversight — providers must notify the firm within 72 hours of a breach affecting its customer information
  • Review access controls and the user list — leavers removed, privileged access justified, multi-factor authentication in place
  • Run or review an incident tabletop exercise — record what worked and what changes
  • State registered only: test against the FTC Safeguards Rule — and your state’s information security rule; many states follow the NASAA model rule
Phase 5 — Custody Only

Phase 5: Custody Rule Testing

Shown only when the firm has custody of client funds or securities. State-registered advisers follow their state’s custody rule, which can differ.

  • Identify every source of custody — fee deduction, standing letters of authority, access to client credentials, trustee roles, general partner of a pooled vehicle
  • Confirm a qualified custodian holds the assets — and that the firm has a reasonable basis to believe clients receive account statements at least quarterly
  • Track the surprise examination by an independent public accountant — the accountant files Form ADV-E within 120 days of the exam date
  • Pooled vehicles: confirm audited financial statements reached investors — within 120 days of fiscal year end; 180 days for a fund of funds
  • Reconcile custody answers in Form ADV Item 9 — amounts, number of clients and the custodians named
Phase 6

Phase 6: Form ADV Annual Amendment & Disclosure Delivery

Due dates offset from the fiscal year end. The Form CRS task shows for SEC-registered firms with retail clients; the state task shows for state-registered firms.

  • Update Part 1A, including regulatory assets under management — and recheck registration eligibility; an SEC adviser below $90 million generally must switch to the states
  • Update the Part 2A brochure and Part 2B supplements — reflecting conflicts, fees and practices found in Phases 2 to 5
  • File the annual updating amendment through IARD — within 90 days of the fiscal year end
  • Deliver the brochure or a summary of material changes — within 120 days of the fiscal year end, with an offer of the full brochure
  • Review Form CRS for material inaccuracy — file amendments within 30 days and communicate them to retail clients within 60 days
  • State registered: complete state-specific filings — IARD renewal, adviser representative registrations and any financial statement, bonding or net worth requirement
Phase 7

Phase 7: Report, Remediate & Sign Off

The CCO signs the report. Senior management approval is a separate task assigned to a named principal, and the checklist stops until it is answered.

  • Write the annual review report — scope, tests performed, findings rated by risk, and changes to policies
  • Assign each finding to an owner with a due date — so remediation is tracked, not buried in the report
  • Update the policies and procedures manual — with a version date and summary of changes
  • CCO sign-off on the report — the review is complete and evidence is attached
  • Senior management approval — the CEO or managing member records Approved or Not approved
  • Retain the report and evidence — Rule 204-2(a)(17) requires records documenting the annual review
  • Schedule next year’s review and the interim testing calendar — quarterly code of ethics checks, marketing sampling and billing tests

The Rules Behind the Annual Review

The table maps each part of the checklist to its main SEC rule. State-registered advisers are not subject to Rule 206(4)-7 or Form CRS, but their state may impose similar duties, so treat the table as a starting point, not legal advice.

Requirement Rule Frequency or deadline Phase
Written policies, annual review, CCORule 206(4)-7Review at least annually1, 7
Books and recordsRule 204-2Generally 5 years from the end of the fiscal year of the last entry, the first 2 in an appropriate office3, 7
Code of ethics and personal tradingRule 204A-1Holdings within 10 days of becoming an access person and yearly; transactions within 30 days of quarter end3
MarketingRule 206(4)-1In force since the 4 November 2022 compliance date3
Privacy and incident responseRegulation S-P, as amended in 2024Compliance from 3 December 2025 ($1.5 billion AUM or more) and 3 June 2026 (smaller advisers)4
CustodyRule 206(4)-2Surprise exam yearly; audited pooled vehicle financials within 120 days5
Form ADV annual updating amendmentRule 204-1Within 90 days of fiscal year end6
Brochure deliveryRule 204-3Within 120 days of fiscal year end6
Form CRSRule 204-5 and Form ADV Part 3Amend within 30 days of a material inaccuracy; communicate within 60 days6

Several things are moving. FinCEN has postponed its anti-money laundering rule for investment advisers to 1 January 2028 and says it will revisit the rule’s scope. The compliance date for the 2024 Form PF amendments has moved to 1 July 2027 while the SEC and CFTC consider an April 2026 proposal to scale them back. In June 2025 the SEC withdrew several pending proposals, including the safeguarding rule and the adviser cybersecurity risk management rule. On 1 October 2026 it voted to propose new custody amendments covering crypto assets; at the time of writing that is a proposal, not a final rule. SEC staff also added marketing rule FAQs in March 2025 and January 2026.

The Division of Examinations’ fiscal year 2026 priorities name adviser compliance programmes, including how firms carry out annual reviews, alongside fiduciary duty, recently adopted rules such as the Regulation S-P amendments, and information security.

Why Run the RIA Annual Review in CheckFlow?

1

The compliance calendar runs itself

Start the review on an annual recurring schedule keyed to your fiscal year end. Due-date offsets put the ADV filing at day 90 and brochure delivery at day 120, and quarterly testing can run as its own recurring checklist.

2

Only the tests that apply

Conditional logic reads the scope answers. A state-registered adviser without custody never sees the custody phase or Form CRS, and an SEC-registered firm with retail clients gets both without anyone remembering to add them.

3

Evidence an examiner can follow

Test samples, holdings reports and the signed report attach to the task they support. Senior management approval is an approval task for a named person, and the timestamped activity trail exports for your records.

CheckFlow is not a compliance management platform, a personal trading surveillance tool or an IARD filing service, and it does not test trades for you. It runs the review workflow around those systems: who tests each area, what they found, who fixed it and who signed off. The asset management overview shows other adviser workflows run the same way, and CheckFlow’s compliance checklist software covers the rest of the compliance calendar.

When an exam letter arrives, the Regulatory Examination Preparation Checklist picks up where this review leaves off. Annual code of ethics attestations can run through the Employee Compliance Certification Tracking Checklist, and advisers preparing for FinCEN’s 2028 date can model their programme on the AML Compliance Programme Review Checklist. Client-facing reviews are covered by the Financial Adviser Annual Client Review Checklist.

Frequently Asked Questions

What does SEC Rule 206(4)-7 require?

+

It requires every SEC-registered investment adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act, to review their adequacy and the effectiveness of their implementation at least annually, and to designate a chief compliance officer responsible for administering them. Records documenting the annual review must be kept under Rule 204-2.

How often must an RIA review its compliance programme?

+

At least once a year. The SEC also expects interim reviews when circumstances call for them, such as a compliance incident, a new business line, a merger or a change in the rules. Many firms spread testing across the year and use the annual review to pull the results together.

When is the Form ADV annual updating amendment due?

+

Within 90 days of the end of the adviser’s fiscal year, so 31 March for a firm with a 31 December year end in most years. The updated brochure, or a summary of material changes with an offer of the brochure, must reach clients within 120 days of the year end. Some information must also be updated promptly during the year when it becomes inaccurate.

Does the annual compliance review apply to state-registered advisers?

+

Rule 206(4)-7 applies to SEC-registered advisers. State-registered advisers follow their state’s rules, and many states have adopted rules based on NASAA model rules covering areas such as business continuity and information security. A yearly review is good practice either way, which is why the checklist keeps the core phases and switches the SEC-only tasks off for state firms.

What did the Regulation S-P amendments change for investment advisers?

+

The 2024 amendments require a written incident response programme, notice to affected individuals within 30 days of becoming aware of unauthorised access to sensitive customer information, oversight of service providers including notice to the firm within 72 hours of a breach, and new records. Advisers with $1.5 billion or more in assets under management had to comply from 3 December 2025 and smaller advisers from 3 June 2026, so this is the first annual review cycle in which every SEC-registered adviser is covered.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Have Next Year’s Annual Review Signed Before the Exam Letter Arrives

Free trial — no credit card required.