Rule 206(4)-7 asks for one review a year, and examiners ask to see it. A review that lives in the CCO’s inbox and a spreadsheet of ticks is hard to evidence when the request list arrives.
Every SEC-registered investment adviser must review its compliance policies and procedures at least once a year, checking both whether they are adequate and whether they work in practice. This free checklist is for chief compliance officers and compliance consultants at registered investment advisers (RIAs). It runs the annual review from planning to a signed report: fiduciary and operations testing, the code of ethics, marketing, books and records, cybersecurity under the amended Regulation S-P, custody, and the Form ADV annual updating amendment. Three scope questions decide what you see: SEC or state registration, whether the firm has custody, and whether it has retail clients who receive Form CRS.
The Annual Review, the ADV Update and the Exam: Three Different Jobs
Rule 206(4)-7 under the Investment Advisers Act, often called the compliance programme rule, has three parts. An SEC-registered adviser must adopt written policies and procedures reasonably designed to prevent violations, review them no less often than annually, and designate a chief compliance officer to run them. The rule does not prescribe a format for the review. The SEC’s adopting release expects it to consider compliance matters that arose during the year, changes in the business and changes in the law.
Two neighbouring jobs are often confused with it. The Form ADV annual updating amendment is a filing with its own deadline. A regulatory exam is the SEC testing your programme from the outside. A good annual review feeds both: it finds the disclosure changes the ADV needs and produces the document examiners ask for first.
Annual compliance review
Rule 206(4)-7(b)
When: at least once every year, plus interim reviews when something changes.
Work: test whether each policy is adequate and effective, find gaps, assign fixes.
Output: a written report and remediation plan.
ADV annual amendment
Rule 204-1
When: within 90 days of the fiscal year end.
Work: update Part 1A and the Part 2 brochure, then deliver within 120 days.
Output: an accepted IARD filing and delivery records.
Regulatory exam
Opened by the SEC or a state
When: on the regulator’s schedule, usually with a short request deadline.
Work: produce records, including the last annual review, and answer questions.
Output: a closing letter or deficiency findings to remediate.
What the RIA Annual Compliance Review Checklist Covers
Six phases run on every review. The custody phase appears only when the firm has custody, and tasks inside the cybersecurity and Form ADV phases switch with the registration and retail client answers.
Phase 1
Phase 1: Plan the Review
Assigned to the CCO. The scope answers recorded here decide which later phases and tasks appear.
Record the review period and the fiscal year end — the ADV and brochure deadlines are offset from it
Answer the scope questions — SEC or state registered, custody Yes or No, retail clients receiving Form CRS Yes or No
Update the compliance risk inventory — new products, strategies, custodians, staff, offices and conflicts since the last review
Collect the year’s inputs — last year’s findings, exam deficiency letters, interim testing, complaints, trade errors and regulatory changes
Assign an owner to each test area — the person who runs a process should not be the only one who tests it
Confirm the CCO designation — that the CCO is knowledgeable about the Advisers Act and has the authority and resources to run the programme
Phase 2
Phase 2: Fiduciary Duty & Operations Testing
Test fee billing against advisory agreements and the brochure — sample invoices for rate, breakpoints, household aggregation and billing on cash
Review the conflicts inventory against disclosure — every material conflict is eliminated or fully and fairly disclosed
Test portfolio management against client objectives and restrictions — sample accounts for drift and breached restrictions
Review trading, allocation and best execution — aggregation and allocation records, the trade error log and the best execution review
Review valuation of hard-to-value holdings — pricing sources, overrides and who approved them
Test the business continuity and succession plan — contact lists, backups and who acts if a key person is unavailable
Phase 3
Phase 3: Code of Ethics, Marketing & Books and Records
Reconcile the access person list and personal trading reports — initial holdings within 10 days of becoming an access person, annual holdings and quarterly transaction reports within 30 days of quarter end (Rule 204A-1)
Check pre-approval of IPO and limited offering purchases by access persons — and test personal trades against the restricted list
Collect each supervised person’s written acknowledgement of the code of ethics — and log any code violations and the action taken
Review a sample of advertisements against the marketing rule — net with gross performance, testimonial and endorsement disclosures, third-party ratings and hypothetical performance controls
Check the Form ADV Part 1A Item 5.L marketing answers — they must match what the firm actually does
Test books and records under Rule 204-2 — required records exist, are retrievable, and electronic communications are captured on approved channels
Phase 4
Phase 4: Cybersecurity, Privacy & Regulation S-P
SEC-registered advisers test against amended Regulation S-P. For state-registered advisers the task list switches to the FTC Safeguards Rule and state rules.
Review the written incident response programme — it must cover detecting, assessing, containing and controlling unauthorised access to customer information
Test the customer notification procedure — affected individuals notified as soon as practicable and no later than 30 days after the firm becomes aware
Review service provider oversight — providers must notify the firm within 72 hours of a breach affecting its customer information
Review access controls and the user list — leavers removed, privileged access justified, multi-factor authentication in place
Run or review an incident tabletop exercise — record what worked and what changes
State registered only: test against the FTC Safeguards Rule — and your state’s information security rule; many states follow the NASAA model rule
Phase 5 — Custody Only
Phase 5: Custody Rule Testing
Shown only when the firm has custody of client funds or securities. State-registered advisers follow their state’s custody rule, which can differ.
Identify every source of custody — fee deduction, standing letters of authority, access to client credentials, trustee roles, general partner of a pooled vehicle
Confirm a qualified custodian holds the assets — and that the firm has a reasonable basis to believe clients receive account statements at least quarterly
Track the surprise examination by an independent public accountant — the accountant files Form ADV-E within 120 days of the exam date
Pooled vehicles: confirm audited financial statements reached investors — within 120 days of fiscal year end; 180 days for a fund of funds
Reconcile custody answers in Form ADV Item 9 — amounts, number of clients and the custodians named
Phase 6
Phase 6: Form ADV Annual Amendment & Disclosure Delivery
Due dates offset from the fiscal year end. The Form CRS task shows for SEC-registered firms with retail clients; the state task shows for state-registered firms.
Update Part 1A, including regulatory assets under management — and recheck registration eligibility; an SEC adviser below $90 million generally must switch to the states
Update the Part 2A brochure and Part 2B supplements — reflecting conflicts, fees and practices found in Phases 2 to 5
File the annual updating amendment through IARD — within 90 days of the fiscal year end
Deliver the brochure or a summary of material changes — within 120 days of the fiscal year end, with an offer of the full brochure
Review Form CRS for material inaccuracy — file amendments within 30 days and communicate them to retail clients within 60 days
State registered: complete state-specific filings — IARD renewal, adviser representative registrations and any financial statement, bonding or net worth requirement
Phase 7
Phase 7: Report, Remediate & Sign Off
The CCO signs the report. Senior management approval is a separate task assigned to a named principal, and the checklist stops until it is answered.
Write the annual review report — scope, tests performed, findings rated by risk, and changes to policies
Assign each finding to an owner with a due date — so remediation is tracked, not buried in the report
Update the policies and procedures manual — with a version date and summary of changes
CCO sign-off on the report — the review is complete and evidence is attached
Senior management approval — the CEO or managing member records Approved or Not approved
Retain the report and evidence — Rule 204-2(a)(17) requires records documenting the annual review
Schedule next year’s review and the interim testing calendar — quarterly code of ethics checks, marketing sampling and billing tests
The table maps each part of the checklist to its main SEC rule. State-registered advisers are not subject to Rule 206(4)-7 or Form CRS, but their state may impose similar duties, so treat the table as a starting point, not legal advice.
Requirement
Rule
Frequency or deadline
Phase
Written policies, annual review, CCO
Rule 206(4)-7
Review at least annually
1, 7
Books and records
Rule 204-2
Generally 5 years from the end of the fiscal year of the last entry, the first 2 in an appropriate office
3, 7
Code of ethics and personal trading
Rule 204A-1
Holdings within 10 days of becoming an access person and yearly; transactions within 30 days of quarter end
3
Marketing
Rule 206(4)-1
In force since the 4 November 2022 compliance date
3
Privacy and incident response
Regulation S-P, as amended in 2024
Compliance from 3 December 2025 ($1.5 billion AUM or more) and 3 June 2026 (smaller advisers)
4
Custody
Rule 206(4)-2
Surprise exam yearly; audited pooled vehicle financials within 120 days
5
Form ADV annual updating amendment
Rule 204-1
Within 90 days of fiscal year end
6
Brochure delivery
Rule 204-3
Within 120 days of fiscal year end
6
Form CRS
Rule 204-5 and Form ADV Part 3
Amend within 30 days of a material inaccuracy; communicate within 60 days
6
Several things are moving. FinCEN has postponed its anti-money laundering rule for investment advisers to 1 January 2028 and says it will revisit the rule’s scope. The compliance date for the 2024 Form PF amendments has moved to 1 July 2027 while the SEC and CFTC consider an April 2026 proposal to scale them back. In June 2025 the SEC withdrew several pending proposals, including the safeguarding rule and the adviser cybersecurity risk management rule. On 1 October 2026 it voted to propose new custody amendments covering crypto assets; at the time of writing that is a proposal, not a final rule. SEC staff also added marketing rule FAQs in March 2025 and January 2026.
The Division of Examinations’ fiscal year 2026 priorities name adviser compliance programmes, including how firms carry out annual reviews, alongside fiduciary duty, recently adopted rules such as the Regulation S-P amendments, and information security.
Why Run the RIA Annual Review in CheckFlow?
1
The compliance calendar runs itself
Start the review on an annual recurring schedule keyed to your fiscal year end. Due-date offsets put the ADV filing at day 90 and brochure delivery at day 120, and quarterly testing can run as its own recurring checklist.
2
Only the tests that apply
Conditional logic reads the scope answers. A state-registered adviser without custody never sees the custody phase or Form CRS, and an SEC-registered firm with retail clients gets both without anyone remembering to add them.
3
Evidence an examiner can follow
Test samples, holdings reports and the signed report attach to the task they support. Senior management approval is an approval task for a named person, and the timestamped activity trail exports for your records.
CheckFlow is not a compliance management platform, a personal trading surveillance tool or an IARD filing service, and it does not test trades for you. It runs the review workflow around those systems: who tests each area, what they found, who fixed it and who signed off. The asset management overview shows other adviser workflows run the same way, and CheckFlow’s compliance checklist software covers the rest of the compliance calendar.
It requires every SEC-registered investment adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act, to review their adequacy and the effectiveness of their implementation at least annually, and to designate a chief compliance officer responsible for administering them. Records documenting the annual review must be kept under Rule 204-2.
How often must an RIA review its compliance programme?
+
At least once a year. The SEC also expects interim reviews when circumstances call for them, such as a compliance incident, a new business line, a merger or a change in the rules. Many firms spread testing across the year and use the annual review to pull the results together.
When is the Form ADV annual updating amendment due?
+
Within 90 days of the end of the adviser’s fiscal year, so 31 March for a firm with a 31 December year end in most years. The updated brochure, or a summary of material changes with an offer of the brochure, must reach clients within 120 days of the year end. Some information must also be updated promptly during the year when it becomes inaccurate.
Does the annual compliance review apply to state-registered advisers?
+
Rule 206(4)-7 applies to SEC-registered advisers. State-registered advisers follow their state’s rules, and many states have adopted rules based on NASAA model rules covering areas such as business continuity and information security. A yearly review is good practice either way, which is why the checklist keeps the core phases and switches the SEC-only tasks off for state firms.
What did the Regulation S-P amendments change for investment advisers?
+
The 2024 amendments require a written incident response programme, notice to affected individuals within 30 days of becoming aware of unauthorised access to sensitive customer information, oversight of service providers including notice to the firm within 72 hours of a breach, and new records. Advisers with $1.5 billion or more in assets under management had to comply from 3 December 2025 and smaller advisers from 3 June 2026, so this is the first annual review cycle in which every SEC-registered adviser is covered.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Have Next Year’s Annual Review Signed Before the Exam Letter Arrives
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more