Reg S-P overview › the annual compliance review
Eight days before this page was written, the SEC's Division of Examinations published Examinations Observations Regarding Investment Adviser Annual Compliance Reviews, dated September 14, 2026. It sets out what staff has been finding when it asks advisers for their annual review under the Compliance Rule, Advisers Act Rule 206(4)-7.
The alert does not mention Regulation S-P anywhere. We are writing about it anyway, because of a structural point that is easy to miss on a first read: four of its five observation categories describe failures against the adviser's own written procedure, not against the text of the rule. The rule says review annually. Most of the findings are versions of "you did not do what your own manual said you would do." That is precisely the exposure a firm creates when it adopts a new program — an incident response program, say, adopted for the June 3, 2026 Reg S-P smaller-entity date — and does not go back and update the procedure that governs how the annual review is scoped.
Read the alert's own disclaimer first. In its footnote 1 the document states that it "represents the views of the staff of the Division of Examinations," that it "is not a rule, regulation, or statement of the" Commission, and that "like all staff statements, [it] has no legal force or effect; it does not alter or amend applicable law, and it creates no new or additional obligations for any person." Nothing on this page adds an obligation either. What a risk alert is good for is knowing what gets asked for.
The alert restates the obligation before listing findings, and the restatement is worth having in front of you because each finding maps back to one clause of it.
"A critical component of the Compliance Rule is the requirement that advisers conduct a review of their compliance policies and procedures at least annually to assess their adequacy and the effectiveness of their implementation."
— SEC Division of Examinations, Examinations Observations Regarding Investment Adviser Annual Compliance Reviews (Sept. 14, 2026), § I
Quoting the 2003 Compliance Rule adopting release, the alert then says these reviews should:
"consider any compliance matters that arose during the previous year, any changes in the business activities of the adviser or its affiliates, and any changes in the Advisers Act or applicable regulations that might suggest a need to revise [their compliance] policies or procedures."
— same document, § I, quoting Advisers Act Rel. No. 2204, 68 FR 74720
And it adds a fourth requirement that has nothing to do with 206(4)-7 at all:
"advisers must maintain any books and records documenting the reviews in a true, accurate, and current manner."
— same document, § I, citing Advisers Act Rule 204-2(a)(17)(ii)
That third quote is the hinge for anyone reading this site. Changes in applicable regulations that might suggest a need to revise policies or procedures is a description of the 2024 Regulation S-P amendments for any review period that includes June 3, 2026 — the smaller-entity compliance date, covered separately on the deadline page. [Inference — the alert never names Reg S-P. The mapping from "changes in applicable regulations" to the Reg S-P amendments is ours. The Division did not make it.]
| What staff observed | The alert's framing | Why a 2026 Reg S-P adoption is exposed |
|---|---|---|
| 1. Timeliness | Reviews skipped entirely, gaps between years, and periods longer than 12 months. | Indirect. This one is about the calendar, not the content. |
| 2. Incomplete procedures for conducting the review | A topic that the firm's own policies say gets annual review testing, omitted from the annual review procedure — so it never got tested. | Direct. A new IRP that says it will be reviewed and tested annually, added to a manual whose annual-review scope still lists the pre-2026 topics. |
| 3. Reviews not run the way the procedure says | Wrong review period, specified workpapers not used, and reviews that assessed "outdated versions of policies and procedures… that had been updated and superseded prior to the review period." | Direct. A firm that rewrote its safeguards and disposal policies in spring 2026 and then reviewed the superseded version is the example, almost verbatim. |
| 4. Policies that do not align with practice | Includes policies "that delegated the execution of services and/or operations to others, but did not identify how the adviser should oversee these delegated responsibilities." | Direct. That is the shape of the Reg S-P service-provider element — see what the vendor rule actually requires. |
| 5. Documentation kept, and corrective action taken | Testing and corrective-action records generated during the review and then not retained; promised written reports never prepared; recommendations never acted on. | Direct. Reg S-P carries its own records duty on top of this one. |
Read categories 2, 3, 4 and 5 together and a pattern falls out. In almost every example, the adviser is not being faulted for breaching the two-sentence text of Rule 206(4)-7. It is being faulted for writing down a more demanding process than it performed.
The alert's own example under category 2 makes this concrete, and it happens to come from the rule next door to ours:
"…adviser's identity theft policies and procedures mandate annual review testing, but this topic was omitted from such annual review testing."
— same document, § II, "Adopting complete policies and procedures for conducting annual reviews"
That is Regulation S-ID — the identity-theft red-flags rule that sits in the same part of the CFR as Reg S-P. The firm's S-ID policy promised annual testing. The firm's annual-review procedure listed the topics to test and S-ID was not among them. Nobody had to breach anything for that finding to exist; the two documents simply did not refer to each other.
Under category 5 the same structure appears twice more. The Compliance Rule does not itself require a written annual review report. But staff observed advisers that:
"Adopted policies and procedures requiring their annual reviews to be memorialized in written reports that covered specific topics… However, no written annual review report was prepared."
"Adopted policies and procedures requiring the annual review to be documented in a specific manner (e.g., using a series of checklists, workpapers, or templates). However, the advisers did not satisfy all of these requirements or only partially completed them."
— same document, § II, "Maintaining documentation made regarding annual reviews"
For a one-to-five-person firm this has a practical consequence that runs against the instinct to buy the most thorough template available. A manual that specifies quarterly testing, named workpapers, a scored risk matrix and a formal written report is a manual you now have to produce all of that against, every year, and keep. The safer small-firm posture is a procedure you will actually execute, described accurately, than an impressive one you will partly perform. [This paragraph is our read of the pattern across the alert's examples, not a recommendation from the Division. The Division does not comment on how detailed a small firm's procedures should be.]
Solo or small RIA? AdviserLedger keeps the Reg S-P paper trail as a short, dated set of records — IRP, incident log, notification-decision template, and a vendor register — so the artifacts an annual review is supposed to test have dates attached to them. The beta waitlist is open; planned pricing is $249/year.
Get Reg S-P ready →Newly registered advisers are often told they have eighteen months before the first annual review is due. The alert lists first reviews "at 18 months post-registration with the Commission" as a timeliness failure, and its footnote 8 explains why:
"…the 18-month annual review period in the Compliance Rule Adopting Release was only available to advisers after the Compliance Rule's effective date on Oct. 5, 2004. All subsequent reviews are required by the Compliance Rule to be performed no less frequently than annually."
— same document, footnote 8
In other words the eighteen-month window was a one-time transition accommodation from 2003–04, not a standing grace period for newly registered firms. This matters for this site's audience twice over: newly registered advisers skew small, and the Division's FY2026 priorities separately say it will prioritise never-examined and recently registered advisers.
The final observation is about corrective action, and one clause in it is sharper than the rest. Staff observed advisers whose reviews recommended changes that were never made — "including instances where the advisers indicated that corrective actions were already implemented (e.g., written annual review reports stated such actions had already occurred) but the issues identified during the prior annual reviews persisted."
A written record asserting a remediation that did not happen is worse than no record, because the record itself is now inaccurate — and Rule 204-2(a)(17)(ii), quoted at the top of this page, requires these books and records to be kept "true, accurate, and current."
What this page does not tell you. The alert is about the review process. It does not say what a Reg S-P review should test, it does not set a scope, and it names no substantive Reg S-P requirement — because it never mentions Reg S-P. Every connection drawn on this page between the alert's findings and the Reg S-P amendments is labelled as our inference above. For what the amendments require, start with the overview; for the records the rule itself demands, see recordkeeping. If your firm is state-registered rather than SEC-registered, Rule 206(4)-7 is not your rule either — see state-registered advisers.
Related on this site: the Reg S-P overview for small RIAs · the June 3, 2026 smaller-entity deadline · what the FY2026 exam priorities say · writing the incident response program · service-provider oversight · the vendor due-diligence checklist · the four records you have to keep · Regulation S-ID, the rule named in the alert's own example · does Reg S-P apply to my RIA?