Annual Compliance Program Review
The CCO's annual workflow to satisfy Advisers Act Rule 206(4)-7: assess compliance risks, refresh policies and Form ADV, train personnel, audit communications, and test internal controls. Pacing assumes a January-anchored calendar-year review cycle.
Risk Assessment & Monitoring
-
Conduct the annual compliance risk assessment
Walk each business line — advisory, custody arrangements, marketing, trading, vendor management — and identify inherent risks against Advisers Act Rule 206(4)-7. Reuse last year's matrix as a starting point but refresh: new services, new custodians (Schwab/Fidelity/Altruist), new staff, new SEC risk alerts. The CCO owns this.
-
Rank risks by business line and severity
Score each risk on inherent severity and likelihood, then on residual after existing controls. Off-channel comms and custody (SLOA, fee debits) typically rank highest for small RIAs based on recent SEC enforcement patterns.
-
Update the firm compliance risk matrix
Save the updated matrix to the compliance file (NetDocuments / ShareFile / Laserfiche) with version date. SEC exam staff will ask to see it; thin or year-old matrices are a common deficiency letter item.
Collects file
Policies & Procedures Review
-
Review the compliance manual against current rules
Walk the manual section-by-section against the latest Advisers Act rules, Marketing Rule (206(4)-1), Custody Rule (206(4)-2), Reg S-P, and any new SEC risk alerts from the last 12 months. ComplySci, ACA, or RIA in a Box redlines are a useful starting point if you subscribe.
-
Identify Form ADV Part 2A material changes
Compare current ADV Part 2A against firm reality: fee schedule changes, new services, new conflicts, disciplinary disclosures, ownership changes, AUM band shifts. Material changes require a summary in Item 2 and amendment filing.
Collects list -
File the ADV amendment through IARD
Annual updating amendment is due within 90 days of fiscal year end; material change interim amendments are due promptly. File via IARD and deliver the updated brochure to all existing clients within 120 days of FYE — track delivery acknowledgments per client in the CRM.
-
Refresh the code of ethics and personal trading policy
Confirm access-person definitions still cover the right staff, restricted/watch lists are current, and pre-clearance and reporting workflows are working. Collect annual holdings reports within 45 days of year-end and quarterly transaction reports within 30 days of quarter-end per Rule 204A-1.
-
Verify books and records retention controls
Rule 204-2 requires five-year retention (first two years easily accessible). Confirm advisory contracts, ADV deliveries, advertising approvals, complaint log, code of ethics records, and trade blotters are all archived in WORM-compliant or equivalent systems.
Training & Education
-
Deliver annual compliance training to all personnel
Cover the firm's code of ethics, off-channel communications policy, Marketing Rule basics, custody/SLOA safeguards, Reg S-P privacy, and current-year SEC risk alerts. Use case-study scenarios over generic slides — staff retention is materially better when training is firm-specific.
-
Track CE credits for IARs and registered reps
NASAA IAR CE: 12 credits annually (6 ethics, 6 products and practice). FINRA Regulatory Element CE annually for registered reps. Pull rosters by license type and chase any rep at risk of failing — late completion is a state and FINRA late-fee event.
-
Archive signed training acknowledgments by employee
Each employee signs an acknowledgment confirming they completed training, received and read the current code of ethics, and understand the personal trading and off-channel communications policies. Save signed PDFs to the employee compliance file.
Collects file
Communications & Marketing Review
-
Audit advertising under the SEC Marketing Rule
Pull a sample of website pages, LinkedIn posts, pitch decks, and one-pagers from the last 12 months. Verify each: testimonials/endorsements have required disclosures, performance presentations meet net-of-fees and time-period requirements, hypothetical performance is restricted to intended audiences. Document the review in the advertising log.
-
Verify email and text archiving coverage by user
Pull the user list from Smarsh / Global Relay / Bloomberg Vault and reconcile against HR's active employee list. Confirm MyRepChat or equivalent is provisioned for any rep who texts clients. The 2022-2024 SEC off-channel sweep produced over $2B in fines — gaps here are not theoretical.
-
Spot-check off-channel communications for violations
Pick a random sample of advisors and review their archived comms for the quarter. Look for patterns suggesting off-channel use: phrases like 'text me at,' 'my personal email,' or sudden gaps in archived volume. Document findings; escalate any rep with apparent off-channel patterns.
Internal Controls & Testing
-
Test custody rule controls and SLOA safeguards
Pull every active SLOA on file and verify each meets the seven IM no-action letter conditions: written client authorization, third-party only, custodian confirmation to client, etc. Reconcile against the firm's surprise exam scope. SLOA gaps are the most common path to inadvertent custody.
-
Run quarterly forensic transaction testing
Sample trades for: best execution review, allocation fairness across blocks, fee billing accuracy (three-way: invoice / custodian debit / internal calculation), and rebalance drift. Document the sample size and results. Errors found get logged to the error account with a five-day resolution SLA.
-
Log compliance findings in the tracker
Each finding gets an owner, severity rating, remediation plan, and target close date. Recurring findings across multiple annual reviews are an SEC red flag — note any item that appears for the second consecutive year.
Collects list -
Escalate material findings to senior management
Material findings get same-week escalation to the managing principal and, where applicable, the firm's board or advisory committee. Document the escalation memo, the response, and the agreed remediation owner. The escalation memo itself becomes part of the annual review file.
-
Sign off on the annual compliance review
The CCO certifies completion of the Rule 206(4)-7 annual review. Attach the executive summary covering risk assessment results, P&P updates, training completion rates, communications audit findings, and controls testing outcomes. Save to the annual review file with date-stamped signature.
Collects signature Collects paragraph
Use this template
Copy it to your account, customize the steps, and run it with your team in minutes.
Browse hundreds of free templates across every team and industry.
Back to template libraryRelated templates
More workflows your team can run.
Run Annual Compliance Program Review with your team
Customize the steps, assign roles, set a schedule, and keep a complete record for every run.