Regulatory Compliance Checklist
Annual compliance review workflow for an RIA Chief Compliance Officer covering Form ADV, AML/BSA, cybersecurity, books and records, custody safeguards, and findings remediation.
Form ADV and Client Disclosures
-
Update Form ADV Part 1A in IARD
The CCO logs into IARD and walks through every Item — Items 1, 5, 7, 9, and 11 are the most common change points. Annual amendment is due within 90 days of fiscal year end; a missed deadline is a near-automatic deficiency at the next SEC exam.
-
Refresh the Form ADV Part 2A brochure
Update fee schedules, AUM, disciplinary disclosure (Item 9), and any new conflicts. Identify whether any change is material — that determination drives Form CRS amendment and interim client delivery, not just the annual cycle.
Collects list -
File a Form CRS amendment
Material changes to Form CRS require an amended filing within 30 days and delivery to existing retail clients within 60 days. Pull the existing CRS, redline against the updated facts, and submit through IARD.
-
Deliver the annual brochure to clients
Send Part 2A (or summary of material changes plus offer to provide) to every existing client within 120 days of fiscal year end. Capture delivery confirmation per client in the CRM — Wealthbox, Redtail, and Salesforce FSC all support a delivery field for exam evidence.
AML and BSA Program Review
-
Re-screen all clients against the OFAC SDN list
Run the full client list through Refinitiv World-Check, LexisNexis Bridger, or your AML vendor of record. Don't forget beneficiaries, trust grantors, and 25%+ beneficial owners on entity accounts — incremental party adds are the most common screening gap.
-
Audit beneficial owner records for entity accounts
For each LLC, corporate, and trust account, verify the CDD beneficial owner certification is on file for any 25%+ owner plus one control person. Stale certifications past 12 months should be refreshed.
-
Review the prior-year SAR filings
Pull every SAR filed since the last review. Confirm each was filed within 30 days of suspicion detection, the narrative met FinCEN's five-W standard, and supporting documentation is preserved for five years.
Collects number Collects paragraph -
Conduct annual AML training
Cover red flags specific to your client base — cash-heavy small business, international wires, unusual structuring. Capture attendance with a sign-in sheet or LMS roster; training is required annually under BSA and is one of the first items examiners ask for.
Cybersecurity and Data Safeguards
-
Run a tabletop on the incident response plan
Walk through a ransomware or vendor-breach scenario with the CCO, COO, and IT lead. Test the notification chain to clients under Reg S-P amendments and applicable state breach laws (the SEC adopted a 30-day client notification rule effective 2024).
-
Verify MFA on every custodian portal
Confirm Schwab Advisor Center, Fidelity Wealthscape, Pershing NetX360, and Altruist all require MFA for every advisor and operations user. Pay attention to service-account exceptions — those are the usual back doors.
-
Confirm the wire-change callback policy
Sample five recent wire-instruction changes and confirm operations called the client back at the number of record — not the number on the requesting email. Email-only wire changes are the single most common loss event in advisory operations.
-
Run a vulnerability scan on firm endpoints
Use the firm's MSP scan or a tool like Tenable, Qualys, or Rapid7. Map findings to the Identity Theft Red Flags program (Reg S-ID) and the WISP under Reg S-P safeguards rule.
Collects file
Books, Records, and Communications
-
Spot-audit the email archive
Pull a 10-message random sample per advisor from Smarsh, Global Relay, or Bloomberg Vault. Verify retention, search, and lexicon-flagging are functioning under Rule 204-2's five-year requirement.
-
Collect off-channel communication attestations
Every advisor signs an annual attestation that personal email, personal text, and WhatsApp are not used for client business. The 2022–2024 SEC sweeps produced more than $2B in penalties for off-channel comms — attestation alone won't save the firm, but the absence of one will sink it.
-
Sample social media posts for Rule 2210
Pull a sample from Hearsay or Smarsh of advisor LinkedIn and Facebook posts. Flag any post recommending a security or making a performance claim without required disclosures — those are retail communications needing principal pre-approval.
-
Reset the gift and entertainment log
Reconcile the prior-year G&E log against expense reports and vendor records. Flag any single item over $100 (FINRA's de minimis under Rule 3220) and investigate omissions before resetting for the new year.
Custody and Client Asset Safeguards
-
Inventory standing letters of authorization
Pull every SLOA on file and verify each meets the seven conditions of the 2017 IM Guidance no-action letter. Any SLOA missing a condition triggers custody under Rule 206(4)-2 — meaning a surprise exam by a PCAOB-registered auditor.
Collects list -
Engage a PCAOB auditor for the surprise exam
If custody is triggered, schedule the surprise verification within the next quarter and update Form ADV Item 9 to reflect the custody answer. The auditor needs unannounced access to client account records and signed confirmations.
-
Reconcile fee billing against custodian debits
Compare the internal fee invoice (Black Diamond, Orion, or Tamarac) against the custodian's actual debit and the period-balance methodology disclosed in the IAA. Three-way mismatches are a leading SEC deficiency in custody and fee disclosure exams.
-
Confirm client statements were delivered by the qualified custodian
Verify with Schwab, Fidelity, Pershing, or Altruist that quarterly statements went directly to clients. If the firm sends supplemental performance reports, confirm they include the custodian-statement reconciliation legend required under Rule 206(4)-2.
Findings and CCO Sign-Off
-
Compile findings into the remediation tracker
Every finding gets a named owner, severity rating, target close date, and verification method. Repeat findings cycle-over-cycle are the single biggest red flag for an SEC exam team.
-
Brief the management committee on results
Walk principals through findings, remediation owners, and any policy changes recommended. Document attendance and decisions in committee minutes — examiners ask for these.
-
CCO sign-off on the annual review
Required under Rule 206(4)-7 — the CCO must annually review the adequacy of the firm's compliance policies and procedures and the effectiveness of their implementation. Sign and archive the memo with the year's working papers.
Collects signature Collects file
Use this template
Copy it to your account, customize the steps, and run it with your team in minutes.
Browse hundreds of free templates across every team and industry.
Back to template libraryRelated templates
More workflows your team can run.
Run Regulatory Compliance Checklist with your team
Customize the steps, assign roles, set a schedule, and keep a complete record for every run.