Internal Audit Checklist
Audit Planning and Scoping
Review the prior-year audit plan, recent SEC / FINRA exam findings, and the firm's risk register. Scope should map to ADV Part 1 business activities — discretionary AUM, custody arrangements, advertising, private fund activity. Document any scope carve-outs and the rationale.
Registration drives applicable rule set. State-registered RIAs follow NASAA model rule books and recordkeeping; SEC-registered RIAs follow Advisers Act 204-2; dual-registrants pull in FINRA Rule 3110 supervision and Reg BI. Capture the answer here so downstream sections only test the rules that apply.
Pull samples per Rule 204-2: advisory agreements, fee invoices, trade blotters, advertising / RIA marketing pieces, e-comms archive (Smarsh / Global Relay), code of ethics personal trading reports, and complaint log. A 90-day sample window is typical; calibrate sample size to firm AUM and prior findings.
Governance and Risk Management
Pull board / management committee minutes for the audit period. Confirm CCO reports were delivered, risk register was reviewed at least annually, and material incidents (trade errors, complaints, breach attempts) were escalated. Missing minutes are an SEC exam citation magnet.
Confirm the firm has a written risk appetite statement covering investment, operational, compliance, and reputational risk. Verify thresholds are quantified (e.g., max single-position concentration, error account loss tolerance) rather than aspirational language.
SEC Rule 206(4)-7 requires an annual review of compliance policies and procedures. Locate the prior-year review memo, confirm CCO sign-off, and verify findings were tracked to remediation. Missing annual review is one of the most-cited deficiencies in OCIE/Exams reports.
If the prior-year 206(4)-7 review is missing or incomplete, open a finding with a named remediation owner and target close date. This finding must be addressed before the next regulatory exam window — late annual reviews are difficult to defend.
Compliance and Regulatory Adherence
Sample at least 20 client files. Confirm Part 2A brochure delivery within 120 days of fiscal year end and any material change update. Confirm Part 2B delivered for each client's primary advisor. Skipped delivery is the #1 ADV-related citation.
Reg BI / IA Form CRS must be delivered to retail at first recommendation, new account, or new service. Pull the CRM trigger log and reconcile against new account openings in the period. Retain client acknowledgments per the firm's books and records policy.
Pull 15-25 recommendations across rollovers, alts, annuities, and concentrated positions. Verify each file documents the why — costs considered, alternatives considered, and best-interest determination. Boxes-checked-only files do not survive a Reg BI exam.
For each sampled new account, confirm CIP completion, beneficial owner collection on entity accounts (25%+ owners per CDD rule), and OFAC screening on every party including beneficiaries added later. Document any PEP status and EDD evidence.
Pull a sample from the marketing log and Hearsay / Smarsh archive. Confirm pre-approval evidence, performance presentation disclosures (Marketing Rule 206(4)-1), and testimonial / endorsement disclosures where applicable. LinkedIn posts by IARs are a common gap.
For dual-registered firms only. Sample principal review evidence under FINRA Rule 3110 — trade reviews, e-comm sampling, OSJ branch inspection schedule, and Form U4 amendment timeliness. Document any rep with disclosure events that warrant heightened supervision.
Information Security and Data Protection
Verify the written information security program, identity theft prevention program (Red Flags Rule), and annual Reg S-P privacy notice delivery. The 2024 Reg S-P amendments require a 30-day breach notification — confirm the policy reflects this.
Pull entitlement reports for Schwab Advisor Center / Fidelity Wealthscape / Pershing NetX, the CRM (Salesforce, Wealthbox, Redtail), portfolio system (Black Diamond, Orion, Tamarac), and email archive. Confirm quarterly access reviews and timely terminations for offboarded staff.
Confirm policy prohibits personal email and unapproved texting for client communications, and that approved tools (MyRepChat, Hearsay Relate, Smarsh Connected Capture) are deployed. Spot-check rep devices or attestations. The 2022-2024 SEC sweep produced $2B+ in fines for off-channel gaps.
Confirm the business continuity plan was tested in the audit period, the recovery point objective is documented, and offsite / cloud backups are validated. Pull the most recent restore-test evidence — many firms have backups that have never been restored.
Pull the incident log for the audit period and confirm each entry has a triage record, root cause, and remediation. Test a tabletop exercise was held. Wire-fraud near-misses are common and should appear in this log if controls are working.
Financial Reporting and Custody Controls
Three-way reconciliation: fee invoice, custodian fee debit, internal calculation. Sample at least one quarter across the audit period. Confirm fee methodology (average daily balance vs. period-end vs. period-start) matches the IAA — this is the single most common operational error.
Material fee exceptions require client-by-client restitution with interest, written notification, and disclosure on the next ADV amendment under Item 9 if custody implications attach. Loop in outside counsel before notifying clients.
Inventory all SLOAs, bill-pay arrangements, and trustee / POA roles. Confirm each meets the SEC no-action letter conditions: ADV disclosure, signed third-party authorization on file, written confirmation. Inadvertent custody from SLOAs is the most-missed custody trigger.
Confirm same-day reporting and a documented 5-day resolution SLA. Sample error account journal entries; verify gains went back to the client and losses were borne by the firm. Confirm no errors were netted across clients.
If the firm claims GIPS compliance, confirm composite construction, dispersion calculations, and verifier attestation are current. For non-GIPS performance shown in marketing, confirm Marketing Rule disclosures are present and net-of-fee returns are shown alongside any gross figures.
Operational Effectiveness Review
Pull 10-15 new accounts from the period. Verify signed IAA, risk profile (Riskalyze / Tolerisk), KYC documentation, OFAC clear, ACATS confirmation, and CCO sign-off on the new client file. NIGO accounts are a common operational drag — note the rate.
Run a drift report from iRebal / Tamarac / Eclipse. Identify accounts beyond threshold for more than 60 days without an advisor sign-off. Persistent drift in volatile markets is how clients end up off-policy without anyone noticing.
Pull the RMD tracker against the custodian's required-minimum-distribution report. Confirm every applicable client has either taken the RMD or has a scheduled distribution before Dec 31. Missed RMDs trigger a 25% excise tax under SECURE 2.0 and are firm-reputational events.
Sample access-person quarterly reports and pre-clearance logs. Test against the restricted list and front-running thresholds. Confirm initial / annual holdings reports were submitted within 10 / 45 days respectively per Rule 204A-1.
Findings and Sign-Off
Each finding gets a severity rating, named owner, and target close date. Cross-reference to prior-year findings — repeated findings escalate severity automatically and require root-cause analysis, not just remediation.
Walk the committee through findings, residual risk ratings, and remediation timelines. Capture committee responses in the minutes. The minutes are part of the books and records and will be requested at the next exam.
Final audit file with workpapers, sample selections, exception listings, management responses, and CCO sign-off. Retain per books and records (5 years easily accessible, 2 years on-site for SEC RIAs).
Use this template in Manifestly
- Business Continuity Checklist
- KYC Checklist
- Employee Termination Checklist
- Accounts Receivable Checklist
- Employee Performance Review Checklist
- Quarterly Operations and Compliance QA Review
- Quarterly Financial Reporting Checklist
- RIA Acquisition Due Diligence Checklist
- Credit Risk Checklist
- Daily Operations Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Anti-Money Laundering (AML) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- AML / BSA Compliance Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Practice Process Improvement Review
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Month-End Close Checklist
- Disaster Recovery Checklist
- Annual Risk Assessment Checklist
- Advisory Firm Operational Efficiency Review
- Data Security Review Checklist
- Client Risk Profile Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- Client Retention Checklist
- Vendor Management Checklist
- Sales Pipeline Checklist
- Campaign Performance Checklist
- Data Protection Checklist
- Investment Due Diligence Checklist
- Asset Allocation Checklist
- Portfolio Management Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- Advisor and Staff Onboarding Checklist
- Annual Budget Planning Checklist
- Business Continuity Plan Checklist
- Annual Risk Management Review Checklist
- Internal Controls Checklist
- Client Onboarding Checklist
- Client Communication Checklist
- Annual Client Review Checklist
- Market Risk Checklist
- Marketing Strategy Checklist
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
