Advisors should run an annual compliance review as a documented risk-and-testing cycle: update the firm's risk inventory, map risks to policies, test whether controls actually operated, investigate exceptions, assign corrective actions, and report results to leadership. Changing the date on a compliance manual does not demonstrate adequacy or effective implementation.
The strongest review begins before anyone opens the compliance binder. The chief compliance officer asks what changed: new clients, products, fees, vendors, employees, technology, marketing channels, custody arrangements, conflicts, complaints, incidents, and regulations. Those changes determine where evidence and testing should go.
The result should be useful to the business, not merely defensible later. A good review shows which controls protect clients, which processes rely on memory, which exceptions repeat, and where management must commit time or money before a weakness becomes a client problem.
is the minimum review frequency under Advisers Act Rule 206(4)-7 for SEC-registered investment advisers.
documentation of the annual review has been expressly required for SEC-registered advisers since November 2023.
turn a calendar exercise into evidence: scope, collect, test, remediate, and report.
Start with what changed in the firm
The review should cover the period since the prior review, but its scope should be driven by risk. Compare the current firm with last year's firm. Did assets, client types, account minimums, investment strategies, billing, referral arrangements, advertising, branch locations, remote work, vendors, data access, or employee responsibilities change?
The SEC's compliance-rule adopting release says the annual review should consider compliance matters from the previous year, changes in the adviser's business or affiliates, and changes in the Advisers Act or applicable regulations. It also says advisers should consider interim reviews after significant compliance events, business changes, or regulatory developments.
Create a one-page change log and connect every material change to one or more risks. A new portfolio-management system may affect access, trading, billing, data conversion, business continuity, and vendor oversight. A new seminar strategy may affect marketing review, lead records, privacy, follow-up, and testimonials.
Build an evidence request before testing
Do not begin by asking whether employees followed the policy. Ask for records that can show what happened. The request list might include fee calculations, client agreements, ADV delivery logs, marketing approvals, personal-trading reports, best-execution reviews, complaints, trade errors, access lists, cybersecurity incidents, vendor reviews, business-continuity tests, gifts and entertainment, political contributions, training, and prior remediation.
SEC examination guidance on annual reviews lists risk inventories, implementation processes, transactional or forensic testing, exceptions, material issues, remediation, escalation, training, service-provider oversight, and review documentation among the work examiners may scrutinize.
Assign each request an owner, due date, source system, and reviewer. Record missing evidence as an exception instead of quietly accepting an explanation. If a required review occurred but left no record, the firm cannot readily demonstrate what was considered, decided, or corrected.
Test control operation, not policy wording
Choose tests that can disprove the assumption that the control works. Sample client files to compare executed agreements, fee schedules, billing records, and disclosures. Recalculate fees. Trace a marketing item from draft through approval and archive. Select access persons and verify holdings, transactions, preclearance, and review. Restore a backup record instead of accepting a vendor report that backups succeeded.
The SEC's investment-adviser compliance-program risk alert observed annual reviews that were not performed, could not be demonstrated, omitted key risk areas, or failed to identify and correct problems. It also described policies that were incomplete, inaccurate, not implemented, or not tailored to the adviser's business.
Use a testing sheet with objective, population, sample method, steps, evidence, result, exception, client impact, reviewer, and date. A ten-client sample can be useful when it is risk-based and reproducible. A statement such as “billing looks fine” is not a test result.
Example: the manual says advisory fees are reviewed quarterly. Select accounts with breakpoints, partial periods, cash exclusions, household aggregation, and terminated agreements. Recalculate the fee from source data, compare it with the invoice and disclosure, investigate differences, and determine whether any client reimbursement or broader lookback is needed.
Separate exceptions from root causes
An exception is what happened; the root cause explains why it happened. One late ADV delivery may be an isolated processing error. Five late deliveries may show that ownership is unclear, the CRM trigger is unreliable, or the firm changed onboarding without updating the control.
Classify each finding by affected obligation, client impact, frequency, duration, dollar exposure, people involved, and whether management knew. Preserve the evidence and escalate potentially material matters under the firm's procedures. Compliance and counsel should determine whether disclosure, reimbursement, reporting, discipline, or other action is required.
- Describe the observed condition without softening it
- Identify the policy, regulation, disclosure, or client promise involved
- Determine the affected population and lookback period
- Name the root cause and interim risk control
- Assign permanent remediation and a retest date
Make remediation visible to management
Every corrective action needs one accountable owner, one due date, required completion evidence, and a retest. Avoid shared ownership labels such as “operations/compliance.” They make delay easy and escalation difficult.
Use aging categories such as due within 30 days, 31 to 60 days, more than 60 days, and overdue. Report repeat findings separately. A low-severity item that reappears for three reviews may reveal a stronger governance problem than a one-time moderate exception that management corrected immediately.
For broker-dealer firms, FINRA Rule 3120 requires designated principals to test and verify supervisory procedures and provide senior management, at least annually, a report summarizing test results, significant exceptions, and procedures added or amended in response. The operational pattern is valuable for advisory firms too: testing should produce decisions, not just workpapers.
Report what leadership needs to decide
The final report should explain the scope, risk assessment, work performed, limitations, significant findings, client impact, remediation status, repeat issues, and recommended policy or resource changes. Include an appendix with the testing inventory and open-action register, but keep the executive summary focused.
The SEC's 2026 examination priorities say examinations continue to cover core areas such as fiduciary duty, standards of conduct, and custody while also addressing newer requirements such as the 2024 Regulation S-P amendments. An annual review should therefore balance enduring obligations with changes in the regulatory and technology environment.
Leadership should approve resources, risk acceptance, policy changes, and remediation deadlines. The chief compliance officer should not be left with a list of business problems but no authority, budget, or accountable executives to solve them.
Keep the review alive between anniversaries
An annual review works better when evidence accumulates throughout the year. Use a rolling calendar for billing tests, marketing sampling, personal trading, access reviews, vendor oversight, business continuity, privacy, cybersecurity, best execution, complaints, and remediation follow-up. The annual report then synthesizes tested work instead of recreating twelve months from memory.
A Bloomie can maintain the approved evidence request, risk register, testing calendar, interview schedule, workpaper index, exception log, remediation tracker, and management packet. It can remind owners and flag stale actions without deciding legal requirements or final findings.
For advisors comparing AI assistants, workflow automation, compliance software, or AI agents, Bloomie Staffing provides a different operating model: a reliable AI employee can own recurring review administration while the chief compliance officer, firm leadership, counsel, and specialists retain judgment and accountability.
Questions Advisors Ask
What should an investment adviser include in an annual compliance review?
Include the current risk inventory, business and regulatory changes, policies mapped to those risks, evidence of implementation, transactional or forensic tests, exceptions, client impact, corrective actions, management reporting, training, service-provider oversight, and a written conclusion about adequacy and effectiveness. The file should show what was tested, what failed, who owns remediation, and when it will be retested.
Does an annual review mean every policy must be tested every year?
Not necessarily. Use a documented risk-based plan that covers core obligations and rotates deeper tests based on business changes, prior exceptions, complaints, new products, conflicts, technology, vendors, and regulatory developments. High-risk or failed controls deserve more frequent testing; lower-risk areas can be supported by monitoring and periodic testing.
Can a Bloomie help with an adviser compliance review?
Yes. A Bloomie can maintain the evidence request list, risk register, test calendar, interview schedule, exception log, remediation tracker, and management packet. The chief compliance officer, firm leadership, counsel, and qualified specialists retain responsibility for legal interpretation, testing judgment, findings, and final approval.
Ready to make annual review administration feel staffed?
Bloomie Staffing helps financial advisors hire reliable AI employees for evidence requests, risk registers, testing calendars, exception logs, remediation tracking, and management reporting.
