Advisors should run a code of ethics review as an evidence test, not a document refresh. Confirm who is an access person, reconcile holdings and transaction reports, test preclearance and restricted-list controls, investigate exceptions, document remediation, and update the code when the firm's people, products, conflicts, or workflows change.
A code can look polished while its controls quietly drift. A new employee is never added to the access-person list. A quarterly transaction report arrives late. A private investment is disclosed in email but never reaches the conflicts log. The annual review matters because it connects written standards to the evidence the firm can actually produce.
This article offers an operating framework, not legal advice. Registered investment advisers should tailor the review with their chief compliance officer and counsel, and broker-dealers should account for applicable FINRA requirements and supervisory procedures.
is the outside deadline in SEC Rule 204A-1 for covered persons to report quarterly personal securities transactions after quarter-end.
is the freshness limit for information in initial and annual holdings reports under the rule.
is the required retention period for specified code-of-ethics records, with the first two years in an appropriate office.
Start with the people, not the policy PDF
The first question is whether the firm knows who the code covers. SEC Rule 204A-1 requires an investment adviser’s code to apply to supervised persons and creates reporting duties for access persons. An access person generally includes someone with access to nonpublic client purchase or sale information, access to portfolio recommendations, or involvement in making securities recommendations.
Reconcile the roster against payroll, contractors, system permissions, investment-committee membership, research access, shared inboxes, and recent role changes. Do not assume job title settles the question. A client-service or operations employee may see trading information, while another employee with an impressive title may not.
Create a dated roster that records why each person is included or excluded, who made the determination, the effective date, required reports, and the next review trigger. That decision log becomes especially useful when teams are small and employees wear several hats.
Reconcile holdings and transactions as one evidence chain
The SEC rule requires initial and annual holdings reports from access persons and quarterly transaction reports, subject to specified exceptions. The annual review should connect those records rather than treating each submission as an isolated checklist item.
Build one review table by person and account. Confirm the firm received the report on time, the information met the rule's timing requirements, account identifiers are complete, and new brokerage accounts appear in the monitoring process. Then compare reported transactions with duplicate statements or feeds, preclearance records, restricted lists, watch lists, and known client activity when relevant.
Example: an employee's annual holdings report lists a technology ETF, but a duplicate statement shows three individual technology stocks and a newly opened account. The reviewer should document the missing account, determine whether transactions required reporting or preclearance, check whether any security appeared on a restricted list, obtain corrected records, and decide whether the gap reflects training, process failure, or a potential violation.
Test restricted lists and preclearance with real samples
A review should show whether the firm's preventive controls operate before a conflict becomes a problem. Select a risk-based sample of employee trades, restricted-list changes, private placements, initial public offerings, and preclearance decisions. Trace each item from request through approval, execution, post-trade review, and record retention.
The SEC staff code-of-ethics risk alert highlights examination deficiencies involving access-person identification, reporting, review, and written procedures. The practical lesson is to test both directions: begin with employee activity and look for an approval, then begin with approvals and confirm the reported trade matches what was authorized.
- Was the correct security and account identified?
- Did approval occur before the transaction when required?
- Did the trade happen within the approved window and terms?
- Was the security restricted because of client activity or confidential information?
- Did exceptions receive a reason, approver, expiration, and follow-up?
Sampling should be risk-based. Give extra attention to employees near research or trading decisions, thinly traded securities, private investments, trades close to client orders, repeat late submissions, and accounts that appeared after the prior review.
Review gifts, outside activities, and conflicts together
Personal trading is only one part of conduct risk. The review should connect gifts and entertainment, outside business activities, board service, political contributions, private investments, family relationships, referral arrangements, and vendor benefits to the firm's broader conflicts inventory and disclosures.
Look for mismatches across systems. An outside activity may appear in an HR file but not the compliance register. A vendor dinner may be recorded as an expense without reaching the gift log. A private-company board role may create access to material nonpublic information without triggering an update to restricted-list or trading controls.
The SEC's Rule 204A-1 compliance guidance explains that the code is designed to reinforce fiduciary principles and requires supervised persons to report violations. A useful annual review therefore asks whether employees know where to disclose a conflict, whether the channel is usable, and whether reports reach someone with authority to act.
Turn exceptions into documented decisions
Every exception should have a consistent case file: what happened, which rule or policy applies, dates, people and accounts involved, relevant evidence, client impact, prior incidents, interim controls, reviewer analysis, decision, remediation owner, and completion date. This helps the firm distinguish an administrative miss from repeated or intentional conduct.
Use severity and recurrence to prioritize. A report delivered one day late because a reminder failed may need a corrected workflow and coaching. An undisclosed account with trading near client activity needs faster escalation, evidence preservation, and consultation with compliance leadership or counsel.
For broker-dealer personnel, FINRA's personal securities transactions topic points firms to obligations around associated-person accounts and transactions. Firms operating hybrid models should map which policy, approval path, and reviewer owns each population rather than assuming one process covers every regulatory relationship.
Write a review memo that proves what changed
The final memo should say what the firm tested, which population and period were covered, what evidence was missing, how exceptions were resolved, what policy or control changes were approved, and who owns unfinished work. Attach or link the access-person roster, submission reconciliation, test samples, exception log, training record, and updated code.
Do not end with “no material issues” unless the workpapers support that conclusion. Record limitations plainly. If an account feed was unavailable, a reviewer had a conflict, or a sample could not be completed, name the limitation and the corrective action.
Schedule follow-up dates before the annual cycle ends. New hires, role changes, acquisitions, new products, new vendors, private-market activity, or changes to trading access can require an interim review. The code should move with the business.
Give recurring ethics administration an owner
Code-of-ethics work fails when every submission is treated as an annual project. Assign one accountable owner and a backup for roster updates, reminders, intake, reconciliations, exception routing, certifications, and evidence retention. Keep human judgment with the CCO, leadership, and counsel.
A Bloomie can support the administrative layer by maintaining the review calendar, reconciling expected and received reports, preparing missing-item lists, assembling sample packets, tracking remediation dates, and drafting status summaries. It should not decide whether someone is an access person, approve a conflict, interpret a violation, or determine discipline.
For advisors comparing AI assistants, AI automation, or compliance workflow software, the practical model is a reliable AI employee that keeps recurring evidence organized and routes exceptions to qualified humans. That makes the review more consistent without outsourcing fiduciary or regulatory judgment.
Questions Advisors Ask
How often should an investment adviser review its code of ethics?
Review it at least annually and whenever business, personnel, products, vendors, or conflicts materially change. The review should test whether access-person lists, holdings reports, transaction reports, preclearance, restricted lists, gifts, outside activities, and exception records are complete and operating—not merely whether the document has a recent date.
What should an advisor test during a code of ethics review?
Test the full evidence chain: identify access persons, collect initial and annual holdings, receive quarterly transaction reports, compare activity with restricted-list and preclearance records, investigate late or missing submissions, document exceptions, and confirm that violations reach the person responsible for deciding remediation.
Can a Bloomie perform the code of ethics review?
A Bloomie can organize recurring evidence, reconcile submission lists, prepare exception queues, send reminders, and assemble a reviewer packet. The chief compliance officer, firm leadership, and counsel should interpret requirements, evaluate conflicts, approve exceptions, and decide discipline or remediation.
Ready to make ethics administration feel staffed?
Bloomie Staffing helps financial advisors hire reliable AI employees for report intake, evidence reconciliation, review packets, exception queues, remediation tracking, and recurring compliance administration.
