Advisors should prepare for a regulatory exam by maintaining an indexed request library, proving records can be retrieved quickly, reconciling policies to actual practice, testing high-risk samples, assigning one response coordinator, and documenting remediation. Exam readiness is not a last-minute binder; it is evidence that the firm's daily controls work as described.
An examination notice creates pressure because a small advisory firm still has client meetings, trading, billing, service work, and supervision to run. The answer is not to send every file the firm can find. It is to produce complete, consistent, responsive records through a controlled process.
This playbook is for SEC-registered investment advisers, with a separate books-and-records checkpoint for hybrid firms. It is operational guidance, not legal advice. Compliance leadership and counsel should control scope, interpretations, representations, privilege, and regulator communications.
response coordinator should control the request log, production set, questions, and deadlines.
core adviser review areas were listed in the SEC's published exam-priorities discussion.
of produced files should map to a numbered request, owner, reviewer, and delivery record.
Build the exam library before the request arrives
Start with the categories regulators are likely to request, then map each category to a system, record owner, backup owner, retention rule, review cadence, and retrieval method. A practical library covers organizational records, Form ADV and disclosures, compliance policies, annual-review evidence, client agreements, portfolio and trading data, billing, personal trading, custody, marketing, complaints, cybersecurity, business continuity, vendors, and financial records.
The SEC's investment-adviser examination risk alert explains how staff may assess risk, scope an examination, and request documents. Use its sample categories as a design input, not a promise that every exam will follow one list. The SEC uses a risk-based approach, and the firm's business, disclosures, history, products, clients, and conflicts affect scope.
Keep an index rather than a giant shared drive. Each entry should identify the authoritative file, reporting period, applicable entity, system of record, and last test date. Archive superseded versions, but make the current version unmistakable. If the CCO is the only person who knows where records live, the firm has a key-person problem.
Test retrieval speed and completeness
Run quarterly retrieval drills using numbered requests. Choose a period and ask operations to produce a client list, advisory agreements, invoices, fee calculations, trade blotter, personal-trading reports, complaints, advertisements, approvals, and archived communications. Time the work and record missing fields, access failures, inconsistent exports, and manual dependencies.
FINRA's 2026 books-and-records report identifies testing third-party recordkeeping vendors by simulating regulator requests as an effective practice. That lesson applies operationally even when an RIA follows a different rule set: outsourcing storage does not outsource retrieval accountability.
Example: a firm believes text messages are archived, but a mock request for one representative's messages produces only firm-issued-phone records. The drill reveals that the representative also used a desktop messaging client that was approved but never connected to the archive. Finding that gap during a test allows the firm to preserve records, correct configuration, retrain staff, and document remediation before a live request.
- Can the firm export the complete population, not screenshots?
- Do dates, account IDs, representatives, and entities reconcile across systems?
- Can a backup owner retrieve records when the primary owner is absent?
- Does the vendor preserve metadata and provide usable, searchable files?
Reconcile policies, disclosures, and actual practice
Examiners can compare what the firm says with what it does. Build a three-column control map: policy requirement, operating evidence, and testing result. Link each material Form ADV statement, client disclosure, privacy notice, and marketing claim to an owner and proof. When practice changed, confirm the policy, disclosure, training, and monitoring changed with it.
The SEC's current examination-priorities library shows that published priorities evolve and are not exhaustive. Review the current report, recent risk alerts, deficiency themes, rule changes, and the firm's own incidents. A small RIA should focus first on risks created by its actual services and conflicts rather than building a generic checklist that treats every topic equally.
Interview the people who perform the process. Ask an advisor how fee exceptions reach billing, ask operations how standing letters of authorization are tracked, and ask marketing where the final approved web page is preserved. A beautiful procedure can hide a workaround that employees use every day.
Sample the areas where client harm can occur
Do not wait for an examiner to select the first samples. Build risk-based samples for fees, custody indicators, best-execution reviews, trade allocations, personal trading, conflicts, rollovers, valuation, marketing, complaints, and vulnerable-client events. Include normal items and exceptions, new and old clients, large and small accounts, different custodians, and different employees.
The SEC's fee-calculation observations describe problems such as inaccurate percentages, incorrect account values, billing frequency errors, and failures to aggregate or apply breakpoints. A useful pre-exam fee test recalculates invoices from contracts and account data, then traces credits, refunds, householding, exclusions, and manual overrides.
For custody, do not rely only on the firm's intended business model. Search for powers of attorney, trustee roles, bill-pay authority, login credential possession, check-writing authority, fee deductions, private-fund arrangements, and standing instructions. For marketing, connect the live item to approval, substantiation, disclosures, performance support, promoter records, and the archived final version.
Document the population, selection method, test steps, exceptions, severity, owner, due date, and validation. A sample without a defined population can look selective; a correction without validation can leave the underlying control broken.
Control the response when an exam begins
Name one coordinator and one backup. Preserve the request exactly as received, create a numbered tracker, identify deadlines, assign owners, and route questions through the coordinator. Counsel and the CCO should decide when clarification is needed and review productions for responsiveness, consistency, confidentiality, privilege, and unsupported commentary.
Use a clean production folder separate from working files. For every item, record the request number, description, date range, entity, source system, preparer, reviewer, file name, delivery date, and any agreed limitation. Never alter an original record to make it look cleaner. If an error exists, preserve it, understand it, and address how the response should explain it.
Prepare employees for factual interviews. They should answer the question asked, avoid guessing, identify when they need to verify something, and understand the difference between actual practice and what they assume the policy says. Do not script false uniformity; use mock interviews to find misunderstandings that need correction.
Run a mock exam that produces evidence
A useful mock exam begins with an unannounced sample request, a realistic deadline, and a coordinator who did not assemble every record in advance. Measure retrieval time, completeness, version conflicts, access problems, response quality, and whether owners can explain the controls. Then interview a few employees and trace exceptions back to supervision and remediation.
Score findings by client impact, regulatory exposure, recurrence, breadth, detectability, and time outstanding. Assign a root cause: design gap, operating failure, training, capacity, data quality, vendor configuration, supervision, or unclear ownership. The remediation record should show the immediate correction, population review, control change, owner, deadline, and independent validation.
Consider a 30-day retest for urgent gaps and a 60- or 90-day retest for broader changes. Update policies only after the firm has chosen a workable process. If a vendor caused the failure, preserve tickets and test the fix with a new export rather than accepting a reassurance email.
Give exam readiness a recurring operations owner
Exam readiness deteriorates when it is an annual scramble owned entirely by the CCO. Assign an operations owner for the library index, retrieval drills, evidence requests, issue tracker, certifications, vendor tests, and dashboard reporting. Compliance still sets the standard and evaluates significance; operations keeps the recurring work from disappearing between reviews.
A Bloomie can maintain request indexes, collect files, reconcile lists, flag missing evidence, prepare drill packets, track retrieval times, and chase remediation dates. It should not communicate legal conclusions to a regulator, waive privilege, decide materiality, or replace compliance leadership and counsel.
For advisors comparing AI assistants, AI automation, or compliance workflow tools, a reliable AI employee can support the administrative layer without replacing professional judgment. The value is a current evidence trail: fewer frantic searches, fewer silent access failures, and clearer ownership when the firm needs to respond.
Questions Advisors Ask
What should an investment adviser do first after receiving an exam request?
Name one response coordinator, preserve the original request, build a numbered request tracker, confirm scope and deadlines with exam staff, assign an accountable owner to every item, and require legal and compliance review before each production. Keep one clean production set and a record of exactly what was delivered.
How often should an RIA run a mock regulatory exam?
Run a full mock exam at least annually and smaller retrieval drills quarterly for higher-risk records. Re-test after major system, vendor, strategy, custody, fee, marketing, or personnel changes. The goal is not theater; it is proving the firm can retrieve complete, consistent records and explain its controls.
Can a Bloomie manage a regulatory examination?
A Bloomie can maintain the request tracker, assemble indexed files, flag missing records, reconcile versions, document retrieval times, and prepare status reports. The CCO, executives, counsel, and qualified subject-matter owners remain responsible for regulatory communications, legal judgments, representations, and remediation decisions.
Ready to make exam readiness feel staffed?
Bloomie Staffing helps financial advisors hire reliable AI employees for request libraries, retrieval drills, evidence collection, issue tracking, vendor tests, and recurring compliance administration.
