On September 14, 2026, the SEC’s Division of Examinations published a risk alert on investment adviser annual compliance reviews under Rule 206(4)-7. It sets out six categories of deficiency observed during examinations. Read together, few of them describe a failure of judgment or expertise. They describe reviews that happened late or not at all, procedures that were not followed as written, issues that were identified and then not recorded, and documentation that was produced and then not kept.
This piece argues those are failures of process consistency and record persistence rather than of compliance expertise, which raises a question buyers rarely ask: whether a platform generates the record as a byproduct of the work or assembles it once the examiner’s request arrives. It closes with a test any buyer can run in a demonstration.
What the Staff Observed
1. Conducting timely annual reviews.
Staff observed gaps between review years, such as reviews for 2021 and 2023 with 2022 omitted, and intervals exceeding twelve months, including initial reviews conducted eighteen months after registration. Extended intervals were often attributed to business, operational, and personnel changes, including chief compliance officer departures. Some advisers substituted compliance training or annual attestations of adherence for the review itself.
2. Adopting complete policies and procedures for conducting reviews.
Policies required documentation and testing but did not set out the direction and processes personnel should follow for those tests and validations. Topics mandated for annual testing, such as identity theft policies, were excluded from the reviews actually performed.
3. Conducting reviews consistent with written procedures.
Reviews departed from the defined review period or scope, did not produce the required documentation, or assessed outdated versions of policies rather than current ones.
4. Ensuring policies align with practices.
Reviews failed to surface disconnects between written policy and actual practice, including fee and expense billing that deviated from disclosures, proxy voting policies stating the adviser would vote proxies when in practice it did not, custody procedures omitting steps to identify relevant accounts to the independent accountant, and procedures not updated for Form CRS. Notably, staff also observed incidents of non-compliance that were identified and reported during the review period but were not addressed or recorded in the annual review.
5. Maintaining documentation.
Advisers created documentation during testing and in recommending corrective action but did not retain it in their books and records. Written reports their own policies required were not prepared, or formats the policies specified, including checklists, work papers, and templates, were only partially completed.
6. Taking corrective action on identified issues.
Advisers did not implement the recommendations their own reviews produced, in some cases representing that corrective actions had been taken while the underlying issues persisted.
The Common Thread
Consider what it takes to fail each of these:
- A review conducted thoroughly but three months late fails the first.
- A review conducted competently by an experienced compliance officer who did not follow the firm’s own work paper process fails the third.
- A review that identified real problems and left no retained record fails the fifth.
- A review whose recommendations were never carried out fails the sixth.
In each case the underlying compliance judgment may have been sound. What was missing was a process that ran on schedule regardless of what else happened that quarter, a record that survived without someone remembering to create it, and a mechanism that carried a finding through to its resolution.
Two observations in the alert are worth sitting with:
- A chief compliance officer’s departure was enough to extend review intervals past the rule’s requirement, which says the process lived with a person rather than in a system.
- And non-compliance incidents were identified and reported during the period, then never made it into the annual review, which says the information existed somewhere in the firm and did not travel.
Where Technology Enters, and Where It Stops Helping
The alert never mentions technology. It does not recommend software, name a category of product, or discuss automation anywhere. That absence makes the point more effectively than an endorsement would, because the staff are describing outcomes, and those outcomes are difficult to produce by hand with any consistency.
The conclusion most readers draw is that a firm should be running its compliance program on a platform. That conclusion is incomplete, because platforms differ on the exact dimensions the fifth and sixth deficiencies test.
A platform assembled from separately built modules, whether developed over years or acquired, keeps review records, certifications, exceptions, and case history in systems that synchronize rather than share a data model. An incident logged in one module does not necessarily reach the annual review compiled in another, which is precisely the failure the staff described. And when an examiner requests documentation, producing a complete record means exporting from several places and reconciling the results first. That is the same reconstruction problem a manual program has, performed faster and with better tooling, and performed after the fact all the same. The seams do not show during ordinary operation. They show on a deadline.
A platform built on a single data model behaves differently. The review runs on a schedule the system enforces rather than one a person remembers. An identified incident is a record that links to the policy it implicates, the corrective action it generated, and whether that action was completed. When the request arrives, the documentation already exists in the form the examiner asked for, because assembling it was never a separate task.
Skematic was built this way deliberately, starting with the workflow and data layer rather than with individual compliance functions, because its founders had spent years watching what happens to platforms assembled the other way. The annual review, the compliance calendar, certifications, trade surveillance, and case management run on one model. An incident raised in March is already part of the record the review compiles in December, and the evidence of both persists without anyone maintaining it.
Documentation generated as a byproduct of the work is difficult to lose. Documentation assembled when someone remembers to assemble it is what the staff kept finding missing.
How to Test This Before You Need It
Ask a vendor to produce, live in the demonstration, what an examiner would request: the annual review for a given period, the testing performed, the exceptions identified, the corrective action taken on each, and the written report the firm’s own procedures require. Watch how it is assembled. Whether it comes from one place or several is the whole question, and it is visible in about ninety seconds.
The test is worth running on every vendor under consideration, whether that is Comply, ACA, StarCompliance, MCO, one of the newer entrants such as Hadrius or Greenboard, or Skematic. It is the rare evaluation question that cannot be answered with a capability claim.
Then ask who helps if that request arrives on a Thursday with a Monday deadline, and what that person did before joining the vendor. At Skematic the answer is generally a former compliance officer who has produced that record for an examiner before. Brian Kesselman, a Skematic founder, spent years assembling these records by hand and answering for the process afterward, which is a substantial part of why the platform generates them continuously instead.
The Division closed by encouraging advisers to reflect on their own practices and implement appropriate modifications, noting that what is adequate depends on each firm’s profile and circumstances. That is the right frame. The question this alert raises is not whether a compliance program is well run, but whether it would still produce the evidence if the person running it were unavailable the week the request arrived.