Financial Services Compliance: What Examiners Actually Test
What Falls Inside the Compliance Perimeter
Firms describe their obligations as if they were one thing. They are four, and each one is enforced by a different body with different tools.
Anti-money laundering and sanctions. The Bank Secrecy Act and its implementing rules in 31 CFR Chapter X, administered by FinCEN, plus the sanctions programs administered by the Office of Foreign Assets Control. These reach banks, broker-dealers, money services businesses, casinos, and, subject to a rule whose effective date has moved, investment advisers.
Securities conduct and disclosure. The Investment Advisers Act for registered advisers, the Securities Exchange Act and FINRA rules for broker-dealers, the Investment Company Act for funds. Fiduciary duty, best execution, fee accuracy, marketing, custody, and books and records all live here.
Privacy, data, and cybersecurity. Regulation S-P, Regulation S-ID, and for New York firms the Department of Financial Services cybersecurity and transaction monitoring parts, which impose their own certifications on a separate calendar.
Prudential and financial responsibility. Net capital, customer protection, FOCUS reporting, and the surprise examination requirements that attach to custody.
A firm can be spotless on three and get an enforcement referral on the fourth. The perimeter is only as good as its weakest documented control.
The AML Program Elements Every Firm Documents
The statutory hook is 31 U.S.C. 5318(h), which requires a program reasonably designed to prevent the institution from being used to launder money or finance terrorism. For broker-dealers the operative regulation is 31 CFR 1023.210, and FINRA enforces the same content through Rule 3310.
The elements are usually described as five pillars. Written policies, procedures, and internal controls. A designated AML compliance officer with authority and access to senior management. Ongoing training for appropriate personnel. Independent testing by someone outside the AML function. And customer due diligence, added as a formal pillar by the rule at 31 CFR 1010.230, which requires identifying and verifying beneficial owners of legal entity customers at a 25 percent equity threshold plus a single control person, understanding the nature and purpose of each relationship, and monitoring on an ongoing basis.
Two filings drive the daily work. A Currency Transaction Report under 31 CFR 1010.311 is due for currency transactions of more than $10,000 by or on behalf of one person in one business day, filed within 15 days. A Suspicious Activity Report under 31 CFR 1023.320 is due for a broker-dealer when a transaction involves at least $5,000 and the firm knows, suspects, or has reason to suspect it involves illegal funds, is designed to evade the rules, has no apparent lawful purpose, or uses the firm to carry out criminal activity. The clock is 30 calendar days from initial detection, extended to 60 if no suspect has been identified, and the filing is confidential.
Independent testing is the pillar most often done badly. It has to be performed by someone not involved in operating the program, it has to be risk-based rather than a checklist walk, and it has to be documented with findings, management responses, and remediation dates. A firm whose testing report says “no exceptions noted” three years running has produced evidence that the testing is not working.
How an SEC Examination Actually Runs
The Division of Examinations selects firms using risk criteria, tips and complaints, disclosure anomalies in Form ADV, and the topics it publishes each year in its examination priorities. Coverage has historically run somewhere around 10 to 15 percent of registered advisers in a given year, so most firms see an exam every several years rather than never.
The sequence is predictable. A phone call and an initial document request letter arrive together, typically asking for two to four years of records across thirty to sixty categories, with a two-week turnaround. Onsite or remote interviews follow with the chief compliance officer, the chief investment officer, operations, and often a portfolio manager. Then a period of silence that can run months. Then either a no-further-action letter or a deficiency letter.
The deficiency letter is where firms learn what the exam was really about. The recurring findings barely change from year to year: fee billing that does not match the advisory agreement, marketing materials that do not satisfy Rule 206(4)-1, an annual compliance review under Rule 206(4)-7 that was never documented, code of ethics reports collected late or not at all, Form ADV disclosures that are stale, and off-channel electronic communications that were never captured under Rule 204-2. That last one has produced enforcement penalties running into the billions of dollars across dozens of firms, and it started as a books and records issue.
Respond in writing, remediate before you respond where you can, and say what you fixed and when. A deficiency letter answered with argument and no correction is the most reliable path to a referral to the Division of Enforcement.
What FINRA Tests at a Broker-Dealer
A broker-dealer carries a second supervisory structure on top of the securities rules. FINRA Rule 3110 requires a written supervisory system, designated supervisors, branch office inspections on a defined cycle, and an annual compliance meeting with every registered person. Rule 3120 requires a supervisory control system and an annual report to senior management summarizing the firm’s testing of it. Rule 3130 requires the chief executive to certify annually that the firm has processes to establish and test those supervisory procedures.
Rule 4530 requires the firm to report specified events, customer complaints, regulatory actions, certain internal conclusions of violations, generally within 30 calendar days of knowing or having reason to know. Firms underreport here constantly, and the reporting failure often costs more than the underlying event would have.
Layered on top is Regulation Best Interest at 17 CFR 240.15l-1, with its care, disclosure, conflict of interest, and compliance obligations, and the Form CRS relationship summary that has to be delivered, filed, and kept current. FINRA publishes an annual regulatory oversight report each winter that reads as a preview of the next examination cycle; it is the single most useful free document in this area and most firms never open it.
The Annual Filing Calendar for a Registered Adviser
Most compliance failures are calendar failures. The dates below assume a December 31 fiscal year end; confirm each one against the current rule text and your own firm’s facts, because thresholds and deadlines change.
| Obligation | Authority | Timing |
|---|---|---|
| Form ADV annual updating amendment | Rule 204-1 | Within 90 days of fiscal year end |
| Delivery or offer of Form ADV Part 2 brochure | Rule 204-3 | Within 120 days of fiscal year end |
| Annual compliance program review | Rule 206(4)-7 | At least annually, documented |
| Access person annual holdings report | Rule 204A-1 | Current within 45 days of the report date |
| Access person quarterly transaction report | Rule 204A-1 | Within 30 days of quarter end |
| Surprise custody examination | Rule 206(4)-2 | Once each calendar year, at an unannounced date |
| Pooled vehicle audited financials to investors | Rule 206(4)-2 | Within 120 days of fund fiscal year end |
| Form 13F holdings report | Exchange Act 13(f) | Within 45 days of each quarter end |
| Annual privacy notice | Regulation S-P | Annually, subject to the delivery exception |
Form PF, Form 13H, Schedules 13D and 13G, state notice filings, and the New York Department of Financial Services certifications each add their own dates for the firms they reach.
The Custody Rule and the Ways Firms Trip on It
Rule 206(4)-2 applies whenever an adviser holds client funds or securities, or has authority to obtain possession of them. Custody triggers four requirements: keep the assets with a qualified custodian, notify clients in writing where the assets are held, have a reasonable belief that the custodian sends account statements at least quarterly, and undergo an annual surprise examination by an independent public accountant registered with the PCAOB, verified on Form ADV-E.
Two exceptions do most of the work. An adviser to a pooled investment vehicle can skip the surprise examination if the fund is audited annually by a PCAOB-registered firm and the audited financials go to investors within 120 days of the fund’s fiscal year end, extended to 180 days for a fund of funds. And an adviser whose only custody arises from the authority to deduct fees still has custody, but is not required to obtain the surprise examination for that reason alone.
The trap is inadvertent custody. Signature authority over a client bank account creates it. Serving as trustee or general partner creates it. A standing letter of authorization allowing the adviser to move money to a third party creates it unless the arrangement satisfies a specific set of conditions the SEC staff has described, including that the client provides written instruction naming the third party, the custodian verifies the instruction, and the adviser has no authority to designate or change the recipient. Holding a client’s private stock certificate in a desk drawer creates it. Firms discover all of this during an exam, after the year in which the surprise examination should have happened.
Related Services from The Reed Corporation
Helpful Guides You Might Also Like
Sources & References
Frequently Asked Questions
What are the required elements of an AML compliance program?
Five. A financial services compliance program has five required elements, and a firm that can produce clean documentation for all five is in reasonable shape even when something goes wrong operationally. The requirement comes from 31 U.S.C. 5318(h), which says the program must be reasonably designed to prevent the institution from being used to launder money or finance terrorism. The Anti-Money Laundering Act of 2020 added that programs should be risk-based and effective, which shifted examiner attention away from whether a control exists and toward whether it does anything.
One: written policies, procedures, and internal controls. Approved in writing by senior management or the board, specific to the firm’s actual products, customers, and geographies. A brokerage that clears through a correspondent and one that self-clears do not have the same risks, and a manual that does not distinguish them is a manual somebody bought rather than wrote.
Two: a designated AML compliance officer. Named, qualified, with authority to act and direct access to senior management. For a broker-dealer the person is identified to FINRA through the contact system, and changes have to be updated promptly.
Three: ongoing training. Role-appropriate rather than uniform. Registered representatives, operations staff, and the finance team need different content, and the training record needs attendance, date, and materials. Annual is the norm; the rule says ongoing.
Four: independent testing. Performed by someone not involved in operating the program, which rules out the AML officer testing her own work. FINRA Rule 3310 calls for testing annually on a calendar-year basis, with a two-year cycle available to firms that do not hold customer accounts and meet specific conditions. The output should be a report with findings, management responses, and dated remediation.
Five: customer due diligence. The rule at 31 CFR 1010.230 requires identifying and verifying the beneficial owners of legal entity customers, each individual owning 25 percent or more of the equity, plus one individual with significant managerial control, and it requires understanding the nature and purpose of each relationship and conducting ongoing monitoring to update information and identify suspicious activity.
Reporting sits on top of the five. A Currency Transaction Report under 31 CFR 1010.311 is required for currency transactions above $10,000 by or on behalf of the same person in one business day, aggregated, and filed within 15 days. A Suspicious Activity Report under 31 CFR 1023.320 is required for a broker-dealer when a transaction of at least $5,000 raises one of the four statutory suspicions, filed within 30 calendar days of initial detection, or 60 if no suspect is identified. Filing is confidential and disclosing it to the subject is itself a violation.
Here is what the arithmetic looks like in practice. A retail brokerage customer wires in $9,400 on a Monday, $9,300 on Wednesday, and $9,600 the following Tuesday from three accounts at two banks, then requests a check to a fourth party who is not on the account. No single transaction hits the $10,000 CTR threshold, which is precisely the point, and is what makes the pattern reportable rather than the amounts. Initial detection occurs when the surveillance analyst opens the alert, not when the last wire clears. From that date the firm has 30 days. If the review takes six weeks because the relationship manager is on vacation, the SAR is late even if it is thorough, and lateness is the finding an examiner writes up.
Sanctions screening is a separate obligation that firms fold into the AML function without always documenting it separately. OFAC screening is not a Bank Secrecy Act requirement; it is a strict liability regime with its own penalties, and a firm that screens at onboarding but never rescreens the book against list updates has a gap that no AML testing scope will find unless someone wrote it into the scope.
Three adjacent requirements ride alongside the five pillars and belong in the same manual. The customer identification program rule at 31 CFR 1023.220 requires risk-based procedures for verifying the identity of each customer opening an account, with defined minimum data elements, a documented verification method, and recordkeeping. The information request system at 31 CFR 1010.520, usually called 314(a), requires a designated contact to search records against law enforcement lists on the published cycle and respond within the stated window, with a log proving each search happened even when there was nothing to report. The voluntary sharing provision at 31 CFR 1010.540, known as 314(b), lets registered institutions share information with each other under a safe harbor after filing a notice with FinCEN and renewing it annually. Firms that never filed the 314(b) notice gave up a defense they could have had for free, and firms that let the 314(a) search log lapse hand an examiner a finding that takes ninety seconds to write.
The common mistake: treating independent testing as a compliance-department deliverable rather than an audit. Reports that say “no exceptions noted” year after year signal that the tester sampled what the firm handed over instead of pulling their own population. Examiners read the testing report first, and a thin one changes the tone of the entire exam. The second common mistake is a beneficial ownership file that was collected at onboarding in 2019 and never refreshed, on entities whose ownership has changed twice since.
Looking ahead, the biggest open question for many firms is whether and when investment advisers become subject to a full program requirement. FinCEN adopted a rule in 2024 that would have applied program and SAR obligations to many registered advisers beginning January 1, 2026, then announced in 2025 that it intended to postpone the date and reconsider the rule. Confirm the current position at FinCEN before you build or defer a build. Advisers who already run a documented know-your-customer and screening process will have far less to do whenever the requirement lands, and the work has independent value with institutional allocators who ask about it in diligence. Our forensic accountant guide covers what happens when a monitoring gap turns into an investigation. This page is general information and not legal or compliance advice for your firm.
What does the SEC examine during an investment adviser exam, and how should a firm prepare?
Financial services compliance examinations are risk-targeted, not random, and the targeting is visible in advance. The Division of Examinations publishes its priorities each year, issues risk alerts through the year describing what staff found in recent sweeps, and selects firms using Form ADV data, disclosure changes, tips and complaints, prior deficiencies, and time since last exam. A firm that reads the priorities and the risk alerts knows roughly 80 percent of what will be asked.
The mechanics are consistent. An advance call, then an initial request letter covering two to four years and thirty to sixty document categories: the compliance manual and code of ethics, the annual review documentation, advisory agreements, a trade blotter, the full client list with fees charged, marketing materials, custody arrangements, electronic communications policies, personal trading records, business continuity plans, and vendor oversight files. Two weeks is a typical production window. Interviews follow. Then a quiet period, then either a no-further-action letter or a deficiency letter listing findings.
The findings repeat across firms with striking consistency. Fee billing that does not match the advisory agreement is the single most common. Marketing that does not satisfy Rule 206(4)-1, performance shown gross without equally prominent net, hypothetical performance distributed without the required policies, testimonials without the compensation and conflict disclosures. Annual review under Rule 206(4)-7 that either did not happen or happened without a written record. Code of ethics reporting under Rule 204A-1 collected late, incompletely, or not reviewed. Books and records under Rule 204-2, especially business communications conducted on personal devices and messaging apps that were never captured.
Work an example with real money in it. A New York adviser with $480 million under management bills quarterly in advance at 1.00 percent on the first $2 million and 0.75 percent above that. Twelve years ago the firm agreed in writing to grandfather nine legacy clients at a flat 0.60 percent. The billing system was migrated in year six and the override did not carry over. The exam sample pulls six accounts, two are legacy, and both were billed at the standard schedule. Extrapolated across nine clients and six years, the overbilling is roughly $62,000. The firm now owes reimbursement plus interest, a disclosure to affected clients, and a remediation plan, and the deficiency letter will describe it as a failure to adopt and implement policies reasonably designed to prevent violations. The dollar amount is small. The characterization is what matters, because it is the same language used in enforcement actions.
Preparation that actually works is a mock exam. Take the current-year priorities and the most recent risk alerts, build a request list, produce the documents on the same timeline the staff would give you, and have someone outside the compliance function read the production the way an examiner would. Firms that do this find the same three or four gaps every time: the annual review memo that exists as a slide deck with no testing behind it, personal trading reports collected but never compared to firm trading, and a marketing file with a fact sheet nobody re-approved after the composite changed.
Three operational habits shorten every exam. Keep a permanent exam binder with the compliance manual, the annual reviews, the code of ethics with signed acknowledgments, and the testing files, updated as things change rather than assembled under deadline. Reconcile advisory fees to the agreements at least annually on a sampled basis and document the sample. And run a quarterly attestation on electronic communications channels, because the off-channel problem is not solved by a policy prohibiting texting. It is solved by capture, supervision, and evidence that someone looked.
One document does more work than any other during an exam, and almost nobody builds it until the request letter arrives: a single spreadsheet mapping every client to the fee schedule in the signed agreement, the fee actually billed each quarter, the account value used, and the billing method. Examiners reconstruct that table themselves from the advisory agreements and the custodial billing files, and whatever they find becomes the finding. A firm that maintains it internally and reviews a sample every year either catches the discrepancy first or can show the staff a dated review proving the control works. That is the difference between a reimbursement and a characterization of failure to implement. The same logic applies to a marketing inventory listing every piece in use, the date it was approved, who approved it, and the performance source behind each number. Both documents take a week to build and about two hours a quarter to maintain.
Two rule areas have moved recently enough to deserve their own preparation. Regulation S-P at 17 CFR Part 248 was amended to require covered institutions to maintain a written incident response program addressing unauthorized access to customer information, and to notify affected individuals within a defined period after becoming aware of an incident, with phased compliance dates that differ for larger and smaller entities. Regulation S-ID in the same part requires an identity theft prevention program with red flags identified, detected, and responded to, plus periodic reporting to the board or senior management. Neither is a technology purchase. Both are documentation exercises a firm can finish in a week and then fail for three years by never testing. Ask whether you could produce, today, the last dated test of the incident response plan and the last red flags program report. If the answer is no, that is item one on the exam preparation list.
The common mistake: arguing with the deficiency letter instead of fixing the underlying issue. Staff expect a written response; what they are reading for is whether the firm understood the problem and corrected it. A response that disputes every finding without remediating any of them is the most reliable route to a referral to the Division of Enforcement, which changes the matter from a compliance exercise into a legal one with a different budget. The second mistake is producing documents that were created after the request letter arrived and not saying so. Metadata exists, examiners check it, and a backdated annual review turns a deficiency into a credibility problem.
Going forward, assume the electronic communications issue is permanent rather than a passing sweep, assume artificial intelligence tools used in research or client communication will be asked about, and assume vendor and third-party oversight files will be requested. The firms that do well are not the ones with the longest manuals. They are the ones that can hand over a dated testing file for every material policy. Our SOC report guide covers the control testing framework that institutional clients ask about alongside all of this. This is general information and not legal or compliance advice about your firm.
What is the custody rule, and when does an adviser have custody without realizing it?
Rule 206(4)-2 under the Investment Advisers Act defines custody as holding client funds or securities, directly or indirectly, or having any authority to obtain possession of them. That second half is where firms get caught, because authority is enough. You do not have to touch the money.
When custody exists, four obligations follow. Maintain the assets with a qualified custodian, a bank, a registered broker-dealer, a futures commission merchant, or a qualifying foreign financial institution. Provide written notice to the client identifying the custodian and the manner in which assets are held, and update it when it changes. Form a reasonable belief, after due inquiry, that the custodian delivers account statements directly to clients at least quarterly. And obtain an annual surprise examination by an independent public accountant registered with and inspected by the PCAOB, at a date the adviser does not choose, with the accountant filing Form ADV-E and, if the engagement terminates, a statement describing why.
Two exceptions carry most of the industry. First, an adviser whose only custody comes from the authority to deduct advisory fees from client accounts has custody but does not need the surprise examination on that basis alone. Second, an adviser to a pooled investment vehicle can substitute an annual financial statement audit for the surprise examination and the account statement delivery, provided the audit is by a PCAOB-registered and inspected firm, is prepared under generally accepted accounting principles, and is distributed to all investors within 120 days of the fund’s fiscal year end, 180 days for a fund of funds. Miss the 120-day mark and the exception evaporates for the year, retroactively.
Now the inadvertent versions, which is what the question is really about. Signature authority over a client’s checking account, even for a single elderly client as an accommodation, is custody. Serving as trustee of a client trust, or as general partner or managing member of a fund, is custody. Standing letters of authorization that let the adviser move money to a third party create custody unless the arrangement meets a specific set of conditions the SEC staff described in guidance, including that the client provides written, signed instruction to the qualified custodian naming the third party, that the client can terminate or change the instruction, that the custodian verifies the instruction and sends a transfer notice, and that the adviser has no authority to designate or change the identity of the recipient. Custody of private securities, a subscription document, an LLC certificate, a stock power sitting in a file, is custody unless a narrow privately offered securities exception applies. And possession of client login credentials with the ability to transfer funds is treated as custody by examiners even where the firm insists it never used them.
Price it out, because the cost drives the decision. A surprise examination for a firm with a few hundred separately managed accounts commonly runs $8,000 to $25,000 depending on account count and custodian mix, and it must happen every calendar year. A fund audit for a $40 million private fund typically runs $15,000 to $40,000. An adviser that discovers in year three that its standing letters of authorization did not meet the staff conditions has three missed surprise examinations, which cannot be performed retroactively, and a Form ADV Item 9 that has been wrong for three annual amendments. That is a disclosure problem layered on a custody problem, and disclosure problems are the ones that produce enforcement rather than deficiency letters.
Form ADV Item 9 is the tell. It asks whether the adviser has custody, in what amount, and over how many clients. Examiners compare that answer to the advisory agreements, the custodial arrangements, and the standing instruction files. A firm reporting no custody while holding general partner status in a fund has effectively flagged itself.
Books and records tie the custody analysis together. Rule 204-2 requires an adviser with custody to keep a journal of all receipts and disbursements of client funds, a separate ledger for each client account showing purchases, sales, receipts, and deliveries, copies of confirmations, and a record showing each security position by client. Most firms with inadvertent custody have none of that, because they never concluded they had custody in the first place. When an examiner reaches the opposite conclusion, the custody finding and a books and records finding arrive together, and the second is harder to remediate because prior-year records cannot be recreated. The Division of Examinations has published risk alerts describing these exact fact patterns, and reading them is a faster education than any summary.
The common mistake: assuming that because a third-party qualified custodian holds everything, the adviser does not have custody. Custody is about authority, not location. The second common mistake is the 120-day audit deadline for private funds. Fund administrators and auditors routinely slip past it, and the adviser, not the auditor, bears the consequence. Build the audit timeline backward from the deadline with a three-week buffer, and put the distribution date in the compliance calendar rather than trusting the fund administrator to manage it.
Worth noting for planning purposes: the SEC proposed a broader safeguarding rule in 2023 that would have extended custody-style requirements to a wider range of client assets, and its status has shifted since. Anything you read about that proposal should be checked against current SEC materials at the Division of Investment Management before you plan around it. In the meantime, the practical move is an annual custody inventory: list every client relationship, every account, every authority the firm holds, and every fund entity where a firm principal is a general partner or trustee, then map each one to a custody conclusion in writing. Firms that do this once are usually surprised by at least one item. Our client accounting services team builds the reconciliations that support that inventory. This page is general information rather than compliance or legal advice; talk to a licensed CPA and securities counsel about your own arrangements.
What belongs on a financial services compliance calendar?
Everything with a deadline, and the deadlines that are not on anyone’s calendar are the ones that get missed. A registered investment adviser with a December 31 fiscal year end runs roughly this cycle. Confirm each date against the current rule text, because thresholds and timing change and a stale calendar is worse than no calendar at all.
January. Access person quarterly transaction reports for the fourth quarter are due within 30 days of quarter end under Rule 204A-1. Annual code of ethics acknowledgments go out. Firms that file a Form 13F under Exchange Act section 13(f) have 45 days from quarter end. The prior year’s compliance testing wraps up so it can feed the annual review.
February and March. The Form ADV annual updating amendment is due within 90 days of fiscal year end under Rule 204-1, which is March 31 for a calendar-year firm. That filing pulls in updated assets under management, client counts, disciplinary disclosure, custody answers, and any change in the advisory business. Part 2A gets refreshed at the same time. State notice filings renew alongside it, and the fee is charged automatically against the firm’s account, so an underfunded account is its own way to miss the deadline.
April. Delivery or offer of the updated Form ADV Part 2A brochure to existing clients is due within 120 days of fiscal year end under Rule 204-3. Private fund audited financial statements are due to investors within 120 days of the fund’s fiscal year end under the custody rule. First quarter access person reports come due at the end of the month. New York firms subject to the Department of Financial Services cybersecurity and transaction monitoring parts file annual certifications on their own schedule and should confirm the current date directly with the department.
Through the year. Annual compliance review documentation under Rule 206(4)-7, the rule says at least annually, and the workable approach is to test different areas each quarter and write the summary once. The surprise custody examination, which by definition the adviser cannot schedule but which must occur once each calendar year. The annual privacy notice under Regulation S-P unless the delivery exception applies. A business continuity plan test. Vendor and third-party reviews. A cybersecurity tabletop exercise and an incident response plan review. Anti-money laundering independent testing for firms subject to it. And for broker-dealers, the annual compliance meeting under FINRA Rule 3110, the supervisory controls report under Rule 3120, and the chief executive certification under Rule 3130.
Event-driven, not calendar-driven. These are the ones firms actually miss, because nothing prompts them. Form ADV other-than-annual amendments when specified items change, promptly. FINRA Rule 4530 reporting within 30 calendar days of knowing or having reason to know of a reportable event. Form U4 amendments within 30 days. Schedule 13D and 13G filings on their own triggers and timelines. Form 13H for large traders. Suspicious activity reports within 30 days of initial detection. Regulation S-P customer notification after a data incident, on a clock that starts when the firm becomes aware.
Here is what a miss costs in cash. A firm with $310 million under management files its Form ADV annual updating amendment on April 18 instead of March 31, because the chief compliance officer was covering for a departed operations lead. The filing fee is a few hundred dollars either way. The real exposure is that the firm was, for eighteen days, an adviser whose registration information was not current, which becomes an examination finding, appears in the deficiency letter alongside whatever else the staff found, and gets described to a prospective institutional client during operational due diligence two years later when they pull the ADV history. There is no line-item penalty. The cost shows up as a lost mandate worth $40,000 a year in fees.
State-registered advisers run a parallel calendar that federal summaries usually skip. A firm under the federal threshold registers with each state where it has a place of business or enough clients to lose an exemption, renews annually through the same electronic system, and answers to a state examiner whose priorities are frequently different from the SEC staff. Investment adviser representative registration, continuing education, surety bonds in some states, and minimum net worth or balance sheet requirements all appear on the state side and nowhere in the federal rules. New York firms carry an extra layer, since advisers doing business in the state have registration and filing obligations administered separately from the SEC. Build the state calendar from each state administrator and its own published requirements rather than from a national checklist, and re-check it whenever the firm adds a client in a new state, because the client count that triggers registration is often as low as five. Privacy notice delivery under 17 CFR 248.30 and the safeguards obligations that go with it apply no matter which regulator holds the registration.
The common mistake: keeping the calendar in one person’s head or in a spreadsheet only that person opens. When a compliance officer leaves, the knowledge of which items are event-driven leaves with them. Put the calendar in a shared system with named owners, due dates, and attached evidence, and review it at a standing quarterly meeting with a principal in the room. The second mistake is treating the annual review as a document produced in December rather than a year of testing summarized in December. Examiners can tell the difference in about four minutes.
Looking ahead, add two items most calendars still lack: a scheduled review of every electronic communication channel with an attestation from each employee, and a dated check each January of whether any new rule compliance dates fall in the coming year. Rules adopted with phased compliance dates, privacy and cybersecurity amendments in particular, arrive quietly, and the obligation starts whether or not anyone put it on a list. Our SOX compliance guide covers the parallel control certification cycle that public companies run. This page is general information and not compliance or legal advice for your firm; confirm every date against the current rule text and with counsel.
Does outsourcing compliance or internal audit actually reduce regulatory risk?
Outsourcing financial services compliance reduces execution risk. It does not reduce legal responsibility, and firms that conflate the two buy the wrong engagement.
Start with what the rule requires. Rule 206(4)-7 obligates a registered adviser to adopt and implement written policies reasonably designed to prevent violations, to review them at least annually, and to designate a chief compliance officer responsible for administering them. The rule does not say the officer has to be an employee. What the SEC has said, repeatedly and in enforcement, is that the person must actually know the firm’s business, must be empowered to develop and enforce policies, and must have the standing to escalate. An outsourced officer who visits quarterly, works from a template manual, and has never met the head trader does not meet that standard, and the deficiency lands on the registrant.
Outsourced arrangements that hold up share four features. The scope is written down, including what the provider does and what remains with the firm. The officer has direct access to the principals and a documented escalation path. There is a real testing program with sampled populations and dated workpapers, not a policy library. And someone inside the firm, usually an operating principal, owns the relationship and reviews the output rather than filing it.
Internal audit support answers a different need. For anti-money laundering programs, the independent testing pillar has an independence requirement that is nearly impossible for a small firm to satisfy internally, since the only person who understands the program is the person running it. Bringing in an outside firm solves that cleanly and produces a report with findings a regulator will actually read. For operational and financial controls, co-sourced internal audit gives a firm testing capacity it could never staff, and the same work feeds service organization control reporting when institutional clients ask for it.
Now the economics, which are the reason this question gets asked. A full-time chief compliance officer at a New York advisory firm costs $180,000 to $300,000 in salary plus benefits and payroll taxes, so call it $230,000 to $380,000 loaded. An outsourced arrangement with a credible provider runs roughly $3,500 to $12,000 a month depending on complexity, or $42,000 to $144,000 a year, plus separate fees for the annual review, mock exams, and any AML testing. For a firm with $250 million under management and 180 households, the outsourced path is obviously cheaper. For a firm with $3 billion, several strategies, a private fund, and forty employees, the in-house path is cheaper on a risk-adjusted basis before you even count the value of having someone in the building when a question comes up at 4 p.m.
Work the arithmetic on a specific decision. A firm with $600 million under management pays an outsourced provider $7,500 a month, or $90,000 a year, and adds $18,000 for the annual review and $12,000 for AML independent testing, $120,000 all in. Hiring a mid-level compliance officer at $165,000 plus roughly 25 percent in benefits and taxes costs $206,000, and that person will still need outside help for the independent AML testing because of the independence rule. The $86,000 difference is real. What the firm gives up is availability and institutional memory, and what it must add back is a designated internal owner who reviews the provider’s work. Firms that make the outsourced model succeed treat that internal owner role as a genuine ten percent of somebody’s job, not a title.
It helps to know how an examiner probes the arrangement, because the questions are consistent. Who wrote these policies. When did you last change one, and why. Walk me through the last time you told a principal no. Show me the testing you performed on fee billing this year, and show me the sample. How many other firms do you serve. How many days were you onsite. Who at the firm reviews your work. None of those questions are about the manual. They are about whether the compliance function has a pulse. A provider who answers them with dated files is worth several times one who cannot, and the price gap between the two is usually smaller than firms assume. The same logic runs through the books and records obligation in Rule 204-2: outsourcing the work never outsources the requirement that records exist, are accurate, and are produced on request. Where anti-money laundering rules apply, the program requirement in 31 CFR 1023.210 sits on the registrant too, and the Division of Examinations will ask the firm, not the vendor, to explain a gap.
The common mistake: buying a manual and calling it a program. Providers who sell a document library at a low monthly rate are selling the artifact examiners care least about. What gets tested is implementation, the evidence that somebody sampled fee calculations, compared personal trades to firm trades, reviewed marketing materials before use, and wrote down what they found. If the engagement does not produce dated workpapers, it is not reducing risk. The second mistake is failing to check the provider’s own capacity: an outsourced officer serving sixty firms cannot know sixty businesses, and examiners have started asking how many clients a provider covers.
Going forward, get three things in writing before you sign. A scope document listing every task with an owner. A sample of the workpapers the provider produces for a firm like yours, redacted. And an answer on what happens during an examination, who responds to the request letter, who sits in the interviews, and whether that time is included or billed hourly. Examinations are where the value of the arrangement is proven or exposed, and the firms that get surprised by an hourly bill in the middle of an exam are the ones that never asked. Our SOC report guide covers the control reporting that often runs alongside this work, and our business management team supports the operational side. This page is general information and not legal or compliance advice; consult a licensed CPA and securities counsel about your firm’s obligations before you restructure anything.