Year-End Compliance Checklist for Investment Advisers

As the new year approaches, now is a crucial time of year for investment advisers to ensure that their compliance programs are up to speed. The SEC’s Risk Alerts and examination findings offer important insight into areas currently under scrutiny, and provide a good starting point for firms when reviewing compliance programs.

Among the SEC’s enduring areas of focus is off-channel communications. The agency has zeroed in on ensuring accurate recordkeeping of business communications, especially those conducted on off-channel platforms like personal devices, and has stressed that advisers must properly archive all business-related communications and make them accessible during examinations to meet regulatory requirements.

The SEC has also scrutinized firms’ compliance with reporting obligations under Section 13(f) of the Securities Exchange Act of 1934, focusing on the accuracy and timeliness of filings, and it continues to prioritize compliance with the Marketing Rule, with particular attention to accurate recordkeeping and disclosure practices.

To help investment advisers prepare, we’ve created a detailed checklist with compliance steps to run before year-end,[1] plus a few developments to keep on your radar for the year ahead. This is designed as an evergreen resource — use it each year, and confirm current dates and requirements as you go.

Registration, Disclosures & Recordkeeping

  • Registration Forms and Disclosure Documents – Review current registration forms and client disclosure documents (e.g., Form ADV, Form CRS, prospectus and statement of additional information, and private placement memorandums) to ensure they are up-to-date and contain required and applicable disclosures.
    • Compliance Step: Review the SEC-issued guidelines for the relevant documents to confirm that all instructions have been followed and required information is included. Consider taking a look at recent SEC enforcement actions to gain insight into the specific disclosures they expect.
  • Form U-4 and Form ADV Part 2Bs – Ensure that all registered personnel have reviewed their current Form U-4 and Form ADV Part 2Bs, as applicable, and confirmed that the information is correct and up to date.
    • Compliance Step: Have each representative provide a written certification that disclosures are accurate and there are no (or no new) disciplinary or legal issues to disclose.
  • Legal Review of Client Agreements – Have legal counsel with securities law expertise review standard client agreement(s) for required and necessary provisions and consistency with disclosures in Form ADV.
    • Compliance Step: Discuss with legal counsel any new or potential future business changes that could impact your client agreements, including plans to offer new products or services, changes in fee structures, or expansion into new markets.
  • Federal and State Filings – Confirm that all applicable required federal and/or state filings are made, such as Form 13F, Form 13H (Large Trader), Form N-PX, Schedule 13D/G, Form PF and Form D (private funds), NFA filings, state net capital filings, state registrations and/or notice filings for firm and representatives, and state blue sky filings (private funds).
    • Compliance Step: Form N-PX is required for institutional managers (Form 13F filers), who must report annually on how they voted on “say-on-pay” related matters via submission of the Form N-PX.[7]
    • Compliance Step: Consider using an automated system to program and track all filing deadlines, and investigate third-party outsourcing solutions to assist with the filings.
  • Books and Records – Perform and document a detailed review of your firm’s books and records.
    • Compliance Step: Keeping in mind recent SEC enforcement actions, it is important to ensure you are capturing and retaining required business communications, including those conducted through off-channel platforms such as Microsoft Teams, WhatsApp, and other messaging tools.
    • Compliance Step: The SEC’s move to a T+1 settlement cycle (effective May 2024) introduced recordkeeping obligations for advisers, requiring them to retain copies of all confirmations received, as well as any allocations and affirmations sent or received, with corresponding date and time stamps. Advisers should review and update their recordkeeping policies and procedures accordingly, ensuring alignment with broker-dealers for completing same-day affirmations.
  • IARD Renewal Calendar[8] Review the IARD (Investment Adviser Registration Depository) Renewal Calendar and schedule all applicable deadlines to ensure timely filings and renewal payments.
    • Compliance Step: Your IARD “Preliminary Renewal Statement,” which outlines your firm’s annual IARD charges and state renewal fees, typically becomes available via your IARD account in early-to-mid November, with renewal fees generally due in early-to-mid December. Confirm this year’s exact dates on the current IARD Renewal Program calendar.
    • Compliance Step: Determine whether any post-dated U-5 filings are needed to remove unnecessary state registrations.

Compliance Program, Reviews & Training

  • Risk Assessment and Conflicts Inventory – Conduct a risk assessment and conflicts inventory to determine if all material risks and conflicts have been properly identified, addressed and disclosed as appropriate.
    • Compliance Step: Take time to map each risk and conflict identified to corresponding policies and procedures, to ensure there are adequate controls in place to either eliminate or mitigate these risks. If gaps are found, update or create new policies and procedures to fill them as needed.
  • Annual Review – Ensure that your annual review is performed and documented[4] as required under Rule 206(4)-7 of the Investment Advisers Act of 1940 (“Advisers Act”).
    • Compliance Step: Ensure that compliance testing protocols are properly set up to identify not only process gaps but also trends or patterns that could signal systemic risks.
    • Compliance Step: Additionally, confirm that all recommendations from the previous year’s annual review have been successfully addressed and that any suggested changes have been implemented and are working as intended.
  • ERISA PTE 2020-02 Annual Review – Complete the annual retrospective review required under ERISA PTE 2020-02, and ensure an executed certification from a senior manager is obtained.
    • Compliance Step: Review the documentation provided to clients supporting rollover recommendations to ensure it clearly demonstrates that the rollover is in the client’s best interest, and confirm that all representatives fully understand the associated requirements.
  • Compliance Calendar – Review your compliance calendar to ensure all steps outlined in your policies and procedures have been completed or are on track to be completed.
    • Compliance Step: Prepare your compliance calendar for the upcoming year by incorporating any regulatory changes, such as new rules, rule amendments, or updates to industry best practices, that will impact your firm.
    • Compliance Step: Look into implementing compliance technology to streamline the management of your compliance calendar. These tools can help automate the tracking of tasks, send reminders for upcoming deadlines, and document the completion of each task.
  • SEC Regulatory Examination Prep – Be proactive in ensuring your firm is ready for a regulatory examination.
  • Employee Training – Provide training to firm personnel that covers compliance policies and procedures, cybersecurity, business continuity, privacy safeguards, identity theft red flags, dealing with senior investors (required Senior Safe Act training), off-channel communications, as well as the Marketing Rule and advertising requirements (just to name a few).
    • Compliance Step: Training can be delivered in a variety of ways throughout the year. Methods include compliance emails (i.e., friendly reminders of compliance requirements), live or recorded webinars hosted by legal or compliance consultation firms, in-person compliance meetings, and third-party educational videos.
    • Compliance Step: Assess whether any training can count toward required continuing education credits.
  • Continuing Education – Confirm that investment adviser representatives have completed their state-mandated continuing education requirements, which apply in a growing number of states.
    • Compliance Step: Review the list of states requiring CE via the NASAA website[5] and remind IARs that it is their responsibility to ensure the states have received notification of completed CE, which can be done via FINRA’s FinPro system.[6]

Custody & Private Funds

  • Annual Surprise Custody Audit – Ensure that an annual surprise custody audit is performed, when applicable, by a third-party accounting firm, and that Form ADV-E is filed with the SEC via the firm’s IARD account.
    • Compliance Step: Perform an internal audit to confirm that all clients’ assets, for which the firm has custody (other than just the ability to debit fees), have been identified and included in the audit. Also, if any clients have Standing Letters of Authorization (“SLOAs”) in place with custodians to allow the firm to transfer client assets to a third party, be sure that they are either identified and included in the surprise audit, or the firm has controls in place for ensuring adherence to the SEC’s No-Action Letter issued to the Investment Adviser Association in 2017.[3]
  • Audit of Affiliated Private Funds – Confirm that the annual audit of the affiliated private fund(s) is scheduled and/or completed and internal controls are established to ensure the audited financial statements are mailed to investors within the required timeframe.
    • Compliance Step: Coordinate with each fund’s third-party service providers and staff to ensure sufficient time is allocated for audit preparation and facilitation.

Cybersecurity, Privacy & Data Protection

  • Cybersecurity and Privacy Measures – Perform an assessment of the risks surrounding your cybersecurity and privacy policies, procedures and safeguarding controls to confirm risk areas have been addressed.
    • Compliance Step: Ensure your incident response plan is customized and comprehensive, clearly outlining roles and responsibilities, preventative measures, and response priorities.
    • Compliance Step: Conduct vulnerability assessments and penetration testing before the end of the year, with a specific focus on identifying compliance gaps that may result from remote work arrangements.
  • Regulation S-P – Confirm your firm complies with the SEC’s amendments to Regulation S-P, which are now in effect.[9]
    • Compliance Step: The amendments require covered institutions to maintain a written incident response program to detect, respond to, and recover from a breach of customer information; to notify affected individuals when their sensitive information is reasonably likely to have been accessed; to oversee service providers; and to keep records documenting compliance.
    • Compliance Step: The compliance dates have passed — December 3, 2025 for larger entities (generally, RIAs with $1.5 billion or more in AUM) and June 3, 2026 for smaller entities — so confirm your incident response and breach-notification procedures are fully implemented, not just drafted.
  • Annual Identity Theft Program Assessment – In compliance with Regulation S-ID, conduct a comprehensive evaluation of your firm’s identity theft prevention program to ensure it aligns with all regulatory requirements and effectively addresses the unique risks your firm faces.
    • Compliance Step: Review the SEC Risk Alert on Regulation S-ID,[2] and consider offering clients — especially any senior or vulnerable clients — resources on how to safeguard against identity theft.
  • Business Continuity Plan (“BCP”) – Perform thorough testing of your BCP to assess its real-world effectiveness.
    • Compliance Step: Ensure testing addresses a variety of disruptions, ranging from localized events such as power outages to broader crises like natural disasters or pandemics.
    • Compliance Step: If any gaps or inefficiencies are uncovered, promptly revise your BCP to address these issues. Be sure to document all test results and implement necessary updates to your plan by the end of the year.
  • Vendor Due Diligence – Perform due diligence reviews on your firm’s key service providers.
    • Compliance Step: Utilize compliance technology that can track, monitor, and document due diligence activities to maintain your due diligence calendar.
    • Compliance Step: Ensure significant areas are thoroughly evaluated, with a particular focus on cybersecurity, privacy, and business continuity, and confirm any vendors handling sensitive data or critical operations have robust cybersecurity measures in place.

On the Horizon: Developments to Watch

Beyond the recurring tasks above, keep an eye on rules that are approaching or under review, and build them into next year’s compliance calendar as dates firm up.

  • FinCEN AML Rule for Investment Advisers – The FinCEN rule that would require registered advisers and exempt reporting advisers to implement risk-based AML/CFT programs — including internal controls, policies, training, independent testing, a designated AML/CFT officer, and Suspicious Activity Report (SAR) filings — was originally set to take effect January 1, 2026. FinCEN has delayed the effective date to January 1, 2028 and is reviewing and potentially tailoring the rule.[10]
    • Compliance Step: The delay is a timing change, not a rollback. Use the additional runway to build foundational elements that are unlikely to change — risk assessment frameworks, governance, and reporting lines — and monitor for FinCEN’s related customer identification program (CIP) rule for advisers.

Frequently Asked Questions

What Should Be on an Investment Adviser’s Year-End Compliance Checklist?

A thorough year-end checklist covers reviewing and updating Form ADV, Form CRS, and Form U-4; conducting a risk assessment and the Rule 206(4)-7 annual review; testing cybersecurity, business continuity, and vendor programs; confirming custody and any surprise-audit obligations; completing federal and state filings and IARD renewals; and finishing required training and continuing education. Each firm should tailor the list to its own business practices.

When Are IARD Renewal Fees Typically Due?

FINRA publishes an IARD Renewal Calendar each year. The Preliminary Renewal Statement generally becomes available in early-to-mid November, with renewal fees typically due in early-to-mid December. Because the exact dates change annually, confirm them on the current IARD Renewal Program calendar.

Is the FinCEN AML Rule for Investment Advisers in Effect Yet?

Not yet. FinCEN delayed the effective date of the investment adviser AML rule from January 1, 2026 to January 1, 2028, and is reviewing the rule in the interim. Covered advisers should use the additional time to prepare rather than assume the requirement has gone away.

Make This Checklist Your Year-End Roadmap

The SEC continues to take enforcement actions for compliance violations very seriously. Its focus on areas such as off-channel communications, cybersecurity, and accurate disclosure underscores the necessity of a proactive and comprehensive compliance strategy. A key takeaway is that although maintaining a strong compliance program may appear costly, the consequences of not having one are far more severe. Use this checklist as a roadmap to help your firm navigate the essential tasks needed to uphold your compliance program and begin preparing for the new year.

Working through all of this takes time and expertise. If you’d like a partner for year-end compliance and ongoing regulatory filings, Core Compliance can help — from running your annual review to handling filings and technology solutions. Contact us at (619) 278-0020 to learn more.

 

Author: Anna Schnitkey, Sr. Operations Associate, Core Compliance & Legal Services (“Core Compliance”). Core Compliance works extensively with investment advisers, broker-dealers, investment companies, and private fund managers on regulatory compliance issues.

 

This article is for information purposes and does not contain or convey legal or tax advice. The information herein should not be relied upon regarding any particular facts or circumstances without first consulting with a lawyer and/or tax professional.

[1] This list is not inclusive of all compliance areas that advisers should be considering and is provided as guidance only.

[2] See Risk Alert: Observations From Broker-Dealer and Investment Adviser Compliance Examinations Related to Prevention of Identity Theft Under Regulation S-ID (sec.gov)

[3] See https://www.sec.gov/divisions/investment/noaction/2017/investment-adviser-association-022117-206-4.htm

[4] The SEC adopted revisions to Rule 206(4)-7 requiring all SEC investment advisers to document in writing the required annual review.  The compliance date for this requirement was November 14, 2023.

[5] See https://www.nasaa.org/industry-resources/investment-advisers/investment-adviser-representative-continuing-education/iar-ce-map/

[6] See https://www.nasaa.org/industry-resources/signing-up-for-a-finpro-account/

[7] See SEC.gov | Enhanced Reporting of Proxy Votes by Registered Management Investment Companies; Reporting of Executive Compensation Votes by Institutional Investment Managers

[8] See https://iard.com/renewal-program

[9] See 34-100155-fact-sheet.pdf (sec.gov)

[10] See Federal Register :: Financial Crimes Enforcement Network: Anti-Money Laundering/Countering the Financing of Terrorism Program and Suspicious Activity Report Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers