On September 14, 2026, the SEC’s Division of Examinations published a Risk Alert, Examinations Observations Regarding Investment Adviser Annual Compliance Reviews, addressing a requirement that has been on the books for more than twenty years. Rule 206(4)-7 under the Advisers Act requires every registered adviser to review, at least annually, the adequacy of its compliance policies and procedures and the effectiveness of their implementation. The staff’s message is blunt: many advisers are still getting the basics wrong, and some are getting them wrong repeatedly.
The Compliance Rule asks whether you have tested your compliance program, documented the testing, and fixed what you found. Examiners are checking all three.
What the Staff Observed
The Risk Alert groups its findings into five buckets.
Timeliness. Examiners found advisers with gaps in their review history (e.g., 2021 and 2023 completed, 2022 missing), advisers stretching the interval well past twelve months, and first-time registrants treating the 18-month grace period as a standing allowance rather than a one-time accommodation that expired in 2005. Some advisers argued that annual compliance training or employee attestations satisfied the requirement. The staff rejected that position outright. Most concerning, the staff called out recidivists: firms that received deficiency letters for missing reviews and then missed them again.
Incomplete procedures for the review itself. Many firms have a policy that says “we conduct an annual review” but no procedures describing how. Who performs the testing, what factors determine adequacy, what workpapers are kept? The staff also observed manuals that mandate annual testing of specific areas (identity theft programs, for example) that never make it into the actual review scope.
Reviews inconsistent with written procedures. Advisers that did conduct timely reviews often did not follow their own playbook, skipping defined tests, ignoring required templates, or, in some cases, evaluating outdated versions of their policies that had already been superseded.
Policies misaligned with practice. This is where the real exam exposure lives. The staff found annual reviews that failed to catch fee billing inconsistent with client agreements and Form ADV, proxy voting policies that contradicted disclosures and practice, custody procedures missing surprise-exam steps, marketing policies never updated for the Marketing Rule, unaddressed delegated functions, and known compliance incidents that were never recorded in the review.
Documentation and follow-through. Advisers produced testing and recommendations but did not retain them under Rule 204-2(a)(17)(ii). Others adopted procedures requiring a written report and never wrote one. And several advisers documented that corrective actions had been taken when the underlying issues persisted.
Why Private Equity Managers Should Pay Attention
The examples in the Risk Alert lean retail, but the framework applies with full force to private fund advisers, and several of the observations map directly onto the areas where PE managers get hit in exams.
- Fees and expenses. The staff’s billing examples (wrong methodologies, missed offsets, no refunds) translate to management fee offsets, monitoring fee and transaction fee crediting, expense allocation across funds and co-investment vehicles, and treatment of broken-deal costs. If your annual review does not test actual allocations against the LPA and Form ADV, it will not catch the deviations examiners will. This Risk Alert should be read alongside the June 9, 2026 Risk Alert on economic conflicts of interest; the two are complementary.
- Business changes. The Compliance Rule adopting release directs advisers to consider changes in business activities. For PE, that means new strategies (credit, secondaries, infrastructure), continuation vehicles and other GP-led transactions, new co-investment programs, NAV facilities, and affiliated service providers. The staff specifically flagged advisers whose CCOs were not informed of operational changes affecting review scope. If deal teams launched something in the last year and compliance learned about it from the annual review, that is a finding waiting to happen.
- Delegated functions. Fund administrators, valuation agents, placement agents, and outsourced compliance providers all perform functions for which the adviser remains responsible. The staff observed policies that delegated work without describing how the adviser oversees it. Your review should evidence that oversight, not merely note that a vendor exists.
- Custody. Most PE managers rely on the audit exception. The annual review should confirm that every entity over which the adviser has custody is covered by a timely audit, including SPVs, co-invest vehicles, and legacy funds in wind-down, which is precisely where recent enforcement has focused.
- Marketing. The staff continues to find marketing policies that were never updated for the Marketing Rule, nearly four years after the compliance date. Between the April 2024 and December 2025 Marketing Rule Risk Alerts, there is no ambiguity about what examiners expect. Fundraising materials, track records, and case studies belong in the annual review scope.
- CCO transitions. The staff cited CCO departures as a cause of missed reviews. PE firms with a single-person compliance function, or a dual-hatted CFO/CCO, are especially vulnerable. The obligation does not pause because the seat is empty.
- Recidivism. If your prior exam produced a deficiency letter on the annual review, expect the next exam to start there. The staff’s use of the word “recidivist” is deliberate and signals a lower tolerance for repeat findings.
Practical Steps
Treat the annual review as a project with a defined scope, owner, and deliverable. Start with a risk inventory that reflects your current business, not the one you had at registration. Adopt written procedures for the review that specify the tests to be performed and the workpapers to be retained. Confirm the review evaluates the current version of your manual. Record every compliance incident from the year, including the ones already remediated. Produce a written report, retain the underlying testing, and track each corrective action to closure with evidence. Finally, consider interim reviews when the business changes materially between annual cycles; the staff has now said twice in one document that it expects them.
How Trillium Can Help
Trillium conducts independent annual compliance reviews and mock examinations for private equity and private fund managers, with testing designed around the specific risk areas the Division of Examinations targets: fee and expense allocation, conflicts, custody, marketing, and vendor oversight. We also assist firms that have received deficiency letters on their annual review process in building a documented, repeatable review framework before the next exam.

