SEC Compliance Support Services 2026: Complete Guide for Investment Advisers, Private Funds and Broker-Dealers
- 4 days ago
- 12 min read

SEC compliance is not one uniform rulebook. A registered investment adviser, private fund adviser, broker-dealer, registered investment company and other market participant can be subject to different federal securities laws, SEC rules, FINRA requirements and filing obligations. A useful compliance programme therefore begins by identifying the registrant type, business activities, clients, products and conflicts before determining which rules and controls apply.
For 2026, the SEC Division of Examinations continues to focus on core compliance programme effectiveness, fiduciary duties, conflicts, custody, marketing, filings, financial responsibility, Regulation Best Interest, privacy and cybersecurity-related controls. The Fiscal Year 2026 Examination Priorities make clear that written policies are only one part of the assessment because examiners also test annual reviews, implementation and whether controls reflect the firm's actual business. Firms should therefore operate continuously with examination readiness in mind.
SEC compliance requirements at a glance
Firm type or area | Core compliance topics |
SEC-registered investment advisers | Rule 206(4)-7 compliance programme, fiduciary duty, Form ADV, Marketing Rule, custody, Code of Ethics, books and records |
Private fund advisers | Adviser rules plus fund disclosures, valuation, conflicts, custody, Form PF where applicable and investor communications |
Broker-dealers | Exchange Act, SEC financial responsibility, Reg BI, books and records, supervision, AML and FINRA rules |
Registered investment companies | Rule 38a-1 compliance, governance, disclosures, fund rules and service-provider oversight |
Regulation S-P | Privacy, safeguards, incident-response and customer information requirements |
Cybersecurity and technology | Governance, information protection, operational risk and exam readiness under applicable rules |
Marketing | Adviser Marketing Rule and broker-dealer communications requirements according to firm type |
Conflicts | Identification, disclosure, mitigation or elimination depending on the duty and activity |
SEC examinations | Document production, interviews, testing, deficiency responses and remediation |
Regulatory filings | Form ADV, Form PF and other filings according to registrant type |
This article focuses principally on SEC-registered investment advisers, private fund advisers and broker-dealers because they account for much of the search intent around SEC compliance support. The exact US legal analysis should nevertheless be confirmed against the firm's registration status and activities. Buckingham Capital Consulting provides compliance consulting and cross-border regulatory support but does not present itself as a US law firm, so formal US legal opinions should be obtained from appropriately qualified US counsel where required.
Rule 206(4)-7 is the foundation of an RIA compliance programme
Rule 206(4)-7 under the Investment Advisers Act requires an SEC-registered adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and its rules. The adviser must review those policies and procedures at least annually for their adequacy and the effectiveness of implementation and designate a Chief Compliance Officer responsible for administering the programme. The SEC's Compliance Rule release remains the core reference point.
The rule is deliberately risk-based rather than a prescribed manual template. The compliance programme should address the adviser's actual activities, conflicts, clients, trading, custody, valuation, marketing and operational model. An adviser that copies a standard policy library without adapting it to its own business can therefore remain non-compliant even where every expected policy heading appears in the manual.
Implementation is equally important. Examiners can test samples, compare policy wording with actual practice, review evidence of monitoring and assess whether identified issues were remediated. A strong programme therefore connects each material risk to a control, responsible owner, evidence source and review process.
The annual compliance review should be substantive
The annual review is not simply a requirement to update the date on the compliance manual. The SEC states that the review should consider compliance matters that arose during the previous year, changes in the adviser's or affiliates' business and changes in the Advisers Act or applicable rules that may require policies to be revised. It should therefore operate as a structured assessment of whether the programme remains adequate and effective.
A useful review should include testing. Marketing, personal trading, custody, valuation, disclosures, conflicts, best execution, filings and other relevant areas can be sampled or tested according to the adviser's risks. Findings should identify root causes and changes needed to the control environment rather than simply list exceptions.
The review should also be documented clearly enough to support examination. The SEC's 2026 priorities expressly identify annual reviews as part of its evaluation of adviser compliance programmes. An adviser should therefore be able to show what was reviewed, what evidence was used, what issues were found and how management responded.
Fiduciary duty remains a core examination priority
SEC-registered investment advisers owe clients a federal fiduciary duty that includes duties of care and loyalty. Firms should identify conflicts, provide full and fair disclosure where disclosure is an appropriate response and avoid circumstances where the conflict cannot be addressed consistently with the duty. The compliance programme should reflect how those principles apply to the adviser's actual compensation and investment arrangements.
The SEC published a June 2026 Risk Alert on economic conflicts of interest, reinforcing examination focus on financial incentives that can influence recommendations or account treatment. Advisers should therefore review revenue sharing, affiliated products, cash sweeps, compensation, account selection, rollovers and other circumstances where the firm or its personnel can benefit differently from available choices.
Disclosure is not always a complete solution. It should be specific enough for a client to understand the nature and significance of the conflict, and the firm's practices should remain consistent with what was disclosed. Compliance monitoring should compare actual economic incentives with Form ADV and other client disclosures.
Form ADV must remain accurate and consistent with the business
Form ADV is a continuing regulatory disclosure, not a one-time registration document. Advisers need to amend it according to the applicable annual and other-than-annual requirements and ensure the information remains accurate as the firm changes. Business activities, disciplinary information, ownership, assets under management, conflicts and other disclosures should correspond with current operations.
Part 2 brochures and supplements are particularly important because they communicate material information directly to clients. The firm should review them when products, fees, conflicts or personnel change rather than wait automatically for the annual amendment. Marketing and client agreements should also be checked for consistency with Form ADV.
Examiners can compare filings with internal documents and observed practices. A mismatch between public disclosures and the firm's actual business can create both compliance and credibility concerns. Change-management processes should therefore include a Form ADV impact assessment before material commercial changes are implemented.
The Investment Adviser Marketing Rule requires structured controls
The Advisers Act Marketing Rule governs advertisements and endorsements or testimonials by registered investment advisers. It includes general prohibitions against materially misleading statements and detailed conditions around performance information, testimonials, endorsements and third-party ratings. Websites, social media, pitch books and other communications should therefore sit within a documented approval and record-keeping process.
The SEC Division of Examinations continues to publish observations on Marketing Rule compliance, including a December 2025 Risk Alert listed on the SEC's current Risk Alerts page. Firms should use those observations to test whether required disclosures, performance presentation and substantiation are working in practice. Compliance should also review whether employees or third parties create content outside the formal marketing process.
Performance advertising deserves particular care. Gross and net performance, extracted performance, hypothetical performance and comparisons should be assessed against the detailed rule and the intended audience. The firm should maintain evidence supporting material factual claims and preserve required records.
Custody remains a fundamental examination area
The Advisers Act Custody Rule applies where an adviser has custody of client funds or securities under the rule's definitions and can create requirements involving qualified custodians, account statements, surprise examinations or audited pooled vehicles depending on the structure. Firms should determine custody status carefully because authority over accounts, related persons or fund structures can create custody even where the adviser does not physically hold assets. The compliance programme should document the basis for its conclusion.
Private fund advisers frequently rely on the annual audit approach where conditions are met. Fund structure, auditor status, timing and distribution of audited financial statements should therefore be monitored. Where an adviser changes administrators, custodians or account authority, custody analysis should be revisited.
The SEC's 2026 examination priorities continue to identify custody as a core area. Examiners can compare agreements, account access, cash movement controls and client statements with the firm's claimed custody status. A written policy should therefore be supported by operational evidence.
The Code of Ethics creates personal conduct controls
Rule 204A-1 requires registered investment advisers to adopt a Code of Ethics containing standards of conduct and provisions addressing personal securities transactions by access persons. The rule supports the adviser's fiduciary duty by helping identify and manage conflicts between employee activity and client interests. Firms should maintain accurate access-person populations and ensure reporting and pre-clearance processes reflect actual roles.
Personal trading reviews should be substantive. Compliance should identify restricted securities, potential front running, conflicts and failures to report accounts or holdings rather than merely confirm that forms were submitted. Exceptions should be investigated and documented consistently.
Training also matters. Employees should understand why the Code exists and how requirements apply to outside activities, gifts, entertainment, political contributions and other conflicts where the firm's policies address them. A Code that employees sign annually without understanding its practical application provides limited protection.
Regulation S-P is a major 2026 compliance issue
The SEC's 2024 amendments to Regulation S-P strengthened requirements around safeguarding customer information, incident response and notification. Larger entities reached their compliance date earlier, while smaller firms had a 3 June 2026 compliance date, making implementation a current examination issue. The SEC held dedicated outreach events in 2026 to help smaller firms prepare for the amendments.
Covered firms should maintain a written incident-response programme designed to detect, respond to and recover from unauthorised access to or use of customer information. The rules also create notification obligations in relevant circumstances and expand record-keeping and safeguarding expectations. Privacy and cybersecurity governance should therefore be connected rather than maintained as unrelated policies.
Vendor risk is particularly important because customer information may be held or processed by third parties. Contracts, due diligence and incident escalation should allow the firm to respond quickly where a service provider experiences a breach. Examination readiness should include evidence of testing and implementation, not only the final written programme.
Cybersecurity remains an examination risk even as rulemaking changes
The SEC has withdrawn or reconsidered some earlier cybersecurity rulemaking proposals, but cybersecurity and information protection remain important examination risks under existing obligations. Advisers and broker-dealers still need controls appropriate to Regulation S-P, fiduciary duties, books and records, supervisory responsibilities and the protection of customer information. A firm should therefore not interpret withdrawal of a particular proposed rule as removal of cybersecurity compliance risk.
The programme should consider access management, incident response, vendor risk, backups, vulnerability management, phishing and protection of sensitive information. The detail should be proportionate to the firm's technology and client exposure. Cloud outsourcing does not transfer regulatory accountability to the provider.
Boards or senior management should understand material incidents and vulnerabilities. Repeated near misses or unresolved security findings can indicate weaknesses in the broader compliance programme. Cyber risk should be included in the annual compliance review where relevant to the adviser.
Books and records need to support the compliance programme
SEC registrants are subject to detailed record-keeping requirements according to firm type. Advisers should preserve records supporting client communications, transactions, marketing, personal trading, policies, filings and other regulated activity, while broker-dealers face separate Exchange Act books-and-records obligations. Retention should be designed around the applicable rule rather than a single generic corporate policy.
Electronic communications are a recurring risk area. Business conducted through personal messaging apps or unapproved channels can escape required retention and supervision. Firms should therefore combine policy, technology and monitoring to ensure business communications are captured appropriately.
Records also support examination response. A firm that cannot locate evidence promptly may struggle to demonstrate compliance even if staff believe the underlying process occurred. Document governance should therefore consider accessibility, retention and the ability to reconstruct decisions.
Private fund advisers face additional conflicts and reporting risks
Private fund advisers need to consider the Advisers Act compliance framework together with the particular conflicts created by fund structures, allocations, expenses, valuation, side letters and transactions involving affiliates. The SEC continues to scrutinise whether disclosures and practices are consistent with the adviser's fiduciary obligations. Compliance should therefore review fund governing documents, Form ADV disclosures and operational practices together.
Form PF applies to certain SEC-registered investment advisers to private funds. The SEC and CFTC extended the compliance date for the February 2024 amendments to 1 October 2026, but the agencies also proposed further Form PF amendments in April 2026. Firms should distinguish the final delayed amendments from the 2026 proposal and monitor whether the regulatory baseline changes before implementation.
Data preparation should begin before a filing deadline. Private fund structures can involve several administrators and data sources, so the adviser needs clear ownership and validation of the information used for Form PF. Inconsistent data can create regulatory risk beyond the filing itself.
Broker-dealer compliance has a different regulatory architecture
Broker-dealers are generally subject to the Securities Exchange Act, SEC rules and FINRA requirements rather than the Advisers Act compliance framework. Written supervisory procedures, financial responsibility, books and records, customer protection, trading practices, communications and AML can all be central depending on the business. A compliance programme should therefore be built specifically for the broker-dealer rather than adapted from an RIA manual.
Regulation Best Interest is a continuing examination focus for retail broker-dealers. Firms should consider recommendations, conflicts, disclosure, care and compliance obligations and test whether registered representatives follow the firm's process. Compensation and product incentives deserve particular scrutiny where they can affect recommendations.
Financial responsibility rules are equally important. Net capital, customer protection and related operational controls need accurate data and senior oversight. Weaknesses can become immediate safety and regulatory issues rather than ordinary compliance exceptions.
Broker-dealer AML and sanctions controls
Broker-dealers are subject to AML requirements under the Bank Secrecy Act framework and applicable FINRA rules, with customer identification, suspicious activity reporting and risk-based controls forming core components. The firm should understand customer types, products, funding methods and geographic exposure and ensure transaction surveillance reflects those risks. Higher-risk products or clients should receive enhanced review.
Sanctions compliance should be integrated with onboarding and transaction processes. Screening should cover customers and other relevant parties and be supported by current data and documented escalation. Potential matches should be investigated by trained staff rather than resolved automatically without context.
The 2026 SEC examination priorities continue to identify AML among cross-market risks. Broker-dealers should therefore maintain evidence of testing, training, governance and remediation. Outsourced tools can support the programme but do not replace the firm's responsibility to understand how controls operate.
SEC examinations should be treated as a business-as-usual possibility
An SEC examination can involve an initial document request, interviews, testing, follow-up questions and a deficiency process. Firms should maintain records and governance so that they can respond accurately without reconstructing years of activity under pressure. Examination readiness is therefore the result of good ongoing compliance rather than a project that begins when the SEC contacts the firm.
A mock exam or focused readiness review can be useful where the firm has not been examined recently, has experienced material growth or has changed its business model. The review should test areas relevant to current SEC priorities and the firm's specific risks. Findings should be remediated before they become regulator-identified deficiencies.
During an examination, responses should be accurate, complete and coordinated. Different departments should not provide inconsistent descriptions of the same process, and document production should preserve version control. Where a deficiency is identified, remediation should address the underlying cause and be evidenced clearly.
Compliance should be tailored to the firm's actual conflicts
The strongest SEC compliance programmes are not necessarily the longest manuals. They identify how the firm makes money, where employees or affiliates can benefit differently from clients, which operational processes can cause harm and which rules govern those risks. Policies, disclosures and monitoring can then be designed around those real circumstances.
This is also why rapid commercial change needs compliance involvement. A new fund, product, distribution arrangement, technology platform or compensation structure can change conflicts and regulatory obligations. The change process should assess Form ADV, marketing, custody, privacy, books and records and other consequences before launch.
Senior management should receive concise information about material risks and remediation. Compliance should be empowered to challenge business decisions where necessary, but it should also understand the commercial model well enough to propose workable controls. The objective is an implemented programme capable of withstanding examination, not compliance documentation in isolation.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting supports financial-services firms with regulatory compliance frameworks, gap assessments, governance, policies, risk management and remediation across multiple jurisdictions. For SEC-regulated businesses, we can support compliance programme design, annual-review preparation, policies, conflict mapping, filing governance, marketing controls, exam readiness and cross-border operating models. Work should be scoped to the registrant type because an RIA, private fund adviser and broker-dealer face different regulatory requirements.
Where the engagement requires a formal interpretation of US federal or state securities law, legal privilege or representation reserved to US counsel, we work alongside appropriately qualified US legal advisers rather than presenting consulting support as a substitute for legal advice. This is particularly important for novel registration questions, enforcement matters or complex broker-dealer structures. Cross-border groups can nevertheless benefit from one coordinated compliance workstream covering governance, regulatory evidence and implementation across jurisdictions. To discuss SEC compliance support, an RIA annual review, examination readiness or a cross-border regulatory project, contact Buckingham Capital Consulting.
Frequently asked questions
What does SEC compliance support include for an investment adviser?
Support can include the Rule 206(4)-7 compliance programme, annual compliance review, Form ADV governance, Marketing Rule controls, custody analysis, Code of Ethics, books and records, conflicts, Regulation S-P and examination readiness. The scope should be tailored to the adviser's business and clients rather than based on a generic checklist. Private fund advisers can require additional fund and Form PF work.
Does an SEC-registered adviser need an annual compliance review?
Yes. Rule 206(4)-7 requires a registered investment adviser to review its compliance policies and procedures at least annually for adequacy and effectiveness of implementation. The review should consider compliance issues, business changes and regulatory changes and should be documented sufficiently to support governance and examination.
What are the SEC's main examination priorities in 2026?
The Division of Examinations continues to focus on adviser fiduciary duties, compliance programme effectiveness, custody, marketing, disclosures and filings, together with broker-dealer financial responsibility, retail conduct and cross-market issues such as privacy and AML. The published priorities are not exhaustive, so firms should still assess risks specific to their own business. Examination preparation should therefore start with both the SEC priorities and the firm's actual conflicts.
What is the Regulation S-P compliance deadline for smaller firms?
The SEC's amended Regulation S-P framework gave smaller covered entities a compliance date of 3 June 2026. The amendments strengthen safeguarding, incident response, notification and record-keeping expectations around customer information. Firms should now be able to evidence implementation rather than simply maintain a future project plan.
What is happening with Form PF in 2026?
The SEC and CFTC extended the compliance date for the February 2024 Form PF amendments to 1 October 2026. In April 2026 they also proposed further amendments, so private fund advisers should monitor whether the final implementation framework changes before the delayed compliance date. Proposed changes should not be treated as final until formally adopted.
#SEC Compliance Support Services 2026: Complete Guide for Investment Advisers, Private Funds and Broker-Dealers
