ALERT: SEC Issues Risk Alert on Top Five Problem Areas in Investment Advisor Examinations

by Pullman & Comley, LLC

For investment adviser firms, an audit by the Securities and Exchange Commission or state regulators can be cause for anxiety. Regardless of how carefully a firm’s chief compliance officer adheres to regulations, deficiencies might be found by the examiners. The SEC’s Office of Compliance Inspections and Examinations (“OCIE”) recently reported on the five most frequent compliance problems found during examinations of investment advisers over the past two years, based on its review of deficiency letters sent to examinees.[1]  The five problem areas – compliance programs, regulatory filings, custody, code of ethics and books and records – are familiar territory for investment advisers but can still give rise to problems. The OCIE report is instructive for investment advisers who hope to have a smooth examination when the SEC comes knocking. If your firm is a Connecticut state-registered adviser, it is likely that the Department of Banking (“DOB”) would have similar concerns when it conducts examinations, as its compliance requirements are similar to those of the SEC.[2]

Compliance Programs

The Investment Advisers Act Rule 205(4)-7 sets forth specific requirements for compliance programs that all SEC-registered advisers must have. The OCIE examiners found several problems with the compliance programs of some of the investment advisers they examined.

– The examiners found that some compliance manuals were not reasonably tailored to the investment adviser’s business practices. Advisers often buy “off-the-shelf” manuals but fail to revise them to fit how they actually do business, making many of the policies and procedures irrelevant to them. In addition, some manuals were not updated to reflect changes in the law, changes in personnel of the investment adviser, or new policies.

– Some advisers failed to annually review their compliance policies and procedures, or reviewed them but did not address problems identified in the review.  In fact, some advisers were not following their own policies and procedures.

Action Items:

  • Make sure that your compliance manual accurately describes your firm’s actual policies and procedures and update it periodically.
  • Conduct an annual review of your firm’s compliance program and address any problems that you identify.
  • Make sure that your firm is following the policies and procedures established by its compliance program.

Regulatory Filings

The examiners found that some advisers provided inaccurate disclosures on their Form ADV annual amendments, and others did not promptly file ADVs when a material event occurred. Advisers to funds with assets over $150,000,000 are required to file Form PF; examiners found that some advisers with this obligation prepared the form inaccurately or incompletely or filed it late. Advisers to funds relying on Regulation D for an exemption from a public offering, in their capacity as organizers of the funds, may be required to file a Form D on behalf of the fund.  The examiners found that some advisers filed the Form D late or that the forms were inaccurate or incomplete.

Action Items:

  • Calendar your firm’s deadlines for form filings and plan ahead to ensure filing is timely.  Ensure that forms are completed and the information is correct.


The SEC’s Custody Rule,[3] created in the wake of the Madoff scandal, requires that advisers with custody of a client’s cash or securities comply with certain requirements in order to ensure the safety of clients’ assets.

Failure to Identify Custody.  Examiners found that some advisers did not realize that they had custody of client assets due to their online access to clients’ accounts and their ability to withdraw funds and securities from the accounts. Certain advisers did not recognize that they had custody due to broad powers of attorney that allow them to withdraw client cash or securities, or because they are trustees of clients’ trusts or general partners of funds.

Improper Use of Surprise Examinations. The Custody Rule requires that independent public accountants conduct surprise examinations of investment advisers in certain circumstances. OCIE’s examiners reported that some advisers did not provide the accountants with all the necessary information to conduct the examination and file the required Form ADV-E. In addition, some examinations were not being done on a “surprise” basis.

Action Items:

  • Periodically review the level of control that your advisers have over client funds and securities in light of the Custody Rule to ensure that all controlled assets are appropriately protected pursuant to that Rule. Ensure that your accountants have all the information they need to conduct their surprise examinations, and that the examinations are done on a truly “surprise” basis.

Code of Ethics Rule

The SEC requires that each SEC-registered investment adviser adopt and maintain a code of ethics, which must contain certain provisions.[4] The examiners found deficiencies particularly in the requirement that the adviser’s “access persons” (which includes employees, partners and directors) periodically report their personal securities transactions and holdings to the adviser’s chief compliance officer. Some advisers did not identify all of their access persons. Some did not require in their codes of ethics that the chief compliance officer review the securities reports, or did not specify time frames within which the reports were required to be submitted. In some cases, the code of ethics provided time frames but certain access persons submitted them less frequently than required.

The adviser's Code of Ethics is required to be described in Part 2A of the investment adviser’s Form ADV, and the adviser must state that the Code of Ethics is available to any client or prospective client upon request. Some advisers did not comply with this requirement.

Action Items:

  • Review your firm’s Code of Ethics and make sure that all access persons are complying with it and that your chief compliance officer is reviewing the securities reports. Ensure that your firm is describing its Code of Ethics in its ADV and making it available to clients and prospective clients.

Books and Records

The SEC’s Books and Records Rule[5] requires investment advisers to make and maintain certain books and records relating to their business. The examiners found that some advisers did not maintain all the books and records required to be kept, that their records were inaccurate or outdated, or that their recordkeeping was inconsistent.

Action Items:

  • Your firm’s policies should include clear statements regarding required recordkeeping. The Chief Compliance Officer should periodically check to be sure that all records are being properly created and maintained.




1. National Exam Program Risk Alert, February 7, 2017.

2. See, for example, the DOB’s February 2005 release, “Investment Advisory Code of Ethics,”, and its discussion of the “Investment Adviser Examination Program,”

3. Advisers Act Rule 206(4)-2.

4. Advisers Act Rule 204A-1.

5. Advisers Act Rule 204-2.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Pullman & Comley, LLC | Attorney Advertising

Written by:

Pullman & Comley, LLC

Pullman & Comley, LLC on:

Readers' Choice 2017
Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
Sign up using*

Already signed up? Log in here

*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
Privacy Policy (Updated: October 8, 2015):

JD Supra provides users with access to its legal industry publishing services (the "Service") through its website (the "Website") as well as through other sources. Our policies with regard to data collection and use of personal information of users of the Service, regardless of the manner in which users access the Service, and visitors to the Website are set forth in this statement ("Policy"). By using the Service, you signify your acceptance of this Policy.

Information Collection and Use by JD Supra

JD Supra collects users' names, companies, titles, e-mail address and industry. JD Supra also tracks the pages that users visit, logs IP addresses and aggregates non-personally identifiable user data and browser type. This data is gathered using cookies and other technologies.

The information and data collected is used to authenticate users and to send notifications relating to the Service, including email alerts to which users have subscribed; to manage the Service and Website, to improve the Service and to customize the user's experience. This information is also provided to the authors of the content to give them insight into their readership and help them to improve their content, so that it is most useful for our users.

JD Supra does not sell, rent or otherwise provide your details to third parties, other than to the authors of the content on JD Supra.

If you prefer not to enable cookies, you may change your browser settings to disable cookies; however, please note that rejecting cookies while visiting the Website may result in certain parts of the Website not operating correctly or as efficiently as if cookies were allowed.

Email Choice/Opt-out

Users who opt in to receive emails may choose to no longer receive e-mail updates and newsletters by selecting the "opt-out of future email" option in the email they receive from JD Supra or in their JD Supra account management screen.


JD Supra takes reasonable precautions to insure that user information is kept private. We restrict access to user information to those individuals who reasonably need access to perform their job functions, such as our third party email service, customer service personnel and technical staff. However, please note that no method of transmitting or storing data is completely secure and we cannot guarantee the security of user information. Unauthorized entry or use, hardware or software failure, and other factors may compromise the security of user information at any time.

If you have reason to believe that your interaction with us is no longer secure, you must immediately notify us of the problem by contacting us at In the unlikely event that we believe that the security of your user information in our possession or control may have been compromised, we may seek to notify you of that development and, if so, will endeavor to do so as promptly as practicable under the circumstances.

Sharing and Disclosure of Information JD Supra Collects

Except as otherwise described in this privacy statement, JD Supra will not disclose personal information to any third party unless we believe that disclosure is necessary to: (1) comply with applicable laws; (2) respond to governmental inquiries or requests; (3) comply with valid legal process; (4) protect the rights, privacy, safety or property of JD Supra, users of the Service, Website visitors or the public; (5) permit us to pursue available remedies or limit the damages that we may sustain; and (6) enforce our Terms & Conditions of Use.

In the event there is a change in the corporate structure of JD Supra such as, but not limited to, merger, consolidation, sale, liquidation or transfer of substantial assets, JD Supra may, in its sole discretion, transfer, sell or assign information collected on and through the Service to one or more affiliated or unaffiliated third parties.

Links to Other Websites

This Website and the Service may contain links to other websites. The operator of such other websites may collect information about you, including through cookies or other technologies. If you are using the Service through the Website and link to another site, you will leave the Website and this Policy will not apply to your use of and activity on those other sites. We encourage you to read the legal notices posted on those sites, including their privacy policies. We shall have no responsibility or liability for your visitation to, and the data collection and use practices of, such other sites. This Policy applies solely to the information collected in connection with your use of this Website and does not apply to any practices conducted offline or in connection with any other websites.

Changes in Our Privacy Policy

We reserve the right to change this Policy at any time. Please refer to the date at the top of this page to determine when this Policy was last revised. Any changes to our privacy policy will become effective upon posting of the revised policy on the Website. By continuing to use the Service or Website following such changes, you will be deemed to have agreed to such changes. If you do not agree with the terms of this Policy, as it may be amended from time to time, in whole or part, please do not continue using the Service or the Website.

Contacting JD Supra

If you have any questions about this privacy statement, the practices of this site, your dealings with this Web site, or if you would like to change any of the information you have provided to us, please contact us at:

- hide
*With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name. Or, sign up using your email address.