top of page
Search

The Five Things Smaller RIAs Consistently Get Wrong Before Their First SEC Examination

Writer: Susan Kim
Susan Kim
Sep 4
5 min read

Your first SEC examination is not just a regulatory event. It is the first time a federal regulator will look closely at how your firm operates, how you treat clients, and whether the compliance program you built on paper actually functions in practice. The outcome matters -- not just for the examination itself, but for how your firm is perceived in every interaction with the SEC that follows.


A CCO of a RIA meeting with an SEC examiner.


Most of the mistakes I see smaller RIAs make are not technical. They are not obscure regulatory violations buried in a footnote. They are practical, avoidable errors that signal to an examiner -- within the first few days -- whether this is a firm that takes its responsibilities seriously or one that is going through the motions.


Here are the five I see most consistently.


1. Getting the tone wrong from the start

This is the one that costs firms the most and gets talked about the least.

The examination begins the moment you pick up the phone or respond to the initial document request. From that point forward, the examiner is forming an impression of your firm. RIAs that are uncooperative, defensive, or slow to respond to basic requests are hurting themselves before the examination has even properly begun. I have seen firms treat routine examiner questions as accusations. I have seen principals get visibly irritated when asked to explain something straightforward. I have seen document productions arrive late, disorganized, and with no explanation.


All of this matters. Examiners are professionals and they respond to professionalism. Be courteous. Be prompt. Be thoughtful in your answers. If you do not know something, say so and follow up. If a request needs clarification, ask for it politely.


One equally important rule: do not volunteer information that has not been asked for. Answer the question in front of you completely and accurately, then stop. This is not about hiding anything. It is about discipline. Volunteering information outside the scope of a question creates new threads for the examiner to pull, extends the examination, and can introduce issues that were never on anyone's radar. Less is more -- as long as what you provide is complete, accurate, and well organized.


2. Producing records that only make sense to you


An examiner is an independent third party trying to verify how your firm operates. They are not inside your systems, they do not know your internal shorthand, and they have no context for how your records are organized unless you provide it.


This sounds obvious. Firms get it wrong constantly.


When you produce records in response to an examination request, organize them as if you are handing them to someone who knows nothing about your firm and needs to reach their own conclusions. Label everything clearly. If a document requires context to be understood, provide that context in a brief explanatory note. If there are nuances to how a particular record should be read, say so upfront rather than waiting for the follow-up question.


Take billing records as an example. When an examiner requests billing records, they are trying to verify that you are charging clients accurately and in accordance with your agreements. That means they need fee agreements, custodial statements, invoices, and any documentation of special arrangements -- minimum billing thresholds, assets excluded from the fee calculation, negotiated rates for specific clients. If you produce invoices without the underlying agreements, or custodial statements without the corresponding invoices, the examiner cannot do the verification they came to do. The result is follow-up requests, extended timelines, and a growing sense that your records are incomplete.


Anticipate what the examiner is trying to understand and organize your production to answer that question completely the first time. Firms that do this well create a very different impression than firms that make the examiner dig.


3. A compliance manual that no longer matches the business


This is the most common finding I encounter and the most preventable. The compliance manual was drafted when the firm registered, reviewed briefly at the first annual review, and has not been meaningfully updated since. Meanwhile the business has changed -- new strategies, new personnel, new client types, new conflicts -- and none of it is reflected in the policies.


An examiner will compare what your manual says to how your firm actually operates. When those two things diverge, it is a finding. Not because the policy was wrong when it was written, but because nobody kept it current.


Your compliance manual is a living document. It should reflect your firm as it exists today, not the firm you described to the SEC at registration.


4. A CCO who has the title but not the role


Smaller RIAs frequently designate a CCO to satisfy the regulatory requirement without genuinely building the function. The CCO -- often the founder, a COO, or an office manager with other responsibilities -- has the title on the Form ADV but limited time, authority, or resources to actually run a compliance program.


Examiners look for this directly. They will ask the CCO what their day-to-day compliance responsibilities look like. They will ask what testing has been done, what the last annual review covered, what regulatory developments the firm has tracked in the past year. If the answers are thin, that is a significant finding -- and it often opens up a much broader examination of whether the compliance program is real.


The CCO does not need to be a full-time position at a small firm. But the function needs to be genuine. If your designated CCO cannot speak credibly to how the compliance program operates, that is worth addressing before the examination arrives.


5. No evidence that the compliance program actually runs


Having policies is not the same as having a compliance program. The SEC requires annual reviews, ongoing monitoring, employee training, and documented testing of key controls. What I consistently find at smaller RIAs is that these activities either did not happen or happened without any documentation.


If you conducted an annual review but did not document it, the SEC has no way to verify that it occurred. If you trained your employees on the Code of Ethics but kept no attendance records or written materials, that training effectively did not happen from a regulatory standpoint. If you tested your personal trading controls but left no written record of what you tested, what you found, and what you did about it, you have done the work without getting any credit for it.


Document everything. Not because you expect to be examined, but because documentation is how a compliance program demonstrates that it functions. It is the difference between a program that exists on paper and one that an examiner can verify actually runs.


The common thread

Every one of these mistakes comes back to the same underlying issue: treating compliance as a formality rather than a function. Smaller RIAs often operate with limited resources and genuine competing priorities. I understand that. But being a registered investment adviser means you are a fiduciary. You are managing the wealth of others and that carries real obligations -- to your clients, to your employees, and to the regulators who oversee the industry on behalf of the investing public.


The firms that fare best in examinations are not necessarily the ones with the most sophisticated compliance programs. They are the ones that take the obligation seriously, keep their programs current, and engage with the examination process like the professionals they are.


If you are not sure where your firm stands on any of these, the time to find out is before you get the call -- not after.


Susan Kim is a former SEC examiner and the founder of No Bad Acts LLC, a compliance advisory firm serving investment advisers and private fund managers. She can be reached at skim@nobadacts.com.

 
 
 

Comments


bottom of page