The SEC Filed 456 Enforcement Actions in 2025. Here Is What RIAs Need to Know.
Every fall, the SEC releases its annual enforcement results. Every year, headlines follow about record penalties and action counts. And every year, a lot of RIAs read those headlines without understanding what the numbers signal for how their firm should be managing regulatory risk.
FY2025 is worth reading carefully, because the story is more nuanced than the top-line figures suggest, and the shift in enforcement posture has direct implications for how your compliance program needs to be structured.
The Numbers, in Context
The SEC filed 456 total enforcement actions in fiscal year 2025, including 303 standalone actions, and obtained orders for monetary relief totaling $17.9 billion.
That $17.9 billion figure will get attention. It should not be taken at face value.
After excluding “deemed satisfied” amounts, where disgorgement was credited against parallel criminal proceedings, and the long-running litigation against Robert Allen Stanford’s $8 billion Ponzi scheme, the monetary relief obtained in fiscal year 2025 totaled $1.4 billion in disgorgement and prejudgment interest and $1.3 billion in civil penalties.
That is a materially different picture than the headline number suggests, and it reflects a deliberate shift in how this Commission is measuring enforcement effectiveness. The prior era prioritized case volume and record-setting penalty totals. The current SEC under Chair Paul Atkins has explicitly rejected that approach in favor of fraud-focused, investor-harm-centered enforcement.
The Off-Channel Communications Reversal
One of the most significant statements in the FY2025 release is what the SEC said about the prior Commission’s enforcement record on off-channel communications.
Since fiscal year 2022, the prior Commission brought 95 actions and $2.3 billion in penalties against firms for failing to maintain and preserve off-channel communications. The current Commission characterized these cases as identifying no direct investor harm, producing no investor benefit or protection, and representing a misinterpretation of the federal securities laws and a misallocation of Commission resources.
This is a meaningful institutional statement. It does not mean off-channel communications compliance is irrelevant. Books and records requirements remain in place, and the SEC has not suggested firms can ignore them. What it does mean is that technical, process-based violations without underlying investor harm are no longer the enforcement priority they once were. Firms that built compliance programs primarily around documenting every communication channel for regulatory optics should understand that the goalposts have moved.
Individual Accountability Is the Real Story
If there is one takeaway from the FY2025 results that RIAs need to internalize, it is this: the SEC is increasingly coming after individuals, not just firms.
Of the standalone actions filed during fiscal year 2025, approximately two-thirds involved charges against one or more individual bad actors, representing a 27 percent year-over-year increase. Nearly nine out of every ten standalone actions filed under the current leadership involved individual charges. The Commission also obtained orders barring 119 individuals from serving as officers and directors of public companies.
For RIA owners and CCOs, this is not an abstract trend. Individual liability means your name, your registration, and your reputation are on the table when something goes wrong at your firm. The structure of your compliance program, who is responsible for what, how decisions are documented, and whether testing catches issues are no longer just organizational questions. They are personal ones.
The prior enforcement environment allowed firms to absorb penalties at the entity level while principals moved on relatively intact. That is becoming less available as an outcome.
What the SEC Is Prioritizing
The FY2025 results make the current enforcement priorities explicit. The SEC is focused on fraud, fiduciary breaches, undisclosed conflicts of interest, market manipulation, and insider trading. These are conduct failures, not process failures.
Notable actions included charges against Vanguard Advisers, Inc. for failing to adequately disclose conflicts of interest when recommending clients enroll in a fee-based advisory service, and the Cutter Financial Group case, where an investment adviser and his firm were found liable for recommending insurance products that paid substantial up-front commissions without adequately disclosing their financial incentive to do so.
Both of those cases are about disclosure quality, not disclosure existence. The forms were filed. The language was present. The problem was that it was not substantive enough for clients to understand the actual conflict. This is the enforcement standard RIAs are operating under right now.
What This Means for Conflict Disclosure
The Vanguard and Cutter cases are a signal worth taking seriously. If your Form ADV Part 2 describes compensation arrangements in general terms without giving clients enough context to understand how those arrangements could influence your recommendations, that is exposure under the current enforcement framework.
Reading your ADV as a client would, rather than as a compliance checklist item, is a useful exercise. Does a client understand, from what you have written, that a financial incentive exists and how it might affect the advice they receive? If the answer requires additional explanation, the disclosure is probably not sufficient.
Cooperation and Self-Reporting Still Matters
One area of the FY2025 results that does not get enough attention is what the SEC said about cooperation credit.
During fiscal year 2025, some market participants self-reported violations, cooperated meaningfully with investigations, and remediated securities law violations. As a result, the Division recommended, and the Commission approved, resolutions imposing reduced civil penalties or declined to recommend enforcement action entirely.
The availability of cooperation credit is not new, but it is worth noting in an environment where fraud-focused enforcement is more selective and resource-intensive. Firms that discover compliance failures internally and address them proactively are in a meaningfully better position than those that wait for an examination to surface the issue.
The Whistleblower Program Is Active
The SEC received a record 53,753 tips, complaints, and referrals in fiscal year 2025, nearly 19 percent more than the prior fiscal year, and awarded approximately $60 million to 48 individual whistleblowers.
For RIAs, this is a reminder that compliance culture matters internally. Employees, former employees, and clients all have direct channels to the SEC. Firms where compliance concerns are dismissed, or where staff feel pressure to overlook issues, are operating with elevated exposure regardless of what their written policies say.
What Your Compliance Program Needs to Reflect
The FY2025 enforcement results, read alongside the SEC’s current examination priorities, point toward a few concrete compliance program requirements.
- Conflict disclosure needs to be substantive, not just present. The question is not whether you disclosed a conflict, but whether the disclosure gave clients enough information to understand its significance.
- Individual accountability needs to be built into your governance structure. Who is responsible for what should be documented clearly, with evidence that those responsibilities are being executed.
- Testing needs to produce findings. A compliance program that runs reviews and finds nothing, cycle after cycle, is not evidence of a clean firm. It is a flag that the reviews may not be substantive. The SEC’s shift toward operational compliance means they are looking for programs that catch issues and remediate them.
- Self-reporting and remediation remain among the most effective tools available when something does go wrong internally.
Where This Leaves You
The SEC under current leadership is more selective and more focused than the prior era. That does not mean enforcement risk is lower for well-run firms. It means the firms most exposed are those with genuine conduct problems, inadequate conflict disclosures, and compliance structures that cannot demonstrate they work under scrutiny.
For growth-stage and institutional RIAs, the question is not whether you have compliance policies in place. It is whether those policies reflect the legal and regulatory risk profile of your firm, and whether you can demonstrate that when it counts.
My RIA Lawyer works with RIAs to build compliance governance structures that meet current regulatory expectations. If you have questions about what the FY2025 enforcement results mean for your firm, contact us.
