Enroll in Compliance U now! Secure your spot now. Learn More
Menu
Call
Contact
Blog

If Your CCO Disappeared for 30 Days, What Would Stop? A Key-Person Risk Test for Growing RIAs

Leila Shaver — RIA CCO key-person risk and compliance continuity

As registered investment advisers grow, one of the least visible compliance risks is also one of the most consequential: the possibility that too much of the compliance program depends on one person.

In many firms, that person is the Chief Compliance Officer. The CCO knows which advisers require additional supervision, which testing exceptions remain unresolved, which policies do not quite match actual practice, what was discussed with exam staff during the last SEC examination, and where the evidence supporting difficult compliance decisions is stored. None of that necessarily looks like a problem while the CCO is available. In fact, it often reflects the competence and experience of a strong compliance professional.

The weakness becomes apparent when that person is suddenly unavailable.

For larger RIAs, the relevant question is not simply whether another person could be named interim CCO. It is whether the compliance program could continue to operate as an institutional function without requiring someone to reconstruct the firm’s compliance history from email, spreadsheets, shared drives, and the departing CCO’s memory.

That distinction matters because the Investment Advisers Act compliance rule is fundamentally an implementation rule, not a documentation rule. Rule 206(4)-7 requires an SEC-registered adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act, to review those policies and procedures at least annually for both adequacy and effectiveness, and to designate a CCO responsible for administering them. When the SEC adopted the rule, it expressly stated that an adviser’s failure to maintain adequate compliance policies and procedures could itself constitute a violation even before a separate securities-law violation occurred.

Growth can turn a strong CCO into a structural dependency

The problem usually develops gradually. A firm grows, adds advisers, opens offices, acquires another practice, expands its marketing program, implements new technology, or adds services. Each time, the CCO absorbs another piece of the process because doing so is efficient and because the CCO already understands the regulatory implications.

Over time, that can produce a compliance function in which the organization has policies, calendars, technology, and staff, but the real operating logic of the program remains concentrated in one individual.

The SEC has repeatedly identified this mismatch between firm growth and compliance resources. In its 2020 Risk Alert on investment adviser compliance programs, examination staff observed advisers that had not devoted sufficient staff, technology, training, or other resources to their compliance functions, as well as CCOs who lacked sufficient authority to develop and enforce policies and procedures. The staff also identified firms that had grown in size or complexity without appropriately adapting their compliance programs.

For an RIA managing several billion dollars across multiple offices, that is not merely a staffing issue. It is a governance issue.

The better test is operational continuity

A useful way to evaluate this risk is to assume the CCO became completely unavailable for 30 days. Could another qualified person identify the testing that is currently open or overdue? Could that person determine which findings remain unresolved and who owns each remediation item? Could they locate the workpapers supporting prior reviews, explain why an exception was accepted, identify which advisers or offices present recurring supervisory concerns, and understand what commitments were made following the firm’s last examination?

Could they identify marketing materials awaiting approval, locate substantiation for material marketing claims, determine whether fee exceptions are still being investigated, and explain the status of any heightened supervision?

Those questions are more revealing than asking whether the firm has a backup CCO. A firm can have a designated successor and still lack operational continuity. The real question is whether someone other than the primary CCO can understand the current state of the program without the CCO narrating it.

SEC examinations expose this problem quickly

This becomes particularly important in an examination. The SEC’s 2023 Risk Alert on adviser examination scoping and document requests provides an unusually practical view into the Division of Examinations’ process. The initial requests are designed not only to collect policies but also to understand the adviser’s business, risks, controls, trading activity, compliance practices, and the effectiveness of the policies and procedures the firm has implemented. Those requests may expand as the examination progresses.

That means the firm must be able to do more than locate documents. It must be able to explain how those documents fit together.

An examiner may want to understand what risk the firm identified, what control it adopted, how the control was tested, what happened when the control failed, what remediation occurred, and whether the firm verified that the remediation worked. If the answer to those questions exists primarily in one person’s memory, the firm does not have a fully institutionalized compliance program.

The SEC’s litigation docket provides a more extreme illustration of why production and institutional knowledge matter. In SEC v. Lufkin Advisors, LLC, the Commission alleged, among other things, that the adviser and its president and CCO failed to produce books and records requested by SEC examination staff. The case involved much more serious allegations than ordinary examination-readiness issues, but it underscores a basic point: a firm’s ability to produce and explain required records is not an administrative afterthought.

Enforcement actions show why implementation matters

The enforcement record reinforces the distinction between having policies and actually implementing them. In September 2024, the SEC brought a settled administrative proceeding against Jordan/Zalaznick Advisers, Inc. for failing to implement written compliance policies and procedures in connection with an umbrella registration structure. The adviser agreed to pay a $150,000 civil penalty. The significance of the matter is not the particular registration structure; it is that the SEC focused on whether a unified compliance program was implemented in practice.

Similarly, in September 2025, the SEC charged Meridian Financial, LLC with violations involving marketing, books and records, implementation of compliance policies and procedures, and its annual compliance review. Again, the weakness identified by the Commission was not simply the absence of written language. It was that the compliance framework did not function as required.

In December 2024, Morgan Stanley Smith Barney agreed to pay a $15 million penalty after the SEC charged the firm with supervisory and policy deficiencies that contributed to failures to prevent and detect financial advisers’ theft of client and customer funds. That matter involved significant investor harm, but the broader lesson is relevant to every RIA: written supervisory structures are only as strong as the controls operating underneath them.

And in July 2025, the SEC brought settled charges involving American Portfolios Advisors, Inc. and separately charged its former CCO and former president after finding that backdated compliance documents were created and provided to SEC staff during an examination. The matter is an especially stark reminder that the evidentiary record of a compliance program must be reliable. A firm that cannot trust its own records has a problem far larger than document organization.

Compliance information should belong to the institution

A mature compliance program should be capable of explaining itself. The organization should be able to identify what was tested, what failed, what corrective action was assigned, what evidence demonstrates completion, whether the control was retested, and whether the issue was formally closed.

That information should not disappear when a particular employee goes on leave, resigns, retires, or becomes unavailable. This does not mean the CCO becomes less important. It means the CCO is no longer forced to serve as the firm’s sole compliance memory.

In fact, reducing key-person dependency should strengthen the CCO’s role. The SEC has emphasized that an effective CCO must have sufficient authority, seniority, resources, and access to management. In a 2020 speech, the then-Director of OCIE described the CCO as needing to be empowered, senior, and supported with appropriate resources. That guidance is consistent with the broader principle that compliance should be embedded in the organization rather than isolated in one individual.

Technology helps only if the operating model is sound

Technology can materially improve this problem, but technology alone does not solve it. A compliance platform can show that a task was completed. It may not explain why an exception was accepted. It can store a workpaper. It may not preserve the reasoning behind a difficult decision. It can show that remediation was closed. It may not tell management whether the underlying control was ever retested.

The objective should not be digitization for its own sake. It should be institutional memory, defensible evidence, clear ownership, and visibility. That requires the compliance operating model and the technology to work together.

This is also where executive visibility matters. Leadership should not need to review every testing workpaper, but it should be able to understand whether significant findings remain open, whether remediation is moving, whether the same issues are recurring, and whether the compliance function has the capacity to keep up with the business.

Executive diagnostic: would your program survive 30 days without the CCO?

A useful diagnostic is to select several active compliance processes and ask someone other than the primary CCO to explain the current status. That person should be able to identify the owner, locate the relevant evidence, explain any exception, and describe the next step without relying on the CCO’s inbox or memory.

If the answer repeatedly becomes “we need to ask the CCO,” leadership has identified a structural dependency. That does not mean the program is failing. It means the firm has discovered where institutionalization has not kept pace with growth.

The same exercise should be applied to examination commitments, recurring findings, branch supervision, marketing substantiation, fee testing, books and records, offboarding, complaint handling, and any area in which judgment or historical context materially affects the compliance decision.

The goal is resilience, not replaceability

The real issue is not whether your CCO plans to leave. Most key-person risks do not announce themselves in advance. The real question is whether the compliance program is capable of operating as an institutional function.

A mature compliance program should survive vacations, medical leave, turnover, growth, acquisitions, regulatory exams, and eventually succession. The firm should not have to rebuild the compliance narrative every time the person who remembers it becomes unavailable.

The compliance program should belong to the institution, not live inside the CCO’s head.

That is the standard I would use to evaluate whether a growing RIA has truly built a scalable compliance program.

My RIA Lawyer works with growth-oriented RIAs to build testing, remediation, documentation, backup capacity, and executive visibility into the compliance function. If one person’s absence would materially disrupt your compliance program, it may be time to pressure-test the operating model before an examination, transition, acquisition, or leave of absence forces the issue.

Learn more about CCO On Call or our outsourced compliance services.

Author Bio

Securities Litigation Lawyer - leila shaver

Leila Shaver is the Founder of My RIA Lawyer, a law firm that provides compliance and legal consulting for financial institutions. With extensive experience as a securities attorney and compliance expert, she has served as Chief Compliance Officer and General Counsel to RIAs, BDs, and TAMPs with billions in assets under management.

Leila understands the challenges RIAs face and is committed to helping RIAs streamline their processes, mitigate risks, and ensure compliance with regulatory requirements. She received her Juris Doctor from Atlanta’s John Marshall Law School and is a West Georgia Young Lawyers’ Association member. Leila has received numerous accolades for her work, including the Carroll County Bar Association’s Outstanding Young Lawyer Award in 2017.

LinkedIn | State Bar Association | Avvo | Google