The Compliance Program You Built at $300M May Not Work at $1B
How RIAs Outgrow Their Infrastructure
An RIA can grow substantially without making an equally substantial change to its compliance program. The firm adds advisers, acquires another practice, expands into new markets, and introduces additional services. Its compliance manual is updated, employees complete their training, and the annual review remains on the calendar. From leadership’s perspective, the program appears to be keeping pace.
The underlying work may tell a different story. Billing now involves several legacy fee schedules. Advisers operate from offices with different supervisory practices. Marketing materials originate from more people and move through more channels. Client records are distributed across systems that were never designed to work together. Exceptions that once required an occasional conversation now require a repeatable process.
The compliance program built for the earlier business may no longer fit the business the firm has become.
The references to $300 million and $1 billion are illustrative, not regulatory thresholds for redesigning a compliance program. Asset growth alone does not determine operational complexity. A firm that grows through market appreciation may face a different compliance challenge from one that reaches the same AUM through acquisitions, new offices, and additional service lines. Leadership needs to understand what has changed underneath the asset figure.
Growth changes what the program must control
Consider a hypothetical RIA that begins with one office, a relatively consistent client base, a standard fee schedule, and a small group of advisers. Its CCO can readily identify who makes decisions, where records are maintained, and how exceptions reach compliance.
Several years later, the firm has acquired two practices. Some clients retain negotiated pricing. One acquired office uses a different portfolio management system. Advisers market under local brands, and a newly hired team introduces investment strategies that the original compliance procedures did not contemplate.
Even if the firm distributes one compliance manual to everyone, its operations now contain meaningful differences. The important question is whether its controls recognize those differences and address them consistently.
That principle is reflected in the SEC’s adopting release for Rule 206(4)-7. The rule requires SEC-registered advisers to adopt and implement reasonably designed written policies and procedures, review their adequacy and implementation effectiveness at least annually, and designate a CCO to administer them. The release explains that policies should reflect the nature of the adviser’s operations.
A program’s adequacy therefore cannot be assessed solely by whether its documents are current. The firm also needs to consider whether the procedures still address how its business actually operates.
Acquisitions bring obligations that must survive integration
A transaction can be commercially successful while leaving significant compliance work unfinished. Assets transfer, employees join the organization, and the acquired practice begins using the buyer’s name. Those milestones do not establish that the firm has reconciled client agreements, billing instructions, disclosures, and supervisory responsibilities.
The SEC’s 2023 Wells Fargo advisory-fee settlement provides a concrete example. According to the Commission, certain negotiated fee reductions recorded in advisory agreements were not entered into billing systems. The SEC also found deficiencies in policies and procedures intended to verify billing data and prevent overbilling of acquired and other clients. More than 10,900 accounts were overcharged more than $26.8 million. The firms agreed to a $35 million civil penalty, without admitting or denying the charges.
For an acquisitive RIA, the practical lesson is that transferring information into a common system does not establish its accuracy. Integration should include verification that the system reflects the obligations the firm has undertaken.
For example, management should be able to identify who reconciles legacy fee agreements to billing instructions, how discrepancies are escalated, and what evidence supports the conclusion that a conversion is complete. If a review identifies errors, the response should address both the affected accounts and the process that allowed those errors to persist.
Those are operational decisions that belong in the integration plan and budget.
Additional offices require deliberate supervision
Geographic expansion changes the distance between leadership and the activity it must oversee. An informal process that worked when the CCO could speak directly with every adviser may become unreliable when the firm operates across multiple offices.
The SEC staff’s 2020 Risk Alert on advisers with multiple branch offices identified policies that were outdated, inconsistently applied, inadequately implemented, or unenforced. Staff also observed situations in which compliance did not receive records that the firm’s procedures required. The alert describes examination observations; it does not create new legal obligations.
The management question is how the firm verifies that its stated supervisory structure operates at each location. A branch manager’s assurance that an office follows the manual is useful information, but it should not be the only basis for that conclusion.
I would look for a clear connection between each office’s activities and the firm’s oversight. Who reviews locally produced marketing? How are unusual client arrangements identified? Which records reach the central compliance team? How does the firm determine whether an office requires closer attention?
A consistent program can accommodate legitimate differences between offices. Those differences need to be understood, documented, and supervised.
Testing must evolve with the business
A growing RIA may continue performing the same tests it performed years earlier because those tests are familiar and easy to schedule. The calendar remains full, but the coverage becomes less representative.
Fee testing illustrates the problem. A sample drawn entirely from the original client population may reveal little about accounts inherited through an acquisition. Reviewing a standard fee schedule may miss negotiated exceptions, householding arrangements, excluded assets, or termination refunds.
The SEC staff’s 2021 Risk Alert on investment advisers’ fee calculations identifies deficiencies involving fee calculations and related controls, including breakpoints, account aggregation, and refunds. These observations provide useful areas to consider when evaluating whether a firm’s testing reflects its billing arrangements.
My recommendation is to revisit the basis for selecting accounts and transactions whenever the business changes materially. The firm should be able to explain why the work performed provides meaningful coverage of its current risks. That explanation becomes particularly important when several business units share one compliance calendar but operate differently.
Testing should also lead to a decision. When a review uncovers an exception, someone needs to determine its scope, assign corrective action, and evaluate whether the correction worked. Repeatedly identifying the same issue without changing the underlying process is a signal that the program needs management attention.
Resource decisions belong alongside growth decisions
The SEC staff addressed this problem directly in its 2020 Risk Alert on investment adviser compliance programs. Staff observed advisers that had grown significantly in size or complexity without adding sufficient compliance staff or adequate technology, contributing to failures in implementing or tailoring their procedures.
For leadership, the practical implication is to evaluate compliance capacity when approving growth. An acquisition may require agreement reviews, data reconciliation, employee onboarding, training, and targeted testing while the existing program continues to operate. A new service can require specialized knowledge as well as additional review time.
Adding every new responsibility to an already full workload creates a resource decision, whether management formally acknowledges it or not. Work will be delayed, performed less thoroughly, or displaced by the most urgent request.
The CCO should be able to identify those tradeoffs and bring them to leadership. Management should then decide how the firm will provide the people, expertise, systems, and authority needed to support the expanded business. The appropriate solution may combine internal staff and outside support; its effectiveness depends on clear responsibilities and coordination.
The annual review should examine the firm’s changes
The annual review is an opportunity to assess whether the compliance program still fits the organization. A useful review begins with the changes in the business and traces their consequences through the program.
Which offices were added? Which services changed? Were client accounts migrated? Did the firm introduce different compensation arrangements or new sources of referrals? For each significant development, leadership should be able to identify the affected policies, controls, training, and testing.
The SEC’s compliance-rule adopting release also explains that advisers should consider interim reviews in response to significant compliance events, changes in business arrangements, and regulatory developments. A firm need not wait for its customary annual review date to evaluate a material operational change.
For a major acquisition or system conversion, I would build that evaluation into the project itself. Before implementation, identify the controls that must be in place. After implementation, verify that they function as intended. Unresolved items should have owners, deadlines, and a clear path for escalation.
Test whether the program can support the next stage
Leadership can begin with a practical exercise: select the firm’s most recent significant growth initiative and trace one affected process from beginning to end. For an acquisition, that might mean following a negotiated fee from the client agreement through account setup, billing, testing, and any required correction.
The exercise should establish who owns each step, what information passes between teams, and how the firm detects a failure. If the process works only because an experienced employee remembers to intervene, the organization has identified an area that needs stronger structure. That concern connects directly to the CCO key-person risk discussed in our previous article.
I would also ask leadership to examine the next planned stage of growth. A program already struggling to cover existing operations needs attention before another transaction or expansion adds to its responsibilities.
A scalable compliance program gives management a credible basis for understanding whether the firm can support the business it intends to build. It makes responsibilities clear, brings exceptions into view, and provides evidence that corrective work is complete.
My RIA Lawyer helps growth-oriented RIAs evaluate and strengthen their compliance operations. If your firm has added assets, advisers, offices, or acquisitions faster than its compliance capabilities have developed, explore our outsourced compliance services to discuss the support your next stage of growth requires.
