Testing Is Not the Same as Oversight: Why RIA Compliance Findings Keep Reappearing
The quarterly compliance report arrives with the testing calendar complete and most findings marked closed. Marketing corrected the advertisements flagged during review. Operations fixed the billing exceptions. Employees submitted their overdue personal trading reports. From the executive team’s perspective, the program appears to be working: compliance identified problems, the business responded, and the report documents the results.
Then the next quarter’s testing finds substantially the same issues. Different advertisements, different accounts, perhaps a different office, but familiar problems. The CCO sends another round of reminders, department heads promise to address them, and the cycle begins again.
For a growing RIA, this pattern should prompt a closer examination of what “closed” actually means. Testing can successfully identify exceptions while the process for resolving them leaves their causes untouched. A firm may have extensive workpapers and a diligently maintained compliance calendar yet struggle to explain why problems it supposedly resolved continue to surface.
The question for the CCO and COO is whether the firm’s response changes how the business operates. Fixing an identified error matters, particularly when a client has been affected. But when the same error returns, leadership needs to understand what the original response missed.
What the testing report cannot tell you
The Advisers Act compliance rule requires SEC-registered advisers to adopt and implement written policies and procedures reasonably designed to prevent violations, review their adequacy and the effectiveness of their implementation at least annually, and designate a CCO to administer them. The SEC’s adopting release explains that the review should consider compliance matters arising during the previous year and changes affecting the business. The effectiveness of implementation is central to that review. SEC compliance rule adopting release
A completed testing calendar provides useful evidence that reviews occurred. Its conclusions depend, however, on what those reviews examined and how the firm responded. Reviewing a sample of advertisements may establish that several were distributed without approval. Removing those advertisements addresses the immediate concern. Neither action, by itself, demonstrates that the approval process now functions consistently across the firm.
SEC examination staff has observed this gap. Its 2017 risk alert describes advisers that did not address or correct problems identified during annual reviews, as well as reviews that failed to assess implementation effectiveness. The alert reports staff observations rather than imposing additional requirements, but the operational concern is clear: identifying a problem and addressing it are separate responsibilities. SEC risk alert on frequent adviser deficiencies
This distinction can disappear in executive reporting. A dashboard that measures tests completed and findings closed may give equal credit to very different responses. One finding may have prompted a process change supported by subsequent testing. Another may have been closed after an employee promised to be more careful. Without examining the basis for closure, management cannot tell how much confidence to place in either result.
How a corrected exception becomes a recurring finding
Consider a hypothetical billing review at an RIA that has grown through acquisitions. Compliance finds that several accounts did not receive the household discounts reflected in their advisory agreements. Operations corrects the account settings, determines the appropriate reimbursements, and provides evidence that the adjustments were processed. The immediate client issue receives attention, and the finding is closed.
The following quarter, the same problem appears in accounts associated with another acquired practice. The firm treats it as a new set of billing exceptions, but the underlying cause may be identical. Perhaps household relationships are recorded during onboarding without a reliable transfer into the billing platform. Perhaps negotiated terms arrive in documents that the billing team does not receive. Perhaps different offices have developed different interpretations of who is responsible for confirming the final configuration.
Correcting the original accounts would not resolve any of those conditions. The first review established that errors existed; the response needed to examine how those errors entered the system and whether other accounts were exposed to the same weakness.
This is where an issue register can obscure a pattern. A finding described as an onboarding error in March may be recorded as a billing discrepancy in June. Each department responds to its assigned item, while the common failure at the handoff between them remains unaddressed. Management sees several relatively small exceptions instead of a process that repeatedly produces incorrect outcomes.
Recurring findings do not automatically establish that the entire compliance program is ineffective. They do, however, provide a reason to revisit the firm’s understanding of the cause. When a response has not prevented recurrence, repeating it deserves more scrutiny than it received the first time.
The work between identifying a problem and closing it
Effective remediation begins with an explanation of what failed that is specific enough to support a change. “Human error” rarely provides that explanation on its own. An employee may have made a mistake, but the circumstances still matter. Was the instruction clear? Was the necessary information available? Did the workflow require someone to enter the same information into multiple systems? Was a review step routinely bypassed because it delayed account opening?
The answers shape the response. Additional training may be appropriate when employees misunderstand a requirement. It will accomplish less when the real problem is missing information, incompatible systems, or an approval process that the business regularly works around. A policy revision can clarify expectations, but someone still needs to establish how the revised procedure will operate in practice.
The firm also needs to consider the scope of the problem beyond the tested examples. If an exception arose from a configuration used across a billing population, reviewing only the accounts in the original sample may leave other affected clients unidentified. If an office distributed an outdated advertisement, the response may require determining where else that version was used. The appropriate additional review depends on the facts, but the reasoning should be clear enough for someone else to understand why the firm considered the response sufficient.
Responsibility often becomes difficult at this stage because the CCO can identify the problem without controlling the resources required to fix it. A change may depend on the operations team, a technology provider, a branch leader, or an executive decision about priorities. Assigning the entire matter to compliance can leave the person tracking the issue responsible for an outcome they lack the authority to deliver.
SEC staff’s 2020 compliance program risk alert described inadequate compliance resources, restricted CCO access to critical information, and limited interaction between CCOs and senior management. Those observations are relevant to firms whose findings remain open because the compliance function cannot obtain the information or decisions it needs. SEC observations on investment adviser compliance programs
A practical response gives the corrective work to someone who can change the affected process, while preserving compliance’s ability to assess, challenge, and escalate the result. If implementation requires funding or a change in business priorities, leadership should see that decision explicitly. Otherwise, the issue can spend months appearing on a report as “compliance following up,” even though the unresolved question belongs to management.
What evidence should support closure?
Before closing a material finding, the firm should be able to explain what was corrected, what changed, and why it believes the response was effective. These are practical standards for evaluating remediation, rather than a prescribed regulatory template. The depth of the work should reflect the significance and scope of the issue.
Evidence of activity has value, but its meaning should be precise. A revised procedure establishes that the written instruction changed. An attendance record establishes that employees participated in training. A vendor confirmation may establish that a requested system update was completed. Those records help document implementation, but further work may be necessary to evaluate whether the change produces the intended result.
In the billing example, checking the corrected accounts confirms that their settings were fixed. Reviewing households established after the new onboarding procedure took effect addresses a different question: whether the revised process reliably captures the required discount. That distinction should influence the firm’s follow-up work.
Timing matters as well. A quarterly control implemented yesterday has not yet operated through its next quarterly cycle. The firm may reasonably record that implementation is complete while leaving validation outstanding. Keeping those stages visible prevents management from assuming that a completed installation, procedure update, or training session has already demonstrated effectiveness.
For significant findings, a qualified reviewer who did not implement the change can provide a useful challenge to the closure decision. The appropriate arrangement will depend on the firm’s resources and the nature of the issue. What matters is that the review evaluates relevant evidence instead of relying entirely on the implementer’s assurance.
The conclusion should also respect the limits of the work performed. A successful review of one office does not necessarily demonstrate consistent implementation across every location. A clean sample supports a conclusion about the activity examined; the firm should be able to explain why that scope was appropriate. If follow-up work finds the same failure, the issue needs renewed analysis rather than another closure based on the same explanation.
Give leadership a clearer view of unresolved risk
Executive reporting should help management decide where to intervene. Testing completion remains useful, but it belongs alongside information about material unresolved findings, recurring causes, remediation awaiting validation, and decisions that require executive action.
An issue’s history should remain visible when its deadline changes. Moving a due date may be justified, particularly when a fix depends on a larger technology project, but the new date should not erase how long the problem has existed. Management needs to understand both the reason for the delay and how the firm is addressing the exposure in the meantime.
Age alone should not determine priority. A newly discovered billing issue affecting clients may require faster action than an older administrative matter. The report should convey the significance of the finding, the current response, and what is preventing resolution. A concise explanation of those facts is more useful than a color designation without context.
Leadership should also be cautious about equating fewer findings with better compliance. Improved testing can uncover problems that earlier reviews missed. The more informative measure is how well the firm understands and responds to what it finds, including whether the same underlying weaknesses persist across reporting periods.
A useful starting point is to select three material findings the firm considers closed and follow each from the original evidence through the closure decision. The responsible team should be able to explain the scope of the problem, the basis for its assessment of the cause, the corrective work, and the evidence supporting the outcome. If that explanation requires reconstructing months of email or relying on someone’s memory, the record may not adequately support the conclusion.
This exercise can also expose premature closure. A file containing a revised policy but no evidence of implementation tells a different story from one containing subsequent activity reviewed under the revised process. Looking closely at a few completed matters can reveal weaknesses that a high-level review of the entire issue register would miss.
When the same findings return, examine what happens after testing
A growing RIA needs testing that identifies meaningful weaknesses and a management process that carries those findings through to an appropriate resolution. As the firm adds offices, systems, and adviser teams, that work increasingly crosses departmental boundaries. The CCO’s diligence remains important, but it cannot substitute for business ownership, adequate resources, and timely executive decisions.
When findings keep returning, the next investment may need to be in how the firm investigates causes, assigns corrective work, and evaluates results. Additional testing can provide more information, but the organization still needs to act on what it already knows.
My RIA Lawyer’s Outsourced Compliance Department provides a compliance team and attorney oversight to support growing RIAs. For a CCO or COO assessing where additional support would help, recurring findings offer a concrete starting point. The evidence behind three recently closed matters can show where the process is working—and where the firm needs stronger follow-through.
