Whatâs Inside â Jump to the Good Stuff
If youâve been following SEC Risk Alerts over the past few years, you already know the drill: every exam cycle, the same compliance deficiencies pop up again and again. Iâve sat through dozens of mock exams and real SEC visits, and trust me â the patterns are painfully predictable. The worst part? Most firms could fix these issues in a weekend if they knew what to look for. Hereâs what the SEC keeps flagging, and exactly how to stop being a statistic.
1. Inadequate Written Supervisory Procedures (WSPs)
This is the #1 deficiency in virtually every Risk Alert. Firms either have outdated WSPs, cookie-cutter templates that donât match actual operations, or they simply donât follow whatâs written. I once walked into a firm where their WSP still listed a phone number for a broker-dealer that had been acquired three years earlier. The SEC examiners noticed within 10 minutes.
Why itâs a problem
WSPs are the rulebook for how you supervise activity. If the book is wrong, every action is suspect. The SEC expects policies that are specific to your business lines, updated at least annually, and actually used in daily workflows.
2. Weak Third-Party Oversight
Outsourcing is everywhere â portfolio accounting, trade execution, even compliance software. But most firms treat vendor due diligence as a checkbox exercise. Iâve seen due diligence files that are just a signed contract and a SOC report from two years ago. The SEC wants to see evidence that you actually monitor third parties, not just collect paperwork.
Real case I encountered
A midsize RIA used a third-party valuation provider that was later sued for inflating private company values. The RIA had no internal backup valuation. When the SEC asked âhow do you validate their numbers?â the compliance officer shrugged. That didnât end well.
3. Cybersecurity & Data Protection Gaps
Cyber risk has been a hot button in every SEC Risk Alert since 2019, yet firms still fail basic hygiene. The most common gaps: no written incident response plan, lack of multi-factor authentication (MFA) on critical systems, and unencrypted client data on laptops. Iâve tested this myself â I can usually find a way into a firmâs network within 30 minutes if they donât have MFA.
What the SEC targets
They look for: policies covering phishing, remote access controls, vendor cybersecurity reviews, and data breach notification procedures. If you handle client personally identifiable information (PII) and donât have encryption at rest, youâre essentially inviting a deficiency.
| Common Gap | Severity | Quick Win |
|---|---|---|
| No MFA on email & trading platforms | High | Enable MFA within 48 hours |
| No written incident response plan | High | Use a template from SANS Institute |
| Laptops without full-disk encryption | Medium | Deploy BitLocker or FileVault |
4. Undisclosed Conflicts of Interest
Conflicts of interest are the bread and butter of SEC exam findings. The problem isnât that conflicts exist â itâs that firms donât disclose them clearly. Iâve seen firms bury conflicts in a 50-page ADV, or use vague language like âwe may receive compensation from third parties.â Thatâs not enough.
Examples that get flagged
- Revenue sharing arrangements with fund managers without explicit client disclosure.
- Advisers recommending proprietary products without explaining the financial incentive.
- Soft dollar arrangements that are not fully described in Form ADV Part 2A.
5. Flawed Valuation Practices
Valuation is especially tricky for illiquid assets (private equity, real estate, restricted stock). The SEC frequently cites firms for not having a documented valuation process, using stale pricing, or failing to back up assumptions. I once saw a firm value a private company based on a single email from the CFO â no financials, no market comps.
The right approach
Your valuation policy should specify which methods you use (market approach, income approach, etc.), how often you review them, and who approves changes. For hard-to-value assets, consider using an independent third-party appraiser â and make sure you actually challenge their numbers, not just rubber-stamp.
6. Recordkeeping & Document Retention Failures
The SEC is obsessed with email and message records. Recent Risk Alerts highlight firms that didnât capture off-channel communications (WhatsApp, Signal, personal email). Even more basic: firms shredding documents before the retention period ends, or not keeping a record of why a client was rejected.
What Iâve seen on exams
An examiner asked a firm for all internal communications about a specific trade. The compliance team only had emails from the official system â but the portfolio manager had been texting the trader via personal phone. Those messages were gone. Thatâs a deficiency right there.
Common Questions â From the Trenches
This article was fact-checked against recent SEC Risk Alerts (2022â2024) and reflects my personal experience as a compliance consultant.
Leave a Comment
Share your thoughts