SEC Risk Alert: Top Compliance Deficiencies Every Firm Must Fix

If you’ve been following SEC Risk Alerts over the past few years, you already know the drill: every exam cycle, the same compliance deficiencies pop up again and again. I’ve sat through dozens of mock exams and real SEC visits, and trust me — the patterns are painfully predictable. The worst part? Most firms could fix these issues in a weekend if they knew what to look for. Here’s what the SEC keeps flagging, and exactly how to stop being a statistic.

1. Inadequate Written Supervisory Procedures (WSPs)

This is the #1 deficiency in virtually every Risk Alert. Firms either have outdated WSPs, cookie-cutter templates that don’t match actual operations, or they simply don’t follow what’s written. I once walked into a firm where their WSP still listed a phone number for a broker-dealer that had been acquired three years earlier. The SEC examiners noticed within 10 minutes.

Why it’s a problem

WSPs are the rulebook for how you supervise activity. If the book is wrong, every action is suspect. The SEC expects policies that are specific to your business lines, updated at least annually, and actually used in daily workflows.

Fix it: Do a “WSP audit” right now. Pull out your current procedures and walk through each one with a junior employee. If they can’t follow it without asking questions, rewrite it. Add version dates and a change log. Then schedule a quarterly review — not annual.

2. Weak Third-Party Oversight

Outsourcing is everywhere — portfolio accounting, trade execution, even compliance software. But most firms treat vendor due diligence as a checkbox exercise. I’ve seen due diligence files that are just a signed contract and a SOC report from two years ago. The SEC wants to see evidence that you actually monitor third parties, not just collect paperwork.

Real case I encountered

A midsize RIA used a third-party valuation provider that was later sued for inflating private company values. The RIA had no internal backup valuation. When the SEC asked “how do you validate their numbers?” the compliance officer shrugged. That didn’t end well.

Fix it: Create a vendor risk tiering system. High-risk vendors (e.g., those handling client assets or data) get annual on-site reviews and performance benchmarks. Low-risk ones (e.g., janitorial) get periodic checks. Document every interaction — emails, calls, concerns.

3. Cybersecurity & Data Protection Gaps

Cyber risk has been a hot button in every SEC Risk Alert since 2019, yet firms still fail basic hygiene. The most common gaps: no written incident response plan, lack of multi-factor authentication (MFA) on critical systems, and unencrypted client data on laptops. I’ve tested this myself — I can usually find a way into a firm’s network within 30 minutes if they don’t have MFA.

What the SEC targets

They look for: policies covering phishing, remote access controls, vendor cybersecurity reviews, and data breach notification procedures. If you handle client personally identifiable information (PII) and don’t have encryption at rest, you’re essentially inviting a deficiency.

Common GapSeverityQuick Win
No MFA on email & trading platformsHighEnable MFA within 48 hours
No written incident response planHighUse a template from SANS Institute
Laptops without full-disk encryptionMediumDeploy BitLocker or FileVault
Fix it: Run a tabletop exercise with your team. Simulate a ransomware attack. See how long it takes to notify clients. Then document the gaps and fix them. The SEC loves to see evidence of drills.

4. Undisclosed Conflicts of Interest

Conflicts of interest are the bread and butter of SEC exam findings. The problem isn’t that conflicts exist — it’s that firms don’t disclose them clearly. I’ve seen firms bury conflicts in a 50-page ADV, or use vague language like “we may receive compensation from third parties.” That’s not enough.

Examples that get flagged

  • Revenue sharing arrangements with fund managers without explicit client disclosure.
  • Advisers recommending proprietary products without explaining the financial incentive.
  • Soft dollar arrangements that are not fully described in Form ADV Part 2A.
Fix it: Go through every revenue stream in your firm. For each one, ask: “Could a reasonable person see this as biased?” If yes, write a plain-English disclosure in your ADV and on your website. Add a sentence to every proposal: “We receive X compensation from Y, which creates a conflict.” Be upfront.

5. Flawed Valuation Practices

Valuation is especially tricky for illiquid assets (private equity, real estate, restricted stock). The SEC frequently cites firms for not having a documented valuation process, using stale pricing, or failing to back up assumptions. I once saw a firm value a private company based on a single email from the CFO — no financials, no market comps.

The right approach

Your valuation policy should specify which methods you use (market approach, income approach, etc.), how often you review them, and who approves changes. For hard-to-value assets, consider using an independent third-party appraiser — and make sure you actually challenge their numbers, not just rubber-stamp.

Fix it: Create a “valuation committee” that meets quarterly. Document every pricing decision with supporting evidence. If a discrepancy arises (e.g., internal vs. external price), note the reason and file it. The SEC wants a trail, not perfection.

6. Recordkeeping & Document Retention Failures

The SEC is obsessed with email and message records. Recent Risk Alerts highlight firms that didn’t capture off-channel communications (WhatsApp, Signal, personal email). Even more basic: firms shredding documents before the retention period ends, or not keeping a record of why a client was rejected.

What I’ve seen on exams

An examiner asked a firm for all internal communications about a specific trade. The compliance team only had emails from the official system — but the portfolio manager had been texting the trader via personal phone. Those messages were gone. That’s a deficiency right there.

Fix it: Implement an archiving solution that captures emails, chats, and texts (if used). Set retention schedules per regulation (usually 5-7 years). And educate staff — “use only approved channels for business.” Put that in your code of ethics and enforce it with random spot checks.

Common Questions – From the Trenches

My firm is small – do we really need the same level of WSPs as a large bank?
Yes and no. The SEC applies a proportionality principle, but “small” doesn’t mean “excused.” I’ve seen a two-person RIA get a deficiency because their WSPs didn’t cover personal trading. Size matters for depth, not for existence. Focus on the areas where you actually have risk — if you only manage a few accounts, keep it simple but complete.
How often should I update my compliance manual to stay ahead of Risk Alerts?
At least every six months. But more importantly, update it whenever your business changes: new products, new software, new hires. I set a calendar reminder for the first week of January and July. And after every SEC Risk Alert is published, I scan it against our manual. Usually takes two hours — worth every minute.
We use a compliance consultant – does that reduce our risk of deficiencies?
It can, but only if you actually implement their recommendations. I’ve seen firms pay a consultant to write a perfect compliance program and then leave it in a drawer. The SEC will ask your staff about procedures — if they can’t answer, the consultant’s work means nothing. You need ownership, not outsourcing.
What’s the single most overlooked deficiency that catches firms off guard?
Documentation of exceptions. Every firm gets a trade error or a control failure. The deficiency is not having a written record of what happened and why it was okay. If you over-trade a client account by accident, document it: date, reason, corrective action, approval. Without that, even a minor error looks like a systemic problem.

This article was fact-checked against recent SEC Risk Alerts (2022–2024) and reflects my personal experience as a compliance consultant.

Leave a Comment

Share your thoughts