Examination Readiness
Rule 206(4)-7 Requires an Effectiveness Review: Test Evidence, Not Just Policy Wording
An annual review should show whether material controls operated, identified exceptions and produced verified remediation—not merely that policies were updated.

An annual compliance review can become a document exercise. The manual is compared with last year’s version. Regulatory developments are listed. Policy wording is updated. A memorandum records that the review occurred.
That process may test whether the programme looks current. It may not test whether the programme worked.
Rule 206(4)-7 requires an SEC-registered adviser to review the adequacy of its policies and procedures and the effectiveness of their implementation at least annually. Those are related but distinct questions.
If the firm cannot show the population tested, evidence inspected, exceptions found and remediation verified, an effectiveness conclusion is difficult to reconstruct.
What the record actually shows
17 CFR § 275.206(4)-7 applies to an investment adviser registered or required to be registered under section 203 of the Investment Advisers Act.
The rule requires the adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and rules adopted by the Commission.
It also requires the adviser to review, no less frequently than annually, the adequacy of those policies and procedures and the effectiveness of their implementation.
The adviser must designate a supervised person responsible for administering the policies and procedures.
The rule text is concise. It does not prescribe a universal testing schedule, sample size or annual-review template. Those details should not be presented as SEC requirements unless supported by another applicable source.
The eCFR is an authoritative but unofficial, continuously updated presentation of the Code of Federal Regulations. The page should be checked for currency when the article is published or materially updated.
What this means for an RIA compliance programme
The annual review should separate design from operation.
Adequacy asks whether a policy and its controls address the firm’s material risks. Effectiveness asks whether those controls operated as intended, produced evidence, identified exceptions and drove remediation.
“The firm reviews electronic communications” is not yet a testable control statement. A reviewer needs to know the population, frequency, selection method, accountable person, escalation standard, evidence retained and expected completion period.
Could the firm produce, within the examination window, the population from which a communications-review sample was selected? Could it show that the population was reconciled against active users and approved channels before sampling began?
A sample is only informative if the population is sufficiently complete. A perfectly executed test can produce false comfort when it examines only the records that successfully entered the system.
For communications, reconcile supervised persons and expected channels with archive users and capture logs. For marketing, reconcile published assets with the approval register. For personal trading, reconcile covered persons with attestations and data feeds. The precise controls depend on the firm’s business and risks.
The review should distinguish design failures from operating failures. If a policy omits a communication channel the firm permits, the design may be inadequate. If the channel is covered but capture failed for certain users, implementation failed. If reviews occurred but repeatedly closed findings without rationale, the supervisory evidence standard may be ineffective.
These distinctions determine remediation. Revising policy text does not repair a failed connector. Retraining a reviewer does not fix an incomplete population. Installing technology does not resolve unclear accountability.
Could the firm show when an exception was identified, who owned it, what corrective action occurred and how completion was tested? Assignment is not remediation. Closure without verification leaves the control conclusion dependent on assertion.
Repeated exceptions should be analysed together. A series of individually minor incidents may reveal a systemic weakness in staffing, data coverage or supervisory design.
Where management accepts residual risk, preserve the decision. Record who accepted it, the evidence considered, the duration of the acceptance, monitoring conditions and the date for reconsideration.
What “good” evidence looks like
A reconstructable annual-review file should contain:
- The material risks selected for review and the basis for prioritisation.
- The policy and control language in force during the tested period.
- A control owner and a testable description of expected operation.
- The complete or reconciled population used for testing.
- Source-system reports and reconciliation evidence.
- The sample method, sample size and selected records.
- Timestamps showing when the control and test occurred.
- The evidence inspected by the reviewer.
- Exceptions classified as design, operating or evidence failures.
- The owner, due date and escalation path for each exception.
- Corrective-action records and evidence of implementation.
- Independent verification or retesting before closure.
- Repeat-exception analysis and any broader programme conclusion.
- Residual-risk acceptance, monitoring conditions and expiry date.
- A signed conclusion that states limitations and unresolved matters.
The conclusion should identify the work supporting it. “The policy was effective” is not enough. A second reviewer should be able to trace the conclusion from risk to control, population, test, exception, remediation and verification.
Where evidence is incomplete, qualify the conclusion. A bounded conclusion is more defensible than certainty created by an unrecorded assumption.
ComplyVault implication
Where control testing depends on meetings, email or messages, the evidence set should preserve source records, participants, topics, timestamps, findings, reviewer decisions and remediation events. Sealed audit packs can keep that factual chain intact without converting the system’s output into the CCO’s conclusion.
What to do this week
- Choose three material controls scheduled for this year’s review and rewrite each as a testable statement covering population, frequency, owner, evidence and escalation.
- By day three, reconcile the population for one control against an independent source. Record all differences before selecting a sample.
- Test a small sample and classify every issue as a design, operating or evidence failure. Do not combine the categories.
- Select two previously closed exceptions and verify that remediation actually operated. Reopen any item supported only by an assignment or assertion.
- Build one evidence index linking risk, control, population, sample, exception, remediation and conclusion. Ask a reviewer outside the original test to reconstruct the result.
- Record any limitation that prevents a firm-wide conclusion and assign an owner and date for resolving it.
Educational content, not legal or compliance advice. Always confirm obligations against current regulations and your firm's counsel.
Build compliance evidence before the examiner asks for it.
ComplyVault helps RIA and compliance teams reconstruct what happened, with sealed, examiner-ready audit packs.