Rule 206(4)-7 requires an adviser to review, at least annually, the adequacy of its compliance policies and the effectiveness of their implementation. Most firms do this faithfully for trading, custody, and marketing — and then the cybersecurity section says something like “the firm’s IT provider confirmed systems are secure.” That sentence answers neither of the questions the rule actually asks — and examiners know it.
The rest of this article is free to read with a BrainTrust account. Free members also get every Insight, the Securing Compliance exam report, the Mock SEC Cyber Exam, and the Document Review Matrix — name and email, no card.