Your Cybersecurity Policies Make Promises. Your Annual Review Has to Keep Them.

On September 14, 2026, the SEC’s Division of Examinations published a six-page risk alert on how investment advisers conduct the annual compliance review required by Rule 206(4)-7(b) (sec.gov, PDF). Most of its examples involve fee billing, proxy voting, custody, the Marketing Rule, and Form CRS. One example names the identity theft program outright, and two others translate readily to how a cybersecurity program is reviewed. This article covers those three, plus two documentation observations that apply to the cyber section as written.

Start with what the alert is. Its first footnote says it represents staff views, has no legal force, and creates no new obligation. That is accurate. The obligations were already on the books: Rule 206(4)-7(b) requires you to review, “no less frequently than annually,” the adequacy of your policies and procedures and the effectiveness of their implementation, and Rule 204-2(a)(17)(ii) requires you to keep “any records documenting” that review. What the alert adds is a description of how examiners have been finding the gaps.

How the staff finds the gap

The method is in one sentence of the alert. The staff “often identified these inconsistencies after observing issues in core areas of the advisers’ business, operations, and services, which were then compared to the advisers’ annual reviews and applicable written compliance policies and procedures.”

That is a three-way comparison: what your policy says, what your firm does, and what your annual review looked at. A cybersecurity program generates more material for that comparison than most of the manual, because it is full of dated commitments and it produces logs.

The rest of the article covers the three places the alert reaches the cybersecurity program: the tests your own policies mandate and your review skipped (the staff’s example is an identity theft program under Regulation S-ID), the incident log that has to reconcile with the review, and delegated functions with no stated oversight method under amended Regulation S-P. It then covers workpapers, superseded policy versions, and corrective actions reported as done, explains why the next review is the first under the amended Reg S-P requirements, and closes with a seven-step self-check to run before the review starts.

The rest of this article is free to read with a BrainTrust account. Free members also get every Insight, the Securing Compliance exam report, the Mock SEC Cyber Exam, and the Document Review Matrix. Name and email, no card.

Create your free account   Already a member? Sign in

Done For You

Need it handled for you? Remote CISO and cyber compliance engagements for RIAs →