Examination Readiness — Worked Examples
Worked scenarios with compliance issues and analysis, supporting the examination-readiness skill.
Example 1: Newly registered RIA receives first SEC examination notification
Scenario: A registered investment adviser that has been in operation for 18 months and manages $350 million in client assets receives its first SEC examination notification letter. The firm has four employees: the founder/portfolio manager (who is also the designated CCO), a junior analyst, an operations manager, and an administrative assistant. The initial document request list contains 45 items spanning compliance policies, trading records, advertising materials, fee calculations, and cybersecurity documentation. The firm has 21 calendar days to produce the documents. The CCO has never been through a regulatory examination.
Compliance Issues:
- New registrants are a high-priority examination category for the SEC Division of Examinations. The staff will assess whether the firm has actually implemented the compliance program described in its Form ADV.
- A firm with the founder serving as both portfolio manager and CCO presents an inherent conflict of interest — the CCO is overseeing the compliance of the person who also manages the firm and makes investment decisions. SEC staff will scrutinize whether the compliance function is genuinely independent and effective.
- With only four employees, the firm has limited resources to manage a 45-item document request while continuing normal operations.
- New registrants frequently have compliance policies that were adopted at registration but never updated or tailored to reflect the firm's actual practices as the business developed during its first 18 months.
Analysis: The CCO should take the following steps immediately upon receiving the notification letter. First, engage outside compliance counsel or a compliance consultant with SEC examination experience — attempting to navigate a first examination without experienced guidance significantly increases risk. Second, assign responsibility for each IDR item to a specific person with a clear internal deadline (at least five days before the SEC deadline to allow for quality review). Third, conduct a rapid self-assessment: compare the firm's written compliance policies to its actual practices and identify any material gaps. If the compliance manual was adopted at registration but not updated since, this gap will be apparent to examiners and should be acknowledged proactively. Fourth, prepare for staff interviews — the SEC will almost certainly interview the CCO/founder at length about the compliance program, fee calculations, trading practices, and advertising. The founder should be able to articulate the firm's investment process, compliance controls, and how conflicts of interest (including the dual PM/CCO role) are managed. Fifth, review the firm's Form ADV for accuracy — the examination staff will compare the ADV disclosures to actual practices, and any inconsistencies will generate findings. Common mistakes first-time examinees make include: producing documents without a quality review (resulting in incomplete or disorganized productions that frustrate staff and extend the examination); becoming defensive during interviews rather than being forthcoming and professional; failing to request a reasonable extension when the production deadline is genuinely unachievable (most examination staff will grant a short extension for first-time examinees if asked promptly and with good reason); and neglecting to implement a document hold, resulting in the routine deletion of emails or records within the scope of the examination.
Example 2: Deficiency letter with six findings requiring structured response
Scenario: A mid-size investment adviser ($2 billion AUM, 30 employees) receives a deficiency letter from the SEC Division of Examinations following a routine examination. The letter identifies six deficiency findings: (1) custody rule violations — the adviser has inadvertent custody over three client accounts where it serves as trustee, but has not obtained a surprise examination or ensured independent verification under Rule 206(4)-2; (2) advertising compliance — the firm's website includes backtested performance for a model portfolio without required disclosures regarding methodology, assumptions, limitations, or risks, and without net performance alongside gross performance, in violation of Rule 206(4)-1; (3) incomplete books and records — the firm failed to retain business-related text messages exchanged between the portfolio manager and a broker-dealer counterparty, in violation of Rule 204-2; (4) code of ethics — two access persons failed to submit quarterly transaction reports for three consecutive quarters, and the firm had no process to identify or follow up on missing reports, in violation of Rule 204A-1; (5) annual compliance review — the firm's most recent annual review under Rule 206(4)-7 was a two-page summary that did not assess the adequacy of any specific policy or procedure; (6) cybersecurity — the firm had no written incident response plan and had not conducted a risk assessment of its information technology systems. The firm has 30 days to respond.
Compliance Issues:
- Six findings spanning multiple compliance areas suggest systemic compliance program weaknesses rather than isolated lapses.
- The custody rule violation is the most serious finding because it directly affects client asset safety. Failure to comply with Rule 206(4)-2 is an area where the SEC has historically pursued enforcement action.
- The off-channel communications finding (failure to retain text messages) aligns with a major SEC enforcement priority — the Division of Enforcement has brought dozens of actions against firms for recordkeeping failures related to off-channel communications.
- The inadequate annual compliance review finding suggests that the firm's overall compliance oversight is deficient, which undermines the credibility of the firm's compliance program as a whole.
Analysis: The firm should structure its response as follows. First, engage compliance counsel to assist in drafting the response — given the number and seriousness of the findings, professional guidance is important. Second, address each finding individually in the order presented in the deficiency letter. For each finding, the response should: acknowledge the finding (or explain the basis for disagreement, if applicable); describe the root cause; detail the specific corrective actions already taken; provide a timeline for any remaining remediation; and identify the responsible person.
For finding (1) (custody), the firm should immediately engage an independent public accountant to conduct the required surprise examination under Rule 206(4)-2(a)(4), or alternatively, ensure that the trustee accounts are subject to an annual audit by an independent public accountant with the results distributed to the beneficiaries. The response should confirm the engagement, provide the accountant's name, and state the expected completion date. For finding (2) (advertising), the firm should remove the non-compliant backtested performance from its website immediately and describe the process for revising the content to include net performance, methodology disclosures, risk and limitation disclosures, and audience access controls as required by Rule 206(4)-1. For finding (3) (books and records), the firm should implement an approved communication platform, deploy mobile device management technology to capture text messages, issue a revised communication policy prohibiting business communications through unapproved channels, and train all employees. For finding (4) (code of ethics), the firm should collect the missing quarterly transaction reports retroactively, implement an automated tracking system that flags missing reports and escalates to the CCO, and discipline or counsel the access persons who failed to file. For finding (5) (annual compliance review), the firm should engage an external compliance consultant to conduct a comprehensive annual review covering all required elements under Rule 206(4)-7, with the results documented in a detailed written report presented to management. For finding (6) (cybersecurity), the firm should engage an information security consultant to conduct a risk assessment and develop a written incident response plan, with testing scheduled within 90 days. The firm should prioritize the custody finding and the off-channel communications finding, as these carry the highest enforcement risk, and ensure that corrective actions for these items are completed — not merely planned — before submitting the response.
Example 3: CCO building the business case for a mock examination program
Scenario: The Chief Compliance Officer of a mid-size broker-dealer (150 registered representatives, 12 branch offices) wants to implement an annual mock examination program. The firm's last FINRA cycle examination, two years ago, resulted in a deficiency letter with findings in trade surveillance, communications supervision, and branch office inspection procedures. The CCO has proposed a budget of $75,000 for annual mock examinations (including external consultant fees) and has presented the proposal to the firm's executive committee. The CEO and head of sales view the program as unnecessary overhead, arguing that the firm "already has a compliance department" and that the prior deficiency findings were "minor." They have asked the CCO to justify the expenditure.
Compliance Issues:
- The firm received deficiency findings in its last examination, which means the next FINRA examination will almost certainly include a review of whether those deficiencies were remediated effectively. Failure to demonstrate effective remediation increases the risk of escalation to formal enforcement.
- FINRA's risk-based examination approach means that firms with prior deficiency findings may be examined more frequently and with greater intensity.
- The firm's characterization of prior findings as "minor" is a red flag for compliance culture — deficiency findings should be taken seriously regardless of perceived severity.
- Under FINRA Rules 3110 (Supervision) and 3120 (Supervisory Control System), the firm is required to test and verify its supervisory procedures. A mock examination program is an effective means of satisfying this obligation.
Analysis: The CCO should build the business case on three pillars: risk reduction, cost avoidance, and regulatory expectation. On risk reduction: the firm's prior deficiency findings create a heightened examination risk profile. FINRA will expect to see documented evidence that the firm identified the root causes of the deficiencies, implemented corrective actions, and tested the effectiveness of those actions. A mock examination program produces exactly this evidence. Without it, the firm enters its next examination unable to demonstrate that it has improved — and if the same deficiencies recur, the likelihood of formal enforcement action (fines, censure, individual sanctions) increases substantially. On cost avoidance: the $75,000 annual investment in mock examinations should be compared to the cost of regulatory enforcement. FINRA fines for supervisory failures regularly exceed $500,000 and can reach millions of dollars for larger firms. Beyond fines, enforcement actions generate legal fees (typically $200,000 to $1 million or more to defend a FINRA enforcement proceeding), reputational damage, increased E&O insurance premiums, and potential loss of clients. The mock examination program is a fraction of the cost of a single enforcement action. On regulatory expectation: both FINRA Rule 3120 (requiring an annual report by designated supervisory control persons certifying the adequacy of supervisory controls) and FINRA's examination priorities consistently emphasize the importance of testing supervisory systems. A mock examination program demonstrates to FINRA examiners that the firm takes its supervisory obligations seriously and proactively identifies and addresses issues.
For program design, the CCO should propose a proportionate program: conduct one comprehensive annual mock examination covering the highest-risk areas (selected based on FINRA's published examination priorities, the firm's prior deficiency history, and any new business activities), supplemented by targeted quarterly reviews of specific compliance functions. The annual mock exam should simulate a FINRA cycle examination, including a mock IDR, document production exercise, and interviews with branch managers and supervisory personnel. Engage an external compliance consultant with FINRA examination experience for the annual comprehensive exam to ensure objectivity and credibility. The quarterly targeted reviews can be conducted internally by the compliance team, focusing on areas such as communications supervision (one quarter), trade surveillance (another quarter), branch office inspections (another quarter), and AML/financial crimes (another quarter). This phased approach distributes the workload across the year and ensures continuous monitoring rather than a single point-in-time assessment. The CCO should present the mock examination results to the executive committee after each exercise, creating a documented record of management engagement with compliance findings — a factor that FINRA considers favorably during examinations.