READ NOWH1 2026, State of Advisor Movement

Winthrop & Co.
Market Insights
GuideFiled October 1, 20266 min read

Does a New RIA Need a Chief Compliance Officer?

Whether a new RIA needs a chief compliance officer, who can hold the role, and what the compliance program around it has to include: written policies and an annual review under SEC Rule 206(4)-7, a code of ethics, books and records, privacy and data security under Regulation S-P, the marketing rule, and the state model rules on continuity and succession. Plus what the SEC's 2026 examination priorities say about newly registered advisers.

Filed by Tyler Noe

GuideRIA Chief Compliance Officer Requirements: Does a New RIA Need a CCO? (2026)

The short answer: Yes. Every SEC-registered adviser must adopt written policies and procedures reasonably designed to prevent violations of the Advisers Act, review them at least once a year, and designate a chief compliance officer who is a supervised person of the firm, under SEC Rule 206(4)-7. NASAA's model rule asks the same of state-registered advisers in the states that adopt it. The founder can be the chief compliance officer, and the SEC's 2026 examination priorities say it will prioritize advisers never examined before, with particular emphasis on recently registered ones.

The chief compliance officer administers a program with several parts, each with its own rule. For where it fits in the order of a launch, see how to build your own RIA from scratch.

What a new RIA's compliance program includes

PieceWhat it requiresThe ruleWho it binds
Policies, annual review and a CCOWritten policies and procedures reasonably designed to prevent violations, reviewed at least once a year, administered by a named chief compliance officerRule 206(4)-7SEC-registered advisers; NASAA model rule where a state adopts it
Code of ethicsStandards of conduct, holdings and transaction reports from access persons, prior approval for IPOs and limited offeringsRule 204A-1SEC-registered advisers
Books and recordsMost records kept at least five years, the first two in an office of the adviser, including the policies and each annual reviewRule 204-2SEC-registered advisers
Privacy and data securityA privacy notice to customers, written safeguards for customer information, an incident response program, and notice to affected individuals generally within 30 daysRegulation S-PSEC-registered advisers
MarketingNo untrue or unsubstantiated statements, fair and balanced treatment of benefits, risks and performance, disclosures on testimonials and endorsementsRule 206(4)-1SEC-registered advisers
Continuity and successionA written plan for records, communications, office loss and the death or unavailability of key peopleNASAA model ruleState-registered advisers where a state adopts it

What does Rule 206(4)-7 require?

Three things, for any adviser registered or required to be registered with the SEC: written policies and procedures reasonably designed to prevent violations by the firm and its supervised persons, a review at least once a year of how adequate they are and how well they work, and a designated chief compliance officer to administer them. When the SEC adopted the rule in 2003, it asked each adviser to identify the conflicts and risks in its own operations first and then write policies that address them, covering, where relevant, topics from portfolio management and trading to disclosures, safeguarding client assets, records, marketing, privacy and business continuity. The policies can sit in more than one document.

Can the founder be the chief compliance officer?

Yes. The rule asks only that the officer be a supervised person of the firm, and the adopting release said firms would not have to hire someone to serve exclusively in the role. The SEC's expectation is that the officer is competent and knowledgeable about the Advisers Act and has enough seniority and authority to make others follow the policies. The same release expected small firms, which typically have one or two employees, to run markedly less complex programs. In states that adopt NASAA's model rule, the officer must also be registered as an investment adviser representative. What a small RIA is covers how a one- or two-person firm is set up.

Can the role be outsourced?

Yes, and Form ADV asks for the name of any outside person paid to provide chief compliance officer services. In 2015, SEC examiners reported on nearly 20 examinations of SEC-registered advisers and funds that outsourced the role. Their risk alert said those firms keep responsibility for adopting and implementing an effective compliance program. The arrangements that worked involved regular, often in-person communication, sufficient access to the firm's documents and information, and an officer who knew the rules and the business; in weaker cases, the outside officer could not describe the firm's business or compliance risks. What outside support costs varies with the firm's size, services and how much the founder keeps in-house, and what an independent RIA platform actually costs covers the rest of a launch budget.

What else goes into the program?

A code of ethics. Rule 204A-1 requires standards of business conduct reflecting the firm's fiduciary duty, and personal-trading reports from access persons: holdings within 10 days of becoming one and every year after, transactions within 30 days of each quarter end, and prior approval for IPOs and limited offerings. A founder who is the only access person keeps the records instead of reporting to themselves.

Books and records. Under Rule 204-2, most records are kept for at least five years from the end of the fiscal year of the last entry, the first two in an appropriate office of the adviser, including every compliance policy in force during that period and the record of each annual review.

Privacy and data security. Regulation S-P applies to SEC-registered advisers. A customer receives a privacy notice no later than when the relationship begins, and the firm keeps written safeguards for customer information. The 2024 amendments added an incident response program and, with limited exceptions, notice to individuals whose sensitive customer information was or is reasonably likely to have been accessed without authorization, as soon as practicable and no later than 30 days after the firm becomes aware of the incident.

Marketing. The SEC's marketing rule governs the advertisements of an SEC-registered firm: no untrue or unsubstantiated statements of material fact, fair and balanced treatment of benefits, risks and performance, and required disclosures on testimonials and endorsements. Safeguarding client assets is on the SEC's list of policy topics as well, and does managing held-away 401(k) accounts create custody works through one common custody question.

What do state-registered firms follow?

Their state's rules. In 2020, NASAA adopted a model rule requiring written policies covering compliance, supervision, proxy voting, physical security and cybersecurity, business continuity and succession, the code of ethics and material nonpublic information, with an annual review and a designated chief compliance officer. It binds a firm only where its state adopts it. The continuity and succession requirements, carried into the 2020 rule from NASAA's 2015 model rule, provide for backup and recovery of records, alternate ways to reach clients, custodians and regulators, office relocation, and reassigning duties if a key person dies or becomes unavailable. Which version applies is a question for the state regulator or counsel.

When will a new RIA be examined?

The SEC's 2026 examination priorities say it will prioritize advisers that have never been examined, with particular emphasis on recently registered advisers, and that compliance program examinations typically review marketing, valuation, trading, portfolio management, disclosure and filings, custody and the firm's annual reviews. The same priorities name the 2024 amendments to Regulation S-P as a focus.

The rules set the minimum; how the program is staffed and who carries it is a launch decision. Winthrop's RIA Search & Launch works through it with the custodian, the registration and the day of resignation, and the RIA Launch Checklist puts it in order on paper. Request an introduction.

Sources (16)

Frequently asked

Does a new RIA need a chief compliance officer?
Yes, if it is registered with the SEC. Rule 206(4)-7 makes it unlawful for an SEC-registered adviser to provide advice unless it has adopted written compliance policies and procedures, reviews them at least once a year, and designates a chief compliance officer who is a supervised person of the firm. State-registered firms follow their state's rules; NASAA's model rule, which states may adopt, carries the same three requirements.
Can the founder of an RIA be the chief compliance officer?
Yes. The rule requires only that the chief compliance officer be a supervised person of the firm, and when the SEC adopted it the agency said firms would not have to hire someone to serve exclusively in the role. The SEC expects the officer to be competent and knowledgeable about the Advisers Act, with enough seniority and authority to make others follow the firm's policies. In states that adopt NASAA's model rule, the officer must also be registered as an investment adviser representative.
Can the chief compliance officer role be outsourced?
Yes. Form ADV asks a firm to name any outside person paid to provide its chief compliance officer services. SEC examiners who reviewed firms using outsourced officers said those firms keep responsibility for adopting and implementing an effective compliance program, and that the arrangements that worked involved regular communication, enough support from the firm, and sufficient access to its documents and information.
What policies does a new RIA have to write?
For an SEC-registered firm: compliance policies and procedures fitted to its own risks, a written code of ethics covering personal trading, a books-and-records system, a privacy notice and written safeguards for customer information including an incident response program, and advertising that meets the marketing rule. A state-registered firm follows its state's rules; in states that adopt NASAA's model rule, those include a written business continuity and succession plan.
What does an RIA code of ethics require?
Under SEC Rule 204A-1 the code sets standards of business conduct that reflect the firm's fiduciary duty, requires compliance with the federal securities laws, and requires access persons to report their holdings and transactions for review. Holdings are reported within 10 days of becoming an access person and once a year after that, transactions within 30 days of each quarter end, and purchases in IPOs and limited offerings need prior approval. A firm whose only access person is the founder keeps records of those holdings and transactions instead of reporting to itself.
How long does an RIA keep its records?
Under SEC Rule 204-2, most required books and records are kept for at least five years from the end of the fiscal year of the last entry, the first two years in an appropriate office of the adviser. The records include the compliance policies in effect at any time in the past five years and the records of each annual review.
When will the SEC first examine a new RIA?
The SEC's 2026 examination priorities say the Division of Examinations will prioritize examinations of advisers that have never been examined, with particular emphasis on recently registered advisers, and that compliance program examinations typically look at marketing, valuation, trading, portfolio management, disclosure and filings, custody, and the firm's annual reviews.
How much does outsourced compliance support cost?
It varies with the size of the firm, the services it offers, how many people and locations it has, and how much of the work the founder keeps. When the SEC adopted the compliance rule, it asked each firm to design its program around the risks in its own operations, so the scope of outside help differs from one firm to the next.

Filed

October 1, 2026

More from Market Insights