Does a New RIA Need a Chief Compliance Officer?
Whether a new RIA needs a chief compliance officer, who can hold the role, and what the compliance program around it has to include: written policies and an annual review under SEC Rule 206(4)-7, a code of ethics, books and records, privacy and data security under Regulation S-P, the marketing rule, and the state model rules on continuity and succession. Plus what the SEC's 2026 examination priorities say about newly registered advisers.
Filed by Tyler Noe

The short answer: Yes. Every SEC-registered adviser must adopt written policies and procedures reasonably designed to prevent violations of the Advisers Act, review them at least once a year, and designate a chief compliance officer who is a supervised person of the firm, under SEC Rule 206(4)-7. NASAA's model rule asks the same of state-registered advisers in the states that adopt it. The founder can be the chief compliance officer, and the SEC's 2026 examination priorities say it will prioritize advisers never examined before, with particular emphasis on recently registered ones.
The chief compliance officer administers a program with several parts, each with its own rule. For where it fits in the order of a launch, see how to build your own RIA from scratch.
What a new RIA's compliance program includes
| Piece | What it requires | The rule | Who it binds |
|---|---|---|---|
| Policies, annual review and a CCO | Written policies and procedures reasonably designed to prevent violations, reviewed at least once a year, administered by a named chief compliance officer | Rule 206(4)-7 | SEC-registered advisers; NASAA model rule where a state adopts it |
| Code of ethics | Standards of conduct, holdings and transaction reports from access persons, prior approval for IPOs and limited offerings | Rule 204A-1 | SEC-registered advisers |
| Books and records | Most records kept at least five years, the first two in an office of the adviser, including the policies and each annual review | Rule 204-2 | SEC-registered advisers |
| Privacy and data security | A privacy notice to customers, written safeguards for customer information, an incident response program, and notice to affected individuals generally within 30 days | Regulation S-P | SEC-registered advisers |
| Marketing | No untrue or unsubstantiated statements, fair and balanced treatment of benefits, risks and performance, disclosures on testimonials and endorsements | Rule 206(4)-1 | SEC-registered advisers |
| Continuity and succession | A written plan for records, communications, office loss and the death or unavailability of key people | NASAA model rule | State-registered advisers where a state adopts it |
What does Rule 206(4)-7 require?
Three things, for any adviser registered or required to be registered with the SEC: written policies and procedures reasonably designed to prevent violations by the firm and its supervised persons, a review at least once a year of how adequate they are and how well they work, and a designated chief compliance officer to administer them. When the SEC adopted the rule in 2003, it asked each adviser to identify the conflicts and risks in its own operations first and then write policies that address them, covering, where relevant, topics from portfolio management and trading to disclosures, safeguarding client assets, records, marketing, privacy and business continuity. The policies can sit in more than one document.
Can the founder be the chief compliance officer?
Yes. The rule asks only that the officer be a supervised person of the firm, and the adopting release said firms would not have to hire someone to serve exclusively in the role. The SEC's expectation is that the officer is competent and knowledgeable about the Advisers Act and has enough seniority and authority to make others follow the policies. The same release expected small firms, which typically have one or two employees, to run markedly less complex programs. In states that adopt NASAA's model rule, the officer must also be registered as an investment adviser representative. What a small RIA is covers how a one- or two-person firm is set up.
Can the role be outsourced?
Yes, and Form ADV asks for the name of any outside person paid to provide chief compliance officer services. In 2015, SEC examiners reported on nearly 20 examinations of SEC-registered advisers and funds that outsourced the role. Their risk alert said those firms keep responsibility for adopting and implementing an effective compliance program. The arrangements that worked involved regular, often in-person communication, sufficient access to the firm's documents and information, and an officer who knew the rules and the business; in weaker cases, the outside officer could not describe the firm's business or compliance risks. What outside support costs varies with the firm's size, services and how much the founder keeps in-house, and what an independent RIA platform actually costs covers the rest of a launch budget.
What else goes into the program?
A code of ethics. Rule 204A-1 requires standards of business conduct reflecting the firm's fiduciary duty, and personal-trading reports from access persons: holdings within 10 days of becoming one and every year after, transactions within 30 days of each quarter end, and prior approval for IPOs and limited offerings. A founder who is the only access person keeps the records instead of reporting to themselves.
Books and records. Under Rule 204-2, most records are kept for at least five years from the end of the fiscal year of the last entry, the first two in an appropriate office of the adviser, including every compliance policy in force during that period and the record of each annual review.
Privacy and data security. Regulation S-P applies to SEC-registered advisers. A customer receives a privacy notice no later than when the relationship begins, and the firm keeps written safeguards for customer information. The 2024 amendments added an incident response program and, with limited exceptions, notice to individuals whose sensitive customer information was or is reasonably likely to have been accessed without authorization, as soon as practicable and no later than 30 days after the firm becomes aware of the incident.
Marketing. The SEC's marketing rule governs the advertisements of an SEC-registered firm: no untrue or unsubstantiated statements of material fact, fair and balanced treatment of benefits, risks and performance, and required disclosures on testimonials and endorsements. Safeguarding client assets is on the SEC's list of policy topics as well, and does managing held-away 401(k) accounts create custody works through one common custody question.
What do state-registered firms follow?
Their state's rules. In 2020, NASAA adopted a model rule requiring written policies covering compliance, supervision, proxy voting, physical security and cybersecurity, business continuity and succession, the code of ethics and material nonpublic information, with an annual review and a designated chief compliance officer. It binds a firm only where its state adopts it. The continuity and succession requirements, carried into the 2020 rule from NASAA's 2015 model rule, provide for backup and recovery of records, alternate ways to reach clients, custodians and regulators, office relocation, and reassigning duties if a key person dies or becomes unavailable. Which version applies is a question for the state regulator or counsel.
When will a new RIA be examined?
The SEC's 2026 examination priorities say it will prioritize advisers that have never been examined, with particular emphasis on recently registered advisers, and that compliance program examinations typically review marketing, valuation, trading, portfolio management, disclosure and filings, custody and the firm's annual reviews. The same priorities name the 2024 amendments to Regulation S-P as a focus.
The rules set the minimum; how the program is staffed and who carries it is a launch decision. Winthrop's RIA Search & Launch works through it with the custodian, the registration and the day of resignation, and the RIA Launch Checklist puts it in order on paper. Request an introduction.
Sources (16)
- SEC Rule 206(4)-7, Compliance procedures and practices (17 CFR 275.206(4)-7)
- SEC - Final Rule: Compliance Programs of Investment Companies and Investment Advisers, Release No. IA-2204 (December 17, 2003)
- SEC - Form ADV Part 1A (Item 1.J, Chief Compliance Officer)
- SEC OCIE Risk Alert - Examinations of Advisers and Funds That Outsource Their Chief Compliance Officers (November 9, 2015)
- SEC Rule 204A-1, Investment adviser codes of ethics (17 CFR 275.204A-1)
- SEC Rule 204-2, Books and records to be maintained by investment advisers (17 CFR 275.204-2)
- Regulation S-P, Procedures to safeguard customer information (17 CFR 248.30)
- Regulation S-P, Initial privacy notice to consumers required (17 CFR 248.4)
- Regulation S-P, Purpose and scope (17 CFR 248.1)
- SEC - SEC Adopts Rule Amendments to Regulation S-P to Enhance Protection of Customer Information (May 16, 2024)
- SEC Rule 206(4)-1, Investment adviser marketing (17 CFR 275.206(4)-1)
- SEC - Division of Examinations Announces 2026 Priorities (November 17, 2025)
- SEC Division of Examinations - Fiscal Year 2026 Examination Priorities
- NASAA Model Rule for Investment Adviser Written Policies and Procedures (adopted November 24, 2020)
- NASAA - NASAA Members Adopt Model Rule Consolidating Existing Policies and Procedures for State-Registered IAs (November 30, 2020)
- NASAA Model Rule on Business Continuity and Succession Planning (adopted April 13, 2015)
Frequently asked
Does a new RIA need a chief compliance officer?
Can the founder of an RIA be the chief compliance officer?
Can the chief compliance officer role be outsourced?
What policies does a new RIA have to write?
What does an RIA code of ethics require?
How long does an RIA keep its records?
When will the SEC first examine a new RIA?
How much does outsourced compliance support cost?
Filed
October 1, 2026