Cybersecurity

Best Practices for Complying With Regulation S‑P’s New Notification Requirements


The SEC’s May 16, 2024, adoption of enhancements to Regulation S‑P (Reg S‑P) has significantly broadened the obligations of registered entities following the detection of a cyber breach that has, or is reasonably likely to have, compromised sensitive customer data. Larger entities faced a compliance deadline of December 3, 2025, while smaller ones have until June 3, 2026.

In addition to the strict requirements that Reg S‑P already imposed with regard to cybersecurity policies and procedures, fund managers must have policies and procedures in place that are reasonably designed to notify customers as soon as practicable, and not more than 30 days, after detection of a breach. As bad actors grow ever more sophisticated and resourceful, the cyber threat facing the private funds sector has never been more acute, as the SEC recognized when the agency devoted a large section of its new 2026 Examination Priorities (Priorities) to Reg S‑P compliance.

This article summarizes the amendments to Reg S‑P; sets forth practical steps that fund managers should take upon discovery of a cyber incident; outlines best practices with regard to customer notification, including what to mention and what to exclude; and provides expert legal analysis.

See “SEC Staff Discuss Regulation S‑P Amendments and Related Examination Process” (Oct. 23, 2025).

Expansion of Existing Requirements

Adopted in 2000, Reg S‑P, in its original form, imposed a number of “safeguards” requiring registered investment advisers to adopt written policies and procedures designed to protect customer records and information. As cyber threats have evolved, and criminals have used ever more sophisticated tools and methodologies in the hope of breaching systems’ defenses, the Commission responded by proposing amendments to Reg S-P in March 2023 that would require covered entities to adopt and implement written policies and procedures around an incident response program.

The final version of that proposal took effect on May 16, 2024, giving larger entities with at least $1.5 billion in assets under management a December 3, 2025, compliance deadline and smaller entities below that threshold until June 3, 2026, to comply. Now, under Reg S‑P, a fully compliant cyber incident response program must:

  • detect any breach that has occurred;
  • respond to the breach;
  • recover from the breach;
  • notify individuals whose sensitive data was, or was reasonably likely to have been, accessed without authorization; and
  • create and maintain required compliance records.

As to the notification requirement, a fund manager must notify all individuals that have been, or could reasonably be expected to have been, impacted by a data privacy incident as soon as practicable but no more than 30 days after the incident’s discovery. If the manager is unable to determine which individuals were impacted by the incident, it should notify all individuals who could have been impacted. Reg S‑P requires such notices to include details about the incident, the breached data and how affected individuals can respond to the breach to protect themselves.

No fund manager should wait until an intrusion in its systems has been detected to begin taking cybersecurity seriously, emphasized Adam S. Aderton, partner at Simpson Thacher & Bartlett LLP and former senior official in the SEC’s Division of Enforcement. Ideally, fund managers will have adopted and implemented policies and procedures well before the latest amendments to Reg S‑P, in keeping with their fiduciary and legal obligations, he stressed.

Now that the December 3, 2025, deadline for larger entities to comply with the amendments has come and gone, those fund managers over the $1.5‑billion threshold should have effective customer notification protocols and procedures in place. For those under the threshold, the June 3, 2026, deadline is fast approaching, continued Aderton. “For those entities not yet in compliance, this is the time to get the incident response plan up and running,” he advised. The fact that the topic figures prominently in the agency’s Priorities, underscores the urgency of the issue, he said.

See “Six Steps to Address the SEC’s Trump Era Cyber Enforcement Priorities” (Oct. 9, 2025); and “A Checklist to Help Fund Managers Assess Their Cybersecurity Programs” (Jul. 14, 2022).

Immediate Steps to Take After a Breach

Following detection of a cyber breach, there are certain steps that an entity needs to take straightaway. These steps are not only necessary on their own terms – to ensure the entity’s survival – but also as preconditions for the entity to be in a position to assess whether the circumstances require investor notification in accordance with Reg S‑P.

1) Mitigate Damage

As soon as a fund manager becomes aware of a breach in cyber defenses, it must take swift action to limit and contain the breach, whether that means shutting down systems, activating antivirus software or calling in specialists with more advanced incident response methodologies. Fast action can often mean the difference between a relatively insignificant incident and an existential threat to the entity’s continued livelihood.

One of the best practices for fund managers is to have an incident response plan in place that will entail notifying fund personnel swiftly to enable it to marshal internal resources, noted Louis Bruno, partner at regulatory compliance consultancy EisnerAmper. “Usually, within an incident response program, there is a defined governance structure and an escalation procedure, and within that governance structure, there is an incident response team who can evaluate the impact of the breach,” he explained. That team should be equipped and authorized to conduct internal IT investigations and report its findings.

“You’ll need to take immediate steps, consistent with that incident response plan, to contain and control any further unauthorized access, which sounds like an obvious first thing to do – stop the bleeding as soon as you know where it is happening,” Aderton affirmed.

However, given the growing variety and sophistication of cyberattacks, even the best-prepared manager needs to be cognizant of the possibility that a breach may happen of a nature and on a scale that it has not seen or heard of before and that internal IT resources are inadequate to counter, noted David S. Slovick, partner at Kopecky Schumacher Rosenburg. Hence, figuring out the scope of the breach – in order to assess what further steps may be required under Reg S‑P – can sometimes require outreach to external service providers.

“The first order of business is to get your arms around where the breach occurred and what the extent of it was,” Slovick affirmed. “That may involve retaining an outside consultant specializing in forensic accounting to trace funds or information trails. A consultant can often tell, based on computer clues, where information went when it left the system.” He added, “The response may also involve employee interviews and email reviews to identify whether there was a human source for the problem, which there often is. It will also involve remediation efforts, not only to fix the breach but also to prevent breaches in the future.”

Managers may wonder whether they should proceed differently under Reg S‑P in the case of an internal breach, as opposed to an external one, such as a breach of a service provider with access to information on the manager’s investors. The short answer to that question is no, Aderton said. “The regulation doesn’t call for a difference in response between those two categories,” he noted. “It may sometimes be easier to ‘get your arms around’ an internal breach, although not in every case. But, either way, managers should respond to both kinds of breaches in the same manner – contain and control; assess; and notify.”

However, one exception, Aderton acknowledged, would be an extreme circumstance in which a bad actor had undertaken a cyberattack of such magnitude and severity that it might pose a danger not only to the fund manager but also to national security. “If your initial assessment finds that this is potentially a nation-state threat actor, that situation may warrant a response that includes outreach to the FBI and other relevant criminal authorities,” he noted.

See “Managing Cybersecurity, Incident Response Planning and Vendor Risk” (Dec. 4, 2025).

2) Identify Affected Parties

Next, the manager must move swiftly to determine, through a reasonable investigation of the facts and circumstances, the scope of the breach and whether it has caused or is likely to have caused “substantial harm or inconvenience” to the customers whose sensitive data was improperly accessed. As part of that process, it is essential to figure out what specific kind of customer information may be involved, whether it is something as sensitive as an investor’s bank account information or simply a contact person’s name. That determination will be important to any assessment of whether the incident meets the “substantial harm or inconvenience” threshold.

Err on the Side of Caution

In amending Reg S‑P, the SEC has framed the question of the seriousness of a breach in terms of whether a reasonable investigation by the fund manager determines that customers have suffered or are likely to suffer “substantial harm or inconvenience.” If they have, they must be notified within the specified time frame. But the SEC’s terminology here does not provide a particularly useful standard in any and all situations that one can envision, according to Aderton.

“The use of those terms presents us with a bit of a challenge, because what one person thinks of as substantial harm or significant inconvenience may not look the same to someone else,” Aderton reflected. “And it is the kind of thing you could see a particularly aggressive regulator assessing in hindsight and making its own determination.” In that scenario, what the impacted entity considered a relatively minor incident, without serious consequences for its investors, could lead to regulatory trouble and potentially an enforcement action for Reg S‑P violations.

“The meaning of substantial harm or inconvenience is, of course, going to depend on the facts and circumstances of the conduct that has come to light,” Slovick concurred. “The SEC’s definition is totally unhelpful for firms trying to make a good-faith assessment of their obligations.”

To avoid second-guessing, managers may decide to automatically notify investors of any breach in an effort to avoid violating Reg S‑P. But what if the breach turns out not to have serious consequences for them? “You don’t want to call investors and say, ‘Hey, your data has been breached,’ only to have to call them again a week later and say, ‘It wasn’t really that big of a deal. Don’t worry about it.’ That’s terrible for investor relations,” Slovick observed.

However, that does not change the reality that the SEC has made Reg S‑P enforcement a centerpiece of its 2026 examination priorities and that, without further guidance, it is unwise to assume the regulators will err on the side of leniency.

“The only thing we can say for sure is that the SEC’s Enforcement Division will take the most expansive view of what ‘substantial harm or inconvenience’ means,” Slovick stated. “And, until we get the first few settlement orders under the new Reg S‑P, it is anybody’s guess what the SEC’s interpretation is going to be.” He concluded, “All of which is to say that you should be careful in your estimation about what may trigger your reporting obligation under the new regulation. Don’t be too cavalier about it.”

“Cyber incidents span a huge spectrum, so any response should be driven by facts on the ground,” stated David L. Hirsch, partner at McGuireWoods and former head of an SEC enforcement unit. “If firms have reason to believe there has been an incident that could have compromised customer information – either information that would allow the attacker to identify the customer or to gain access to customer accounts or authorization – then there’s going to be a notification requirement.”

Refer to the Proposal’s Release

In general, it really is best to err on the side of caution, Aderton agreed. What fund managers and compliance personnel fortunately do know is that the initial proposal for amending Reg S‑P clearly listed a number of factors the SEC did understand to constitute substantial harm or inconvenience, he noted. Although not included in the final adopting release, those criteria can still be useful in post-incident assessments of a breach’s severity and scope. Those consequences include investors’ experiencing personal injury, financial loss and/or more than a trivial expenditure of time and effort related to any of the following:

  • theft;
  • fraud;
  • harassment;
  • physical harm;
  • impersonation;
  • intimidation;
  • damage to reputation;
  • impaired credit eligibility; and
  • misuse of someone’s information to obtain a financial product or service, or otherwise misuse a customer account.

Any investor who suffers one or more of the above consequences is unlikely to be persuaded that no serious harm or inconvenience has occurred, Aderton noted. In the end, SEC staff contemplating how to word the adoptive release may have not wanted to “pin themselves to an enumerated list” and exclude other potential categories of harm or inconvenience, he reasoned. The agency has left the door open to the identification of further consequences, reserving some latitude for itself when it comes to Reg S‑P enforcement.

“So, for now, [all we have is] the enumerated list, plus some factors that we’re not really sure about yet and may not be sure about until we get additional guidance from the SEC,” concluded Aderton.

3) Determine Who Will Make Any Required Notifications

If the fund manager has determined that the “substantial harm or inconvenience” threshold has been met, it must move swiftly to notify the affected investors. The question arises as to who, within the organization, should handle such a sensitive task. It is essential to be clear about which divisions and personnel are integral to that effort. For example, the IT department plays a crucial role in detecting and remedying the breach. However, that role typically does not extend to customer outreach, Aderton noted.

The fund manager’s compliance department will play a vital role, often in consultation with the IT department, in examining the scope of the breach and making a determination as to whether the incident triggers Reg S‑P’s notification requirement. “You want to have your compliance and legal teams involved, whether that means in-house lawyers or outside counsel, because you want to ensure your process complies with Reg S‑P,” Slovick concurred. “And you should also ensure that you’re properly recording the steps that you have taken, so that you can show your work down the road if the SEC ever asks you about it.”

But when it comes to who will actually conduct the outreach – typically by sending emails to affected investors – the role is likely to fall squarely within the domain of the investor relations (IR) team, Aderton argued. “If the IR team is regularly making contact with your investors, then it makes the most sense for that team to make the outreach,” he said.

Of course, that does not mean the IR team is operating within a silo, continued Aderton. It will utilize findings from IT, and send out the message, which will be vetted – or, in some cases, drafted – by the compliance department and, in the event of a highly serious incident, will include input from the leadership of the firm, he said.

In Slovick’s view, the question of who should do the actual investor notifications turns largely on “what the normal chain of communication is within a firm.” Here, managers need to use common sense and think about who the public-facing individual or team has typically been. “If I’m used to hearing from the head of IR, or I receive a letter from the CEO, CFO or the chief portfolio manager monthly or quarterly, and then all of a sudden I get a letter from a lawyer I’ve never heard from before,” he hypothesized, “that might make me panic. So, the messaging should go through whatever the normal chain is, backed up by and supervised by compliance and legal.”

4) Determine Scope of Notifications

Whether to notify all of a fund manager’s investors, or just those definitively known to have had their information compromised in the breach, is another critical question. Managers may be naturally concerned with minimizing any potential investor relations and reputational harm, especially given the risk of a chain reaction in which investors unaffected by the breach rush for the exits, acknowledged Slovick. Once again, best practices revolve around making the most transparent disclosures that a manager can based on the information it has – but not going further.

“It all comes down to what you know at a given time. As in any other disclosure situation under the federal securities laws, you can’t be liable for failing to accurately predict the future,” Slovick said. “What you can be liable for is making misrepresentations or disclosing half-truths about the information you do have already.”

How to proceed will depend largely on what the reasonable investigation has uncovered, Slovick explained. If a manager knows that, say, one third of its investors were definitely affected and one third were definitely not, and it is uncertain about the remaining third, then it should err on the side of caution and notify those definitely affected and those who may have been – fully two thirds of its total investor base, he reasoned.

“If you can say definitively that certain clients were not affected, then they don’t need to be notified,” continued Slovick. “There is a very serious issue here of investor relations and perceptions. If you start telling people that they might have been affected but you don’t know, then you just look incompetent and you may well end up triggering a fire sale,” he warned.

“But, at the end of the day, it’s going to be the SEC’s enforcement staff that gets to judge whether the firm guessed the future use of that stolen data correctly,” Slovick conceded. “The takeaway here is that firms should err on the side of notifying more rather than fewer customers if there has been a wide data breach.”

See “Enforcement Actions Highlight Advisers’ Duty to Accurately and Honestly Communicate With Investors” (Oct. 10, 2024).

5) Make Notifications

Timing of the Notification

The language of Reg S‑P is quite clear: notification should go out to customers as soon as practicable but no more than 30 days after discovery of the breach. In other words, the clock starts ticking as soon as the fund manager becomes aware of the issue.

A further consideration involves notification of insurance providers, pointed out Hirsch. “You likely should notify quite quickly if you have cyber insurance or if you have just broad insurance,” he said. “You want to notify your carrier immediately. They tend to impose deadlines, written into their policies, about when notification has to be provided to ensure you’re going to be covered. So check those policies carefully and follow them to the letter.”

See “Avoiding Pitfalls in Cyber Insurance Applications and Claims” (Apr. 11, 2024); and “Tips for Working With Cyber Insurance Carriers Following a Ransomware Event” (Oct. 26, 2023).

What to Include

Reg S‑P requires the notification to include:

  • general information about the breach;
  • the types of sensitive customer information involved; and
  • steps affected individuals may take to protect themselves.

Receiving this notification from a fund manager can be highly upsetting to investors who trusted the manager to safeguard that data. One of the keys to such communications is to avoid fanning the flames by appearing evasive. Put simply, transparency is of the essence, Aderton said.

“The first principle is to be accurate with respect to what you are disclosing to investors,” Aderton explained. “Candidly, investors in general understand that these breaches have the potential to happen all the time nowadays. Your best practice is to be transparent about the nature of the breach and be clear about the types of information affected.” He recommended that fund managers “provide sufficient information so that, at least at a high level, the individuals whose information has been compromised can generally understand what has happened – to the extent possible within the notification period – as well as the type of information accessed.”

See “New Pressures Shift Best Practices for Ransomware Crisis Communications” (Nov. 10, 2022).

What to Exclude

At the same time, it is important to exclude any information that has not yet been verified and exists only as rumor or supposition, Aderton added. Not only will including such information not help the situation, but it can cause still more embarrassment and confusion later if it turns out to be inaccurate and add to already significant damage to investor relations and reputation.

“It is a better course to say that ‘We’re continuing to evaluate,’ as opposed to speculating about what might have happened,” Aderton commented. “You are better advised to reserve judgment on those things rather than make a statement you’re not wholly confident about in a notification to your investors.”

Even if fund managers have what they believe to be an exact figure for investors affected – say, 100 investors or 10 percent of the total number in the fund – that specific data does not need to be in the notification. “It is fine to say, ‘We understand that some customers have been affected,’” Aderton clarified. “At the time of the notification, this is another area where you may not have all the information you need to give a number with any precision.”

Finding the perfect language to include in such communications can be especially challenging when the manager is still trying to get to the bottom of how and why the breach occurred, Slovick agreed. When drafting such communications, it is crucial to exclude any language that might give investors the wrong impression and even potentially incur legal penalties, if it is construed to discourage them from exercising their legal rights in the situation, he cautioned.

“You don’t want to word your instructions in such a way that they can be interpreted to have told your investors that they can’t cooperate with the SEC. That’s a real no-no,” Slovick observed. “Definitely don’t tell people that they should not participate in an enforcement investigation.”

However, from a legal standpoint, Slovick said he sees nothing wrong with wording a communication in a manner that emphasizes the sensitive nature of the incident without in any way discouraging recipients from exercising their rights. He gave an example of some of the language that a thoughtfully worded notification might include: “We informed you of the incident as soon as we could because we want to protect you. But our investigation is ongoing. Therefore, we ask for your help in keeping the matter confidential until we are able to come back to you with more information.”

The thing to remember here, Slovick emphasized, is that such a request will be exactly that – a request that in no way inhibits people from speaking to the government or the media.

Examinations

SEC 2026 Exam Priorities: Retail Investor Protection In, Crypto Out


On November 17, 2025, the SEC Division of Examinations (Division) released its 2026 examination priorities (Priorities). The new Priorities once again stress examining regulated firms on fiduciary duties, compliance program effectiveness, fees, expenses and conflicts of interest, while omitting cryptocurrency as an area of exam focus. In particular, the regulators are taking investor protection seriously. Although President Donald J. Trump and SEC leaders have publicly supported broadening retail investor access to private funds, the Division stresses that it will scrutinize how investment advisers, fund managers and broker-dealers treat retail customers – particularly those saving for retirement.

The Hedge Fund Law Report interviewed several legal experts on the Priorities’ areas of emphasis and notable omissions, with an eye toward helping fund managers prepare themselves for examinations in 2026. This article summarizes the Priorities’ key takeaways that are the most relevant to private fund managers and the experts’ accompanying insights.

See “What to Expect on SEC Examinations Under the New Administration” (Jul. 17, 2025).

Leadership Team Message

At the start of the Priorities, Division Acting Director Keith Cassidy; Program Directors Allison M. Fakhoury, Marshall M. Gandy, Kevin W. Goodman, Vanessa L. Horton and Michael G. Rufino; and Program Acting Director Alexis L. Hall (together, the Leadership Team) presented an introductory message assuring that the core components of the Division’s basic mission remain unchanged – namely, promoting compliance, preventing fraud, informing policy and monitoring risk.

At the same time, the Leadership Team acknowledged the change in direction under current SEC Chair Paul S. Atkins, causing them to revisit the assumptions behind longstanding policies and reassess how best to deploy the Division’s resources to keep pace with ever-growing responsibilities, as well as the evolution of the risks that macroeconomic and geopolitical forces pose to the market.

To ensure the continuing effectiveness of the Division’s exams, the Leadership Team has targeted four key operational fronts:

  1. transparency about observations made in examinations;
  2. engagement with the market through regional and national outreach events;
  3. consolidation of relations with the Divisions of Trading and Markets and Investment Management; and
  4. risk alerts to help entities identify and adopt elements of effective compliance programs.

The Leadership Team emphasized their reliance on a collaborative approach that incorporates engagement and dialogue throughout the agency, along with insights derived from examinations and following the market closely. “We’ve moved away from the regulatory deluge of rulemaking, at least for the moment,” observed Morgan Lewis partner Christine L. Lombardo. “And so compliance officers and internal legal staff can take this opportunity to ‘kick the tires’ on their internal programs, perhaps to an extent that they were unable to when dealing with all the new rulemaking coming out at such a rapid pace under the prior administration.”

Exam Priorities

The Priorities affirm the Division’s ongoing commitment to scrutinizing investment advisers’ adherence to their duties of care and loyalty, with particularly close attention in 2026 to those duties as they apply to business and operations involving retail investors. The Division will also scrutinize the conduct of investment companies, broker-dealers and retail sales.

See “Advances and Challenges in ‘Retailization’ of Alternative Investment Products” (Jun. 19, 2025).

Investment Advisers

Adherence to Fiduciary Standards

Investment Recommendations

The Division plans to undertake close reviews of investment advice that advisers provide to their clients, with a particular interest in three general areas:

  1. conflicts of interest that may have improperly influenced advice given to clients;
  2. advisers’ consideration of, or failure to consider, factors relevant to the investment advice they provide, including:
    • cost;
    • investment objectives of the product or strategy;
    • characteristics, including any unusual features;
    • liquidity;
    • risks;
    • potential benefits;
    • volatility;
    • likely performance under different market conditions;
    • time horizon; and
    • cost of exit; and
  3. advisers’ seeking of best execution, with a view to maximizing value for clients in the circumstances prevailing at the time of the transaction.

The Division will also study advisers’ investment recommendations to assess their consistency with clients’ goals, risk tolerance and backgrounds, including:

  • recommendations made to older investors and/or people saving for retirement;
  • advisers to private funds simultaneously advising separately managed accounts (SMAs) and/or newly registered funds;
  • advisers to newly launched private funds;
  • recommendations of products with abnormal sensitivity to market volatility; and
  • advisers with no past experience advising private funds.

The emphasis on examining so many varied strategies and approaches – and SMAs, in particular – mirrors current fundraising practices in the private funds market, observed Alston & Bird partner Heather N. Wyckoff. “We see fund managers offering different strategies, managing liquidity with long lockups or, when fundraising gets tight, raising SMAs, which then puts pressure on allocations between the fund and the SMA.”

See “Report Examines Appetite for Separately Managed Accounts and Key Terms” (Oct. 27, 2022).

Types of Advisers and Services

Further, the Division will closely examine advisers and advisory services that pose added risks to investors and the market, and that present a greater likelihood of actual or potential conflicts of interest. By way of example, the Priorities identify three broad areas:

  1. advisers with dual registration as broker-dealers, especially when advisers have dually licensed registered representatives whose receipt of compensation may present conflicts of interest;
  2. advisers using third parties to access client accounts, without due regard for the security of the data and assets in those accounts; and
  3. advisers that have merged or undergone acquisition by existing advisory practices, potentially leading to compliance complications or further conflicts of interest.

Effectiveness of Compliance Programs

The Priorities emphasize that examinations designed to assess the effectiveness of compliance programs tend to be broad in scope, covering:

  • marketing;
  • valuation;
  • trading;
  • portfolio management;
  • disclosure and filings; and
  • custody.

Division staff will also probe for any failures of compliance within the context of the Investment Advisers Act of 1940, checking whether advisers have policies and procedures in place that are reasonably designed to address any conflicts of interest. The Division is especially sensitive to the danger of advisers’ placing their own interests ahead of those of their clients. With that in mind, examinations will strive to assess whether policies and procedures:

  • are adopted and enforced; and
  • properly address fee-related conflicts of interest, notably those involving compensation structures.

Broker-Dealers

The Priorities make clear that the Division will focus on broker-dealers’ compliance with Section 240.15c3‑1, the net capital requirements, and Section 240.15c3‑3, the customer protection requirements, under the Securities Exchange Act of 1934, and will scrutinize all relevant internal policies and controls. The “best interest” standard enshrined in Regulation Best Interest (Reg BI) will also be a focus, as discussed in a separate section of the Priorities.

The Division will take a particular interest in the timeliness of notifications and other mandatory filings and disclosures, as well as entities’ supervision of any third-party vendors brought in to provide records that go into financial reporting. (As discussed below, the emphasis on the use of third-party vendors, and oversight of their role, is a running theme in the Priorities.)

Specific areas of broker-dealers’ operations that will be scrutinized during exams include:

  • broker-dealer risk management controls designed to ensure sufficient liquidity to handle stress events;
  • cash sweep programs;
  • prime brokerage activities; and
  • concentration, liquidity and counterparty credit risks.

This is an area in which the Division has affirmed its continuing devotion to traditional areas of focus, in the view of Kopecky Schumacher Rosenburg partner David Slovick. “The net capital and customer protection rules have historically been standard items on the exam staff’s punch list,” he said. “By highlighting those two rules as items the staff will ‘continue to’ focus on, the staff is signaling that it will be business as usual for broker-dealer compliance in those key areas.” Noting the Priorities’ reference to “related internal processes, procedures and controls,” he added that “it is not too far off to characterize the SEC’s broker-dealer examination regime as consisting mostly of reviewing firms’ ‘processes, procedures and controls.’ That doesn’t signal a change in direction for the Division.”

Retail Sales and Reg BI Compliance

With respect to broker-dealer sales practices, particularly those to which Reg BI applies, the Priorities identify four key areas of interest:

  1. recommendations of products and investment strategies, including account and rollover recommendations;
  2. conflict identification and mitigation practices, especially those touching on recommendations related to accounts and/or rollover and involving limited product menus;
  3. processes in place for the review of “reasonably available” alternatives; and
  4. processes for complying with the care obligation, including:
    • consideration of factors within a client’s investment profile; and
    • characteristics of products and account types.

Complex, or tax-advantaged, products will undergo particular scrutiny in exams, as will recommendations that do any of the following:

  • move an investment to a “substantially similar product”;
  • relate to opening different account types, i.e., margin, option or self-directed IRA accounts; and
  • target older investors or those trying to save up for retirement or college.

The Division’s emphasis on broker-dealers should not be viewed in a silo, because it is key to understanding how the Division views actual or potential market risk more broadly, in Lombardo’s view. “When the Division talks about broker-dealers, that is where we see an interesting tie-in to private funds, because of the distribution of private funds through brokerage channels,” she observed. “The regulators are calling out – in softer ways, perhaps – Reg BI determinations and how broker-dealers are specifically determining that a particular type of recommendation, including an alternative investment, is in the client’s best interest.”

“The Priorities note that, in particular, exams will focus on recommended products that are complex,” continued Lombardo. “And they call out private placements and alternative investments specifically, among other things, because those products typically are a bit more expensive and may have less liquidity.”

The Priorities have obvious ramifications for advisers to private funds, but their impact on broker-dealers in 2026 – and potentially beyond – will be no less significant, as the exam staff scrutinizes broker-dealer sales practices and recommendations, Lombardo stated.

See “SEC Risk Alert Discusses Broker-Dealer Exam Selection, Scoping and Document Requests” (Sep. 26, 2024).

Self-Regulatory Organizations

The Priorities go to great lengths to explain how the role of self-regulatory organizations (SROs) complements – but does not in any way supersede – that of the SEC and how the Division will conduct extensive oversight of SROs to ensure they help promote transparency and compliance in the private funds market. The Division goes to considerable lengths to delineate its oversight authority of regulators with a more limited purview.

The Priorities acknowledge an important role for FINRA as a source of forums for securities arbitrage and mediation, as well as a regulator with broad responsibilities in areas such as broker-dealer advertisements and the testing and licensing of registered persons. To ensure FINRA does its job, the Division noted that it carries out risk-based oversight examinations of FINRA, selecting areas within the organization to scrutinize.

Two investor protection initiatives, for which FINRA bears responsibility, are identified as of particular concern to examiners:

  1. Reg BI; and
  2. Form CRS.

In undertaking assessments, the Division utilizes diverse methodologies designed to support a holistic assessment of FINRA’s performance. “The assessment is informed by collecting and analyzing extensive information and data, regular meetings with key functional areas within FINRA, and outreach to various stakeholders, including investor and industry groups,” the Priorities state. “The Division also conducts oversight examinations of FINRA’s examinations of certain broker-dealers and municipal advisors that are FINRA members.”

That last line holds the key to a potential double-bind facing broker-dealers in 2026, in Lombardo’s view. “Because broker-dealers are subject to both FINRA oversight and the SEC’s oversight – unlike advisers that don’t have their own SRO – there is certainly the potential for a broker-dealer that is recommending complex products to have to answer to two different sets of regulators,” she observed. “Although ideally there is coordination to avoid duplication of examinations, unfortunately, that isn’t always the case.”

See “A Look at FINRA’s 2025 Oversight Report” (Mar. 13, 2025); “Reg BI Risk Alert Focuses on Deficient Policies and Procedures” (Oct. 26, 2023); and “SEC Committee Statement Details Shortcomings in Form CRS Compliance” (Feb. 10, 2022).

Other Risk Areas

Cybersecurity

The Division pledges to continue to review policies and procedures that registrants have implemented with a view to thwarting cyber breaches and protecting the data, records and assets of investors from improper access and misuse. The Priorities characterize the current risk of breaches as “elevated” in view of four general factors:

  1. growing incidence of cybersecurity attacks;
  2. dispersed operations of firms;
  3. weather-related events; and
  4. geopolitical tensions and problems.

Recognizing the “vital” role of its cybersecurity exams, the Division intends to pay special attention to firms’ policies and procedures in the following key areas:

  • governance practices;
  • data loss prevention;
  • access controls;
  • account management; and
  • cyber incident response and recovery, especially as to ransomware incidents.

See “CFTC Commissioner Urges Tougher Diligence and Closer Cooperation to Thwart Cyber Threats” (Sep. 11, 2025).

Regulation S‑ID and Regulation S‑P

Along with cybersecurity, the Priorities identify two core areas of operational resiliency on which the Division will focus in 2026.

Regulation S‑ID

The first is Regulation S‑ID, which requires firms to develop a theft prevention program. To verify compliance with Regulation S‑ID, the Division assesses whether firms’ policies and procedures:

  1. are reasonably designed to spot red flags, especially in the course of fraudulent transfers and customer account takeovers; and
  2. include identity theft prevention training.

Regulation S‑P

The other focus is firms’ compliance with Regulation S‑P, which requires firms to have policies and procedures designed to protect sensitive customer assets and data from breaches, and to promptly notify affected customers as soon as practicable and not more than 30 days after discovering a breach.

Entities with $1.5 billion in assets or more were required to comply with Regulation S‑P by December 3, 2025, while smaller firms have until June 3, 2026. In preparation for the upcoming compliance date, the Division will engage with firms during examinations to assess their progress toward developing and adopting the requisite incident response programs. After both compliance deadlines have passed, the Division will scrutinize firms’ development, adoption and maintenance of policies and procedures to meet the Regulation S‑P requirements as to administrative, technical and physical protections of customer data.

With one of the compliance deadlines having passed and another coming up soon, it would be hard to overstate the importance of vigorous Regulation S‑P compliance for all firms to which it applies, Slovick asserted. “The Division loves to ‘play with new toys,’ so to speak, and the updates to Regulation S‑P are shiny new toys,” he said. “And because Regulation S‑P applies so broadly – to broker-dealers, investment advisers and investment companies – this exam priority is likely to have an impact on a large number of firms.”

Also, it is worth noting that smaller firms should not wait until the June 2026 compliance deadline to get their house in order, emphasized Morgan Lewis partner Christine Ayako Schleppegrell. “The SEC is still looking at smaller firms’ preparedness and whether they are ready for the compliance deadline,” she stated. “In examinations, we have seen the Division ask, ‘We know that you are technically not required to comply right now, but are you ready for it when it comes? And if you are not ready, what are you going to do to get ready?’”

See “SEC Staff Discuss Regulation S‑P Amendments and Related Examination Processes” (Oct. 23, 2025).

Emerging Financial Technology

Recognizing the swift adoption of new technologies throughout the economy in general and the financial services industry in particular, the Division pledged to examine training and security oversight that firms implement to identify and mitigate threats related to two fast-growing areas of concern: artificial intelligence (AI) and polymorphic malware attacks.

See “Benchmarking Fund Managers’ Adoption and Governance of Generative AI” (Nov. 6, 2025).

Growing Threats

Firms using automated investment advisory services, recommendations and related tools and methods can expect intensive scrutiny. Regulatory assessments in that area will focus on four key topics:

  1. fairness and accuracy of representations;
  2. consistency of relevant operations and controls with disclosures made to investors;
  3. consistency of algorithm-generated advice or recommendations with investors’ profiles and/or strategies; and
  4. controls confirming that advice or recommendations generated through such tools are consistent with fiduciary and other regulatory obligations to investors, particularly retail and older investors.

The Priorities go on to set forth a broad mandate for AI regulation. “With respect to AI, the Division will focus on recent advancements in AI and will review for accuracy registrant representations regarding their AI capabilities or AI,” the Priorities state. “The Division will assess whether firms have implemented adequate policies and procedures to monitor and supervise their use of AI technologies,” the Priorities continue, with particular attention on four areas:

  1. fraud prevention and detection;
  2. back-office functions;
  3. anti-money laundering (AML); and
  4. trading functions.

Strict compliance is definitely advisable but will not be easy for advisers to implement – in part due to vagueness in the AI mandate in the Priorities, Slovick acknowledged. “Those two statements are fairly general and could just as accurately apply to any other aspect of a regulated entity’s business,” he observed. “It will be a bit of a guessing game for advisers to decide what level of disclosure about their AI use is sufficient and what amount of monitoring and detail in their policies and procedures will satisfy Division staff.” Until more guidance comes out and a few enforcement cases have been litigated, the industry will find itself in a “wait-and-see” situation, he opined.

Role of Third Parties

The Division not only expects sponsors and managers to make use of input from expert third parties on evolving threats from bad actors using AI and malware but will make it an issue in exams. In fact, the Priorities stipulate that the Division will take an interest in how entities in the market “are operationalizing information from threat intelligence sources.”

The Division’s increased focus on third-party vendors is reasonable given the growing use of outside service providers to carry out critical functions and, in some cases, to provide input and guidance on cybersecurity risk mitigation, Lombardo observed. “As firms continue to use more technology, there is at least a perception of vulnerability. Accordingly, I’m not surprised this is a priority for the Division.”

Internal Diligence

Proper oversight of AI usage is a necessity and requires a sophisticated understanding of AI that goes far beyond any specific niche application, Wyckoff emphasized. “AI usage is expanding beyond algorithmic trading and investment, as it can be used to give people a head start on all sorts of tasks,” she observed.

Understanding employees’ AI usage is an important first step to properly monitoring it going forward. “Policies, procedures and compliance programs can really only be adequately designed if you have an understanding of the operational universe that you’re trying to supervise,” Wyckoff reasoned. “For example, if I don’t know that my team is using ChatGPT to generate content, then how can I properly supervise and monitor that content generation and how the results are being used?”

Further, firms’ use of third-party expertise does not absolve them from their compliance responsibilities over automated functions and AI generally. Firms should continuously self-assess whether they are properly monitoring not only the impact of external AI but also internal use of technologies whose applications are fast evolving, Wyckoff reasoned. “Managers should focus on it in their routine monitoring and testing of whether their compliance program is adequately designed.”

“AI technology as a whole, and a firms’ usage of it, is a moving target, and regulators will want to know how often you are checking in to understand what’s going on in the organization and ensure that policies and procedures are up to date,” Wyckoff summarized.

See “AI Widely Used by Hedge Funds, AIMA Study Finds” (Apr. 25, 2024).

AML

The Division maintains a strong focus on AML compliance pursuant to requirements under the Bank Secrecy Act of 1970 (BSA). The BSA makes it mandatory for broker-dealers, among other entities, to adopt and implement policies and procedures reasonably designed to prevent misuse for money laundering and the financing of terrorism and to file suspicious activity reports (SARs) when appropriate. Another crucial aspect of AML compliance is acting in accordance with sanctions that the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) imposes on entities, nations and regimes.

See “SEC Risk Alert Highlights Continuing Broker-Dealer AML Shortcomings” (Sep. 28, 2023); as well as our three-part “Sanctions 101” series: “How Sanctions Regimes Work” (Jun. 16, 2022); “Impact on Private Fund Investors and Investments” (Jun. 23, 2022); and “How to Comply With Them” (Jul. 7, 2022).

Just as importantly, regulated entities need to be thoughtful about what policies and procedures are ideally suited to their size, location and role, the Priorities stress. When it comes to scrutinizing what AML compliance measures firms have taken, the Division will pay close attention to four key areas:

  1. tailoring and updating AML programs to match the business model of the entity in question and the risks it faces or is likely to face;
  2. independent testing of those programs;
  3. establishing a suitable customer ID program that can reliably identify both legal entity customers and their beneficial owners; and
  4. filing of SARs as and when required under the BSA.

When examining firms, Division staff will make a point of reviewing policies and procedures in place for oversight of applicable financial intermediaries. Finally, the Division will ascertain whether firms are paying attention to, and are in compliance with, any and all sanctions that OFAC rolls out.

See “FinCEN Proposes Pushing Back AML Rules Compliance Date to January 2028” (Oct. 23, 2025); as well as our three-part series on tailoring a compliance program: “Why Fund Managers Should Customize” (Jul. 16, 2020); “What Fund Managers Should Consider” (Jul. 23, 2020); and “When Fund Managers Should Review and Update” (Jul. 30, 2020).

Key Omission: Crypto

The omission of crypto from the Priorities is notable, given how prominently the SEC included the issue in priorities from prior years, Schleppegrell noted.

The omission of crypto from the Priorities can be explained partly in terms of the Division leadership team’s explicit acknowledgment, in its opening message, that it has revisited its priorities and decided to pursue a different approach from that characterizing the Gensler SEC, agreed Paul Hastings partner Ryan Swan. “The lack of an SEC exam focus on crypto is consistent with statements from current SEC leadership about fostering innovation in the capital markets and adjacent financial sectors, including in the crypto space,” he acknowledged.

“It may also be just the SEC showing some self-awareness, given various pieces of pending federal legislation that would clarify jurisdictional authority over crypto,” Swan added. “I don’t think the SEC is standing down, but it may be waiting for congressional directives as it moves to develop its regulatory and oversight framework.”

However, the omission of crypto from the Priorities should not be taken to mean that the SEC has “gone soft” in a traditional area of enforcement. “The current leadership has been clear, including in conversations around crypto, that it will continue to pursue fraud, bad actors and illicit conduct – the ‘bread and butter’ of financial services regulation,” continued Swan. “But that arguably doesn’t require a specific exam focus. They have the tools, under other provisions of the securities laws, to correct that kind of misconduct.”

See “Study Finds Increasing Hedge Fund Interest in Digital Assets” (Mar. 13, 2025).

Marketing

Marketing Rule Risk Alert Focuses on Testimonials, Endorsements and Third-Party Ratings


In May 2021, the SEC adopted Rule 206(4)‑1 (Marketing Rule or Rule) under the Investment Advisers Act of 1940 (Advisers Act). Since then, the Division of Examinations (Division) has issued multiple risk alerts on Rule-related examinations and compliance expectations. The SEC has also resolved multiple enforcement proceedings for alleged violations of the Rule and associated compliance failures. The Division’s fourth risk alert (Risk Alert), released on December 16, 2025, is based on the staff’s review of advertisements disseminated to investment advisers’ current or prospective clients, including private fund investors, that included testimonials, endorsements and/or third-party ratings. Just weeks after the Division issued the Risk Alert, the Division of Investment Management issued two new FAQs regarding the Rule. This article discusses the relevant provisions of the Rule, the deficiencies identified in the Risk Alert and the two new FAQs.

See “Nine More Advisers Fined by SEC in Ongoing Marketing Rule Sweep” (Nov. 7, 2024).

Ongoing Focus on Marketing Rule Compliance

The Division has previously issued three risk alerts on the Rule:

  • September 19, 2022: announcing an examination initiative focused on policies and procedures; the substantiation requirement for material statements of fact; performance advertising; and books and records;
  • June 8, 2023: announcing additional focus on the Rule’s general prohibitions; testimonials and endorsements; third-party ratings; and Form ADV; and
  • April 17, 2024: discussing deficiencies associated with Advisers Act Rule 206(4)‑7 (Compliance Rule), Rule 204‑2 (Books and Records Rule) and Form ADV.

The latest Risk Alert “does not address all observed deficiencies related to the Marketing Rule,” cautioned the Division. In addition, the deficiencies under the referenced provisions of the Rule could also constitute violations of other provisions of the Advisers Act or other rules thereunder. For example, a promoter that provides endorsements might also be acting as an investment adviser or broker-dealer. “The Division encourages advisers to reflect upon their own practices, policies, and procedures and to implement any appropriate modifications to their training, supervisory, oversight, and compliance programs,” states the Risk Alert.

See “Third Marketing Rule Risk Alert and New Settlements Portend Vigorous Enforcement” (Jun. 6, 2024); “Second Marketing Rule Risk Alert Provides Little Substantive Guidance” (Aug. 3, 2023); and “Marketing Rule Risk Alert Forecasts Coming Exams” (Oct. 20, 2022).

Inadequate Policies and Procedures or Implementation

Notwithstanding the SEC’s substantial outreach and enforcement activity since adopting the Marketing Rule, some advisers have still failed to adopt policies and procedures to govern their use of testimonials, endorsements and/or third-party ratings, according to the Risk Alert. Others that adopted such policies failed to implement them.

See “SEC Order Reminds Advisers of Fundamental Obligations Under Marketing and Compliance Rules” (Dec. 18, 2025); and “SEC Penalizes Nine Advisers for Marketing Rule Violations in Ongoing Sweep” (Nov. 9, 2023).

Testimonials and Endorsements

Definitions and Requirements

The Rule defines “testimonial” as a statement by an adviser’s current client or an investor in a private fund advised by the adviser about such person’s experience with the adviser or that solicits or refers a person to be a client/investor. An “endorsement” is a statement by a person other than a current client/investor recommending the adviser or soliciting/referring a person to be a client/investor.

Rule 206(4)‑1(b) provides, “An advertisement may not include any testimonial or endorsement, and an adviser may not provide compensation, directly or indirectly, for a testimonial or endorsement,” unless the adviser complies with the following conditions or an exemption applies:

  • Disclosures: The adviser must disclose, or reasonably believe the person giving the testimonial or endorsement discloses:
    • that a person has made the testimonial or endorsement (Promoter);
    • that the adviser paid compensation for the testimonial or endorsement, if applicable; and
    • any relevant material conflict of interest. Such disclosure must be “clear and prominent” and must be made at the time of disseminating the testimonial or endorsement.
  • Oversight and Compliance: The adviser must have:
    • a reasonable basis for believing the testimonial or endorsement complies with the Rule; and
    • a written agreement with each paid Promoter describing the scope of the testimonial/endorsement arrangement and the terms of compensation, unless the total compensation paid to such Promoter is no more than $1,000 over the course of the prior year (de minimis exemption).
  • Ineligible Paid Promoters: The adviser may not compensate a person for a testimonial or endorsement if the adviser knows or should know that the person is subject to any of the specified disqualifying events or disqualifying SEC actions.

See “Navigating Substantiation of Facts, Testimonials and Performance Claims Under the Marketing Rule” (Nov. 21, 2024); and “The New Marketing Rule: Key Takeaways for Private Fund Managers (Part One of Two)” (Mar. 18, 2021).

Observed Deficiencies

Untimely Disclosures

The most common shortcoming identified by the Division was failing to make the requisite disclosures at the time of disseminating the testimonial or endorsement.

Unrecognized Testimonials and Endorsements

Some advisers that used lead-generation firms, social media influencers, referral networks and/or client referral incentives failed to recognize that the arrangements constituted covered testimonials or endorsements.

See “Navigating Use of Social Media Under the SEC’s New Marketing Rule” (May 12, 2022).

Inadequate Disclosures

Missing Information

Certain advisers failed to disclose whether a Promoter:

  • was a current client or investor;
  • received compensation; or
  • had a material conflict of interest.
Not “Clear and Prominent”

Certain disclosures did not satisfy the “clear and prominent” requirement because they were:

  • accessible only via a hyperlink; or
  • in a smaller or lighter font than the testimonial/endorsement.
Third-Party Websites

Certain advisers incorporated testimonials or endorsements from third-party websites without disclosing that the Promoter was a current or former client. Others gave clients gift cards to write reviews on third-party websites without having a reasonable basis for believing the clients would make the requisite disclosures.

Compensation Arrangements

Some advisers failed to disclose the material terms of compensation arrangements or omitted material information about such terms. In that regard, the Rule’s adopting release indicates that the disclosure should include, as applicable:

  • the specific amount of cash compensation, if any;
  • if tied to a percentage of advisory fees, the relevant percentage and time period covered; and/or
  • the value of non-cash compensation, if “readily ascertainable.”
Material Conflicts of Interest

Advisers failed to disclose material conflicts associated with their relationships with Promoters and/or compensation arrangements for paid testimonials and endorsements. For example, some failed to disclose that a Promoter had a financial stake in, was an investor in or was a principal of the promoted adviser or one of its affiliates.

See “Identifying and Managing Common Conflicts of Interest” (May 9, 2024).

Inadequate Oversight and Compliance

Failures to comply with the Rule’s oversight and compliance requirements included:

  • being unaware that certain statements were endorsements;
  • failing to have a reasonable basis for believing the advertisement complied with the Rule;
  • failing to enter into or maintain agreements with paid Promoters that fully described:
    • the scope of the Promoter’s activities; and/or
    • the compensation terms; and
  • improperly relying on the de minimis exemption when aggregate annual compensation to a Promoter exceeded $1,000.

Affiliated Persons

The Rule exempts testimonials and endorsements by partners, officers, directors, employees and other affiliated persons and entities of an adviser from the Rule’s disclosure as well as paid-Promoter requirements provided that, at the time the adviser disseminates the advertisement, the affiliation is “readily apparent to or is disclosed to the client or investor” and the adviser documents the affiliate’s status. Certain advisers failed to satisfy that exemption, including by failing to disclose the affiliation at the time of dissemination.

Compensation for Ineligible Persons

Certain advisers compensated Promoters when they “knew, or in the exercise of reasonable care should have known,” the Promoters were ineligible, including by having been subject to state disciplinary actions.

See “SEC Provides Guidance on When the Bad Actor Rule Disqualifies Hedge Fund Managers from Generally Soliciting or Advertising” (Mar. 7, 2014); and “Implications for Hedge Fund Managers of the SEC’s Recent Guidance on the Rule 506 Bad Actor Disqualification Provisions” (Dec. 12, 2013).

New FAQ on Disqualifying Events

One of the events that makes a Promoter ineligible to receive compensation for providing a testimonial or endorsement is entry of a final disciplinary order against the Promoter by the SEC or a self-regulatory organization (SRO) within the 10 years prior to dissemination of the advertisement containing the testimonial or endorsement. There is an exception to disqualification for SEC orders that do not result in a bar, suspension or prohibition from acting in any capacity under the federal securities laws, provided the Promoter is in compliance with the order’s terms and the advertisement includes certain disclosures about the disciplinary event. The Marketing Rule, however, does not have a similar exception for SRO final orders that do not result in a bar, suspension or prohibition.

The new FAQ indicates that the staff of the Division of Investment Management will not recommend enforcement action if an adviser compensates a Promoter when the adviser knows or should know that, within the past 10 years, the Promoter is or was subject to an SRO disciplinary order that does not or did not bar, suspend or prohibit the Promoter from acting in any capacity in connection with the disqualifying conduct, provided:

  • the order is the sole reason the Promoter is ineligible to receive compensation for providing the testimonial or endorsement;
  • the SRO did not expel or suspend the Promoter from membership or impose a bar or suspension from association or other prohibition on the Promoter;
  • the Promoter is in compliance with the order, including payment of all financial remedies; and
  • for 10 years following issuance of the order, the advertisement containing the testimonial or endorsement discloses that the Promoter is subject to the order and provides a copy of the order or a link to it.

Third-Party Ratings

Definition and Requirements

As used in the Rule, a “third-party rating” is “a rating or ranking of an investment adviser provided by a person who is not a related person . . . and such person provides such ratings or rankings in the ordinary course of its business.” Rule 206(4)‑1(c) provides that an adviser may not include a third-party rating in an advertisement unless the adviser satisfies the following conditions:

  • Due Diligence: The adviser must have a reasonable basis for believing that any questionnaire or survey used in preparing the rating makes it equally easy to provide favorable and unfavorable responses and is not designed to produce any predetermined result.
  • Disclosure: The adviser must clearly and prominently disclose, or reasonably believe the third-party rating clearly and prominently discloses:
    • the date of the rating and the relevant time period it covers;
    • the identity of the third party that created the rating; and
    • if applicable, that the adviser paid direct or indirect compensation to obtain or use the rating.

See “The New Marketing Rule: Key Elements and SEC Commissioner Concerns” (Mar. 4, 2021).

Observed Deficiencies

Inadequate Due Diligence

Advisers sought to satisfy the obligation to have a reasonable basis for believing a third-party rating is unbiased by:

  • reviewing publicly disclosed information about questionnaire or survey methodologies;
  • obtaining the questionnaires or surveys used in preparing the rating; and/or
  • obtaining representations from third-party rating agencies regarding their rating processes.

Some advisers, however, lacked sufficient information to form a reasonable basis for their belief, explains the Risk Alert. They either did not have appropriate policies or procedures for doing so or failed to take steps to satisfy the due diligence requirement.

Inadequate Disclosures

Certain advisers failed to make clear or prominent disclosures regarding third-party ratings and/or did not have a reasonable belief that the third-party was making such disclosures.

Third-Party Websites

Certain advisers’ website advertisements had links to third-party websites containing ratings, but none of the websites contained the requisite disclosures. Such advisers also could not have had a reasonable basis for believing the third-party websites contained such disclosures.

Date, Time Period and Identification

Certain advertisements failed to provide the date of a rating or the period it covered. Others incorrectly stated the adviser had received a rating in a year or years when it had not received such rating. Still others included rating logos without clearly and prominently identifying the third-party responsible for the rating.

Compensation

Certain advisers paid direct or indirect compensation for ratings without providing the requisite disclosures. Deficiencies included failing to disclose:

  • paying for a rating in the place where the adviser posted the rating;
  • paying for using a rating provider’s logo, reprinting ratings and/or obtaining priority placement or enhanced exposure; and/or
  • paying a rating provider for linking to the adviser’s website.

Additionally, certain advisers’ disclosures were not clear or prominent, including disclosures:

  • accessible only by hyperlink;
  • in smaller font than the associated rating; or
  • located at the bottom of a webpage, away from the rating.

For a discussion on several SEC enforcement actions involving third-party rating violations, see “Compliance Corner Q4‑2024: Regulatory Filings and Other Considerations Hedge Fund Managers Should Note in the Coming Quarter” (Sep. 26, 2024).

New FAQ on Using Model or Actual Fees to Calculate Net Performance

The Marketing Rule requires an adviser that presents gross performance in an advertisement to present net performance with equal prominence. In calculating net performance, an adviser may use the actual fees charged to the relevant fund/accounts or a model fee. A model fee must be either the highest fee that would be charged to the relevant audience or one that would not result in better performance figures than the actual fee.

Footnote 590 from the adopting release for the Marketing Rule caused confusion about when an adviser must use model fees. It provides, “If the fee to be charged to the intended audience is anticipated to be higher than the actual fees charged, the adviser must use a model fee that reflects the anticipated fee to be charged in order not to violate the rule’s general prohibitions.” Consequently, “in some circumstances . . . it may be inconsistent with the Rule’s general prohibitions to solely present net performance reflecting actual fees,” notes the new FAQ.

However, footnote 590 does not categorically require net performance to be calculated using a model fee, according to the FAQ. “In the staff’s view, whether the use of actual fees violates the general prohibitions depends on all of the facts and circumstances of a specific advertisement, including, but not limited to, relevant disclosures,” notes the FAQ. “The staff’s view is that advisers may use various means to illustrate the effect of differences between actual fees and anticipated fees on performance.”

See “Navigating Performance Advertising Challenges Under the Marketing Rule and GIPS” (Nov. 6, 2025); and “SEC FAQs Clarify Marketing Rule Treatment of Extracted Performance and Portfolio Characteristics” (Apr. 24, 2025).

Broker-Dealers

Key Takeaways From FINRA’s 2026 Annual Regulatory Oversight Report


FINRA has released its latest annual regulatory oversight report (Report), with insights from its regulatory operations. This year’s Report includes a new section for trends in generative artificial intelligence (AI). It also covers the perennial topic areas of financial crime prevention; firm operations; digital assets; communications and sales; market integrity; and financial management. As in prior reports, each topic area identifies relevant laws and regulations; weaknesses FINRA has observed in members’ compliance programs; findings from FINRA’s examination, enforcement and other regulatory activities; and effective practices FINRA has observed that may help firms enhance their compliance programs. As always, the Report “does not create any new legal or regulatory requirements or new interpretations of existing requirements, or relieve firms of any existing obligations under federal securities laws and regulations.” This article discusses the key takeaways from the Report.

See “A Look at FINRA’s 2025 Oversight Report” (Mar. 13, 2025); and coverage of its 2023, 2022 and 2021 reports.

FINRA Forward

In April 2025, FINRA launched “FINRA Forward,” a series of initiatives to enhance the organization’s efficiency and effectiveness. Key elements of the initiative include:

  • modernizing rules to facilitate innovation and eliminate unnecessary burdens;
  • empowering compliance by enhancing support for members’ compliance programs; and
  • expanding FINRA’s cybersecurity and fraud prevention activities to support members’ efforts.

“The Report reinforces FINRA’s commitment to providing transparency to member firms about its regulatory observations and activities to help firms strengthen their compliance programs,” said FINRA.

See “FINRA Requests Comment on Potential Changes to Workplace and Other Rules” (May 22, 2025).

Useful Lessons, but Little New Information

With the exception of a new section devoted to AI, the Report breaks little new ground, with many of the findings and effective practices nearly identical to those in last year’s report. Notably, several effective practices appear in many – if not most – sections of the Report, which reflects the importance FINRA places on them. They include:

  • conducting risk assessments, risk-based analyses and testing;
  • maintaining up-to-date written supervisory procedures (WSPs) that are tailored to the relevant activity and specific circumstances and reflect changes in regulations, operations and market conditions;
  • establishing robust supervisory and governance mechanisms; and
  • conducting relevant training.

The Report also identifies ways firms have used the Report and other information from FINRA. They include:

  • assessing which findings and practices apply to a particular firm;
  • incorporating relevant information into risk assessments;
  • conducting gap analysis;
  • putting together interdisciplinary project teams and workstreams;
  • sharing reports and other information with compliance departments;
  • advising business leaders on action plans to address findings and recommendations; and
  • training and preparing internal guidance.

Financial Crime Prevention

Cybersecurity and Cyber-Enabled Fraud

Relevant regulatory obligations include:

  • Rules 17a‑3 and 17a‑4 under the Securities Exchange Act of 1934 (Exchange Act), which set forth recordkeeping requirements for broker-dealers;
  • Regulation S‑P, which requires firms to safeguard customer information;
  • Regulation S‑ID, which requires them to adopt an identity theft prevention program with respect to covered accounts;
  • FINRA Rule 3110, which requires members to establish an appropriate system for supervising associated persons; and
  • FINRA Rule 4370, which covers business continuity plans and emergency contacts.

The SEC amended Regulation S‑P in May 2024. The compliance date for large firms was December 3, 2025; the compliance date for small firms is June 3, 2026.

The Report highlights the growing threat from AI‑enabled fraud. Attackers are using AI to generate fake content and create more effective malware. They are also offering “cybercrime-as-a-service.” The Report also discusses more traditional threats, including:

  • ransomware and extortion;
  • phishing and similar attacks;
  • new account frauds, account takeovers and account impersonations;
  • impostor websites;
  • relationship frauds; and
  • insider threats.

The Report includes several new effective practices:

  • monitoring for account takeovers, impostor websites and third-party vendor risks;
  • establishing clear “bring your own device” policies; and
  • encouraging communication among cybersecurity, IT and anti-money laundering (AML) teams.

Other effective practices include identity verification, including multifactor authentication (MFA); training and awareness, including tabletop exercises; and network segmentation.

See “The Growing Dangers AI-Based Deceptions Pose to Hedge Fund Managers” (Jan. 15, 2026); “Managing Cybersecurity, Incident Response Planning and Vendor Risk” (Dec. 4, 2025); and “Six Steps to Address the SEC’s Trump Era Cyber Enforcement Priorities” (Oct. 9, 2025).

AML, Fraud and Sanctions

FINRA Rule 3310 establishes the minimum standards for firms’ AML compliance programs. It covers policies, procedures and internal controls; independent testing; training; customer due diligence (CDD) and customer identification programs (CIP). The Report identifies shortcomings in the following AML compliance areas:

  • AML program design, including:
    • tailoring programs and providing sufficient resources;
    • identifying and investigating red flags, including those associated with omnibus accounts, small-cap offerings, identity theft and red flags detected by other teams or clearing firms; and
    • reporting suspicious activities;
  • CIP and CDD policies and procedures, including:
    • recognizing customer relationships;
    • verifying customer identities, especially when red flags are present;
    • detecting and investigating red flags; and
    • ongoing risk-based CDD;
  • due diligence on correspondent accounts at foreign financial institutions;
  • testing; and
  • training.

Effective practices for AML compliance include:

  • keeping abreast of regulatory requirements and updating compliance programs as appropriate;
  • clearly delegating AML responsibilities among functions in the best position to identify red flags and suspicious activity;
  • conducting reasonably designed independent testing;
  • conducting appropriately tailored training; and
  • conducting risk assessments and assessing alerts and exception reports to ensure they are functioning as intended.

The Report also discusses the prevalence of external fraud risks, including account takeovers, new account frauds and other scams. Firms can combat such risks with:

  • strong risk-based compliance;
  • enhanced verification when anomalies are detected;
  • risk-based controls over funds transfers;
  • cross-function communications channels;
  • training and educational materials;
  • using temporary holds under Rule 2165 when exploitation is feared;
  • emphasizing the importance of trusted contacts;
  • having response plans to aid defrauded customers; and
  • customer outreach.

See “FinCEN Proposes Pushing Back AML Rules Compliance Date to January 2028” (Oct. 23, 2025); and “SEC Risk Alert Highlights Continuing Broker-Dealer AML Shortcomings” (Sep. 28, 2023).

Manipulative Trading

In addition to the overarching duty to supervise under Rule 3110, broker-dealers are subject to:

  • Rule 2010 (standards of commercial honor and principles of trade);
  • Rule 2020 (manipulative, deceptive or other fraudulent devices);
  • Rule 5210 (publication of transactions and quotations);
  • Rule 5220 (offers at stated prices);
  • Rule 5230 (payments involving publications that influence the market price of a security);
  • Rule 5240 (anti-intimidation/coordination);
  • Rule 5270 (front running of block transactions);
  • Rule 5290 (order entry and execution practices); and
  • Rule 6140 (other trading practices).

FINRA continues to see deficiencies around:

  • inadequately designed or tailored WSPs for identifying manipulative conduct; supervising different sources of order flow; and considering red flags from external sources; and
  • surveillance systems, controls and thresholds, including inadequate:
    • program assessments;
    • resources;
    • customer monitoring;
    • reviews of alerts and exception reports; and
    • documentation of findings.

Effective practices to combat manipulative trading include:

  • tailoring surveillance parameters and thresholds based on product class;
  • monitoring for red flags involving:
    • customer accounts that may have a relationship with an issuer;
    • conflicts of interest; and
    • involvement of unregistered individuals in underwriting or selling;
  • monitoring activities across multiple platforms and related products;
  • with respect to exchange-traded products (ETPs):
    • tailoring the firm’s compliance program;
    • developing robust systems to safeguard material nonpublic information; and
    • reviewing for manipulative strategies tied to ETPs’ unique characteristics; and
  • monitoring for wash and prearranged trading, including trading in related accounts and activity related to information provided on account opening.

See “SEC, CFTC and FINRA Division Heads Discuss Enforcement Outlook” (Apr. 24, 2025).

AI

FINRA has not adopted any AI-specific rules. Because its rules are “technologically neutral,” however, firms must comply with Rule 3110 and all other relevant rules when deploying AI or other new technology.

Member firms have been deploying AI to improve efficiency, especially for internal processes and information retrieval. The Report discusses the various AI use cases it observed among member firms, the most common of which was summarizing and extracting information. Other use cases include:

  • sentiment analysis;
  • drafting and content generation;
  • workflow automation;
  • database queries;
  • tailoring products, services and content;
  • converting and standardizing data;
  • chatbots, virtual assistances and other interfaces;
  • translation;
  • sorting, labeling and organizing information;
  • coding;
  • creating synthetic databases;
  • analysis and pattern recognition; and
  • modeling and simulation.

A firm contemplating deploying AI should:

  • develop appropriate supervisory processes;
  • consider how to mitigate the risks of hallucination and bias;
  • assess whether its cybersecurity program appropriately addresses risks associated with the firm’s and third-party vendors’ use of AI;
  • consider how AI may be used against the firm and its customers;
  • ensure appropriate supervision and governance, including a formal review and approval process; a governance framework; and policies and procedures;
  • implement robust testing; and
  • conduct ongoing monitoring of prompts, responses and outputs, including storing relevant activity logs, tracking model versions, output validation and human-in-the-loop reviews.

The Report also highlights the potential risks associated with AI agents, which can act autonomously. In addition to hallucination, bias and other more general AI risks, AI agents may operate beyond their intended scope or authority; disclose or compromise sensitive information; lack requisite industry-specific knowledge; or optimize decisions that negatively affect investors, firms or markets. In addition to the more general deployment considerations, firms contemplating using AI agents should also consider how to:

  • monitor agent system access and data handling;
  • track agent actions and decisions; and
  • establish appropriate guardrails and controls over the agent.

See “Benchmarking Fund Managers’ Adoption and Governance of Generative AI” (Nov. 6, 2025); and “Managing Third-Party AI Risk” (Jul. 31, 2025).

Firm Operations

Third-Party Risk Management

Rules relevant to outsourcing by member firms include Rule 1220 (registration categories), Rule 3110, Rule 4370 and Regulation S‑P.

FINRA has received an increasing number of reports of cyberattacks and outages at members’ third-party vendors. To help address those concerns, FINRA has collected updated information on members’ third-party vendors, which facilitates alerting members about vendor-related events that may affect firms. A firm may contact its Risk Monitoring Analyst to update information on vendors that support its key systems and any relevant cybersecurity events.

The Report provides little new information on effective third-party practices, which include:

  • establishing appropriate risk management policies and controls;
  • conducting initial and ongoing due diligence, including around third-parties’ use of AI;
  • having appropriate data- and AI-related contractual provisions;
  • ensuring appropriate configuration of third-party tools;
  • maintaining inventories of:
    • all third-party services, software, hardware and systems used by a firm; and
    • all data types accessed or stored by third parties;
  • monitoring third parties for vulnerabilities or data breaches;
  • assessing the impact of a cyber or technological incident at a third party;
  • involving third parties in incident response planning;
  • ensuring data return/destruction and access revocation when terminating a third party’s engagement; and
  • assessing risks posed by fourth-party vendors handling firm data.

See “Considerations for Managing Third-Party Cyber Risks” (Dec. 21, 2023); and “Checklist for Framing and Assessing Third-Party Privacy and Information Security Risk” (Sep. 28, 2023).

Technology Management

FINRA has observed the following effective practices for managing technology:

  • establishing a comprehensive governance framework with “clear accountability, oversight structures and documented processes”;
  • conducting routine risk assessments and using them to update the governance program;
  • establishing a governance framework for AI development and implementation, including appropriate documentation;
  • implementing robust identity management controls, including least-privilege access, MFA and comprehensive access reviews;
  • performing routine backups and testing;
  • having robust branch office procedures;
  • ensuring robust configuration management;
  • preparing appropriately for use of cloud-based systems;
  • capturing and retaining relevant log data; and
  • ensuring resiliency in the event of a firm or third-party outage.

Outside Business Activities and Private Securities Transactions

FINRA Rules 3270 and 3280 require registered representatives and associates to notify their firms of their proposed outside business activities (OBAs) and private securities transactions (PSTs). FINRA observed deficiencies involving:

  • erroneously determining that certain activities were not PSTs for compensation;
  • approving a PST without considering how the firm would supervise it;
  • failing to record or document PSTs or the associated supervision;
  • representatives’ failing to report OBAs and firms’ failing to review OBA reports; and
  • inadequate controls around OBAs and PSTs.

Effective practices for OBAs and PSTs include:

  • requiring representatives and associated persons to complete detailed, open-ended questionnaires both at hire and periodically thereafter, as well as compliance attestations;
  • conducing due diligence on all OBAs and PSTs when first disclosed and periodically thereafter;
  • monitoring for significant changes and red flags in representatives’ and associated persons’ performance, production levels or lifestyle;
  • having clear, detailed WSPs;
  • conducting training both at onboarding and periodically thereafter; and
  • imposing “significant consequences” on employees who fail to comply with OBA and PST policies.

See “FINRA Requests Comment on Revised Rules for Outside Business Activities and Securities Transactions” (Jun. 5, 2025).

Books and Records

SEC Rules 17a3 and 17a4, as well as FINRA Rules 2210(b)(4), 3110 and 4511, set forth recordkeeping requirements for broker-dealers. FINRA found ongoing deficiencies involving inadequate WSPs, preservation of off-channel communications, supervision, third-party due diligence and review of electronic communications. The Report also identifies new concerns involving:

  • inaccurate Financial and Operational Combined Uniform Single reports resulting from inaccurate calculations; and
  • failing to capture and review correspondence of associated persons, including part-time CCOs and financial and operations principals (FINOPs) who use third-party vendor email addresses.

Effective practices for recordkeeping continue to include testing and verifying vendor capabilities; ensuring access to books and records by CCOs; and monitoring for off-channel communications.

See “FINRA Sanctions Brokerage Representative for Unreported and Unauthorized Outside Activities and Trading” (Dec. 7, 2023).

Digital Assets

“FINRA is actively monitoring and responding to market, legislative and policy developments in this rapidly evolving area and encourages member firms to do the same,” advises the Report. FINRA observed deficiencies involving multiple rules, including:

  • Rules 2010 and 2210: inappropriate disclosures and false and misleading statements;
  • Rule 3110: inadequate due diligence on digital asset products and offerings;
  • Rules 3270 and 3280: disclosure failures involving crypto-related OBAs and PSTs;
  • Rule 3310: inadequate AML policies for digital assets; and
  • Rule 11870 (customer account transfer contracts): improperly rejecting certain customer asset transfer requests.

Effective practices around digital assets include:

  • conducting appropriate due diligence on unregistered offerings;
  • conducting risk-based on-chain fraud and AML reviews; and
  • informing customers about differences in asset protection, oversight and supervision of digital assets and traditional securities products.

See “NSCP to SEC’s Crypto Task Force: Focus on Clarity, Custody and Coordination” (Nov. 20, 2025); as well as our two-part series on an SEC Crypto Roundtable on custody of digital assets: “Custody Challenges” (Jun. 5, 2025); and “Custody Models” (Jun. 19, 2025).

Communications and Sales

Communications With the Public

Rules 2210 and 2220 govern, respectively, communications with the public and communications regarding options. The Report cites deficiencies under those rules regarding supervision of social media influencers; record retention; disseminating false, misleading or unbalanced information in mobile applications; and inadequate review of electronic communications. Effective practices for public communications include:

  • maintaining appropriate WSPs;
  • using reasonably designed procedures for monitoring and supervising digital communications, including training and disciplinary measures; and
  • implementing appropriate controls around using AI to communicate or generate content.

Regulation Best Interest and Form CRS

The Report includes multiple examples of firms’ failures to comply with the care, conflict of interest, disclosure and compliance obligations established by Regulation Best Interest (Reg BI), as well as with the filing, posting, delivery and amendment requirements for Form CRS. The Report emphasizes the importance of training and reiterates other effective compliance practices for each of the relevant obligations:

  • Care: improving processes and controls for assessing costs and reasonably available alternatives and heightening scrutiny of complex or risky investments for retail customers;
  • Conflicts: enhancing policies and procedures, changing fee schedules and prohibiting certain sales practices;
  • Disclosure: enhancing account recommendation disclosures and systems for documenting disclosures; and
  • Compliance: enhancing supervision of Reg BI compliance through reviews of recommendations; communications surveillance; branch examinations and documentation of compliance.

See “Reg BI Risk Alert Focuses on Deficient Policies and Procedures” (Oct. 26, 2023); as well as our two-part coverage of the SEC Division of Examination’s risk alerts on Reg BI and Form CRS: “What to Expect in Future Exams” (May 28, 2020); and “Key Takeaways for Broker-Dealers and Advisers” (Jun. 4, 2020).

Private Placements

FINRA rules pertaining to private placement recommendations include:

  • Rule 2111 (suitability);
  • Rule 2210 (communications with the public);
  • Rule 3110 (supervision);
  • Rule 3280 (private securities transactions of an associated person);
  • Rule 5122 (private placements of securities issued by members); and
  • Rule 5123 (private placements of securities).

The Report identifies deficiencies associated with private placements, including failures to:

  • have appropriate policies, procedures and processes for complying with filing requirements, resulting in untimely filings or reliance on inapplicable exemptions;
  • conduct reasonable investigations and/or maintain records of due diligence;
  • comply with Reg BI obligations; or
  • comply with SEC rules for contingency offerings.

Effective practices for private placements include:

  • enhancing due diligence checklists;
  • reviewing “bad actor” information for both issuers and placement agents;
  • conducting and documenting independent reviews of offerings;
  • reviewing offering terms for compliance with applicable rules; and
  • maintaining a reasonable understanding of offering terms and changes.

See “FINRA Sanctions Firm Over Private Placement and Marketing Practices” (Jan. 15, 2026); and “SEC Commissioner Uyeda Discusses Private Offering Framework and Accredited Investor Definition” (Aug. 15, 2024).

Annuities Securities Products

Rule 2330 covers broker-dealers’ responsibilities with respect to deferred variable annuities. The Report details concerns and effective practices regarding recommendations of variable annuities and registered index-linked annuities, including compliance with Reg BI obligations; WSPs; annuity exchanges; documentation; disclosures; supervision; surveillance and other controls; and data collection and analytics.

Market Integrity

Consolidated Audit Trail (CAT)

Exchange Act Rule 613 and the FINRA Rule 6800 Series set forth requirements for CAT reporting. In early 2025, the SEC issued exemptive relief with respect to reporting certain customer information, notes the Report. A pending proposal would eliminate other reporting requirements.

FINRA found ongoing issues around incomplete or inaccurate submissions; error correction; supervision, including sampling; and recordkeeping. Effective practices for CAT reporting continue to include:

  • mapping internal data to CAT fields;
  • archiving CAT feedback;
  • ensuring CAT clock synchronization;
  • appropriate supervision of CAT submissions; and
  • self-reporting CAT reporting issues.

See “Risk Alert Focuses on ‘Large Trader’ Disclosure, Reporting and Recordkeeping Duties” (Jan. 21, 2021); and “Present and Former SEC Attorneys Discuss Retail Investors, CAT Implementation, Enforcement Issues, Reg BI and SRO Oversight” (Dec. 12, 2019).

Best Execution and Order Routing Disclosure

FINRA Rule 5310 requires firms to use reasonable diligence to achieve best execution of customer trades and conduct thorough reviews of execution quality. SEC Rule 606 of Regulation NMS requires firms to disclose order handling information.

As in prior years, broker-dealers failed to assess execution in other markets; conducted inadequate best execution reviews; published incomplete or inaccurate order handling reports; and failed to adopt appropriate procedures for securities with limited pricing information and/or Rule 606 compliance.

Effective practices for best execution and order routing disclosure include:

  • for best execution:
    • ensuring appropriate supervision and monitoring of order flow;
    • leveraging exception and surveillance reports;
    • fine-tuning notification thresholds;
    • assessing the impact of payment for order flow;
    • conducting “regular and rigorous” reviews and being able to explain and evidence best execution analysis;
    • updating WSPs to address market and technology changes; and
    • using best execution committees; and
  • for order routing disclosure:
    • ensuring accurate, complete and timely reports; and
    • conducting appropriate due diligence for identifying execution venues and assessing third-party vendors’ reports.

See “SEC Division of Exams Finds Quantitative and Qualitative Deficiencies in Rule 606 Compliance” (Mar. 16, 2023); and “FINRA Issues Notice on Best Execution Duties and Payment for Order Flow” (Jul. 29, 2021).

Fixed Income Pricing

FINRA Rule 2121 requires firms that trade for their own account to trade at a fair markup or markdown from the prevailing market price (PMP). Perennial issues involving Rule 2121 include incorrectly determining PMP, using outdated information, failing to consider impacts of markups on yield to maturity and unreasonable supervision. Effective practices for Rule 2121 compliance include:

  • maintaining appropriate documentation;
  • conducting periodic reviews;
  • leveraging exception reports; and
  • assessing total charges borne by customers.

See SEC Sanctions Adviser That Used Unaffiliated Brokers to Trade Illiquid Securities Between Funds” (Nov. 9, 2023); and “FINRA Report Highlights Common Broker-Dealer Compliance Shortcomings” (Jan. 24, 2019).

Market Access Rule

SEC Rule 15c3‑5 imposes risk management obligations on broker-dealers that have or provide market access. FINRA identified ongoing issues with inadequate policies, procedures, surveillance, documentation, controls and thresholds, as well as reliance on third-party vendors without performing appropriate due diligence. Effective practices include:

  • using appropriate pre-trade “hard blocks,” “soft blocks” and other controls;
  • enabling intra-day adjustments to thresholds;
  • implementing reasonable post-trade controls and surveillance;
  • conducting regular tests of market access controls; and
  • conducting training on ad hoc credit limit adjustments and soft block releases.

Extended Hours Trading

FINRA Rule 2665 established risk disclosure requirements for firms that permit after-hours trading. FINRA found deficiencies involving reporting trading information to FINRA and/or CAT, as well as inadequate controls and supervision of after-hours trading. Effective practices for after-hours trading are essentially unchanged from last year and include:

  • conducting best execution reviews;
  • ensuring appropriate and complete risk disclosures;
  • implementing appropriately tailored WSPs; and
  • assessing operational readiness and customer support needs.

Financial Management

Net Capital Requirements

SEC Rule 15c3‑1 establishes minimum net capital requirements for broker-dealers. FINRA Regulatory Notice 25‑12 announced updated interpretations of such requirements. FINRA noted deficiencies involving improper recordkeeping, inadequate supervision, untimely notification of capital deficiencies and operating as an underwriter with insufficient capital. Effective practices include:

  • performing ongoing net capital assessments;
  • ensuring compliance with revenue recognitions requirements;
  • assessing the impact of new or complex transactions on net capital; and
  • implementing appropriate net capital WSPs and control processes for underwriting activities.

See “SEC 2025 Exam Priorities Stress Core Fiduciary Duties and Effective Compliance Programs” (Dec. 5, 2024).

Liquidity Risk Management

The SEC Customer Protection Rule (Rule 15c3‑3) and Rule 15c3‑1 both affect firms’ liquidity positions. “FINRA continues to emphasize effective liquidity and funding risk management as an important component of broker-dealers’ financial responsibility,” states the Report. However, certain firms have provided inaccurate or incomplete FINRA Supplemental Liquidity Schedules. Effective practices for liquidity risk management include:

  • ensuring policies and procedures are up to date and include appropriate governance mechanisms and a detailed liquidity management plan;
  • conducting carefully tailored stress tests, including robust data governance; and
  • assessing contractual provisions that might affect contingency funding.

See our two-part series on IOSCO’s revised liquidity management guidance: “Revised Liquidity Management Recommendations for Private Funds” (Dec. 4, 2025); and “How Guidance Conflicts With Market Realities” (Dec. 18, 2025).

Protecting Customer Assets

The Customer Protection Rule requires firms to segregate and safeguard customer assets. The SEC has extended the compliance date for daily reserve formula computations by certain firms under the Customer Protection Rule to June 30, 2026, notes the Report.

FINRA cited inadequate supervision of compliance processes, including reserve calculations, as well as issues with transfers of client funds, segregation of customer assets, data reconciliations with third parties and FINOPs’ access to books and records. To address those concerns, firms should:

  • conduct periodic reviews of the reserve computation process;
  • ensure relevant documents are maintained in good control locations; and
  • implement appropriate supervision of the reserve calculation and control processes.

See “FINRA Exam Findings Report Covers Four Aspects of Its Supervisory Activities” (Jan. 30, 2020).

Technology

A Baker’s Dozen AI Governance Resolutions for 2026


Many firms spent 2025 scrambling to integrate artificial intelligence (AI) into all aspects of business, just as a second transformative technology, which allows for independent decision-making by an AI agent (agentic AI), was entering early adoption. With pressure building throughout the business environment to incorporate these new technologies, the humans responsible for corporate AI efforts should pause at the start of 2026 to reflect on how risks have evolved and continue to do so.

The Hedge Fund Law Report asked a group of experts, including presenters at the AI Summit NYC conference in December 2025, what firms should resolve to do for their AI governance efforts in 2026. They recommended a baker’s dozen practical resolutions for organizations to develop greater trust in their AI use, advance responsible AI development, mitigate the technology’s array of risks and respond in a balanced way to the AI-related pressure building inside and outside organizations.

See “Benchmarking AI Uptake by Compliance Functions” (Dec. 4, 2025).

1) Gather Genuine Feedback About AI Use

The first thing firms should do in 2026 is resolve to catalogue the AI tools in use after a busy year of changes. “Companies began to license AI tools in earnest in 2025,” said Covington partner Yaron Dori. “They have made these tools available to a wider range of employees” and encouraged daily use, he reported.

Firms that adopted AI policies should “move to the next step” by gathering feedback from employees on how they take advantage of those tools and whether they follow best practices, advised Wiley Rein partner Duane Pozza. “For example, if employees use LLMs (large language models) for drafting routine documents, are they appropriately reviewing the output for accuracy?”

Firms should regularly seek feedback and create a dedicated, cross-disciplinary team to adjust policies to shifts in AI tools and usage patterns, Pozza urged. Employee surveys should ask whether “employees have an understanding of what kind of data can be used in connection with an AI tool” and "if a need exists for additional controls or training for confidential or personal data,” he suggested.

Areas needing thorough scrutiny include the use of AI agents and any mixing of unrelated Generative AI (Gen AI) tools. “More complex systems are being deployed in the real world,” noted Hogan Lovells partner Bret Cohen. “AI governance programs should carefully consider the additional risks, security and trust issues that their use might create before driving forward simply due to the promise of efficiency or innovation.”

See “Benchmarking Fund Managers’ Adoption and Governance of Generative AI” (Nov. 6, 2025).

2) Prepare for E.U. AI Act Compliance

“One of the prevailing themes of AI governance for 2026 will be establishing compliance with the E.U. AI Act,” since the bulk of compliance obligations for providers and deployers of high-risk AI systems take effect in August 2026, Cohen said.

Firms that provide or deploy AI systems in the E.U. should take stock of which of their systems are likely to be considered “high-risk,” Cohen advised, and then “start chipping away at the many compliance steps needed by August,” such as:

  • evaluating all high-risk systems;
  • documenting mitigation measures; and
  • implementing clear human oversight.

3) Apply Recognized Frameworks to Accelerate Governance

Firms can address the challenges of AI governance with a framework, but it does not need to be built from scratch. “Companies should consider using existing standards, some of which, like the National Institute of Standards and Technology (NIST) AI Risk Management Framework and International Organization for Standardization (ISO)/IEC 42001:2023, have been used to draft or have been incorporated directly into existing and proposed AI law,” BakerHostetler partner James Sherer observed.

Working from these existing frameworks “helps companies to create a plan and punch list approach in an area where there is so much uncertainty,” Sherer noted. “Companies can embark on meeting the NIST or ISO standards as a papering exercise, fully commit to improving processes or somewhere in between,” he advised. In his experience, “every bit of effort counts,” so even a box-ticking exercise can still have positive effects.

See our four-part AI compliance playbook: “Traditional Risk Controls for Cutting‑Edge Algorithms” (Sep. 29, 2022); “Seven Questions to Ask Before Regulators or Reporters Do” (Oct. 6, 2022); “Understanding Algorithm Audits” (Oct. 13, 2022); and “AI Adapting the Three Lines Framework for AI Innovations” (Oct. 20, 2022).

4) Prioritize Top Risks

New AI-related governance tasks add to a growing list of cyber and privacy obligations, complicating risk assessment, which makes prioritization a key task.

“Businesses and compliance professionals face risk assessment fatigue, while risk assessment obligations keep piling up,” Cohen observed. Compliance leaders should scan their AI uses and prioritize actions “to avoid this fatigue and to make sure that they are most effectively mitigating the most serious risks,” he advised.

Firms following NIST or other governance frameworks often err when completing a risk-based AI impact assessment by counting risks too broadly, TrustedAI CEO Pamela Gupta revealed. They may evaluate risks by department, for example, when they instead “need to have a use-case-based awareness in the organization,” she said. An illustration of why each AI use requires separate evaluation is evident in a class action lawsuit against insurer Humana, she noted. As alleged, Humana’s adoption of AI decision-making for one category of prior authorization requests produced a denial rate more than 16 times higher than its overall rate of denials across the rest of the categories.

Firms should not default to leaving the “risk” professionals to assess risks on their own. Department heads, data scientists, marketers, CEOs and boards should be brought into the risk assessment conversation to gain a full picture for each set of AI uses and share what each sees as the impacts of bad results, such as a high rate of request denials, Gupta advised.

Additionally, firms should move beyond quarterly or periodic risk assessments and inventories, Pozza urged. “Organizations must update their risk management practices on a continuous basis to account for new AI tools and [their] potential new risks that range from IP protection to privacy to security threats,” while also tallying the benefits of the tools when deployed with care.

See “CFTC’s Report Calls for Engagement and Development of AI Risk Management Frameworks” (Nov. 7, 2024); “Dos and Don’ts for Employee Use of Generative AI” (Oct. 24, 2024); and “Understanding and Mitigating Risks of Using ChatGPT and Other AI Systems” (Jul. 6, 2023).

5) Invest in Compliance Staffing

Privacy, cybersecurity and legal teams have deep experience with compliance procedures and documentation, so it makes sense for these existing functions to add AI governance to their portfolios, Sherer suggested. Doing so can increase consistency and support resource optimization, he said.

However, compliance budgets are already stretched thin, Cohen warned, and AI has already dramatically added to the workload.

Additionally, vetting and procuring AI tools can take up a significant portion of the compliance team’s time, Pozza noted.

Thus, firms should consider rolling some of the increased revenue from adopting AI tools into compliance resourcing. “As companies start to realize savings from the use of AI tools, they should make sure to similarly invest in resources for AI governance and security risk mitigation, which will help to avoid the more serious risks,” Cohen recommended. This includes increasing compliance headcount “to help avoid burnout of the existing team,” he suggested. AI also brings novel imperatives that are increasingly complex, such as the traceability of AI decisions, adding to the strain on compliance leadership.

See “ACA Compliance Testing Survey: AI and AML Are Now Top Compliance Concerns” (Aug. 28, 2025); as well as our two-part series “The Algorithmic CCO: AI’s Role in Shaping the Future of Hedge Fund Governance”: Part One (Feb. 13, 2025); and Part Two (Feb. 27, 2025).

6) Fund Monitoring Tools

In addition to bolstering compliance teams with capable team members, firms should also consider supporting those teams with governance and compliance tools such as automatic monitoring systems.

“Governance up till now has been focused on a one-time audit process or policy, a static approach,” said Eleanor Treharne-Jones, CEO of BigEye, a technology vendor. However, “with the relentless pace and speed of AI, that approach is no longer a match for the potential risk and opportunity that AI can bring,” she argued.

To better match internal AI governance to the pace of AI integration into the business, firms are seeking real-time monitoring during development so that they can feel more confident about scaling their AI initiatives, noted Treharne-Jones. Some automated governance tools are programmed to go beyond alerts to enforce compliance policies, she said, and the number of offerings on the market is growing.

Firms should consider budgeting to use “automated controls to make sure it’s not just a pinky promise from the rest of the team that they have done what they were supposed to,” BigID senior privacy counsel Heather Kuhn agreed.

Firm leaders may be besieged by AI-related spending requests and say “no” at first to AI governance spending, Treharne-Jones predicted. In response, compliance teams can highlight that a glitch with a wrong data input or output can be costly, possibly freezing development or requiring multiple people to drop everything, she noted. “Putting in place a proactive, ongoing monitoring control solution can avoid the cost of errors and mistakes,” she said.

If a firm does invest in AI governance tools, it must protect that investment by auditing to confirm they functioned as expected in the real world, Kuhn warned. “We are seeing enforcement actions where companies get in trouble for not doing what they said they would,” she noted.

See “SEC Continues to Target ‘AI Washing’” (May 22, 2025); and “SEC Settlements Target ‘AI Washing’” (May 23, 2024).

7) Prepare for More Sophisticated Cybercrime

As Gen AI advances, firms should warn employees about deepfakes and other forms of cybercrime that might be enabled by generative and agentic AI.

Robert Blanchard, a principal data scientist at business software giant SAS, recounted to an AI Summit audience that he was shaken that his wife, an AI scientist, had just been fooled by a multi-layer scam. The culprits wove together “a lot of sophisticated social engineering video” and fake documents, he noted. “In 12 to 24 months, we are going to be inundated with really sophisticated frauds and scams,” he warned.

More broadly, cybercrime AI tools are augmenting brute system penetrations to “more effectively exploit gaps in security procedures” with greater speed, acuity and thoroughness, Cohen noted, so cyber leaders need to comprehensively adjust their program for a new set of threats.

Agentic AI and other innovative tools allow novel exploits that have been scarcely studied, Cohen highlighted. Firms individually and collectively will need to expand their threat intelligence resources and generally seek out reports of new vulnerabilities and mitigations, such as those from AI vendor Anthropic. “Organizations that increase their use of AI tools or give more autonomy to AI agents will need to be vigilant to try to stop these threat actors, when the risks may not yet fully be appreciated,” he cautioned.

See “The Growing Dangers AI-Based Deceptions Pose to Hedge Fund Managers” (Jan. 15, 2026).

8) Demand Information and Audits From Vendors

For many firms, the riskiest cyber threats are the ones that sneak in along with third-party software. Indeed, cybersecurity professionals are having nightmares about all the AI features added to their software tools, reported Brennan Lodge, a New York University professor specializing in risks from fine-tuning Gen AI models who hosted the AI Summit’s cybersecurity sessions. “Let’s push back and get some transparency from our vendors as to what is going on with [their] AI,” he urged. He also recommended that firms’ cyber teams prioritize logging and auditing to closely watch the AI-enhanced software’s interactions with their own systems.

Firms should require third-party vendors to provide clear, standardized documentation that demonstrates “their AI is operating correctly and responsibly,” said ZwillGen’s AI director Brenda Leong. Components of that evidence package, she enumerated, ideally provided by vendors in an industry-standard sheet, should include:

  • system architecture;
  • acceptable use-case descriptions;
  • summaries of performance testing results;
  • applicable bias and impact metrics;
  • access controls; and
  • training data provenance details.

These transparency requirements can be standardized via requests for proposals and procurement checklists. “Buyers should be demanding this clarity, as they are accountable to boards and regulators,” Leong said.

See “Managing Third-Party AI Risk” (Jul. 31, 2025).

9) Commit to Higher Standards in Contracts

Firms should consider incorporating AI governance language in contracts to document and ensure their commitment to responsible AI use. “Forcing accountability” in contract language and public statements “will make companies more committed to the cause,” Sherer suggested, and might insulate AI governance from cost-cutting measures in the event of economic hardship.

Formalizing AI governance in an enterprise’s contract language can also help distinguish the firm from competitors, continued Sherer. He recommended backing this up with external third-party audit reports that confirm the company’s adherence to its commitments, e.g., following the NIST framework.

10) Boost Data Governance

Throughout 2025, business strategists stressed a “data-first culture” and the importance of an enterprise’s “data pipeline” to thrive in the AI era, which may mean that data governance is top of mind for business leaders and compliance professionals alike.

Firms must make sure they can classify and cleanse all the data across the firm to guarantee consent before the data gets to an AI model, Kuhn noted. Firms do not want to retroactively fix models, she observed.

Andra Vaduva, CEO of consultancy Safespace AI, conducts audits for clients and finds “a lot of data in silos, sitting in different formats and third-party software systems.” Firms rarely can persuade employees to classify, clean and standardize governance of data, which “requires building new routines and habits into people’s workflows,” she reported.

Unstructured data poses a higher risk than ever before with the introduction of agentic AI, Treharne-Jones warned. “Previously, no one was searching through [Microsoft] Sharepoint with the relentless dedication of an agent,” which likely “can find that screenshot with customer data that someone saved two years ago.”

To serve both the business and compliance effort, firms should seek controls and tools that root out anomalies in datasets and improve dataset completeness, quality and freshness, Treharne-Jones recommended.

Given the business value of data, firms should particularly limit employee access to the data going into AI training, Gupta recommended.

See “How to Apply Alt Data Best Practices to AI Systems” (Oct. 10, 2024).

11) Get Employees On Board and Share Knowledge

To achieve trustworthy AI, firms will need employees to follow policies, which is no easy task. “Monitoring for compliance across an entire employee base – not to mention across key business partners – is difficult,” Dori observed. Lessons from the past decade of data security have proven how difficult it is to monitor at scale, he said. “Companies that have made meaningful investments in AI tools and are loosening restrictions in their eagerness to demonstrate that those investments are worthwhile” will have a particularly challenging time ensuring employees comply with AI governance policies, he warned.

Further complicating the matter, pockets of employees inside businesses are wary of AI adoption after 2025 headlines about job losses and wrongful death lawsuits against chatbot makers. Only 27% of 1,000 working adults trusted their employers to use AI responsibly, consultancy SHL found in November 2025. A clear disconnect between Silicon Valley’s excitement about Gen AI’s demonstrable advances and the broad public’s skepticism may make employees less enthusiastic for a firm’s AI projects.

With these employee concerns in mind, firms must engage their workforce directly to foster trustworthy AI. “Collaboration and training will be key,” Dori predicted. “Sharing stories of successes – and failures – will be important” for strategic reasons, because firms have yet to find many impactful uses of Gen AI, he explained. At the same time, “knowledge sharing and collaboration can be used to emphasize governance, security and trust standards, thereby injecting a training element into everyday uses” of the AI, he recommended.

Firms should ensure that employees recognize that the company runs the AI, not the other way around, said Miles Bakenhus, partnerships and solutions lead for TrustVector. Assigning and announcing clear ownership of AI projects is crucial to build comfort among employees. “The starting point is identifying chains of accountability, who is responsible for what aspect of the system and what are the goals of the system,” he explained. The stakeholders also must know what the plan is to ensure the system aligns with those goals, he added.

An AI center of excellence can help firms pragmatically enable AI governance and communicate internally about it, Gupta suggested. Such a center can feed awareness of designated owners responsible for compliance “so that whoever in the company is looking to embark on an AI initiative can go to them,” and then recruit others to participate, she detailed. The center can gather what is involved in reviewing AI, ways to conduct the assessment for each AI initiative, an inventory of the company’s AI projects and tracking of assessments, she said.

See our two-part series on compliance training: “SEC Expectations and Substantive Traps to Avoid” (Sep. 23, 2021); and “Who Conducts the Training and Five Traps to Avoid When Providing Training” (Sep. 30, 2021).

12) Nurture Human Oversight

Even in firms with established AI governance programs, agents making business decisions is a reigning fear. “The aftermath of blind reliance on AI output to make business decisions has the potential to erase and worsen the advantages or productivity gains the AI tool was intended to achieve,” noted Woods Rogers attorney Ross Broudy. “Organizations must have in place – and enforce – AI governance policies that require a human to use their own judgment, expertise and common sense to verify AI output,” he stressed.

Firms should review decision checkpoints and confirm these gates block by default the automated output or agent action from proceeding.

Chatbots are an area where firms should resolve to ensure human oversight. Firms have grown more comfortable having the public interact with their chatbots, a years-old technology that improved and was increasingly adopted in 2025. Organizations and AI centers of excellence should put on the agenda to discuss guardrails for chatbots, particularly their “reference architectures” or data they can access.

13) Offer Safe Places to Play

“Employee use of unsanctioned AI tools, or ‘shadow AI,’ is an increasingly pervasive problem for organizations, resulting in higher costs to remediate data breaches and heightened legal liability,” Broudy noted. According to IBM’s Cost of a Data Breach Report 2025, data breaches that involved shadow AI featured the compromise of 65% more personally identifiable information and 40% more intellectual property than other breaches, he pointed out.

Along with reminders to employees about which AI tools are approved, firms can highlight the availability of sandboxes that would allow employees to try newer AI features. Hopefully, this will draw many of the employees perpetually tempted to experiment, decreasing the risk of a breach or a business problem. Gartner consultants predicted that, by 2027, AI agents will automate or augment 50% of business decisions. Amid such buzz, some employees will want to show initiative with agents.

“As a backstop, organizations should also ensure their insurance policies cover the risks associated with shadow AI,” Broudy recommended.

People Moves

Andrew Cross Joins Morgan Lewis in Pittsburgh


Morgan Lewis strengthened its investment management and digital assets team with the arrival of Andrew P. Cross as counsel. Based in Pittsburgh, Cross brings deep experience in the legal and regulatory aspects of CFTC matters, advising commodity trading firms, family offices, public companies, investment advisers and investment funds on complex derivatives transactions and related trade agreements.

For insights from other Morgan Lewis attorneys, see “SEC Regulatory and Examination Priorities in 2025” (Aug. 14, 2025); and “How to Approach Marketing Material Reviews” (Feb. 27, 2025).

Cross represents a wide range of clients in complex regulatory and transactional matters related to derivatives, repurchase agreements and other structured transactions. His clients include registered and private investment funds; registered investment advisers; financial institutions; commodity trading firms; family offices; and public companies.

See “How to Convert a Private Fund Manager Into a Family Office” (May 12, 2022).

For more than 10 years, Cross has also advised companies on the development of digital asset, crypto- and blockchain-related projects, as well as decentralized finance platforms. He has been involved in client projects related to the structuring of crypto derivatives and the tokenization of various financial and physical assets, including gold, agricultural warehouse receipts and environmental credits.

See “Study Finds Increasing Hedge Fund Interest in Digital Assets” (Mar. 13, 2025); “Benefits and Challenges Associated With Tokenization of Assets” (Apr. 25, 2024); and “Landscape of On-Chain Asset Tokenization & Blockchain Technology’s Path Toward Maturity” (Apr. 13, 2023).