Your Form ADV isn't the exam. Your access controls are.
The SEC's 2026 examination priorities are explicit: examiners are moving past whether you have a written policy and into whether anyone actually follows it — with employee access controls named directly. That gap between policy and practice is where deficiencies cluster.
The exam priorities already told you where they're looking.
The SEC's Division of Examinations publishes its priorities every year. For 2026, cybersecurity and access controls aren't a side note — they're a named focus, alongside a new written-response requirement most firms haven't operationalized yet.
are named directly in the SEC's 2026 Examination Priorities, alongside incident detection, response capability, and vendor risk.
is the window under the amended Regulation S-P to report a significant cybersecurity incident, with a written incident response program now required.
registered investment advisers were overseen by the SEC as of the most recent published count — a large, closely watched field.
Examiners aren't only asking about hackers. They're asking about your own people.
The insider-risk patterns that matter most to an RIA rarely make headlines — but they're exactly what a deficiency letter cites.
Access outside the book of business
An advisor or ops staffer reaches into client accounts or holdings they have no assignment to — curiosity, a personal connection, or simply because nobody restricted it.
The departing advisor's export
A registered rep resigning to join a competitor exports client lists or account details before they go — one of the most common and costly RIA insider incidents, and one that's visible in the weeks before it happens.
Shared credentials into the CRM or custodian portal
Staff share logins into portfolio management or custodial systems for convenience. When something goes wrong, there's no clean record of who actually acted.
Financial pressure preceding a shortcut
Personal financial stress on staff precedes unauthorized trading, fee manipulation, or misappropriation more often than firms expect — and the pressure is visible before the act.
Firms with fiduciary exposure and a compliance team of one.
Small and mid-size RIAs & wealth management firms
Registered investment advisers with real client assets under management and real exam exposure — but a Chief Compliance Officer wearing three other hats, and no formal process for reading behavioral risk among advisors and staff.
Three ways to work together.
Same arc every time: find the gaps, train the eyes, build the program that holds.
Before the Breach
A half-day session for advisors, ops, and compliance staff — the precursor framework adapted to client access, trading systems, and the behaviors examiners now ask about directly, plus a one-page escalation path your CCO can point to.
Program Readiness & Gap Assessment
2–3 weeks: access review across your CRM and custodial systems, offboarding process, and policy review — benchmarked against the SEC's 2026 exam priorities, with a prioritized roadmap ahead of your next exam cycle.
Program Advisory
Ongoing advisory as headcount and AUM grow — access reviews, refresher training, and exam-readiness prep so your next visit from examiners isn't a surprise.
Curious where your firm actually stands?
A 20-minute call, no pitch. Tell me where you're exposed — I'll tell you honestly whether I can help and where I'd start.
Book a 20-minute call