The first flag is human · Financial advisors & RIAs

Your Form ADV isn't the exam. Your access controls are.

The SEC's 2026 examination priorities are explicit: examiners are moving past whether you have a written policy and into whether anyone actually follows it — with employee access controls named directly. That gap between policy and practice is where deficiencies cluster.

The regulatory backdrop

The exam priorities already told you where they're looking.

The SEC's Division of Examinations publishes its priorities every year. For 2026, cybersecurity and access controls aren't a side note — they're a named focus, alongside a new written-response requirement most firms haven't operationalized yet.

Access controls

are named directly in the SEC's 2026 Examination Priorities, alongside incident detection, response capability, and vendor risk.

SEC Division of Examinations, 2026 Examination Priorities
4 days

is the window under the amended Regulation S-P to report a significant cybersecurity incident, with a written incident response program now required.

SEC Regulation S-P, as amended
21,600+

registered investment advisers were overseen by the SEC as of the most recent published count — a large, closely watched field.

SEC data, reported 2025
What actually goes wrong

Examiners aren't only asking about hackers. They're asking about your own people.

The insider-risk patterns that matter most to an RIA rarely make headlines — but they're exactly what a deficiency letter cites.

Access outside the book of business

An advisor or ops staffer reaches into client accounts or holdings they have no assignment to — curiosity, a personal connection, or simply because nobody restricted it.

The departing advisor's export

A registered rep resigning to join a competitor exports client lists or account details before they go — one of the most common and costly RIA insider incidents, and one that's visible in the weeks before it happens.

Shared credentials into the CRM or custodian portal

Staff share logins into portfolio management or custodial systems for convenience. When something goes wrong, there's no clean record of who actually acted.

Financial pressure preceding a shortcut

Personal financial stress on staff precedes unauthorized trading, fee manipulation, or misappropriation more often than firms expect — and the pressure is visible before the act.

Who this is for

Firms with fiduciary exposure and a compliance team of one.

Financial advisors & RIAs

Small and mid-size RIAs & wealth management firms

Registered investment advisers with real client assets under management and real exam exposure — but a Chief Compliance Officer wearing three other hats, and no formal process for reading behavioral risk among advisors and staff.

Services

Three ways to work together.

Same arc every time: find the gaps, train the eyes, build the program that holds.

Start here 01 · Workshop

Before the Breach

Train the eyes

A half-day session for advisors, ops, and compliance staff — the precursor framework adapted to client access, trading systems, and the behaviors examiners now ask about directly, plus a one-page escalation path your CCO can point to.

From $3,500Founding rate $2,500 for the first cohorts
02 · Assessment

Program Readiness & Gap Assessment

Find the gaps

2–3 weeks: access review across your CRM and custodial systems, offboarding process, and policy review — benchmarked against the SEC's 2026 exam priorities, with a prioritized roadmap ahead of your next exam cycle.

From $5,500Fixed fee · scope set before we start
03 · Retainer

Program Advisory

Build it for real

Ongoing advisory as headcount and AUM grow — access reviews, refresher training, and exam-readiness prep so your next visit from examiners isn't a surprise.

From $3,000/mo6-month minimum
Let's talk

Curious where your firm actually stands?

A 20-minute call, no pitch. Tell me where you're exposed — I'll tell you honestly whether I can help and where I'd start.

Book a 20-minute call