The SEC’s Division of Examinations published its fiscal 2026 priorities on November 17, 2025, addressed to a record audience: 16,544 registered investment advisers running $176.8 trillion for 73.7 million clients. The document doubles as a study guide for what follows.
An RIA risk assessment is where every one of those firms starts answering. Rule 206(4)-7 requires policies reasonably designed to prevent violations plus an annual review of their adequacy, and a documented, scored risk assessment is how examiners expect that review to begin.
| The RIA Risk Assessment Brief |
| The SEC’s FY2026 exam priorities, published November 17, 2025, target fiduciary advice on complex products, older investors, AI use, and core marketing, valuation, and custody programs. |
| A record 16,544 SEC-registered advisers manage $176.8 trillion for 73.7 million clients, and Rule 206(4)-7 obliges each one to an annual, documented compliance review. |
| Reg S-P’s amendments reached every adviser on June 3, 2026: a written incident response program plus 30-day customer notification. |
| The IA AML rule moved to January 1, 2028, by a FinCEN final rule effective January 1, 2026; keep the row, resize the schedule. |
| Inventory risks by function, score against appetite, and spend forensic testing on the top decile; document all of it for a reader you have not met. |
| Different RIA: robotics readers want R15.06-2025 and our robot risk assessment guide. |
One housekeeping note before the method. RIA also abbreviates the former Robotic Industries Association, whose robot safety standard now lives at A3 as R15.06-2025; readers hunting that topic want our robot risk assessment guide, and everyone else should keep reading.
What an RIA Risk Assessment Covers
The assessment inventories every way the firm could breach its fiduciary duty, its rules, or its clients’ trust, then scores and ranks the list. Conflicts of interest sit at the center, because disclosure obligations flow from them and exam findings keep proving it.
The Adviser Population Behind Every RIA Risk Assessment

Figure 1. The examined population, at record size. Sources: IAA/COMPLY Snapshot 2026; SEC.
Scale cuts both ways in this industry. Most of the 16,544 firms are small, the SEC’s own adviser statistics show the median firm runs lean, and a lean firm cannot test everything, which is precisely the argument for scoring before testing. Testing everything is how nothing gets tested well.
The method itself is transferable. Our guide to conducting a compliance risk assessment carries the generic loop, the compliance risk assessment template holds the format, and this article supplies the adviser-specific inventory, calendar, and exam mapping the generic loop lacks.
The Rules That Shape an RIA Risk Assessment in 2026
Four dates set this year’s assessment apart from last year’s. Reg S-P’s amended safeguards reached every adviser on June 3, 2026, the FY2026 priorities landed November 17, the AML rule’s delay took effect January 1, and its new compliance date, January 1, 2028, is already a project plan.
Deadlines on the RIA Risk Assessment Calendar

Figure 2. Two rules in force, one repriced to 2028. Sources: SEC; FinCEN.
| Rule | Status in 2026 | What the assessment must cover |
| Rule 206(4)-7, compliance | In force since 2004; annual review required | The whole program, reviewed and documented yearly |
| Marketing rule, 206(4)-1 | In force; a standing exam priority | Performance claims, testimonials, substantiation |
| Reg S-P, as amended 2024 | Fully in force June 3, 2026 | Incident response program, customer notice in 30 days |
| Reg S-ID | In force | Identity theft red flags program |
| IA AML rule | Delayed; effective January 1, 2028 | Program build now, obligations later |
| Form ADV | Annual amendment | Disclosure accuracy against actual practice |
The Reg S-P amendments carry the sharpest new teeth. Every adviser now needs a written incident response program and a 30-day clock to notify affected customers, and the eCFR text of Part 248 puts both duties in black and white.
State-registered advisers read a parallel rulebook through NASAA, and the marketing rule applies to nearly every promotional sentence a firm publishes. Score marketing risk with the substantiation file open, because that is how the examiner will read it, side by side.
Building the RIA Risk Assessment: A Risk Inventory by Function
Inventory beats intuition, and functions beat org charts. Walk the firm by what it does, advice, trading, marketing, custody arrangements, technology, vendors, people, and list what could go wrong in each, in the firm’s own vocabulary rather than a template’s.
| Function | Example risks to score | Exam angle |
| Investment advice | Suitability drift, concentration, complex products | Fiduciary duty, the FY2026 headline priority |
| Trading and portfolio | Best execution, allocation fairness, errors | Side-by-side account favoritism |
| Marketing | Unsubstantiated performance, testimonials | Marketing rule sweeps continue |
| Custody and assets | Surprise exam triggers, fee withdrawals | Custody rule technicalities |
| Technology and data | Breach response, vendor access, AI tools | Reg S-P incident program, AI governance |
| People and culture | Off-channel comms, outside activities | Recordkeeping enforcement history |
Vendors and models need their own lines. A portfolio optimizer is a model with model risk, the SR 11-7 discipline banks use translates almost verbatim, and SOC 2 reports from custodians and software vendors feed the technology rows without new fieldwork.
New York adds its own layer for advisers under NYDFS jurisdiction, and the NIST Cybersecurity Framework gives the technology rows a common grammar. Our NYDFS 23 NYCRR 500 guide and NIST CSF risk assessment walkthrough carry both in working detail.
Scoring and Testing Inside the RIA Risk Assessment
Scores exist to ration testing hours. Rate each inventory line for likelihood and impact against the firm’s risk appetite, and let the top decile absorb the forensic testing, email samples, trade allocation reruns, fee recalculations, while lower scores get attestation and rotation.
Five Moves Inside the RIA Risk Assessment

Figure 3. The assessment drives the testing; the testing feeds the 206(4)-7 file.
| Score band | Testing depth | Evidence filed |
| Top decile | Forensic tests: recalculate, resample, reperform | Test workpapers with data pulls |
| High | Targeted transaction testing each quarter | Sampled results and exceptions |
| Moderate | Annual walkthrough plus attestations | Signed attestations, walkthrough notes |
| Lower | Rotational review every two to three years | Rotation schedule and completions |
| Any exam finding | Immediate retest regardless of score | Remediation memo and retest proof |
Blend the scales the way the wider profession does. Qualitative bands work for most lines, quantitative estimates fit fee and trading errors where dollars are countable, and our qualitative and quantitative guide plus the ERM framework place the assessment inside the firm’s larger risk picture.
Write the file for the examiner who has not met you. Scores, rationales, testing results, and changes since last year, all dated; our guidance on how often risk assessments should be conducted turns the refresh into policy instead of memory.
Reading the 2026 Exam Priorities as an RIA Risk Assessment Checklist
The Division of Examinations tells firms where it will look; the assessment should look there first. The FY2026 document names fiduciary treatment of complex and higher-cost products, older and retirement-focused investors, AI usage, and the core marketing, valuation, custody, and disclosure programs.
FY2026 Priorities Mapped for the RIA Risk Assessment

Figure 4. Where the SEC says it will look. Source: Division of Examinations, November 17, 2025.
| FY2026 priority | Assessment question to add | Quick test |
| Complex and alternative products | Which clients hold them, and does the file show why | Sample five accounts against objectives |
| Older and retirement investors | Are recommendations senior-suitable and documented | Pull accounts over age 70 for review |
| AI and emerging technology | What models touch client accounts, who validated them | Inventory every AI-assisted workflow |
| Marketing and performance | Can every claim be substantiated on request | Trace three ads back to source data |
| Custody | Do any arrangements trip the custody rule | Re-answer the ADV custody items cold |
| Disclosure accuracy | Does ADV match practice today, at filing | Read Part 2A against current operations |
The sanctions and AML file rides along even with the 2028 date. Screening customers is already a contractual and reputational expectation, our sanctions risk assessment questionnaire guide covers the mechanics, and firms building AML programs now get two years of dry runs at exam pace.
Banking practice offers borrowable tooling here too. The RCSA template banks maintain adapts cleanly to advisory functions, operational risk categories from Basel translate, and compliance KRIs keep the register moving between annual reviews, with the legal and compliance KRI set as the starter list.
RIA Risk Assessment FAQs for Compliance Officers
What is an RIA risk assessment?
A documented inventory of the compliance, fiduciary, and operational risks a registered investment adviser faces, scored for likelihood and impact, mapped to policies, and tested where scores run highest. It anchors the Rule 206(4)-7 annual review and steers exam preparation.
Is an RIA risk assessment required by the SEC?
Not in those exact words. Rule 206(4)-7 requires policies reasonably designed for your business and an annual adequacy review, and examiners read a missing risk assessment as a program built on guesswork; the deficiency letters say so with tiresome regularity.
How often should an RIA risk assessment be updated?
Annually at minimum, aligned to the 206(4)-7 review, and on every trigger that lands in between: new products, new marketing channels, an acquisition, a breach, or a rule change like Reg S-P’s June 2026 date. Static assessments age into exam findings.
What should a small RIA risk assessment cover first?
Marketing, fees, and disclosure accuracy, because those three carry most small-firm deficiencies. A two-person shop can inventory its risks in an afternoon using the definition of financial risk assessment as a primer and the compliance template as the container for the output.
Does the delayed AML rule change the RIA risk assessment for 2026?
The obligation moved to January 1, 2028; the risk did not. Keep an AML and sanctions row in the assessment now, size the program work across 2026 and 2027, and treat FinCEN’s delay notice as schedule relief rather than a cancellation.
Is this the same as the robotics RIA risk assessment?
Different acronym owner entirely. The Robotic Industries Association wrote robot safety standards before merging into A3 in 2021, and that discipline now runs under R15.06-2025; our robot risk assessment guide covers it, while this page serves investment advisers and their CCOs.
Where Examiners Poke the RIA Risk Assessment First
Deficiency letters repeat a short list of assessment failures year after year. Each row below shows up in enforcement and exam feedback often enough to plan against, and managing compliance risks well means retiring them before the exam letter arrives.
| Failure | How it reads to an examiner | Fix |
| Off-the-shelf assessment, unedited | The firm has not thought about itself | Rewrite the inventory in firm-specific terms |
| No link from risks to testing | Scores decorate while testing wanders | Let the top decile drive the test plan |
| ADV and assessment disagree | Disclosure or assessment is wrong | Reconcile both against actual practice annually |
| Conflicts listed, never scored | The center of the fiduciary duty went unranked | Score every conflict like any other risk |
| Cyber outsourced and forgotten | Reg S-P duties cannot be delegated away | Own the incident response program in-house |
| Last year’s file, redated | The annual review never happened | A date-stamped changes section every year |
What’s Coming Next: 2026-2028 for the RIA Risk Assessment
The AML build is the standing project. January 1, 2028 arrives faster than a program gets built, FinCEN has signaled further tailoring during the delay, and firms that draft the risk-based program in 2026 will absorb whatever changes emerge as edits, and the late starters as emergencies. Two years is exactly enough time to do it calmly once.
AI is the exam question with no settled answer yet. The FY2026 priorities put adviser AI use on the desk, disclosure and validation expectations are forming exam by exam, and an assessment row that inventories every model touching client money is the low-drama way to be early.
Recordkeeping enforcement shows no sign of retiring. The off-channel communications sweeps that produced hundreds of millions in penalties, including a $390 million day across 26 firms in August 2024, keep expanding down-market, and text-message risk belongs in every people row.
Advisers manage other people’s futures; regulators price the trust accordingly. A register that names the firm’s actual risks, scores them honestly, and shows the testing behind each number is how 16,544 firms stay boring to the SEC, and boring is the goal.
Get the RIA Risk Assessment Exam-Ready With Risk Publishing
Compliance calendars fill; assessments slip. Risk Publishing builds and refreshes RIA risk assessments mapped to the FY2026 priorities, complete with the scored inventory and testing plan an examiner expects to see; the services page carries specifics, and the contact form is the shortest path to a scoping call.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.