A year-end compliance calendar with organized review milestones
    Back to Insights
    Compliance Program

    The Q4 2026 Compliance Checklist for RIAs

    October 7, 2026
    •
    7 min read
    •
    Joao Chagas

    You know the moment. You open the compliance calendar in early October, scan the next 90 days, and realize how many items still depend on someone else sending you a report, answering a question, or signing an attestation.

    None of the work is surprising. That is what makes the fourth quarter difficult. Quarterly reviews are closing while annual testing is still underway, renewal deadlines are approaching, and the people you need will soon be harder to reach. A good Q4 plan is less about adding tasks and more about deciding what needs attention now, what can be scheduled, and what evidence must exist when the work is done.

    Here is how I would work through the quarter.

    1. Close Out Q3 by October 30

    Start with the items tied to the quarter that just ended. Most should be completed by October 30. They are familiar tasks, but they often arrive at the same time and depend on records collected from several people.

    • Q3 financial statements and attestations: Review the statements, obtain any required attestations, and reconcile custody items. This is one of those areas where a small unresolved difference can consume far more time in December than it would in October.
    • Code of Ethics quarterly transaction reports. Access persons' reports are due within 30 days of quarter end, which makes October 30 the deadline for Q3. Receipt is only the first step. The review and any follow-up should be documented.
    • Q3 electronic communications review. If your review cycle is quarterly, complete it and record the findings, follow-up, and resolution. A completed search with no record of what was reviewed will not help you later.
    • Complaints review. Review the log if your cycle is quarterly and confirm how each matter was handled. Also ask whether anything came through another channel that never made it into the log.

    Pro tip: If the log is empty, ask the team whether any complaints were received and document the response. "None reported" is a conclusion you can support. A blank spreadsheet is not.

    2. Complete or Schedule by December 31

    Once the Q3 work is closed, turn to the items that need to be completed or firmly scheduled by December 31. I find it more useful to group them by how the work is performed than to treat them as one long checklist.

    The Annual Review

    The annual compliance review under Rule 206(4)-7 anchors the year-end process. This is a great exercise to look back at what happened throughout the year: Where exceptions came up, whether testing identified any recurring issues, and whether the firm’s business changed in ways the compliance program hasn’t fully caught up with yet. It’s also a good opportunity to make sure the policies and procedures actually reflect how the business operates today. Capture the key findings, changes, and any action items in a written report.

    Communications and Marketing

    Finish the remaining electronic communications reviews at the frequency your program sets. Include off-channel communications. This is easy to say and harder to execute if employees have been using new platforms or informal channels that never made it into the surveillance process.

    Then confirm that website and social media captures are complete and retained. While you are there, review the live content. Archiving proves what was published. It does not tell you whether the content still complies with the Marketing Rule.

    For the Marketing Rule review, pay particular attention to performance presentations, testimonials and endorsements, and third-party ratings.

    People and Conduct

    Complete Code of Ethics annual training and collect the annual acknowledgments and holding reports required from access persons. The training itself is usually straightforward. The follow-up is where firms get stuck, especially when one late response holds up the entire file.

    Review gifts, entertainment, and political contributions, with pay-to-play considerations in mind. This is also the right time to complete the best execution and trade error review and document the conclusions, including why any exceptions were resolved appropriately.

    Pro tip: Send a short policy reminder about a month before mid-term elections and again before the holidays. A timely reminder is more useful than pointing someone back to the annual training after a problem occurs.

    Operations, Data, and Vendors

    For Regulation S-P, confirm that the incident response program, customer notification procedures, and service provider oversight are operating as designed. Smaller advisers had to comply by June 3, 2026, so this may be the first year-end review of the amended program. Do not stop at the policy. Check whether the people who would use it understand their roles and whether the vendor provisions are reflected in practice.

    Cybersecurity and business continuity testing should also be completed, with the results documented. If the test revealed a gap, record the owner and the remediation date. A test that identifies an issue but never assigns the follow-up is unfinished work.

    Finally, complete annual due diligence on critical vendors and service providers. This is one of those items that looks simple until questionnaires come back incomplete or a material subcontractor appears for the first time.

    Filings and Fees to Watch

    Keep two operational dates visible. Form 13F for Q3 is due in mid-November, if applicable. For IARD renewal, preliminary statements usually arrive in November, with payment due in mid-December for state notice filings and representative registrations.

    Neither item is complicated when it is handled early. Both become disruptive when the underlying information or funding is addressed at the last minute.

    Pro tip: Do not wait until the payment deadline to fund the E-Bill account. Funds may take up to three business days to appear. Put the funding date on the calendar, not only the due date.

    Evidence Is the Real Deliverable

    You will notice that nearly every item above ends with the same instruction: document it. That is intentional.

    A review may have happened. A CCO may know exactly what was considered and why the conclusion was reasonable. But months later, the file needs to tell that story without relying on memory. The real year-end deliverable is evidence that the program operated as designed, including what was tested, what was found, who followed up, and when the matter was closed.

    This is where the quarter becomes demanding. The tasks are manageable one by one. Producing clean evidence for all of them while the firm continues to operate is what stretches a compliance team.

    For a sense of where examiners tend to find gaps, read SEC Examination Readiness: Where RIAs Fall Short.

    Key Takeaways for RIAs

    Start with the October 30 items. Then assign owners and dates to every remaining review, filing, and remediation item. Give extra attention to Regulation S-P, Marketing Rule reviews, and off-channel communications. Put the IARD funding date and Form 13F deadline on the calendar now.

    Most importantly, leave a file that shows what the firm did. That includes reviews that found nothing. A clean result is still a result, and it should be documented that way.

    Too much to finish before year end?

    NextReg works alongside compliance teams to complete reviews, testing, follow-up, and documentation, so the year closes with a program you can stand behind.

    Schedule a Consultation