Every November, the SEC’s Division of Examinations publishes a list that compliance officers read the way pilots read a weather report: not because it tells them everything that’s coming, but because ignoring it is how you end up grounded. The Fiscal Year 2026 Examination Priorities, released on November 17, 2025, cover the period running through September 30, 2026, and they read less like a routine refresh than a recalibration. Some perennial concerns — fiduciary duty, cybersecurity, custody — are back with sharper teeth. A few high-profile 2025 fixtures, notably crypto assets as a standalone category, have quietly disappeared. And a new theme runs through nearly every section: examiners no longer just want to know what a firm says it does. They want proof it actually does it.
For registered investment advisers, broker-dealers, and fund managers, that shift matters more than any single line item. Below is a breakdown of where examiners are actually looking in 2026, and what firms should be doing about it before an exam letter shows up.
Fiduciary Duty Is Still the Headline Act
Fiduciary obligations have topped this list for years, and 2026 is no exception. What’s changed is the level of specificity. Examiners are drilling into conflicts of interest tied to compensation arrangements, revenue sharing, and affiliated products, then checking whether disclosures actually match practice. Best execution reviews are getting more granular too, with examiners comparing trade execution quality against what a firm’s Form ADV and client agreements promise.
The other piece examiners keep circling back to: whether recommended investments actually fit the client’s stated objectives, liquidity needs, and risk tolerance — not at account opening, but on an ongoing basis as circumstances change. A model portfolio that made sense for a client five years ago isn’t automatically still appropriate, and examiners are asking firms to show their work on that point.
Compliance Program Effectiveness, Not Just Existence

Having a written compliance manual has never been enough, but the gap between “having a policy” and “having a policy that functions” is where the 2026 priorities focus most of their attention. The Division specifically flags marketing practices, valuation methodologies, portfolio management processes, disclosure accuracy, custody arrangements, and the annual compliance review itself.
Marketing Rule compliance in particular remains an active enforcement area — examiners are still finding advisers using performance claims, testimonials, or third-party ratings that don’t hold up against the rule’s substantiation requirements. Valuation is getting closer scrutiny for firms holding hard-to-price assets, where a stale or optimistic mark can quietly distort performance reporting for months before anyone notices.
The practical takeaway is that a compliance program built to satisfy a checklist won’t hold up well against an examiner asking “show me the testing” or “walk me through what happened the last time this control caught something.” Firms that document not just their policies but the evidence that those policies get followed are in a materially better position.
AI Claims Are Getting a Reality Check
This is the most notable new emphasis in the 2026 priorities. The SEC isn’t examining artificial intelligence as a technology in the abstract — it’s examining the gap between what firms say about their AI use and what’s actually happening inside the business. If a firm’s marketing materials describe AI-driven portfolio construction or AI-assisted research, examiners want to see that the tool genuinely influences decisions, not that it produces a report nobody reads before the human portfolio manager does what they were always going to do anyway.
This concern, sometimes called “AI washing,” mirrors enforcement actions the SEC has already brought against advisers for overstating AI capabilities in client communications. Firms should expect examiners to ask for the underlying model documentation, testing records, and a clear account of who supervises the tool’s outputs — governance questions that many compliance programs haven’t caught up to yet.
Cybersecurity, Regulation S-P, and Data Protection

Cybersecurity has been a fixture of exam priorities for close to a decade, but 2026 sharpens the focus around two specific rules: the amended Regulation S-P and Regulation S-ID. Reg S-P’s updated requirements — covering incident response programs, customer notification obligations after a breach, and oversight of third-party service providers who handle client data — are now something examiners will test directly rather than take on faith.
Expect exam requests around governance and risk-assessment processes, access controls and data-loss prevention, incident response and recovery planning, and staff training on emerging threats, including AI-enabled phishing and social engineering attacks. Firms that outsource IT or custody functions should also expect questions about how they vet and monitor those vendors, since a third party’s weak controls become the adviser’s problem the moment client data is exposed.
Never-Examined and Newly Registered Advisers Are a Priority Target
The Division is explicit that it will prioritize advisers that have never been through an exam, with particular emphasis on firms that registered recently. The logic is straightforward: a firm’s compliance program is most likely to have gaps in its first few years, before controls have been tested against real situations. If your firm has grown quickly, added new strategies, or registered with the SEC in the past two to three years and hasn’t yet had a first exam, it’s reasonable to assume one is more likely, not less.
This is also where many firms first discover how much distance exists between a compliance manual purchased off the shelf and one that actually reflects how the business operates day to day. Bringing in outside RIA compliance consultants before that first exam — rather than after a deficiency letter arrives — tends to be the difference between a routine visit and a drawn-out remediation process.
Private Funds: Narrower, But Still Watched
Private funds got noticeably less standalone attention in the 2026 priorities compared with prior years — there’s no dedicated section devoted exclusively to private fund advisers this time. That doesn’t mean the topic disappeared. Examiners will still focus on advisers managing both private funds and separately managed accounts side by side, firms that have recently launched new funds, and advisers with no prior history of managing private capital. Conflicts around fee calculations, expense allocation, and side letters remain fair game even without a dedicated section calling them out by name.
Broker-Dealers: Capital, Liquidity, and Customer Protection
For broker-dealers, the 2026 priorities keep the focus on fundamentals: compliance with the net capital rule and the customer protection rule, along with the internal controls supporting both. Examiners are also looking harder at credit, market, and liquidity risk management — specifically, whether a firm’s stress-testing and contingency planning would hold up during an actual market disruption rather than just on paper. Firms handling customer securities lending, margin, or clearing arrangements should expect detailed questions about how those risk controls behave under stress, not just how they’re described in a policy manual.
How Firms Can Prepare Before the Letter Arrives

A few practical steps make the biggest difference between an exam that goes smoothly and one that turns into a months-long back-and-forth:
- Test your compliance program, don’t just document it. Run a mock walkthrough of your annual review, marketing review, and trade allocation process, and keep records showing the test happened and what it found.
- Audit every AI-related claim in your marketing and disclosures. If a pitch deck or ADV brochure mentions AI, be able to show exactly how it’s used, who oversees it, and what happens when it’s wrong.
- Confirm your Reg S-P incident response plan is current and rehearsed. A written plan nobody has practiced is a common finding examiners flag.
- Revisit vendor oversight. Know which third parties touch client data and confirm you have current due diligence on file for each.
- If you’ve never been examined, act now rather than later. Gap analyses, mock exams, and outside reviews are far cheaper before an exam notice than after one.
Firms without in-house compliance depth often find it worthwhile to bring in specialists rather than stretch an already-thin team across every one of these areas at once. A focused outside review, timed months ahead of an anticipated exam rather than during one, tends to surface the kind of gaps that examiners are specifically trained to find.
Frequently Asked Questions
When exactly do the 2026 priorities apply?
They cover the SEC’s fiscal year running from October 1, 2025 through September 30, 2026. Exams already underway may reflect elements of both the 2025 and 2026 priorities, since the Division doesn’t pause ongoing work when a new list is published.
Does the removal of crypto as a standalone priority mean crypto firms are off the hook?
No. The Division still examines digital-asset-related activity where it intersects with existing rules on custody, disclosure, and valuation — it’s simply no longer called out as its own category, partly due to pending federal legislation in that space.
Does a small RIA really need to worry about this list?
Yes, especially the never-examined-adviser emphasis. Size doesn’t exempt a firm from scrutiny, and smaller shops often have thinner compliance staffing, which is exactly the combination examiners are told to prioritize.
What’s the single biggest change from 2025 to 2026?
The AI-washing focus. It’s the clearest example of examiners shifting from “do you have a policy” to “does your practice match what you tell clients and regulators,” and it’s likely to show up in exam requests across nearly every registrant type.
The full text of the priorities is available directly from the SEC’s Division of Examinations, and it’s worth a firm’s compliance team reading in full rather than relying solely on secondary summaries — the specific wording around each priority often signals exactly what documentation examiners will ask for first.








