Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program

In plain language

Rule 206(4)-7 does not mention firewalls, encryption, or passwords. It says a registered adviser must have written policies and procedures reasonably designed to prevent violations, review them at least annually, and designate someone to run them. Cybersecurity enters through that door: if a technology failure could cause you to breach the Advisers Act or your duty to clients, then controlling it is part of your compliance program, and the annual review has to actually look at it.

What Rule 206(4)-7 says

17 CFR 275.206(4)-7 — the compliance rule — makes it unlawful for an SEC-registered investment adviser to provide advice unless it has done three things:

  1. Adopted and implemented written policies and procedures reasonably designed to prevent violation of the Advisers Act and the rules under it.
  2. Reviewed the adequacy of those policies and procedures, and the effectiveness of their implementation, at least annually.
  3. Designated a chief compliance officer responsible for administering them.

Each of those three words carries weight in an examination. Implemented distinguishes a program from a binder. Effectiveness of their implementation is why a review that only re-reads the policy does not satisfy the rule. And designated means a specific person, not a committee that meets when something goes wrong.

Why cybersecurity is inside this rule

Rule 206(4)-7 never uses the word cybersecurity. It gets there by consequence. Consider what a technology failure can cause:

  • Loss of required records is a books-and-records violation. See books and records.
  • Exposure of client information is a Regulation S-P matter, and for an adviser it lands back here as well. See Regulation S-P.
  • An extended outage can prevent the adviser from meeting obligations to clients.
  • A compromised email account used to redirect a wire implicates the adviser’s fiduciary duty directly.

Because each of those is a potential Advisers Act violation, controls that prevent them are inside the program the rule requires. The SEC staff made the connection explicit in its IM Guidance Update 2015-02 on cybersecurity, which describes assessing the firm’s information and systems, creating a strategy to address the risks, and implementing the strategy through written policies and training.

The annual review, as examiners read it

This is the single highest-yield thing to get right, because it is where a program that exists on paper separates from one that operates.

A review needs a reasonable basis

A review with a reasonable basis has looked at output, not just intent. The question is not “does the policy say we do access reviews” but “what did the last access review find, and what happened to the accounts it flagged.” A short memo that names four tests and their results is stronger than a thirty-page restatement of the policy.

Practically, the review should be able to answer:

  • What was examined this year, and what was deliberately not?
  • What did each test show?
  • What was remediated, and what was accepted as an open risk, with whose sign-off?
  • What changed in the firm — new systems, new people, new vendors — and did the policies follow?

It has to be findable a year later

The review is also a record. Advisers Act Rule 204-2(a)(17) requires advisers to keep copies of the compliance policies and procedures in effect, along with records documenting the annual review. A review that lives in a personal folder is a record-keeping problem in addition to a compliance one.

Once a year is a floor, not a rhythm

The rule says at least annually. Firms that only look once a year tend to find twelve months of drift at once. The workable pattern is a light quarterly touch on the things that change — access, vendors, exceptions — feeding an annual conclusion that has something to conclude from.

What the CCO needs from technology

The designation in the rule creates an information problem: the CCO is accountable for controls they usually do not administer. The fix is to make reporting arrive on a schedule rather than on request.

A workable minimum, delivered quarterly:

  • Accounts added, removed, and privileged, with exceptions
  • Security incidents and near-misses, including ones that were contained without impact
  • Patch and endpoint protection status, with the machines that are out of policy
  • Backup and restore test results, including failures
  • Vendor changes — new providers, expanded access, terminations
  • Open control exceptions and their age

If those six arrive every quarter, the annual review is largely assembled before it starts.

Common findings

  • The policies describe a firm that no longer exists — an on-premises server room, a vendor that was replaced two years ago, a headcount that has doubled.
  • The annual review has no date or author.
  • The CCO has no independent access to technology evidence and must request everything from the provider, which means the provider is effectively reviewing itself.
  • Exceptions are remembered rather than recorded, so nobody can say how long the one unenrolled MFA account has been unenrolled.

Regulation S-P for the substantive safeguards, vendor oversight for the service-provider half of the program, incident response and exam evidence for what the review is expected to produce, and monitor and review for the aggregated checklist.

Pylon’s delivery view of this work is on SEC & FINRA compliance and RIA cybersecurity.

Primary sources

Frequently Asked Questions

Does Rule 206(4)-7 require a cybersecurity policy?

Not by name. The rule requires written policies and procedures reasonably designed to prevent violation of the Advisers Act and its rules. Because a technology failure can cause such a violation — losing required records, exposing client information, or being unable to serve clients — cybersecurity controls are within the scope of the program that the rule requires you to have and review.

What makes an annual review defensible?

Evidence that someone tested something. A review that restates the policy is a reading, not a review. A defensible one names what was examined, what was found, what was changed, and what was accepted as an open risk with a reason — and it can point to artifacts such as access review output, restore test results, and training completion records.

Who has to perform the annual review?

The rule does not require an outside party. It requires the review to happen at least annually and it requires a designated chief compliance officer responsible for administering the policies and procedures. Firms commonly split the work: the CCO owns the conclusion, and technology staff or an outside provider produce the underlying test results.

How does this rule interact with Regulation S-P?

Regulation S-P states the substantive safeguards and notification obligations. Rule 206(4)-7 is the rule that requires an adviser to have written policies and to review them. An S-P shortfall at an adviser therefore tends to produce two findings rather than one.

Scheduled actions

The recurring work this section implies. Each action carries a stable action-id so it can be tracked in a compliance calendar and rolled up on all scheduled actions.

Complete the annual review of the compliance program's technology components and record what was tested, what was found, and what was changed.

Cadence:
Annually
Owner archetype:
CCO
action-id:
act.advisers-act.annual-compliance-review

Refresh the technology risk assessment that the policies are designed against, so the program reflects the systems the firm uses now rather than the ones it used at adoption.

Cadence:
Annually
Owner archetype:
CCO, MSP
action-id:
act.advisers-act.risk-assessment-refresh

Record every material change to a technology policy or procedure with its date, reason, and approver, so the program's version history is reconstructable.

Cadence:
On change
Owner archetype:
CCO
action-id:
act.advisers-act.policy-change-log

Deliver security awareness training covering phishing, wire-transfer verification, and reporting, and retain the completion records by person.

Cadence:
Annually
Owner archetype:
CCO, MSP
action-id:
act.advisers-act.security-awareness-training

Read the Division of Examinations priorities when published and note which technology items apply to the firm, and which of those the program does not yet address.

Cadence:
Annually
Owner archetype:
CCO
action-id:
act.advisers-act.exam-priorities-read

Confirm the CCO receives technology incident and exception reporting on a defined interval, rather than on request, and that the last interval's report exists.

Cadence:
Quarterly
Owner archetype:
CCO, MSP
action-id:
act.advisers-act.cco-escalation-review

Configuration touchpoints

Where this section lands in a real environment. Each touchpoint is stated as a plain configuration rule — not a vendor setting — and carries a stable config-id.

Configuration ruleApplies toconfig-id
One current version of each technology policy is the version of record, stored where the CCO controls it, with superseded versions retained rather than overwritten.Document management / compliance repositorycfg.advisers-act.policy-of-record
The artifacts the annual review depends on — access reviews, restore tests, training records, patch status — are produced on a schedule and stored somewhere the CCO can retrieve them without asking IT.Reporting and evidence storecfg.advisers-act.review-evidence-collection
Accepted technology risks and control exceptions are recorded with an owner, a reason, and a review date, instead of existing only as an understanding.Risk / exception registercfg.advisers-act.exception-register
Security incidents and control failures generate a report that reaches the CCO on a defined interval without a person remembering to send it.Monitoring platform, ticketingcfg.advisers-act.incident-reporting-to-cco

More in the Compliance Library

Rollups: all scheduled actions and monitor and review.

Author
Rachel Lannon and Byron Foley
Reviewed by
Tim Quinn
Last updated

This is operational technology guidance for regulated firms, not legal advice. Confirm how each requirement applies to your firm with your compliance counsel.