Preparing your operations for an SEC examination

Most exam pain is not a compliance failure. It is an operational one: the record exists somewhere, and nobody can produce it quickly.

The document request list arrives and the firm spends three weeks assembling things it already has. That is the common experience, and it is worth being precise about what is actually going wrong, because it is usually not what people assume.

In most cases the firm is compliant. The policies exist, the reviews happened, the disclosures went out. What is missing is the ability to demonstrate it without a manual reconstruction.

The difference between having a record and producing one

A record that lives in somebody’s email, or in a file named by whoever saved it, or in a note that describes what was decided but not when or by whom, is a record you have. It is not a record you can produce on request in the form somebody asked for it.

The gap between those two states is entirely operational. It is naming conventions, retention applied consistently, an audit trail that shows what changed and who changed it, and a filing structure that somebody who did not file the document can search.

When compliance asks how something happened, the question is whether the system holds the trail or whether somebody has to rebuild it from email.

What to fix before you are asked

  • One naming convention and one filing structure, with retention applied, so a document can be found by search rather than by memory
  • An activity trail on the processes that touch client records, showing what changed, when, and who did it
  • Named access rather than shared logins, with a register that says who has what
  • Written procedures for the processes an examiner asks about, which are usually onboarding, money movement, and annual reviews

None of that is a compliance project. It is document architecture and workflow design, which is why it usually falls between the compliance consultant, who is not configuring your systems, and the software vendors, who are not responsible for how you use theirs. It is most of what a build covers.

You are the registrant

Whatever a vendor or an outside firm does for you, the recordkeeping obligation is yours, and everything built for your firm should sit inside your accounts and inside your examination record. That is the reason our own arrangement is structured the way it is: no environment of ours carries your data, access is named and revocable by you, and every configuration change is logged in a form your compliance people can read.

It is worth asking any operations vendor the same question, and asking it before you grant a login rather than during an exam.

Also here

What a buyer is actually pricing when they look at your firm

Two advisory firms with the same revenue can be worth different amounts. The difference is how much of the business leaves when the owner does.

Using the fourth quarter to fix what slowed you down this year

Q4 is the only stretch where an advisory firm has both the visibility and the slack to change how it operates. Here is what fits in it.