Scenario: A mid-size investment adviser ($2 billion AUM, 30 employees) receives a deficiency letter from the SEC Division of Examinations following a routine examination. The letter identifies six deficiency findings: (1) custody rule violations — the adviser has inadvertent custody over three client accounts where it serves as trustee, but has not obtained a surprise examination or ensured independent verification under Rule 206(4)-2; (2) advertising compliance — the firm's website includes backtested performance for a model portfolio without required disclosures regarding methodology, assumptions, limitations, or risks, and without net performance alongside gross performance, in violation of Rule 206(4)-1; (3) incomplete books and records — the firm failed to retain business-related text messages exchanged between the portfolio manager and a broker-dealer counterparty, in violation of Rule 204-2; (4) code of ethics — two access persons failed to submit quarterly transaction reports for three consecutive quarters, and the firm had no process to identify or follow up on missing reports, in violation of Rule 204A-1; (5) annual compliance review — the firm's most recent annual review under Rule 206(4)-7 was a two-page summary that did not assess the adequacy of any specific policy or procedure; (6) cybersecurity — the firm had no written incident response plan and had not conducted a risk assessment of its information technology systems. The firm has 30 days to respond.
Compliance Issues:
- Six findings spanning multiple compliance areas suggest systemic compliance program weaknesses rather than isolated lapses.
- The custody rule violation is the most serious finding because it directly affects client asset safety. Failure to comply with Rule 206(4)-2 is an area where the SEC has historically pursued enforcement action.
- The off-channel communications finding (failure to retain text messages) aligns with a major SEC enforcement priority — the Division of Enforcement has brought dozens of actions against firms for recordkeeping failures related to off-channel communications.
- The inadequate annual compliance review finding suggests that the firm's overall compliance oversight is deficient, which undermines the credibility of the firm's compliance program as a whole.
Analysis:
The firm should structure its response as follows. First, engage compliance counsel to assist in drafting the response — given the number and seriousness of the findings, professional guidance is important. Second, address each finding individually in the order presented in the deficiency letter. For each finding, the response should: acknowledge the finding (or explain the basis for disagreement, if applicable); describe the root cause; detail the specific corrective actions already taken; provide a timeline for any remaining remediation; and identify the responsible person.
For finding (1) (custody), the firm should immediately engage an independent public accountant to conduct the required surprise examination under Rule 206(4)-2(a)(4), or alternatively, ensure that the trustee accounts are subject to an annual audit by an independent public accountant with the results distributed to the beneficiaries. The response should confirm the engagement, provide the accountant's name, and state the expected completion date. For finding (2) (advertising), the firm should remove the non-compliant backtested performance from its website immediately and describe the process for revising the content to include net performance, methodology disclosures, risk and limitation disclosures, and audience access controls as required by Rule 206(4)-1. For finding (3) (books and records), the firm should implement an approved communication platform, deploy mobile device management technology to capture text messages, issue a revised communication policy prohibiting business communications through unapproved channels, and train all employees. For finding (4) (code of ethics), the firm should collect the missing quarterly transaction reports retroactively, implement an automated tracking system that flags missing reports and escalates to the CCO, and discipline or counsel the access persons who failed to file. For finding (5) (annual compliance review), the firm should engage an external compliance consultant to conduct a comprehensive annual review covering all required elements under Rule 206(4)-7, with the results documented in a detailed written report presented to management. For finding (6) (cybersecurity), the firm should engage an information security consultant to conduct a risk assessment and develop a written incident response plan, with testing scheduled within 90 days. The firm should prioritize the custody finding and the off-channel communications finding, as these carry the highest enforcement risk, and ensure that corrective actions for these items are completed — not merely planned — before submitting the response.
场景: 一家中等规模投资顾问(管理20亿美元资产,30名员工)在常规审查后收到SEC审查部的缺陷函。函件列出6项缺陷认定:(1) 托管规则违规——顾问在担任三个客户账户受托人时拥有无意托管权,但未按Rule 206(4)-2要求进行突击审查或确保独立验证;(2) 广告合规——公司网站包含模型投资组合的回测业绩,但未按Rule 206(4)-1要求披露方法、假设、限制或风险,且未同时展示净业绩和总业绩;(3) 账簿与记录不完整——公司未保留投资组合经理与经纪交易商对手方之间的业务相关短信,违反Rule 204-2;(4) 道德准则——两名访问人员连续三个季度未提交季度交易报告,公司无流程识别或跟进缺失报告,违反Rule 204A-1;(5) 年度合规审查——公司最近一次Rule 206(4)-7项下的年度审查是两页摘要,未评估任何特定政策或流程的充分性;(6) 网络安全——公司无书面事件响应计划,未对信息技术系统进行风险评估。公司需在30天内回复。
合规问题:
- 涵盖多个合规领域的6项认定结果表明存在系统性合规计划薄弱环节,而非孤立失误。
- 托管规则违规是最严重的认定结果,因为它直接影响客户资产安全。未遵守Rule 206(4)-2是SEC历来采取执法行动的领域。
- 非官方渠道通信认定结果(未保留短信)与SEC主要执法重点一致——执法部已对数十家公司提起非官方渠道通信记录保存失败的执法行动。
- 年度合规审查不足的认定结果表明公司整体合规监督存在缺陷,这削弱了公司合规计划的整体可信度。
分析:
公司应按以下方式构建回复。首先,聘请合规律师协助起草回复——鉴于认定结果的数量和严重性,专业指导很重要。其次,按缺陷函中列出的顺序逐一回应每个认定结果。对于每个认定结果,回复应:确认认定结果(如适用,解释不同意的依据);描述根本原因;详细说明已采取的具体纠正措施;提供未完成整改的时间线;确定负责人。
对于认定结果(1)(托管),公司应立即聘请独立注册会计师按Rule 206(4)-2(a)(4)要求进行突击审查,或确保信托账户接受独立注册会计师的年度审计,审计结果分发给受益人。回复应确认委托事项,提供会计师姓名,并说明预计完成日期。对于认定结果(2)(广告),公司应立即从网站上移除不合规的回测业绩,并描述修订内容的流程,包括按Rule 206(4)-1要求添加净业绩、方法披露、风险和限制披露,以及受众访问控制。对于认定结果(3)(账簿与记录),公司应实施批准的通信平台,部署移动设备管理技术以捕获短信,发布修订后的通信政策,禁止通过未批准渠道进行业务通信,并对所有员工进行培训。对于认定结果(4)(道德准则),公司应追溯收集缺失的季度交易报告,实施自动跟踪系统,标记缺失报告并上报给CCO,并对未提交报告的访问人员进行纪律处分或指导。对于认定结果(5)(年度合规审查),公司应聘请外部合规顾问进行全面年度审查,涵盖Rule 206(4)-7要求的所有要素,结果记录在详细的书面报告中并提交给管理层。对于认定结果(6)(网络安全),公司应聘请信息安全顾问进行风险评估并制定书面事件响应计划,计划在90天内完成测试。公司应优先处理托管认定结果和非官方渠道通信认定结果,因为这些具有最高执法风险,并确保在提交回复前完成(而非仅计划)这些事项的纠正措施。