The compliance rule for advisers requires more than having policies; it requires checking that they work. At least once a year, a firm must review the adequacy and effectiveness of its compliance program, and this annual review is where a program proves it is alive rather than filed.
A meaningful annual review looks back at the year: the compliance issues that arose, the changes in the business and the rules, and whether the written policies actually matched practice. It tests the program against the firm's real risks and conflicts, identifies gaps, and produces recommendations and fixes. It is a genuine assessment, not a certification that everything is fine.
The temptation is to reduce the review to a memo that says the program was reviewed and found adequate. Examiners look for evidence of real testing, samples pulled, controls checked, gaps found and remediated, because a review that never finds anything is usually a review that never really looked. A program with zero findings year after year is itself a yellow flag.
The chief compliance officer typically owns the review, and its output should feed back into updated policies and the compliance calendar. The review is the mechanism by which a program improves rather than ossifies.
A program that is never tested is a program that never works.
Greenridge L&C Advisors is a compliance consultancy, not a law firm. This is general information, not legal advice.