2026 RIA Compliance Calendar Deadlines, Checklists, and Practical Tips for Solo and Small Firms
Last Updated: July 20, 2026
If you've ever found yourself wondering, "Wait...when is that filing due again?" you're not alone.
Running an RIA means juggling client work, business operations, and a growing list of regulatory responsibilities. It's easy for compliance tasks to get pushed aside until a deadline is staring you in the face. That's where a well-planned compliance calendar can make all the difference.
Instead of reacting to deadlines, you can build simple, repeatable workflows that keep your firm organized year-round. This guide walks through the key RIA compliance deadlines for 2026, along with practical reminders and best practices that fit the realities of solo and small fee-only firms. Use it as a starting point, adjust timelines to align with your fiscal year-end and state requirements, and bookmark the official resources so they're always within reach.
One important note before we dive in: the Securities and Exchange Commission (SEC) expects registered investment advisers to maintain compliance policies and procedures that are "reasonably designed" to prevent violations and to review those policies at least annually under Advisers Act Rule 206(4)-7. While a 2024 court decision removed the requirement to document that annual review in writing, examiners still expect firms to demonstrate that the review took place. Likewise, Form ADV must be updated annually within 90 days of your fiscal year-end, with prompt updates for any material changes, and Form CRS must be updated within 30 days of material changes and delivered to retail clients within 60 days when required.
Your 2026 RIA Compliance Calendar (Dec 31 fiscal year-end example)
Use this as a template. If your fiscal year-end differs, shift the annual items accordingly.
Remember Compliance Mantra: Document what you do, and do what you document.
| Month | Deadline / Task | What to do | Notes & Links |
|---|---|---|---|
| January | IARD/CRD Final Renewal Statement | Reconcile any outstanding state/FINRA renewal fees. Verify registrations and notice filings. | FINRA Renewal Program |
| By March 31 | Annual Form ADV amendment | Update Parts 1 and 2A; update Part 2B (brochure supplements); and deliver to clients as required. File Part 1 and Part 2A via IARD. Update website brochure links. | Form ADV; due within 90 days of FYE; SEC filers do not submit Part 2B via IARD |
| By April 30 | Brochure delivery or offer | Deliver the updated Part 2 brochure (or an offer to deliver) to all clients. | Within 120 days of FYE (Rule 204-3) |
| Quarterly | Code of Ethics transactions; gifts; complaints; pay-to-play log | Collect access persons' personal trade reports; review gifts/entertainment and client complaints; update political contributions per firm policy. | Rule 204A-1; Rule 206(4)-5 |
| Q2 | Best execution and trading review | Evaluate custodians/brokers, research soft dollars (if any), and trade aggregation/allocation. | Document analysis and conclusions |
| Annually | Annual compliance review (A–Z) | Test each policy area, track issues, and adopt fixes. Report findings to leadership/owners. | Compliance Rule |
| Q3 | Business continuity & vendor risk tests | Run a tabletop exercise. Review critical vendors and data backups. Update contact trees. | See Reg S-P updates below |
| Rolling | Marketing Rule reviews | Supervise advertisements in accordance with your written policies; maintain substantiation, disclosures, and performance backup. | SEC Marketing Rule |
| Rolling | Form CRS updates | Update within 30 days of material changes; deliver to clients within 60 days; post the current version to your website. | Form CRS |
| By Dec 31 | IAR Continuing Education | Complete the required CE in states that have adopted NASAA's Model Rule. | NASAA IAR CE |
| November–December | Preliminary IARD Renewal Statement | Review your renewal roster and pay by the due date to avoid a lapse. | FINRA Renewal Program |
Recurring Tasks to Work Into Your Rhythm
Most compliance responsibilities don't revolve around a single filing deadline. They're the ongoing habits that help keep your firm running smoothly throughout the year. By building these tasks into your regular workflow, you'll spend less time reacting to surprises and more time confidently serving your clients.
Here's a practical cadence to help you stay ahead.
Quarterly
- Personal trading: Collect and review access persons' quarterly transaction reports (Rule 204A-1)
- Client complaints: Document, investigate, and resolve complaints while noting root causes and any process improvements
- Pay-to-play: Track political contributions and confirm applicable lookback periods (Rule 206(4)-5)
- Email and communications: Conduct periodic spot checks to confirm required disclosures, recordkeeping, and supervisory procedures are being followed
Semiannual
- Privacy and cybersecurity: Test user access controls, review data protection measures, and update your incident response plan as needed
- Vendor due diligence: Review service providers, including available SOC reports, service level agreements (SLAs), and termination provisions for critical vendors
Annual
- Annual compliance review: Evaluate your compliance program from end to end and maintain evidence that the review was completed (Rule 206(4)-7)
- Code of Ethics: Collect annual holdings reports and acknowledgments from access persons (Rule 204A-1)
- Best execution: Review brokerage and custodian relationships to confirm clients continue to receive quality execution at reasonable costs
- Privacy notice: Deliver annual privacy notices unless your firm qualifies for the annual notice exception under the Gramm-Leach-Bliley Act (GLBA) and Regulation S-P
Marketing Rule Essentials: A Quick "Don't Forget This" Checklist
Marketing your firm is an important part of growing your business. Before you hit publish, though, take a minute to make sure your content checks a few important compliance boxes. A quick review now can save you from headaches later.
Before publishing your next website update, blog, email, social post, video, or other marketing piece, ask yourself:
- Can I back this up? Every material statement of fact should be supported by documentation. Keep that evidence on file in case you're ever asked to substantiate your claims.
- Are testimonials and endorsements properly disclosed? If you're featuring a client or third party, disclose whether they're a client, whether they were compensated, and any material conflicts of interest.
- Am I presenting performance correctly? If you include gross performance, you must also show net performance. Document your methodology, and only use hypothetical performance when appropriate policies, criteria, and audience restrictions are in place.
- Did I follow my firm's review process? Your written advertising policies aren't just for regulators. Follow your firm's review procedures before publishing, and retain final versions along with any supporting documentation to satisfy books-and-records requirements.
A good rule of thumb? If you're unsure whether a piece of marketing raises a compliance question, it's worth pausing and reviewing it before it goes live. Spending a few extra minutes upfront is much easier than correcting an issue after publication.
Cyber, privacy, and vendor risk: what changed for 2026
The SEC adopted amendments to Regulation S-P in 2024 that require RIAs to maintain written incident response programs and to notify affected individuals of certain data breaches "as soon as practicable, but no later than 30 days" after becoming aware of unauthorized access or use of sensitive customer information. Compliance dates begin in late 2025/2026, depending on firm size.
-
Build a contact tree and a duty roster for incidents.
-
Inventory where client data lives (custodian portals, planning software, email, file storage).
-
Update vendor agreements to cover breach notice, cooperation, and timelines.
The SEC's Division of Examinations continues to prioritize safeguarding client information, third-party risk, and marketing practices. Expect requests in these areas during the SEC Exam (SEC Exam Priorities).
State Rules to Watch: IAR CE & Custody Nuances
Many states have adopted or are adopting NASAA's IAR Continuing Education, typically 12 credits per year (6 in Products & Practices, 6 in Ethics & Professional Responsibility). Confirm your state's status and complete CE by December 31 (NASAA IAR CE).
Custody treatment varies by state. Under the SEC's Custody Rule, the authority to directly deduct advisory fees from client accounts is considered "custody," but advisers that have custody solely due to fee deduction are generally exempt from the surprise exam if safeguards are met. Some states still deem fee deduction to be custody and may require a surprise exam or specific disclosures. Check your state's rules and your advisory agreement language. When in doubt, document your interpretation and controls. Learn more about RIA custody of funds or securities and how it applies to your firm.
Make Compliance Easier with a Few Simple Systems
The best compliance process isn't the most complicated one. It's the one you'll consistently follow.
A few simple systems can help you stay organized throughout the year, reduce last-minute scrambling, and make it much easier to demonstrate your process if you're ever asked.
Here are a few worth putting in place:
- Create a master compliance calendar. Keep all of your key dates in one place, including Form ADV updates, brochure delivery, continuing education (CE), state renewals, annual reviews, and other recurring obligations. If you have a team, assign an owner to each task so responsibilities are always clear.
- Automate recurring reminders. Use your customer relationship management (CRM) system, project management software, or compliance platform to create recurring tasks. Include prompts to upload supporting documentation like PDFs, meeting notes, screenshots, or other evidence as you complete each item.
- Keep your documentation organized. A straightforward folder structure makes finding records much easier during an exam. Consider organizing folders by categories such as Policies, Compliance Testing, Marketing Approvals, Vendor Due Diligence, Training and Continuing Education, and Incident Response.
- Start with repeatable templates. Save yourself time by creating templates for the documents you use year after year, such as brochure delivery emails, incident response communications, marketing review checklists, best execution summaries, and annual compliance review reports.
Remember, the goal isn't to build the perfect compliance system overnight. It's to create a process that's easy to maintain, document, and repeat as your firm grows.
One Last Note
Compliance isn't about checking boxes for regulators. It's about building a practice your clients can trust and creating systems that give you confidence year-round.
A thoughtful compliance calendar helps turn deadlines into routines. When you know what's coming, document your work as you go, and revisit your processes regularly, you'll spend less time scrambling to prepare for exams and more time focused on serving your clients.
No advisor has ever memorized every rule, and that's okay. The most successful firms build repeatable processes, lean on trusted resources, and ask questions when something new comes up. Compliance is an ongoing practice, not a one-time project.
Whether you're launching your first RIA or refining the processes you've built over the years, having the right guidance can make the journey much more manageable. At XYPN, we've helped thousands of fee-only financial advisors navigate registration, ongoing compliance, and the operational realities of running an independent firm. Explore our compliance resources, educational content, and community to continue building a compliance program that grows alongside your practice.
