Expect Focus Life, Annuity, and Retirement Solutions, December 2019

OCIE Risk Alert Highlights Compliance Program Catch-22

Life, Annuity, and Retirement Solutions   |   Financial Services Regulatory   |   Securities & Investment Companies   |   Securities Litigation and Enforcement   |   February 6, 2020

A risk alert issued on November 7, 2019, by the SEC’s Office of Compliance Inspections and Examinations underscores a continuing dilemma faced by SEC-regulated entities.

The risk alert undertakes to summarize the “most often cited deficiencies and weaknesses that the staff has observed in recent examinations of registered investment companies.” Many of the summarized deficiencies involve failures to adhere to the various types of compliance policies and procedures that the registrants have adopted — even in cases in which the failure did not result in whatever type of legal violation the procedures might have been designed to prevent.

OCIE’s tendency to cite failure to adhere to compliance policies and procedures as a discrete compliance deficiency naturally incentivizes registrants to limit the scope and detail of their compliance policies and procedures as much as possible, consistent with being reasonably designed to prevent violations of relevant legal requirements.

However, attempts to pare back on any arguably superfluous compliance policy and procedure provisions also risk incurring OCIE’s ire. Indeed, the preponderance of the risk alert summarizes numerous areas in which the staff seems ready to second-guess registrant judgments that more detail is unnecessary in compliance policies and procedures, even if no other legal violation has resulted.

It can be appropriate for some compliance policies and procedures to be quite general in nature — e.g., simply assigning to a particular person responsibility for compliance with a given legal requirement, perhaps specifying some key principles for that person to follow. To ensure compliance with other legal requirements, however, it may be necessary or advisable to adopt a more prescriptive approach that specifies in some detail what steps the responsible personnel are to take.

The process of crafting compliance policies and procedures, therefore, necessarily involves difficult judgment calls, and the Risk Alert makes clear that registrants will not be immune from OCIE criticism after the fact, regardless of what approach they take. This doubtless also applies to registered broker-dealers and investment advisers, although the risk alert by its terms only covers mutual funds, insurance company separate accounts, and other registered investment companies.


©2023 Carlton Fields, P.A. Carlton Fields practices law in California through Carlton Fields, LLP. Carlton Fields publications should not be construed as legal advice on any specific facts or circumstances. The contents are intended for general information and educational purposes only, and should not be relied on as if it were advice about a particular fact situation. The distribution of this publication is not intended to create, and receipt of it does not constitute, an attorney-client relationship with Carlton Fields. This publication may not be quoted or referred to in any other publication or proceeding without the prior written consent of the firm, to be given or withheld at our discretion. To request reprint permission for any of our publications, please use our Contact Us form via the link below. The views set forth herein are the personal views of the author and do not necessarily reflect those of the firm. This site may contain hypertext links to information created and maintained by other entities. Carlton Fields does not control or guarantee the accuracy or completeness of this outside information, nor is the inclusion of a link to be intended as an endorsement of those outside sites.

Subscribe to Publications


The information on this website is presented as a service for our clients and Internet users and is not intended to be legal advice, nor should you consider it as such. Although we welcome your inquiries, please keep in mind that merely contacting us will not establish an attorney-client relationship between us. Consequently, you should not convey any confidential information to us until a formal attorney-client relationship has been established. Please remember that electronic correspondence on the internet is not secure and that you should not include sensitive or confidential information in messages. With that in mind, we look forward to hearing from you.