No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Financial Services

SEC 2026 Examination Priorities: What FinServ Firms Need to Know

Examiners will assess whether policies and procedures are implemented and enforced, not just whether they exist on paper

by Jamie Hoyle
January 5, 2026
in Financial Services
front of SEC building washington dc

The SEC’s 2026 examination priorities emphasize existing regulatory expectations extended to technologies that didn’t exist when compliance frameworks were established. Jamie Hoyle of MirrorWeb explores how examiners will review AI-related marketing claims for accuracy, assess whether preservation systems capture communications in formats that maintain context and authenticity, and determine if compliance programs translate policies to actual practice through substantive implementation rather than relying on well-drafted documentation that provides no protection if it exists primarily on paper. 

The SEC’s Division of Examinations has released its fiscal year 2026 examination priorities, outlining focus areas for investment advisers, broker-dealers and other market participants. While the document addresses numerous examination areas, three themes warrant particular attention from compliance professionals — two explicitly stated, one revealed through notable absence.

AI supervision and algorithmic transparency

Section VII.B directly addresses AI technologies in financial services. The division will examine “whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies.” The focus extends beyond mere adoption to governance, oversight and substantiation.

Examiners will “review for accuracy registrant representations regarding their AI capabilities,” requiring firms to validate any claims about AI-powered systems. This creates a dual challenge: Firms must both govern AI use internally and ensure external representations align with actual capabilities.

The transparency question becomes central. When AI systems generate recommendations or flag potential issues, can firms explain the underlying logic? The SEC expects firms to understand how AI-driven decisions align with regulatory obligations, particularly regarding investor protection and fiduciary duties.

This emphasis on explainability reflects broader regulatory trends. The SEC’s recent focus on AI-driven investment recommendations and robo-advisers demonstrates growing concern about automated decision-making without adequate human oversight or understanding. Compliance programs must address not just whether AI is used but whether its use remains comprehensible and defensible under examination.

Key considerations for compliance programs:

  • Documentation of AI technologies in use across the organization
  • Governance frameworks demonstrating supervision of algorithmic systems
  • Ability to explain AI-driven decisions to staff without technical expertise
  • Validation that AI-related marketing claims reflect actual capabilities
  • Assessment of whether AI recommendations remain consistent with regulatory obligations

Channel-agnostic recordkeeping

The 2026 priorities reference recordkeeping throughout but never specify communication channels. No mention appears of email, messaging applications, collaboration platforms or any particular technology. This absence reinforces fundamental regulatory architecture.

SEC Rules 17a-4 (for broker-dealers) and 204-2 (for investment advisers) have required comprehensive recordkeeping for decades without technological specifications. They mandate preservation of business communications regardless of medium. The multibillion-dollar enforcement actions between 2022 and 2024 for off-channel communications didn’t punish violations of new rules; they enforced existing obligations that firms failed to apply to evolving technologies.

The regulatory approach deliberately avoids channel-specific language. This allows rules to adapt as technology changes without requiring constant amendment. Whether employees use established platforms or adopt emerging technologies, recordkeeping obligations remain constant.

This creates ongoing compliance challenges. Firms must identify which communication channels employees actually use for business purposes, not simply which channels the firm officially sanctions. 

The examination focus will likely center on completeness and accessibility. Can firms produce comprehensive records when requested? Do preservation systems capture communications in formats that maintain context and authenticity? These questions apply regardless of which technologies employees prefer.

sec building in washington dc
FCPA

Dismissal of FCPA Charges Against Ex-Cognizant Execs Sends Early Sign That SEC Will Follow DOJ’s Lead

by Gina Castellano, Martin Weinstein and Laura Perkins
August 13, 2025

Read moreDetails

Compliance program effectiveness over documentation

Sections I.B and III.C emphasize assessment of compliance program effectiveness as “a fundamental part of the examination process” for both investment advisers and broker-dealers. The critical phrase appears repeatedly: whether “policies and procedures are implemented and enforced.”

This distinction matters. Well-drafted policies provide no protection if they exist primarily on paper. Examiners will look for evidence of active implementation: testing, monitoring, enforcement and adaptation based on findings.

Annual compliance reviews face particular scrutiny. Are these substantive exercises that identify genuine vulnerabilities and drive improvements, or box-ticking exercises conducted solely to satisfy documentation requirements? The latter approach — reviews performed because regulations mandate them, not because firms expect to discover anything meaningful — meets the letter of regulatory obligation while failing the effectiveness standard examiners now emphasize.

Marketing materials will receive attention, especially given AI supervision concerns. Firms must substantiate claims about compliance capabilities, risk management or technological sophistication. The intersection of marketing oversight and AI governance creates heightened examination risk for firms promoting AI solutions.

The effectiveness standard extends beyond individual policies to overall program assessment. Do firms allocate adequate resources to compliance functions? Do compliance staff have sufficient authority and access? Are compliance findings addressed through meaningful remediation rather than acknowledgment without action?

Preparing for examination expectations

These three themes suggest priorities for compliance program assessment:

  • Evaluate AI governance comprehensively. Map where algorithmic decision-making occurs across the organization. Assess whether supervision frameworks address these systems adequately and whether decision-making logic remains explainable to non-technical staff and regulators.
  • Test recordkeeping completeness. Identify all business communication channels in actual use, not just those officially sanctioned. Verify preservation systems capture communications adequately and assess ability to produce records efficiently during examinations.
  • Demonstrate program effectiveness. Review whether policies translate to actual practice through testing, monitoring and enforcement. Ensure annual compliance reviews identify genuine issues and drive substantive improvements. Validate that marketing materials accurately represent compliance capabilities.

Foundational principles, not new obligations

The 2026 examination priorities emphasize existing regulatory expectations extended to technologies that didn’t exist when compliance frameworks were established. AI supervision may address novel capabilities, but it reflects the same fundamental obligation firms have always faced: supervising the tools and systems that drive business decisions and client recommendations. Comprehensive recordkeeping and compliance program effectiveness operate from the same logic, established principles applied to evolving contexts.

As technologies mature and business practices adapt, compliance programs must maintain effectiveness without requiring regulatory restatement of fundamental obligations. Firms that treat these themes as ongoing compliance imperatives rather than cyclical focuses will maintain examination readiness regardless of specific priorities.

 


Tags: SEC
Previous Post

Mission-Driven Work: Why the Next Generation Should Choose Infosec Careers

Next Post

The $2 Billion ‘Free-Rider’ Problem: Why AI Scraping is Now a Boardroom Crisis

Jamie Hoyle

Jamie Hoyle

Jamie Hoyle is vice president of product for MirrorWeb, a provider of communications archiving and surveillance software.

Related Posts

sec sign on building

Banks Shouldn’t View the Treasury Clearing Rule Simply as a Compliance Exercise

by Cindra Maharaj
December 12, 2025

Extended deadlines give banks time to create access packages for indirect participants without requiring them to build infrastructure

emblem on sec building

What Non-US Firms Need to Know Before Conducting Securities Activities in the United States

by Kathy Rocklen
December 2, 2025

Solicitation is viewed broadly to include calls, emails, research distribution, conference sponsorships and investor meetings in the US

front of SEC building washington dc

Q&A: The SEC Is Up & Running After Shutdown; Now What?

by Staff and Wire Reports
November 18, 2025

With shutdowns increasingly likely, registrants should prepare now for future delays

technician working with test tubes in lab

Securities Risk Disclosure Lessons for Life Sciences Companies

by Jennifer Windom, Elizabeth Jungman and Bolton Smith
October 27, 2025

The threshold for securities disclosure is very different from the “statistically significant” standard used by most scientists and researchers

Next Post
big data filtering concept

The $2 Billion ‘Free-Rider’ Problem: Why AI Scraping is Now a Boardroom Crisis

reminder to speak up
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights