CCO Resource Hub: OCIE Risk Alerts

Chief Compliance Officer Committee

EXAMS Risk Alerts

As discussed under EXAMS Document Requests, it is not uncommon for EXAMS to publish a Risk Alert following a targeted review conducted by EXAMS. EXAMS began publishing these Risk Alerts several years ago. They were published to respond to concerns raised by the ICI that the SEC lacked a vehicle to communicate with registrants regarding practices observed by EXAMS in conducting targeted reviews. The Risk Alerts address this concern by EXAMS detailing in these publications observations from the EXAMS staff regarding practices EXAMS has observed in conducting inspections, which appear to be more effective or less effective than others. EXAMS stresses the fact that the information in these Risk Alerts is not intended to be read as imposing any compliance obligations on registrants. Instead, they are intended as a resource to registrants to assist them in their own compliance efforts.

Typically, these Risk Alerts are published following some, but not all, targeted reviews. EXAMS has also published Risk Alerts in advance of conducting a targeted inspection (e.g., cybersecurity) to alert registrants to the type of information it expects to review in conducting an inspection. It does so in hopes that, for those registrants that are not visited as part of the targeted inspection, they can review their own compliance policies and procedures and determine how they might measure up were EXAMS to inspect the firm. As noted in the Risk Alerts:

This Risk Alert is intended to highlight for firms risks and issues that the staff has identified. In addition, this Risk Alert describes factors that firms may consider to (i) assess their supervisory, compliance and/or other risk management systems related to these risks, and (ii) make any changes, as may be appropriate, to address or strengthen such systems. These factors are not exhaustive, nor will they constitute a safe harbor. Other factors besides those described in this Risk Alert may be appropriate to consider, and some of the factors may not be applicable to a particular firm’s business. While some of the factors discussed in this Risk Alert reflect existing regulatory requirements, they are not intended to alter such requirements. Moreover, future changes in laws or regulations may supersede some of the factors or issues raised here. The adequacy of supervisory, compliance and other risk management systems can be determined only with reference to the profile of each specific firm and other facts and circumstances.

The Risk Alerts published by EXAMS relevant to ICI’s members include the following:

The documentation provided by ICI that may be accessed by the CCO Committee members is restricted to members’ use only and not for distribution or reproduction. Documentation may be used internally at member organizations as needed.