Free Self-Assessment — Under 90 Seconds

How ready is your solo RIA firm for an SEC exam?

Quick yes/no check across the four exam areas solo RIAs get hit on most: your SEC compliance program, Form ADV, Reg S-P, and cybersecurity. You'll see a partial readiness score after the first three questions — your full results, scoring breakdown, and printable report unlock by email.

Readiness score
0%
1 — SEC Compliance Program 0 / 2 answered
Do you maintain written compliance policies and procedures, reviewed and approved at least annually?
Weight: 3 — Rule 206(4)-7 requires written policies reviewed annually
Have you designated a Chief Compliance Officer with clear authority and enough time to administer the compliance program?
Weight: 3 — CCO designation with authority is a core 206(4)-7 test
2 — Form ADV Filing 0 / 2 answered
Is your Form ADV Part 2A updated within 30 days of any material change (new services, conflicts, disciplinary events, ownership)?
Weight: 3 — Rule 204-1 requires 30-day interim amendment
Do you deliver the current ADV brochure (Part 2A) and Form CRS to every client before engagement, and annually after a material change?
Weight: 3 — delivery obligations are tested in every exam
Your score is ready
Enter your email to see the full breakdown
We'll send your section-by-section read across all eight questions, plus a printable PDF readiness report. No spam, no list-selling.
3 — Reg S-P (Privacy & Safeguards) 0 / 2 answered
Have you delivered your written privacy notice (initial and annually) to every client, opt-outs honored, and shared affiliate-marketing opt-outs in place?
Weight: 3 — annual delivery is a Reg S-P bright-line test
Do you have a documented, tested incident response procedure for unauthorized acquisition of client NPI — with client notification ready within 30 days?
Weight: 3 — untested IR is a top exam deficiency
4 — Cybersecurity 0 / 2 answered
Is firm-wide multi-factor authentication enabled on every system that stores or accesses client nonpublic personal information?
Weight: 3 — MFA is the de facto baseline under Reg S-P
Do you maintain tested, encrypted backups for client data with a documented recovery procedure your firm can actually execute?
Weight: 3 — encryption + tested recovery is an exam checklist item
Here's your full breakdown
Printable report
Download your compliance readiness report
Single-page summary you can save, email, or bring to your next team meeting. Includes your score, per-section breakdown, and the next three actions to take.
Download PDF report
Founding 100
100 of 100 founding spots remaining
Get alerted the next time the SEC flags solo RIA gaps.
RegAxis monitors SEC enforcement, FINRA disciplinary actions, and NAIC bulletins 24/7. Founding members lock in $49/mo for life — after seat 100, regular pricing is $149/mo.
Claim founding seat →
Solo RIA compliance

Common questions from solo RIAs

Why does the SEC drill solo RIAs on Reg S-P in 2025?
The SEC's 2025 Division of Examinations priority letter elevated cybersecurity and Reg S-P compliance as a top focus for investment advisers. The 2024 amendments tightening Reg S-P incident response are now in force, and firms without documented, tested IR procedures are routinely cited — regardless of firm size. Solo RIAs without a written IRP and a tested client-notification procedure are the most exposed population.
How fast do I have to amend Form ADV?
Rule 204-1 requires an interim amendment (Form ADV-W) within 30 days of any material change to Part 1A or Part 2A — new services, conflicts, disciplinary events, ownership changes, or new affiliates. Form CRS has the same 30-day window. The annual updating amendment is due within 90 days of your fiscal year end.
If I outsource IT, am I responsible for Reg S-P anyway?
Yes. Reg S-P applies to you as the adviser — your service-provider agreement needs to require them to meet your information security standards, and you retain responsibility for the program overall. Outsourcing IT does not transfer regulatory liability.
Is MFA actually required for solo RIAs?
MFA is not a single-rule mandate, but the SEC's enforcement record-plus the 2024 Reg S-P amendments make it the de facto baseline for any adviser system that touches client NPI. Firms without MFA on cloud email, CRM, custodian portals, and document storage are getting cited in nearly every cybersecurity sweep. The cost of not having MFA now dwarfs the cost of enabling it.
What's the fastest way to move out of "Critical Exposure"?
In priority order: (1) enable MFA on every system that touches client data, (2) write a Reg S-P IRP and walk through one tabletop exercise, (3) review Form ADV Part 2A against your actual services and amend within 30 days of any material change, (4) document annual policy review with date-stamped approval. Two of those four are under $500 of effort and remove most of the "red flag" exposure a sweep would surface.