You're the advisor. You're also the CCO. That conflict is the entire problem.
Solo RIAs carry the disclosure, ADV, cybersecurity, and exam-response load by themselves — while trying to bill clients, run reviews, and not miss a 30-day filing window. This page separates "what your firm is exposed to" from "what to do about it." The same score bands that drive the readiness check apply here, and the recommended tier in the comparison column comes from the same rule the check uses.
What each readiness score actually means at a solo RIA firm
The thresholds below match what the readiness check uses — if you take the check and land in the same band, this is exactly how your firm reads to an SEC examiner.
- Written policies and procedures, current within the last 12 months, with a designated CCO.
- Form ADV Part 2A and Form CRS are accurate and amended within 30 days of any material change.
- Reg S-P information security plan documented, incident response tested in the last quarter.
- ADV brochure is mostly accurate but missing recent affiliation changes or fee-schedule edits.
- Reg S-P written plan exists but has not been tested with a tabletop or live incident.
- Marketing Rule reviews are happening but not on a documented cadence with retention.
- No written Reg S-P information security program, or no MFA on systems that touch client NPI.
- Backups either unencrypted or never tested for actual restoration.
- Cybersecurity vendor list undocumented; no on-file due diligence for any service provider.
Polsia Solo vs. a DIY compliance stack vs. a fractional CCO
Three ways a solo RIA firm tries to keep up with SEC exam-priority changes — what each one costs in dollars, in hours, and in alerts you still have to triage by hand.
- SEC enforcement alerts — same-day, ranked by solo-RIA impact.
- SEC exam-priority updates — flagged before your next filing window.
- Reg S-P and Reg S-ID action tracking — incident-response triage cues.
- FINRA & NAIC monitoring — filtered to the rules that hit RIAs and producers.
- Weekly regulatory digest — five-minute scan, plain English.
- Free 8-question readiness scorecard + printable report.
- Free compliance Q&A — grounded in SEC, FINRA, and NAIC text with citations.
- Google Alerts + RSS feeds + free SEC / FINRA / NAIC pages.
- A calendar reminder for ADV-W renewals every quarter.
- Two hours a week scanning the Federal Register for new rule proposals.
- Your own spreadsheet of 30-year-old rule citations and IRP notes.
- An Excel checklist of Reg S-P controls, last reviewed 14 months ago.
- No audit trail when an examiner asks "how did you catch this?"
- 24-hour SEC sweep alerts get buried under personal trading reviews.
- A named CCO with two or three other solo clients competing for their time.
- 20 hours a month minimum, often retainer with separate hourly for exams.
- Annual marketing-rule review workpaper written in their template, not yours.
- Only covers what your retainer specifies — silent on new SEC sweeps.
- Doesn't pivot on a 24-hour SEC enforcement alert at 8am on a Friday.
- Won't run your weekly trade blotter or personal-trade pre-clearance.
- Cybersecurity tabletop exercises billed as add-ons, not retainer.