SEC Marketing Rule Compliance Automation for RIAs

Key takeaways
- SEC Rule 206(4)-1, the Marketing Rule, requires substantiation and specific disclosures for testimonials, endorsements, and third-party ratings in adviser marketing, and does not mandate any particular software to achieve compliance.
- The SEC Division of Examinations issued a risk alert on December 16, 2025, focused on testimonials, endorsements, and third-party ratings deficiencies, including missing promoter disclosures and incomplete recordkeeping.
- Marketing changes, including new promoter or third-party rating arrangements, are a common trigger for a Form ADV amendment, most often to Part 2A.
- An automated first-pass marketing review should flag issues by specific rule provision and route close calls to a compliance officer, who retains the final sign-off.
- The audit trail an examiner asks for, including who reviewed what, when, and why, is easier to produce when review history is logged automatically rather than reconstructed from memory after the fact.
A compliance officer at a 40-advisor RIA described her week to me like this: three advisors want to post client-outcome language on LinkedIn, one wants to add a "5-star rated on Google" badge to the firm's website, and marketing has a new email template with a returns chart that needs a disclosure block before it goes out Friday. Each one lands in her inbox separately. Each one needs the same checklist run against it: is this a testimonial, is this an endorsement, is this a third-party rating, does it have the required disclosures, is there a written agreement with whoever is being paid to say it. She runs that checklist by hand, in her head, one item at a time, because the alternative is a compliance platform that costs real money and still needs her to feed it every piece of content one at a time.
That is the actual shape of Rule 206(4)-1 compliance at a firm above a certain size. The Marketing Rule did not just change what advisers can say in an advertisement. It turned advertising review into a standing operational function that runs every week, forever, with no natural stopping point.
Why manual marketing-rule review is the wrong scale for a growing RIA
Before the 2021 amendments, a firm's marketing compliance workload was lumpy: annual brochure updates, occasional ad hoc reviews when a new campaign launched. Rule 206(4)-1 changed the unit of work. Every social post, every advisor's individual LinkedIn update, every client-facing deck, every review-site badge is now a piece of regulated advertising that needs the same disclosure and substantiation analysis a brochure used to get once a year.
A solo adviser can survive on manual review because the volume is manageable. A 30-, 50-, or 100-advisor RIA cannot. Marketing output scales with headcount and with how many channels the firm uses, and the checklist per item does not get any shorter. What actually happens at that scale is not that firms do less review. It is that review quality degrades unevenly: some items get a careful pass, others get a rushed one on a Friday afternoon, and the gap between the two is invisible until an examiner picks the wrong item to ask about.
The SEC has made clear this is exactly where it is looking. On December 16, 2025, the Division of Examinations issued a risk alert on Marketing Rule compliance that focused specifically on the testimonials and endorsements provisions and the third-party ratings provisions of Rule 206(4)-1. The deficiencies it described were not exotic. Advisers were missing or using generic disclosures about promoter compensation and conflicts of interest, particularly on firm websites and through referral and lead-generation arrangements. Written agreements with compensated promoters were absent. In some cases, firms had paid people with disciplinary histories that should have made them ineligible promoters in the first place. The alert also flagged weak recordkeeping: no archived copies of the social content that ran, no documentation of how a third-party rating was vetted before it went on the site.
None of that is a hard legal question. It is a volume-and-consistency problem. A firm that reviews 40 pieces of marketing content a month by hand, with a different person doing the review depending on who is free that day, will eventually produce exactly the pattern the SEC just described in writing.
What a first-pass automated marketing-rule reviewer actually does
The system we build does not replace the compliance officer's judgment, and it does not sit as a separate login she has to remember to check. It sits inside the tools the firm already uses to produce and manage marketing content, and it does the first pass before anything reaches her queue.
Here is what that looks like in practice. Marketing drafts a LinkedIn post or an email in the tool the team already uses, the CRM already tracking that advisor's client relationships, or a shared drive folder the marketing team works from. The system picks up the draft the moment it is created or edited, rather than waiting for someone to remember to submit it for review. It reads the content against the specific triggers in Rule 206(4)-1: does the language constitute a testimonial or endorsement, is there a performance number that needs substantiation and time-period disclosure, is a third-party rating referenced without the required disclosures about who paid for it and how it was calculated. It checks the content against the firm's own promoter list and flags anything referencing an individual who isn't on record as an eligible, agreement-covered promoter.
Where it finds a clean pass, it logs that and moves the item forward with a note showing which rule provisions it checked and why it passed. Where it finds something that needs a human, it stops, flags the specific clause or claim, and routes it to the compliance officer with the exact provision it is worried about, not a generic "needs review" tag. She makes the actual call. That is the alongside-not-replace design: the system removes the repetitive first pass of reading forty near-identical LinkedIn drafts against the same checklist, and leaves the judgment calls, the close ones, and the final sign-off with the person the SEC actually holds accountable.
This is also where the system earns its keep beyond marketing review alone. Marketing-rule changes are one of the more common triggers for a Form ADV amendment: a new advertising practice, a new third-party rating arrangement, a change in how performance is presented can all require an update to Part 2A or the relevant ADV item. A tool bought purely to check marketing copy has no idea that a change it just approved also needs to show up in the firm's next ADV filing. Because we build this as one layer inside the firm's actual compliance calendar, alongside books-and-records retention and the ADV amendment schedule, a marketing decision that trips an ADV trigger gets flagged there too, in the same system, instead of surfacing three months later when someone happens to notice the ADV is stale.
We have found that firms evaluating this space are typically choosing between two options: a marketing-review SaaS platform, something like Luthor AI or ComplySci on the compliance-tooling side, bought as a standalone subscription, or building nothing and continuing to review by hand. Both of those miss the same thing. A subscription platform reviews marketing in isolation from the rest of the compliance calendar, and the firm's client data, communications, and marketing content still have to flow out to a third party's servers to get reviewed. Building nothing means the volume problem described above just keeps compounding as the firm adds advisors. The build we do sits between those two, closer to what we have described as moving RIA compliance automation beyond legacy, single-purpose platforms: custom software, deployed in the firm's own cloud environment, wired into the systems and calendar the firm already runs, instead of one more vendor login and one more place client data has to leave the building.
Why the audit trail is the part that actually matters to an examiner
For a compliance officer at a firm of this size, the real fear is not that automation gets something wrong once. It is standing in front of an SEC examiner and being unable to explain, item by item, how a piece of marketing content was reviewed, who approved it, and why. That is the deficiency the December 2025 risk alert describes over and over: not that advisers made one bad call, but that they could not produce the paper trail behind the calls they made.
Every determination the system makes is logged: the exact text of the content reviewed, the specific rule provision checked, the system's finding, and, where a human made the final call, who that was and when. If the system flags something and a compliance officer overrides it, that override is recorded too, with her reasoning attached, not silently discarded. The result is closer to a permanent, timestamped record of every review decision than to a dashboard that shows the current status and loses the history. When an examiner asks about a testimonial that ran eight months ago, the firm can produce exactly what was checked, what was found, and who signed off, rather than reconstructing it from memory or a compliance officer's personal notes.
The second piece of the apprehension is where the data lives. A firm above a certain size is rightly cautious about sending client names, advisor performance data, and unreleased marketing copy to a third-party SaaS vendor's servers, especially one that could be acquired, change its data-retention policy, or simply go out of business with the firm's compliance history sitting on its infrastructure. We deploy this kind of system inside the firm's own cloud environment, AWS, Azure, or whatever the firm already runs on, using access controls the firm's own IT and compliance teams configure and control. The firm's data does not leave its environment to get reviewed. If the relationship with us ends, the system and the audit history stay where they were built, because they were never anywhere else to begin with.
Frequently asked questions
Does the SEC require RIAs to use compliance software for marketing review?
No. Rule 206(4)-1 does not mandate any specific tool or software. It requires that an adviser's marketing materials meet the rule's substantiation, disclosure, and recordkeeping requirements, and that the firm's compliance program under Rule 206(4)-7 is reasonably designed to catch violations before they happen. How a firm gets there, by hand, with off-the-shelf software, or with a custom system, is the firm's choice. The SEC's exam focus is on outcomes and documentation, not on the specific tool used to produce them.
What triggers a Form ADV amendment tied to marketing changes?
A firm generally needs to amend its Form ADV, most often Part 2A, when it materially changes how it advertises performance, adds a new arrangement with a compensated promoter or third-party rating provider, or changes a disclosure practice that Part 2A describes. Because these triggers often originate inside a marketing decision rather than a compliance-calendar reminder, they are easy to miss unless the marketing-review process and the ADV amendment schedule are checked against each other rather than run as two unconnected tasks.
Can AI actually review investment adviser marketing for Rule 206(4)-1 compliance?
It can handle the first pass reliably: checking content against known disclosure requirements, flagging unsubstantiated performance claims, and cross-referencing promoters against the firm's approved list. It should not make the final compliance determination on a genuinely close call. The firms that get this right treat the system as the reader that catches the routine issues at volume, the same design we have seen work for AI agents deployed inside SEC and FINRA compliance structures more broadly, with a compliance officer making every final sign-off, which is also what an examiner expects to see documented.
What did the SEC's most recent Marketing Rule risk alert find?
The Division of Examinations' December 16, 2025 risk alert focused on the testimonials and endorsements provisions and the third-party ratings provisions of Rule 206(4)-1. It found advisers with missing or generic disclosures about promoter compensation and conflicts of interest, an absence of written agreements with compensated promoters, payments to individuals with disciplinary histories that should have made them ineligible, and gaps in recordkeeping, including missing archived copies of social content and missing documentation of how third-party ratings were vetted.
Book a strategy call
If your firm is reviewing marketing content one item at a time and the volume has outgrown what one compliance officer can carry by hand, we can walk through what a first-pass reviewer wired into your existing systems and compliance calendar would look like for your firm specifically. Book a free strategy call.
Get new articles when they publish
One email per post. No pitch, no spam.


