Video: The SEC in 2026 and Beyond: Enforcement Priorities in a Deregulatory Era | Duration: 3608s | Summary: The SEC in 2026 and Beyond: Enforcement Priorities in a Deregulatory Era | Chapters: Introduction and Welcome (26.43s), Enforcement Priorities (127.695s), AI Governance and Risk (965.685s), SEC Engagement on AI (1667.08s), Reg SP Compliance (1868.27s), Compliance Priorities (2929.38s), Closing Remarks (3595.26s), Upcoming Events (3603.4014s)
Transcript for "The SEC in 2026 and Beyond: Enforcement Priorities in a Deregulatory Era":
Thanks everyone for joining today. We're seeing a lot of interest in these topics, so we appreciate you taking the time. My name is Patrick Mullen. I'll kick things off and then turn it over to our panel. This session is being recorded and we'll share the recording afterwards. We're also leave time for questions and we encourage participation throughout, especially since this session is eligible for IECCP continuing education credit and potentially other credits. We're focused on a simple but important question. If rulemaking slows, where will enforcement actually intensify and what does that mean in practice for how firms operate day to day? And more importantly, what should firms be doing now to make sure they're prepared? I'm pleased to be joined by a great panel. Jamila Mayfield is our Chief Regulatory Services Officer here at Comply. Jamila is a former regulator and works closely with firms on SEC examinations and enforcement trends. Ned Dana is our SVP of Compliance Advisory Services here at Comply. He works directly with firms on operational implementation, surveillance programs and regulatory readiness. And Gail Bernstein, General Counsel at the Investment Advisor Association, leads legal and policy efforts on behalf of the industry and brings a broad perspective on regulatory developments impacting investment advisors. With that, I'll turn it over to Jamila to kick us off. Thank you so much, Pat. And, again, as you said, welcome to everyone joining us today. We have a packed agenda, a lot to cover. We'll start with talking about enforcement and what's really shifting from an enforcement priorities perspective. We'll move into artificial intelligence, the topic everybody's talking about and what it means for compliance. Then we'll dive into Reg SP. We've been chatting about this one for quite some time and coming up on an important June date. We'll talk about what that means. And then the marketing rule, it is not going away. We've gotten more insights from the latest risk alerts, so we'll hear more about what that means for the industry as well. Finally, we'll talk about what is important for compliance leaders to be thinking about. How should they prioritize? And we'll get Ned and Gail's perspective on that. So without further ado, we'll go forward. And enforcement in 2026, what is really shifting? Gail, I'd love you to give us some perspective on how you see the enforcement agenda. Yes. Thank you, Jamila, and thank you very much to comply for having me, again, speaking to everybody. What we are seeing right now is a real attempt to reset, following the chair Gary Gensler era. I think what I would want to emphasize is that this is not about deregulation. It is about recalibration. And for anybody who thinks that we are entering into or in anything like the Wild West, we are nowhere close to the Wild West and that is not the intent of this SEC. It is not the intent of this SEC not to continue to have enforcement as as a core, sort of principle of of what it does. So again, deregulation does not mean reduced scrutiny. It's different, but not in any way diminished. And this does also not mean a retreat from bread and butter enforcement. I think what we're seeing is that the focus is different. The question for advisers is what is the SEC gonna choose to enforce and and how rather than whether. So chairman Atkins has talked about getting back to basics, not regulating through enforcement, which has been very important to to us, and going after misconduct and situations where there has been or is likely to be investor harm. Just to underscore that point, the IAA recently had our annual conference and commissioner Mark Ueda spoke there. And he made the point, at the IAA conference that a strong enforcement program remains central to the SEC mission. And I think we're seeing that. So before I get into some of the, substantive priorities and areas of focus, it's worth noting a few major developments structural developments inside the division of enforcement itself over the past year. I think what we're seeing internally is also driving what we're seeing externally. So some statistics. Enforcement activity is down and it's more focused. The division published its 2025, fiscal year statistics, quite recently, and they really tell a story. In 2025, there were 456, total actions down from 583 in 2024. Of these, there were 303 stand alone cases down from 431, which is about a 30% drop, and the lowest level that we've seen in a decade. In terms of what penalties that the, commission collected, we saw in 2025 $17,900,000,000 in monetary relief, collected. But that number is really misleading because it was heavily driven by some legacy cases and one in particular. So if you strip out the legacy cases, you're closer to 2,700,000,000 in real penalties, which is about a 70% drop from the year before. So the trend in numbers is pretty clear. We're seeing fewer cases. We are seeing less reliance on broad sweeps, and we're seeing more targeted enforcement. So if we work under the sort of assumption that resources to a degree are shaping strategy, The SEC also just put in a budget proposal, and it has asked for about 11% less than what it asked for last year. It asked for about $1,900,000,000 total. And so enforcement funding remains well below prior peak levels. And at the same time, given the, the sort of attrition, for various reasons that we saw over the course of 2025, The, enforcement staffing is down close to about 25 20%. Sorry. So the practical effect is that the division and the commission have to be more selective in the cases that they're going to bring. So there has to be a higher bar for what they're willing to investigate and and, and pursue. And they also are gonna wanna see a greater focus on clear and provable violations with either investor investor harm or likelihood of investor harm. The division has also seen leadership and policy shifts. There's been significant leadership turnover. Just recently, judge Margaret Ryan, who was the most recent, enforcement director, she was brought in last fall. She left after about six months, and chairman Atkins has now named David Woodcock as the new director. He's not going to start until May 4. And so the acting director who who was actually acting before judge Ryan came on board, Sam Walden is gonna be leading in the interim. David Woodcock brings he's got an interesting background. He brings very deep experience including deep SEC experience as the former Fort Worth regional director. He has a background in traditional enforcement and litigation. His experience focus focuses primarily on the or more on the public company space. So it'll be interesting to see if we see an uptick of actions there. And he also has academic and private practice, experience. And then with respect to policy directions, chairman Atkins has been very clear about what he wants to see. He has said that the division of enforcement has undergone a significant course correction, restoring congressional intent by prioritizing cases that provide meaningful investor protection and strengthen market integrity. So what does this mean for what the, division is pulling back from? We're seeing a shift away from crypto enforcement cases, including dismissals of very high profile matters. We are seeing a, I think a stop really in off channel communications cases. And this when I talked about, we're gonna see fewer broad sweeps, this is really what I had in mind. These off channel communications were resource intensive for the commission. They were viewed largely as penalty driven rather than substantively driven, and they were largely without claims of investor harm. We are, I think that's fair to say that we all expect that we will not see cases like this under this administration. We're also unlikely to see aggressive or novel legal theories, particularly where courts have shown skepticism. So one example is obviously in the crypto space. Another example is where there have been novel, insider trading like shadow shadow insider trading, theories pushed by the SEC. More broadly, and this is a very welcome development, we're hoping to see and expect to see less policy making through enforcement and less experimentation. We are also likely to see more effort to, to resolve things at the exam level rather than at the referral to enforcement level. So I think we're gonna see, more, requests and push for remediation by exams and fewer referrals, to the enforcement division. So we've I've talked about what we won't see. So what will we see? What what replaces all of this? As I said, it's gonna be back to basics. We're seeing a return to bread and butter enforcement. This commission is going to focus on fraud, misappropriation, fiduciary duty violations, both duty of loyalty and duty of care, clear conflict of interest violations, and very importantly, retail investor harm. We're also gonna see a focus on more individual accountability cases, which doesn't translate into more CCO liability or more potential CCO liability. I think that the standards for when a CCO is going to be looked at, as as to whether or not, he or she should be held personally liable. Those standards will, I think, stay the same. They're they're gonna be looking for some direct involvement or, really, really bad, not paying attention to to what's going on at at the firm. We are also gonna see more straightforward and fact driven matters. So fewer theory driven cases and more fact pattern cases. This is definitely much closer to what IAA members have been advocating for. We we've wanted to see a focus on misconduct and investor harm and not just on technical footfalls. We've seen a lot in the past, pre 2025, a focus on technical footfalls, and we think that that's unfortunate. It's not the best use of enforcement resources. We are hoping to see, and this is consistent with, sort of what we've been pushing for, greater predictability in what goes to enforcement and much less reliance on enforcement to set policy. You know, we're hoping that policy really comes out of the policy divisions, like the division of investment management with input from enforcement, input from exams, but really less reliance on enforcement to set the policy. So just a full circle moment for me. Again, this is not a stand down moment, Jamila. It is a refocus moment. And for advisers, I would say the key takers of the way would be that even with more targeted enforcement, the fundamentals have not changed. So we're gonna stress documentation, supervision, and most importantly, how advisers are treating their clients under their fiduciary duty. All of these are still very much under the microscope. That was a wonderful overview. And thank you so much, Gail, for just kind of walking us through the complete, thought process on where we were, where we're going, and also the differences in the past administration and kinda where we are today. I love that you said less regulation by enforcement. And you used a word I I wasn't expecting, less experimentation. I wanted to dig a little bit there, and I think it's related to what you were talking about with taking theory and trying to apply it to an adviser's situation and then maybe moving to enforcement. But would love for you to just pull that thread a little bit on when we say less experimentation, what do what do you mean by that? Yeah. And I'm really thinking of of sort of novel theories like the presumption that that all crypto assets are securities and then having enforcement be the mechanism for creating, for for regulating a developing market rather than going back to the policy divisions and thinking through what is the right framework to think about to to think about these new issues. I'm thinking, as I said, about, shadow insider trading. You know, if you're, trading on, trading trading securities in a in a, an issuer that is related to but not the issuer of, on which or for which you have inside information, they we will see less of that. And and definitely the off channel communications cases, which, came a little bit out of the blue for people and then became the thing, we're we're hopefully gonna see less of that. We're we're I think that the commission is going to want to look at the existing legal framework, find a clear violation, and then proceed. Those are great examples, Gail. And, to your point on on crypto and the recent actions we've seen with the SEC and the CFTC coming together and creating some of a framework and re reorganizing how we thought about certain categories of crypto into commodities versus securities, really starting to, like you say, step back and establish a policy and a and a rule of law about how we think about these type of investments. I'm sure we'll see more from that kind of first big step with aligning together and and going forward. So, I I think this was a great way to think about enforcement for all those that may have been wondering you know, where are we, where we're headed. Matt, I don't know if you wanna add anything. No. That was a wonderful summary. I guess, I'm I'm I find myself wondering if, the fiscal year twenty twenty five results, sort of signal also that self reporting and meaningful cooperation and remediation can materially affect outcomes and whether we are, ultimately referred to enforcement or at least result in reduced penalties, in some instances. So Yeah. And then I would I would respond to that. I think definitely remediation, is going to be helpful in in almost all cases. I think that similar thinking needs to go into whether or not to self report. That that that should that should be a facts and circumstances and and often in consultation with counsel, whether or not it makes sense to to self report. But this, this commission is definitely looking to firms to remediate themselves and then preferably not to punish the firms, you know, that that have that have remediated. So I would agree with that. Yeah. Yeah. Great conversation points. And just so we keep it rolling, I'm gonna move forward to to everybody's favorite topic. And before we launch into artificial intelligence, we'll have a polling question. So are you testing or validating AI tools for bias, hallucinations, or false positives? A, yes, b, no, or c, n a. So we'll let folks answer that, and we'll keep the conversation going. And, Matt, I'd love you to tell us, you know, what you're thinking around artificial intelligence. We know you have an opinion because everybody does. What you're seeing, what clients are asking about, what we're doing at Comply, all the things, and and what you think the regulatory expectations are going to be and how they might evolve. Yeah. Thank you, Jamila. Yeah. So artificial intelligence is, at this point, already embedded in core operations and even compliance functions, across so many firms. And while there is no AI specific rule, we know that was, there was, an attempt to, propose under Gensler that was, rolled back, but even that rule didn't cover all the risks as we know. But even in the absence of a rule, we know that the SEC's expectation, and that's across speeches, exams, enforcement is, transparency, accountability under existing fiduciary and compliance frameworks. I think one of the biggest risks, unfortunately, is using AI without governance, without controls, and, I think that's a current reality for many, many firms. Now Comply conducted a survey back, last fall twenty twenty five. Lot a lot can change in six months, certainly in the AI world, but, one of the things that came out of that, and that that, poll included approximately 600 compliance professionals, mostly in The US, some in The UK. And of those polled at that time, 69%, responded that they had adopted AI tools into their operations or or compliance functions. And less than 50% at that time, that had implemented or rolled out AI tools had adopted governance structures, policies, or or guardrails. So firms are adopting, AI faster than they're building control frameworks, around them. So that's, I think, probably one of the more, troubling things. Now, again, six months has gone by since then. I'm hoping that firms are are catching up with with that. So, if you think about the SEC's approach under existing under the existing framework in the absence of a rule and there no rule is needed. We have the fiduciary duty. So you consider the duty of care. In this context, we wanna make sure that all AI outputs are reasonable, that they're, in the client's best interest. You can't, as an adviser, outsource your judgment to a model for duty of loyalty. You know, we're we're looking at identifying and then disclosing conflicts of interest that may be embedded, in AI tools or how we are using those tools. So, those, I think, are the primary, tools that the SEC will use both in examinations and enforcement, to address AI, this lack of governance, or any issues that may arise at firms for the foreseeable future. Also, if we think about, the fiduciary duty and section two zero six under the advisers act, also rule two zero six four dash seven, the compliance program rule adopted, under that. You wanna follow that very same process at your firms when when dealing with, AI deployment, including a risk assessment, you know, asking the proper questions, where is AI being used, what specific risks arise from that use, you know, using an AI notetaker, internally to to track meetings and takeaways and who's responsible and when are we gonna follow-up on this item is a much, much lower risk, than, you know, deploying AI to formulate advice or, prioritize investment opportunities or or place trades. Right? So that so that's kind of the the spectrum that we're looking at here, and firms really need to do their homework to identify the risk, tie those risks specifically to the uses of AI. We've seen in the rapid growth of AI, gives me some pause or concern that firms will do this initial analysis and then AI will once again outstrip the controls that they put in place based on the initial risks that were identified as they begin to continue to deploy it in new ways. So this is one of those things that will constantly have to be revisited by firms, conducting that risk assessment tied to specific uses. So anytime there's a new use, a new deployment of AI or a new AI tool brought in, you wanna conduct that risk assessment and make sure that you adopt policies, controls, guardrails, guidelines for your staff, that specifically address, those risks. The other, obviously, is, disclosure. I don't see a lot of AI specific disclosure, for example, being embedded into, ADV, part two for for firms. But I would say, if your particular use of AI introduces material risks or conflicts of interest, I think the firm should consider full and fair disclosure regarding those uses, those risks, those conflicts, and how the firm mitigates those risks and conflicts. And then, of course, just the ongoing testing, for accuracy, for bias, and and making sure that there's validation review by some qualified trained human being, in the loop there. So those are my initial thoughts on on AI. And I could go on if you'd like me to. No. That that that's a great, you know, kind of grounding for us so much here. But the thing that I'm thinking about most is, does this change the way we look at third party risk in any way? Because a lot of these firms are not building homegrown AI technology. You know, advisors are are buying the biggest the best that's the right size fit for them, doing the testing they know to do, right, based on maybe their own personal use of AI. You know, they may not have an expert in house that knows how to test whether this is working properly. And then exactly what you said, they have to figure out when is the time to test this again to ensure it hasn't out control the control environment we put in place. Right? So how are you thinking about third party risk? Any changes to to the way people deploy their current vendor vendor risk program, vendor risk management program, any heightened risk from a due diligence perspective when you're deploying AI, or is it more of the, you know, follow the current fiduciary duty standard and and then, you know, do the do your best? Kinda what do you think about when you think about how you should view third party risk? Yes and yes. I think the current fiduciary standard would require that, based on the risk that that that our approach changes and evolves. Right? So, I think of if you are, I think you you hit the nail on the head. I mean, certainly, we're talking about our vendor due diligence. If we're looking at a vendor that is providing an AI tool or providing a functionality that has embedded AI capabilities, then we need to be asking all of those appropriate questions around, the development bias. What about this information? What happens to all the information that I input here? And I know a lot of firms have begun experimentation through enterprise licenses, with some of the larger, AI specific vendors and and tools. But I'm really mapping, your data, having an another is, even just looking at our vendors, that may not be specifically AI or have AI embedded in them and understanding what sort of sub vendors they use that may have AI tools that and and, whether those AI tools have access to your information and what happens to that information once it's out of your hands and in the vendor's hands. So really robust due diligence around this. And look, we need to be able to explain, we need to have some explainability around AI, the tools that we use, but I I sort of liken this to, you know, to driving a car. You know, you need to show, the officer how you, drove that car in a safe manner. You operate it in a safe manner, but you don't necessarily have to explain how the engine runs. So I I think, you know, not necessarily having technical transparency, but some sort of functional transparency around the tools that you've adopted and that you are using, to serve your clients is is a requirement of fiduciary duty. Love the car analogy, Ned. Also, like that you highlighted fourth party risk because that is gonna be something that I do think folks should consider. Right? Now that everybody's got their hands on AI, you know, what is not just the third party but the fourth party risk to you deploying these type of tools. Gail, anything you wanna add? Yeah. Just a couple of thoughts. The first is that we were hearing a lot of questions from our members, and I'm sure you you're hearing the same thing. It's around these note takers transcripts, you know, whether or not prompts need to be retained. I think those are are hard questions, and we're pleased to to hear, and it's not it's not official, but we think that, we're looking at the record keeping rule partly because of AI, partly because of the off channel cases, but we think we're gonna see that on the SEC's agenda. We think the SEC is gonna be working on it, and we'll try to address these questions. The challenge is how you update a rule to make sense and and still be future proof. Right? So that it it it, doesn't ask for more than it needs. It doesn't make you keep more than more than you have to keep. It doesn't sort of increase litigation risk unnecessarily, but it still, meets the the SEC's policy goals of of giving exams, what it what it needs to be able to see. But that's an area where we're getting a ton of questions. The other point I'd make is that this SCC is not just, comfortable with innovation and AI. It is affirmatively, promoting use of AI both internally at the SCC and among advisers, which is which is very interesting. You know, the the technology as MedCities developing way faster than governance frameworks or or than regulatory frameworks can deal with it. So so these are some, really big, challenges. We at the IAA have set up an AI working group. We have calls at least once a month, sometimes more frequently, and we have we've never had fewer than a 100 people on each call. So these are very live issues. Folks are grappling with them, and they keep on becoming more complicated. Yeah. A couple couple quick responses to that, Gail. Thank you. Very interesting. I was not aware that the SC might be looking at the AI note takers and the record keeping. I think in the interim, what we have heard people say is, look, if it's, if this note taker is not creating a record that will be, wholly or partially client facing in any way, put into some sort of client communication, then it's probably not a required record. I tend to push back on that because I think it's very content specific. If you have a wholly internal conversation around, that involves the investment committee and it's around a particular investment choice and what what the basis was for a recommendation or why you're gonna vote proxies in a certain way, that directly implicates books and records requirements under rule two zero four. So, so I think it's right now, at least, barring new guidance from the SEC, a very facts and circumstances case whether those are required records. The other thing is, yeah, just to I think it was in February, the current director of, the division investment management expressly, offered to, to the industry engagement around AI and how that could be, how tools could be implemented, in a way that is, that safeguards, the best interest of investors. So that I think that was very refreshing coming from, from Brian Daley soon. It's a great point to kinda end on that, again, this is not something that you should be worried that the SEC is gonna come in and wonder why you're doing it, but they are understandably embracing it and expecting to see it. So it's about having your story around governance and what you're doing and due diligence and and and using these tools to, do better compliance and risk management. So thank you, Mitt, for that. Oh, sorry. Do we gotta add something else there? Yeah. Just quickly. I I think there is a history around the reluctance. Right? And and Brian Daley in that speech specifically mentioned, anytime there's a new, technology that's sort of introduced into into the industry, algorithmic trading, for example, there is sometimes a flurry of enforcement activity, and that has left the industry a little bit reluctant to just jump on the bandwagon. So I think that was the whole point of his speech as I as I understood it, was to try to counter that, reluctance. Couldn't agree more. And I continue to see him in other spaces because he's been speaking a lot. He's on the speaking circuit talking about this very issue. So, great point to make, Mitt. So just to move us on so we make sure we stay on time. Reg SP, I'm gonna start with the polling question, and then I'll I'll key up Gail to take us away. So have you conducted a tabletop exercise to test your breach notification process? A, yes, b, no, c, n, a. And we'll let you all submit your answers, and I'll have Gail move forward with telling us a little bit more about where we are with REG SP. We're getting close. Right, Gail? Yes. Well, we're we're we're we've dipped one leg in, I'd say. It's been a gone into effect, right, in December Right. For what's what's the right? What they call the larger firms, which is $11,500,000,000 in AUM or more. And for everybody else, it's gonna go into effect on June 3. So, you know, I'm gonna build on the questions, on the polling questions, you know, by focusing on sort of what's actually changed, what is what is the rule expect you to do, what should firms be doing right now. So what has changed, firms now need a formal incident response program, not just policies, but you have to have the ability to detect, assess, contain, and respond to incidents in more or less in real time. And this means that you have to operationalize your incident response plan, not just sort of have it sitting on the shelf. There's also now a mandatory breach notification requirement for, for customers or clients if if we're talking about advisers. And this is triggered by unauthorized access to sensitive customer information or the likelihood that sensitive customer information was accessed. Notice is required within 30 of becoming aware of that breach. And we're seeing and this this goes back to the third party risk vendor issue. We're seeing a significant, expansion in expectations around vendor oversight. And this includes an expectation that that you will have policies and procedures reasonably designed to ensure that your, service providers will give you notice within twenty two hours of a breach of their systems that that that store, customer information, not even sensitive customer customer information. The SEC will expect firms to understand what data they have, where it is, and what is sensitive. And then, of course, there's record keeping. And firms will have to document the incidents, their investigations, and very importantly, their judgments and and decisions. So in practice, this has required firms to build out data mapping, incident response playbooks, vendor frameworks, and it's a it's a very meaningful and significant infrastructure lift. We had pushed pretty hard to try to get an extension when, this administration came in. One of the first, things that they did under acting chair, Ueda, was to, issue some extensions for rules that for for some recently adopted rules. And for some reason, just would not issue an extension for SP even though it was such a lift for people to get ready. And they've also begun, exams right out of the right out of the gate. This was one of the few, if not, perhaps the only I don't wanna say the only without confirming, but one of the very few, rules under the Gensler administration that was unanimously adopted. And so we can understand that there was some reluctance to, issue extensions and and, of course, people at the SEC and everywhere are very concerned about a big data breach and not, you know, having being being sort of thought to have been asleep at the wheel. So these are have gone into effect, are going into effect. And what we're hearing from our members, you know, the biggest implementation challenges are around these gray areas. The rule is very clear at a high level and some elements of it are very clear. But there are some key points where, it's not entirely clear what you need to do and what the triggers are. So for example, the notification trigger. When does an incident become reasonably likely to, you know, for a system to have been accessed or information to have been accessed? When does it, when when do you become aware that it involves sensitive customer data? What does it mean to cause substantial harm or inconvenience? Though those things are really, there's there's a lot of judgment involved there and that these terms aren't clearly defined. And so firms are are really having to make these, judgment calls in real time. I would say that vendor oversight may be the biggest challenge here. In particular, we're hearing, concerns around the seventy two hour notification requirement that, the SCC expects from service providers. And this, of course, is even before it's determined whether or not the information is sensitive. Firms are dealing with vendor pushback, contract limitations, and limited transparency into their vendors, and really struggling with, what if you can't get vendors to commit to giving you seventy two hours to giving you notice within seventy two hours. And what if they say they're going to, but then they don't? And, like, it what when will the SEC sort of come and, issue a deficiency or or worse than enforcement action? Because at the end of the day, the adviser is still responsible. So I'll come back to that in in a in a minute. But exams have started, as I said. So what are we seeing so far? The FCC is approaching this in a pretty structured, way, and it's it's really diving deeply into the technology. It wants to see your risk assessment. It wants to see, you know, what what documentation you have. It's doing interviews. It it's really looking at testing and and thinking about sort of doing its own, sort of reality checks but in detail. They're looking at, does your program accident actually works? So not just policies, but, how are you operationalizing your your incident response plans, what are your monitoring tools, and how are you evidencing detection and response. You know, documentation is is obviously a big one here, and staff are wanting to see what data was involved, how decisions were made, and why you've made the judgment that notification was or wasn't required. So it's more than just, you know, show me your policy. It's really show me your process and then show me how the process works. Going back a little bit to vendor oversight, I think that exams, what we've heard is that they're looking at what kinds of terms you've managed to agree to with your vendors, not necessarily via contract service level agreements there. You know, do you have certifications? What what are you doing to get to a reasonable assurance that you're gonna get notification? What due diligence are you doing? How are you monitoring your vendors to to make sure that nothing's falling through the cracks? And, you know, what else are you doing to meet your own notification expectations. Phones should be able to demonstrate the the data inventories and how they got there, their risk assessments, and they they need to show that they understand their data flows, and and who has what. We haven't yet seen, observations come out of the exams division, and we were hoping, but I think it's it was probably a little way too optimistic, not a little, that we would get something like a risk alert before the June deadline for the sort of second batch of compliance. I think that's it's unrealistic to expect that. It'll take a while for exams to put its, observations together. But at some point, we will see a risk alert come out with what they're seeing, where they think the deficiencies are. And I think the deficiencies that we'll see early will be around you didn't even know there was an a rule amendment. Right? Like, have you been asleep at the wheel? But they'll also be around whether or not your policies are gonna be deemed to be reasonably designed, whether you have okay policies, but you may not be following them, properly. You know, or in some cases, you don't have policies at all. So, you know, it it is early days. From our perspective, I just, you know, kind of wanna end with this maybe. We have been actively engaging with SCC staff on some of what we understand from our members are the hardest issues. And this includes the seventy two hour vendor notification requirement. And also when does the duty to notify customers when when is it actually triggered? Like, when do you become aware, of of a breach or or reasonably likelihood of a breach? We are continuing to work with them. We think that in these two areas, guidance would be guidance some kind of relief. Right? Whether it's a no action position or guidance would be enormously helpful for advisers. This SEC and and the investment management staff are quite open to talking to us about about guidance, but we've been pressing them now for several months to get something out quickly. And, you know, we're we're working through it with them. The, the staff really has some bandwidth issues. We talked at the beginning about loss of staff across the board at the SEC. Investment management has lost the most in terms of percentage, of of all the divisions. It's, I think, 23 or 24%. It's where it's it's it's high. So a lot of expertise has gone away, and a lot of people have gone away. But but Daly, in particular, has talked about being open for business in terms of engagement and and really wanting to listen. So we are taking him up on that and we're we're really trying to get guidance. And hopefully, we'll get some relief around the seventy you know, what it means to have policies that are reasonably designed to ensure the seventy two hour notification. So I'd say that's you know, those are the high points or low points depending on how you're looking at a a reg SP. Again, you know, documentation, monitoring, be ready for production. These are gonna be critically important. I think you highlighted the the main thing that people are still wondering what is gonna be the judgment call notification. You know, prior to this, you have a level of judgment inside your own firm. So there's this idea that I wanna remediate I kinda wanna know how bad this is before I start ringing alarm bells. Right? And and you had a little bit of a leverage on other issues before you started notifying clients from definitely from our perspective. So it's trying to figure out, like you said, how to engage with the SEC. I love that they are open to hear and talk to folks. Vendors most vendors that we are aware of and and obviously comply, we are submitting to this. We are we are absolutely going to make sure our clients can rely on us to be responsive in that time frame, but we recognize that it's gonna be, depending on the issue, it's it's going to be an experience. Right? So I I do think we'll we'll try to get more, like you said, from the commission on this. I'd love a risk alert. You you hit it, Gail. So, hopefully, if somebody's listening and watching this, they they say, okay. You know, we heard you from Gail. We heard you from Gail. We heard you from Gail. Mid nodded. And we get something more around timing because that's gonna be the criticality. You know, folks like us, we've been in the industry for a long time. Remember when BCPs, business continuity plans, were big time tested as an examiner, like, going to a firm and being like, let me see the hot site, coal site. Let's run the plays. You know, this is a little bit different in that it's data and it's systems, and there's nowhere to go. And there's not a, you know, off-site place I gotta go and look at boxes on shelves. Right, Gail? But it's even more important. And to your point about expectations, I think you don't have to go anywhere, but you gotta get the right vendors. You gotta have the right oversight. You gotta stay on top of it, because it's more risky now that this is not physical in the way that it was before, but it's it's data that can be abstract I mean, really just, taken away in a in a blink of an eye with a quick attack or breach. So, I am happy we have this. I do think you're right, Gail. This is something that all the commissioners agreed on because they recognize the risk. Right? And they don't wanna have a fallout, but but interested to see how how compliant firms can be, given that very short period of time to notify clients. I don't know, Matt. Anything you wanna add? I think, I I mean, I've witnessed firms sort of struggle with this issue. I would love to see some guidance. My thought is the standard imposed on investment advisers is reasonableness, that their policies be reasonably designed, to address the risk, to address the the regulation. And as long as they have done that and have discharged their duties under those policies or, you know, running those policies appropriately, then we we should be fine. That and that's a big should. Right? I don't know. But the SEC does not regulate these third party vendors, and it seems to me that this SEC potentially comes dangerously close to being susceptible to some of the criticism that was levied against the last administration under some of the rules that had previously been withdrawn. You know, that that, the FCC is not the regulator of custodians or, you know, some of the the the that criticism that we saw under the safe safeguarding or, rule of cybersecurity rule. So so I'm hopeful, that that we get that guidance because I don't think that's a position that this SEC wants to be in. And then one observation that I would make and maybe a caution to the industry, some of the very large firms that we work with, a few of them had reached out to, all of their vendors again and asked for refreshed vendor due diligence under this, amended reg SP, and they got reams and reams and reams of documentation. So now they're sitting on reams and reams of documentation and someone needs to go through that and find the necessary information. Now look, maybe AI can help with that. But, in the interim, we know that sort of creates some risk in and of itself. So when when, submitting these requests to vendor due diligence, I think we wanna be very specific around what we're looking for. Are there written policies and procedures that require that you will adopt, that will require this notification within seventy two hours? Can you show me the the escalation, methodology? What are the handoffs? Are there time frames, linked to specific reviews and things? And and that is gonna make the adviser's job so much easier, just sort of lessons learned from round one, that I wanted to share there with the with the the audience. That is a great point. And you're you're spot on. Reams and reams of of data paper, you know, for lack of better word. You're you're you're right in getting specific on answering the call for Reg SP versus trying to solve for other issues like vendor due diligence, third party risk management in this exercise. Alright. Well, Ned, thank you. Thank you, Gail, for giving us some insights on RegSP. Our final topic is the marketing role, and I'll start with a polling question. So given the December 2025 risk alert, have you increased or enhanced documentation for marketing materials review? A yes, b no, or c n a. And, Med, you know, this is one of the topics where we are getting some risk alerts, and we are getting constant engagement since, this new new but not so new rule came out. And so I'd love to hear your views on the latest and greatest of what we've gotten from the commission and any changes in the ways things that things firms should be thinking about the the differences in what was highlighted in the risk alert. Yeah. So I guess I I would start initially thank you, Jamila, with noting that advertising by investment advisers has been a poor has been a perennial issue, if we wanna call it that, or regulatory risk area for almost a century, really. I mean, it it it was, misleading investment promotions and statements, you know, that that really led to to to getting us the Investment Advisors Act of 1940. So, this area has a a really long history. And in fact, that designation two zero six four dash one for the rule is a signifier that it was top priority number one under the anti fraud provision of that that act, to adopt adopt a rule. And that long standing rule, was obviously recently replaced in in 2022 with the the modernized marketing rule, that we deal with today, which consolidated, of course, that original long standing advertising role and and the cash solicitation rule, but it it introduced some new concepts, or at least consolidated a lot of concepts that were in a lot of other documentation, no action letters and position, papers and and enforcement actions around testimonials and endorsements in that framework, and requirements, third party ratings, requirements. And I think critically, the general prohibitions, which includes this explicit substantiation, standard now that I think is a a really I don't wanna say it was underestimated when the rule was first adopted, but, has become quite the lever, for the SEC. And I think we've seen that in in the latest risk alert. I think you're right. The we've had four risk alerts, since adoption of the role in 2022. First one was really like, hey. We're coming. I hope you understand the rule. I hope you've adopted some policies, and we've steadily moved on and kind of picked up and focused on various areas. And the latest one was December 2025, so I think that is most indicative of what we may see in terms of trends or what's coming in 2026 and beyond. And the one of the first things, just major themes is a misclassification, a failure to recognize that certain, arrangements were testimonials or endorsements that had to abide by the rule. And I think it's funny because I remember and think back to by way of analogy, the custody rule, this is a little more than a decade ago, 2013, there was a risk alert that came out where, staff identified failure to recognize the adviser had custody as a core deficiency with, I think it was one third or two thirds of advisers that were examined, fell victim to that. And, and then in 2014, that was reinforced. Again, the same, finding that you didn't recognize the ad custody. And the same sort of principle applies here under this risk alert under the new marketing rule. You can't comply with the rule if you don't recognize that it applies. So I think that's one major theme that we saw. Some of these are, you know, kind of ticking down the list of what the requirements are and just finding failures. Failures, with respect to disclosures that they're not clear and prominent, when required in the context of, disclosures around testimonials and endorsements, using smaller font, using a grayed out font, using hyperlinks to to bury some of those disclosures, failing to include compensation details, failing to to provide details around conflicts of interest and so forth. So so that's one major theme. The other is just oversight failures. Again, we're sort of taking down the requirements of the rule, having no written agreements in place, and again, no monitoring of of activity of the of promoters, no reasonable basis, for believing that, the promoter complied with the delivery of, required disclosure and so forth. So, all of that much of that also goes back to some of these specific circumstances not recognizing that the rule applies. So at this point, I think the FCC is not sympathetic to that any longer. We're years into this rule, And if it was, the first risk alert, I don't know that we would have necessarily seen that because we were had a much softer tone. Softier tone. We have moved on from that at this point. We're also seeing documentation failures that came up in that, 2025 risk alert, firms that could not produce substantiation of material claims, approval records, supporting, supporting materials around performance. So I think substantiation is emerging as kind of a centerpiece of of the SEC's focus around the marketing role likely to be a focus in in 2025. And just to refresh your memories, the rule requires that firms have a reasonable basis just to substantiate material claims at the time they are made in advertising. So the burden of proof is on the adviser, not not the SEC. The SEC does not have to prove that a material claim, is false or or misleading. And I think where firms are getting this wrong is they're trying to later reconstruct this substantiation when they're requested, and that's the wrong approach. We need to have this substantiation in place contemporaneously with the development of the marketing materials and before it is then disseminated. Another area where we're seeing some issues is that, and my staff of consultants have have highlighted this on a few occasions where they will test substantiation and go back to the firm and say, so you claim x and you point to this as your substantiation. This does not stand for that proposition at all. So I don't know who read this. So we wanna be very careful to make sure that our substantiating documentation actually stands for and supports the material plan that we're including in marketing materials. And there's and this actually was in the, the risk alert, and and I think we've seen it in recent cases where there's been inconsistent support, across channels for for claim the same claims made, across channels where the supporting evidence either differs or the claim is only substantiated in some context but not others, and we've kind of expanded the claim in on the website or some other tear sheet, and did not go back and update substantiating documentation. So that's that's another area. So the substantiation really has to be claims specific and firms need to be careful about that. One one thing that I typically recommend in this area for firms is to create, a substantiation, tracking matrix, which is just a simple, grid the way that I envision it, which repeats the claim, which materials that claim appears in, what substantiation or support the firm has, for that claim, where that substantiating documentation can be found. And then I also recommend typically that there'd be some kind of expiry date on that, depending on the context, depending on what the claim is. Because the claim might be material at the time. It might grow stale. The other thing with, substantiation, and then I'll, kind of pause for a little bit because I know I've been rambling, is this complication that AI adds. It introduces a a a new substantiation, I think, risk layer because AI can generate, claims that sound super credible, but are maybe not factually, supported. We know that AI can hallucinate. We also know that AI can be bullied into coming to the conclusion that you've gone round and round and wanted it to get to sometimes. So, it, you know, it can exaggerate, differentiation, include in implications. So I I think that adds another layer of risk, and we wanna be very, very careful. AI can be super helpful in creating copy or creating, material that can be included in marketing. But, if there are material claims, we wanna make sure that we have a human being that reviews, that validates, those claims and produces the supporting information, and keeps that in the firm's records. This is a great overview on substantiation. I agree with you, Ned. This is the the thing that most people focus on, and I don't think we were saying the word substantiation nearly as much before November 2022. We were talking about it thematically, but you're right. Everybody's focused on this and in a way that is necessary to keep up with the technology developments. Like you said, there are firms that kinda kinda automate disclosure reviews and and amendments via AI. Are you comfortable letting AI do that based on, you know, what it's gathering from the industry and or you do you need really to have every time a legal review, a compliance review? How are you really thinking about infusing not just the creation of materials from an AI perspective, but all of the governance and the disclosure framework, that would certainly save time, but is it the right use of AI right now? So I think we're we're really in the in the middle of of what we'll see more of, which is a development of marketing being scaled faster to clients, faster to prospects, but hopefully with well governed principles around it. Gail, anything you wanna add from a marketing perspective? And I know we'll have to to kinda round out the conversation soon. Yeah. No. I think, Meg, you did a you did an excellent job, and I actually got some great insights from you. So thank you. Of course. Well, with that, I'll kinda round it out. I'll give you a last poll question, which really hits on what focus areas are most important for you as you've been listening to our discussion. If you had an SC information next quarter, of these three areas would require the most immediate remediation? Is it, a, artificial intelligence compliance? Is it, b, reg SP implementation? Or is it, c, marketing rule compliance? So we'll let those answers come in, and I'll really just round it out, with some final comments from from Gail and Med on what compliance leaders should be doing now. I mean, Gail, we'll start with you. What do you think is the the single most important thing that our compliance leaders should be thinking about and doing right now? I'd say to really pay attention to what the SEC is saying about its exam and enforcement priorities. You have to focus on the areas that the SEC has prioritized, and those will always include fiduciary duty and conflicts, always include, as Ned alluded to, marketing, data privacy and cybersecurity, always include custody. And then I'd say use and controls around emerging technology. That's where your focus you should be looking at your programs holistically, but but focusing on where the SEC is prioritizing because it's trying to get its messages out publicly and then it sort of means what it says. Great. Matt, what about you? Yeah. I couldn't agree more. You definitely wanna focus where your regulator is focused, certainly. But, and just in any area that is an emerging risk area, this area is where you're looking for the So, so that risk analysis, I would say, if you are going to deploy AI in an AI in any way, you want to build out and maintain that AI inventory, and I would make that a a priority, at your firms. Thank you, Meg. And thank you, Gail, for such a robust dynamic conversation. I say this every time, but I can't wait till part two when we discuss where things have gone with the enforcement agenda and beyond. Before we wrap up, I wanna do a quick overview of some upcoming events.