Financial Audit Management & Pre-IPO Compliance3 min readUpdated September 2026

What an SEC Exam Actually Tests, Versus a SOX Audit

A registered investment advisor lives under a different compliance regime than most businesses comparing FloQast and AuditBoard. For most registered advisers the SEC (or your state securities regulator, for smaller advisers), not the PCAOB, is the regulator that actually shows up, and what it tests, fee billing accuracy, custody arrangements, disclosure consistency, isn't the same thing a SOX 404 control framework is built around.

Understanding that difference first changes how useful either tool actually is for registered investment advisors (RIAs).

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

The Custody Rule Changes Everything

If a registered RIA has custody of client assets, directly holding funds or securities or having the authority to move them, SEC Rule 206(4)-2 generally requires an annual surprise examination by an independent public accountant (with exceptions, such as custody solely from fee-deduction authority), a very different process from a financial statement audit. Most advisory firms structure themselves specifically to avoid custody, using a qualified third-party custodian for client accounts, precisely to sidestep that heavier compliance burden.

Confirm with securities counsel exactly which of the firm's activities, including any authority to deduct fees directly from client accounts, might trigger custody rule obligations, since the answer changes what kind of audit and controls actually apply, well before either FloQast or AuditBoard becomes relevant.

Where Close Software Fits: Advisory Fee Reconciliation

Advisory fees billed based on assets under management, whether in advance or in arrears, have to tie precisely to the fee schedule in each client's agreement and to the actual AUM balance on the billing date. A fee calculated off a stale balance, or a tiered fee schedule applied incorrectly as a client's AUM crosses a breakpoint, is exactly the kind of error an SEC examiner samples directly.

Reconciling billed fees against the client agreement and the AUM snapshot used to calculate them, every billing cycle, is close-process work, and it's the kind of repeatable check close management software handles well: standardizing the template and enforcing a reviewer other than whoever manages that client relationship.

Check each billing cycle for these fee reconciliation points:

  • Confirm the fee rate applied matches the schedule in each client's agreement, including any tiered structure that steps down as assets grow.
  • Tie the assets under management balance used for billing to the actual balance on the billing date, not a stale prior figure.
  • Flag any account that crossed a fee breakpoint since the last cycle and confirm the calculation was updated to reflect it.
  • Document who reviewed the billing run and how any variance was explained, so an examiner can follow the trail.
  • Reconcile advance and arrears billing separately so timing differences do not hide an overbilling pattern.

Where a Documented Control Framework Fits

Separate from fee billing, SEC exams also probe the firm's documented policies and procedures, the ones required under the Advisers Act's compliance rule, covering everything from trade allocation to advertising claims to how conflicts of interest get disclosed. A firm can bill fees perfectly and still draw a deficiency letter if its policies exist on paper but aren't demonstrably followed.

A GRC platform is useful here mainly for larger, multi-strategy advisors that need to map policies to specific business activities and evidence that testing actually happened on schedule, rather than relying on the chief compliance officer's memory that a review took place.

A Worked Example: A Breakpoint That Never Applied

Picture a client whose account grows past the AUM level where the fee schedule steps down to a lower tier, but the billing system keeps charging the prior, higher tier because nobody updated the calculation when the account crossed the threshold. Over several quarters, that's a real overbilling that a client, or an examiner sampling billing records, will eventually catch.

A reconciliation that recalculates the applicable tier against actual AUM every billing cycle, rather than assuming last period's tier still applies, catches this the same cycle it happens, letting the firm correct and, if needed, refund the client proactively rather than explaining an overbilling pattern to an examiner months later.

Sequencing the Decision

If the firm's last exam or internal review flagged fee calculation errors or billing that doesn't tie to client agreements, fix that first with close management software; it's the discipline protecting the firm from the most common and most damaging kind of finding. If the firm is scaling into a multi-strategy or institutional business with a larger compliance team, a GRC platform helps organize policy testing and evidence across more activities than one compliance officer can track manually.

Either way, confirm custody status and required policies with securities counsel first. Those determine which controls actually matter before any software decision does.

Personal Trading and Conflicts Disclosures Round Out the Picture

Beyond fee billing, SEC exams also review whether the firm's code of ethics is actually followed: personal securities trades by advisory staff reported and reviewed against client holdings, gifts and outside business activities disclosed, and conflicts described in Form ADV matching how the firm actually operates day to day. A firm can bill fees flawlessly and still draw a deficiency if its Form ADV describes a review process nobody is actually performing.

Treat code-of-ethics attestations and personal trading reviews as a recurring compliance task with its own documented cadence, not an annual formality, since that consistency is exactly what an examiner checks for when comparing disclosed policy to actual practice.

Executive Capability Standard

What Good Looks Like

An RIA's compliance and billing operations are in good shape when advisory fees tie to the client agreement and current AUM every billing cycle, custody status is documented and confirmed with counsel, and required compliance policies are tested on a set schedule with evidence retained, not just described.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Confirm with securities counsel whether any of the firm's current activities could trigger custody rule obligations under Rule 206(4)-2.
2. Do Manually:Build a standard fee reconciliation template that recalculates the applicable fee tier against actual AUM every billing cycle.
3. Delegate:Assign someone other than the client's relationship manager to review and sign off on that client's fee calculation each cycle.
4. Automate:Deploy FloQast to standardize and time-stamp fee reconciliations, and add AuditBoard once the firm needs to test and evidence compliance policies across a growing set of business activities.
5. Buy:Engage a compliance consultant to conduct a mock SEC exam before the firm's actual next examination.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Does SOX 404 apply to a registered investment advisor?

Only if the advisory firm itself is a public company subject to SEC reporting requirements, which is uncommon for most RIAs. The compliance regime that actually applies to nearly all RIAs is the Investment Advisers Act, enforced through SEC examinations, not SOX.

How often should advisory fee billing be reconciled?

Every billing cycle, tied to the current fee schedule and the actual AUM balance on the billing date. Waiting until an annual review to catch a stale fee tier or an incorrect calculation lets an overbilling pattern compound across multiple cycles.

Do we need a GRC platform if we don't have custody of client assets?

Not necessarily. Avoiding custody removes the surprise examination requirement, but the firm still needs documented compliance policies under the Advisers Act. A GRC platform mainly helps once the firm is large enough that manual policy testing and evidence tracking becomes unreliable.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides