Fiscal Year 2026 Examination Priorities

Fiscal Year 2026 Examination Priorities

United States

RAI-US-NA-EXAMINA-2025
Effective: October 1, 2025
In Force(In Force)
PolicyGovernance and OversightRisk ManagementTransparency and Disclosure
Export PDF

The SEC's 2026 priorities focus on AI oversight, cybersecurity, and data protection compliance for financial institutions.

Overview

The Securities and Exchange Commission (SEC) Division of Examinations (EXAMS) released its Fiscal Year 2026 Examination Priorities on November 17, 2025. This annual report serves as a strategic roadmap for registered entities, including investment advisers, broker-dealers, and self-regulatory organizations, outlining the specific risk areas the Division intends to scrutinize in the coming year. The FY 2026 priorities are grounded in the Division's four core pillars: promoting compliance, preventing fraud, monitoring risk, and informing policy. Under the leadership of Chairman Paul S. Atkins and Acting Director Keith Cassidy, the Division has emphasized a shift toward a more transparent and practical examination process, aiming to foster constructive dialogue with market participants rather than pursuing a 'gotcha' regulatory environment. The priorities reflect the SEC's commitment to protecting retail investors while acknowledging the rapid evolution of the financial services landscape through technological innovation.

For the 2026 fiscal cycle, the Division has identified several cross-cutting themes that impact the entire financial services ecosystem. These include the rapid adoption of emerging technologies such as artificial intelligence (AI), the escalation of cybersecurity threats, and the implementation of new regulatory standards like the 2024 amendments to Regulation S-P. The priorities reflect a dual focus on maintaining traditional fiduciary standards while addressing the complexities introduced by modern digital infrastructure. By publishing these priorities, the SEC aims to encourage firms to proactively assess their internal controls and align their compliance programs with the agency's mission to protect investors, maintain fair and orderly markets, and facilitate capital formation in an increasingly automated financial landscape. The document serves as a notice to the industry that the SEC will be looking for substantive evidence of compliance rather than mere 'check-the-box' exercises.

Definitions and Scope

In the context of the FY 2026 priorities, the term 'Artificial Intelligence' (AI) refers to a broad spectrum of automated technologies, including machine learning, algorithmic trading tools, and generative AI models used in client communications or investment decision-making. The SEC distinguishes between 'AI capabilities' (the actual technical functionality) and 'AI representations' (the marketing claims made to investors). A primary concern for the Division is 'AI washing,' defined as the deceptive practice of overstating a firm's AI integration to gain a competitive advantage. This practice is viewed as a violation of the anti-fraud provisions of the Investment Advisers Act and the Securities Exchange Act. Furthermore, 'Emerging Financial Technology' encompasses not only AI but also automated investment advisory services (robo-advisers) and alternative data sources used to generate alpha or manage risk.

The document also heavily references 'Regulation S-P' and 'Regulation S-ID' in the context of data protection. Regulation S-P governs the privacy of consumer financial information and requires firms to implement robust safeguards for customer records. The 2024 amendments to Regulation S-P, which are a major focus for 2026, introduce stricter incident response requirements and expanded notice obligations. 'Fiduciary Duty' remains the foundational legal standard for investment advisers, consisting of the 'Duty of Care' (providing advice that is in the client's best interest based on their profile) and the 'Duty of Loyalty' (avoiding or disclosing conflicts of interest). These definitions form the boundary for how examiners evaluate whether a firm's technological adoption compromises its legal obligations to its clients. The scope of the priorities extends to all SEC-registered entities, including investment advisers, broker-dealers, clearing agencies, and national securities exchanges.

Governance and Institutional Framework

The institutional framework for the 2026 priorities is centered on the Division of Examinations' authority to conduct risk-based oversight of the U.S. capital markets. The Division operates as the 'eyes and ears' of the SEC, utilizing a decentralized structure with staff across various regional offices to monitor thousands of registrants. Governance expectations for FY 2026 place a heightened premium on 'Board Oversight' and the 'Tone at the Top.' The SEC expects boards of directors and senior management to take an active role in supervising the firm’s compliance culture, particularly regarding the adoption of high-risk technologies like AI and the management of third-party vendor relationships. This involves ensuring that Chief Compliance Officers (CCOs) are sufficiently empowered and resourced to execute their duties effectively. The SEC has explicitly stated that a firm's compliance program must be more than a manual on a shelf; it must be integrated into the firm's daily operations and strategic decision-making.

Furthermore, the framework emphasizes the 'Compliance Program' as a living entity that must be tailored to a firm's specific business model. For 2026, the Division will evaluate whether firms have updated their governance structures to account for structural changes such as mergers and acquisitions, dual registrations, or the use of decentralized fintech platforms. The governance model also includes the role of Self-Regulatory Organizations (SROs) like FINRA and the MSRB, which the Division oversees through its own risk-based examination program. By focusing on governance, the SEC seeks to ensure that firms have the internal checks and balances necessary to detect and remediate compliance failures before they result in significant investor harm or market instability. Examiners will look for evidence of regular compliance testing, robust reporting lines, and a culture that prioritizes ethical conduct over short-term profit motives.

Technological Focus: Artificial Intelligence

Artificial Intelligence and Emerging Financial Technologies represent the most significant technological focus area for FY 2026. The Division will conduct targeted examinations to verify that firms' representations regarding their AI capabilities are fair, accurate, and not misleading. This includes a deep dive into the supervision of AI tools used for fraud detection, anti-money laundering (AML) monitoring, and back-office operations. Examiners will look for evidence that firms have implemented specific policies and procedures to monitor the outputs of these algorithms, ensuring that automated advice or trading decisions remain consistent with the firm’s regulatory obligations and the specific investment profiles of their clients. The SEC is particularly concerned with 'black box' algorithms where the firm cannot explain the rationale behind a specific investment recommendation or trade execution.

Beyond marketing, the SEC will scrutinize the 'Supervision of AI' in the context of portfolio management. This includes assessing whether firms are conducting adequate due diligence on the data sets used to train their models and whether they have implemented safeguards to prevent 'hallucinations' or biased outputs that could lead to discriminatory outcomes. The Division will also examine the use of AI in client-facing chatbots and automated communication tools to ensure that these systems do not provide unauthorized investment advice or fail to disclose their automated nature. Firms are expected to maintain detailed documentation of their AI testing protocols and the results of their ongoing monitoring efforts. The goal is to ensure that as firms embrace innovation, they do not lose sight of their fundamental obligation to provide clear and honest information to the investing public.

Cybersecurity and Data Protection

Cybersecurity and Operational Resiliency constitute a major focus area, particularly in light of escalating ransomware attacks and geopolitical threats. The Division will prioritize examinations of firms' incident response plans, data loss prevention strategies, and access controls. A specific emphasis will be placed on compliance with the amended Regulation S-P, which requires firms to maintain a written incident response program designed to detect, respond to, and recover from unauthorized access to customer information. This includes the new requirement to provide notice to affected individuals as soon as possible, but no later than 30 days after the firm determines that a breach has occurred. Examiners will review the adequacy of these notices and the firm's internal investigation procedures.

Additionally, the SEC will scrutinize 'Third-Party Risk Management,' assessing how firms oversee the cybersecurity practices of their vendors, especially those providing mission-critical services like cloud computing or financial reporting tools. This focus reflects the SEC's concern that a failure at a single major service provider could trigger systemic risks across the financial system. Firms must demonstrate that they have conducted thorough due diligence on their vendors and that they have contractual protections in place to ensure the security of customer data. The Division will also look at 'Identity Theft Prevention Programs' under Regulation S-ID, ensuring that firms have effective 'red flag' indicators to detect and prevent identity theft. In an era of increasingly sophisticated phishing and social engineering attacks, the SEC expects firms to provide regular cybersecurity training to their employees and to maintain a high level of vigilance regarding the protection of sensitive financial information.

Fiduciary Duty and Standards of Conduct

The SEC continues to prioritize the protection of retail investors through the enforcement of fiduciary duties and standards of conduct. For investment advisers, this means adhering to the 'Duty of Care' and the 'Duty of Loyalty.' Examiners will focus on whether advisers are providing advice that is suitable for their clients' financial situations and investment objectives, particularly when recommending complex or high-fee products such as private credit, non-traded REITs, or interval funds. The Division will also look for undisclosed conflicts of interest, such as revenue-sharing arrangements or affiliations with product sponsors, that could bias an adviser's recommendations. For broker-dealers, the focus remains on 'Regulation Best Interest' (Reg BI), which requires that recommendations be in the customer's best interest and that firms mitigate or disclose conflicts.

A specific area of concern for 2026 is the 'Cost and Performance' of investment products. Examiners will evaluate whether firms are considering the total cost of ownership when making recommendations and whether they are accurately representing the historical performance of the products they sell. This includes a review of 'Cash Sweep Programs,' where the SEC will look at whether firms are fulfilling their duty to seek best execution and whether they are adequately disclosing the interest rates and fees associated with these programs. The Division will also examine the use of 'Dual Registrants'—firms that act as both broker-dealers and investment advisers—to ensure that they are clearly communicating the capacity in which they are acting and that they are not steering clients toward higher-fee accounts without a clear benefit to the client. The overarching goal is to ensure that the interests of the firm are never placed above the interests of the investor.

Monitoring, Evaluation, and Enforcement

Monitoring and evaluation under the FY 2026 priorities are conducted through a combination of on-site inspections, remote examinations, and continuous monitoring of registrant filings. The Division evaluates the effectiveness of a firm’s compliance program by testing whether its stated policies are actually followed in practice. For instance, if a firm claims to use AI for portfolio rebalancing, examiners will review the underlying algorithms and the firm’s testing logs to ensure the technology operates as described. The evaluation process also includes 'Transaction Testing,' where examiners trace specific trades or client interactions to verify adherence to fiduciary duties and disclosure requirements. The SEC also monitors the broader market through its 'Quantitative Analytics Unit,' which analyzes large datasets to detect anomalies that might indicate fraud or systemic risk.

While the Division of Examinations does not directly impose fines, its findings can lead to significant legal and financial consequences. The most common outcome of an examination is a 'Deficiency Letter,' which outlines specific areas where the firm has failed to comply with SEC rules. Firms are generally required to respond in writing, detailing the steps they have taken to remediate the identified issues. Failure to adequately address these deficiencies can lead to follow-up examinations or a referral to the Division of Enforcement. Enforcement actions can result in civil penalties, disgorgement of ill-gotten gains, and industry bars for individuals found to have committed serious misconduct. The Atkins administration has signaled a preference for clear communication and 'Practical Compliance,' suggesting that firms that demonstrate a good-faith effort to remediate issues may face less severe outcomes than those exhibiting willful negligence or intentional fraud.

International Alignment and AML

The SEC’s 2026 priorities reflect an awareness of the global nature of financial markets and the need for international cooperation. This is most evident in the Division’s continued focus on 'Anti-Money Laundering' (AML) and 'Sanctions Compliance.' Firms are expected to maintain AML programs that comply with the 'Bank Secrecy Act' (BSA) and are tailored to their specific business risks. This includes conducting independent testing, establishing 'Customer Identification Programs' (CIP), and meeting 'Suspicious Activity Report' (SAR) filing obligations. The SEC coordinates closely with the Department of the Treasury’s 'Office of Foreign Assets Control' (OFAC) to ensure that registrants are not facilitating transactions with sanctioned individuals or jurisdictions. This is particularly critical in the context of global digital asset flows and the use of offshore entities.

Furthermore, the SEC participates in international forums such as the 'International Organization of Securities Commissions' (IOSCO) to align its approach to AI and cybersecurity with global best practices. As AI technologies are often deployed across borders, the SEC’s focus on 'Algorithmic Transparency' and 'Operational Resiliency' mirrors similar regulatory initiatives in the European Union and the United Kingdom. By aligning its examination priorities with international standards, the SEC aims to reduce regulatory arbitrage and ensure that U.S. firms remain competitive while maintaining the high standards of investor protection that characterize the American capital markets. This international alignment is crucial for managing the cross-border risks associated with global financial networks and ensuring that the U.S. regulatory framework remains robust in the face of evolving global threats.

Implementation Timeline

MilestoneDateNotes
Start of Fiscal Year 20262025-10-01Official beginning of the 2026 examination cycle.
Release of 2026 Priorities2025-11-17Formal publication of the Division's focus areas.
Reg S-P Large Firm Compliance2026-06-11Compliance date for large entities under amended Regulation S-P.
Reg S-P Small Firm Compliance2026-12-11Compliance date for smaller entities under amended Regulation S-P.
End of Fiscal Year 20262026-09-30Conclusion of the 2026 priority cycle.

Compliance Checklist

CheckRequired Action
AI Representation AuditReview all marketing materials and disclosures to ensure AI capabilities are not overstated (prevent AI washing).
Regulation S-P UpdateUpdate written incident response programs to meet the 2024 amendment requirements for data breach notification.
AML Independent TestingConduct and document the annual independent test of the firm's Anti-Money Laundering program.
Fiduciary Duty ReviewAssess whether recommendations for complex or high-fee products (e.g., private credit) align with client profiles.
Vendor Cyber OversightPerform due diligence on third-party service providers' cybersecurity and operational resiliency controls.
Algorithmic SupervisionEstablish monitoring procedures for AI-driven trading tools to ensure they operate within stated risk parameters.

Sources and References

SourceType
Plain English

The Securities and Exchange Commission's Division of Examinations has published its Fiscal Year 2026 priorities, signaling a focused oversight on how financial firms manage emerging technologies like artificial intelligence, bolster cybersecurity, and protect customer data. These priorities apply to all SEC-registered entities, including investment advisers, broker-dealers, clearing agencies, and national securities exchanges, serving as a roadmap for what examiners will scrutinize starting October 1, 2025.

Firms must pay close attention to several key areas. First, on artificial intelligence, the SEC will examine whether firms are accurately representing their AI capabilities and properly supervising AI tools used for everything from client communications to investment decisions. A major concern is "AI washing"—overstating AI integration to gain an unfair advantage, which the SEC views as a form of fraud. Second, cybersecurity and data protection are paramount, especially with new amendments to Regulation S-P taking effect. Large firms must comply by June 11, 2026, and small firms by December 11, 2026, requiring robust incident response plans and prompt customer notification for data breaches. This also extends to managing the cybersecurity risks of third-party vendors. Third, traditional fiduciary duties remain central, with examiners checking that investment advice is in clients' best interests, particularly for complex or high-fee products, and that conflicts of interest are properly disclosed or avoided. Anti-Money Laundering (AML) programs will also be under review for compliance with the Bank Secrecy Act.

While the Division of Examinations doesn't issue fines directly, non-compliance can lead to deficiency letters, follow-up examinations, or referrals to the SEC's enforcement division, potentially resulting in civil penalties, disgorgement of profits, or industry bans. A practical pitfall to avoid is treating compliance as a mere "check-the-box" exercise; the SEC expects firms to demonstrate that their compliance programs are actively integrated into daily operations and strategic decision-making, with strong board oversight and empowered compliance officers.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Fiscal Year 2026 Examination Priorities. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalDefinitions and Scope

    Applies to: All SEC-registered entities.

    A primary concern for the Division is 'AI washing,' defined as the deceptive practice of overstating a firm's AI integration...
  2. #2CriticalCybersecurity and Data ProtectionInvalid Date

    Applies to: All SEC-registered entities.

    requires firms to maintain a written incident response program designed to detect, respond to, and recover from unauthorized access to customer information.
  3. #3CriticalCybersecurity and Data Protectionas soon as possible, but no later than 30 days after the firm determines that a breach has occurred.

    Applies to: All SEC-registered entities.

    new requirement to provide notice to affected individuals as soon as possible, but no later than 30 days after the firm determines that a breach has occurred.
  4. #4CriticalInternational Alignment and AML

    Applies to: All SEC-registered entities.

    Firms are expected to maintain AML programs that comply with the 'Bank Secrecy Act' (BSA)
  5. #5CriticalInternational Alignment and AML

    Applies to: All SEC-registered entities.

    This includes conducting independent testing
  6. #6CriticalTechnological Focus: Artificial Intelligence

    Applies to: SEC-registered entities using AI for advice or trading.

    implemented specific policies and procedures to monitor the outputs of these algorithms, ensuring that automated advice or trading decisions remain consistent
  7. #7CriticalFiduciary Duty and Standards of Conduct

    Applies to: Investment advisers.

    providing advice that is suitable for their clients' financial situations and investment objectives
  8. #8CriticalFiduciary Duty and Standards of Conduct

    Applies to: Investment advisers.

    look for undisclosed conflicts of interest, such as revenue-sharing arrangements or affiliations with product sponsors
  9. #9ImportantCybersecurity and Data Protection

    Applies to: All SEC-registered entities.

    Firms must demonstrate that they have conducted thorough due diligence on their vendors
  10. #10ImportantTechnological Focus: Artificial Intelligence

    Applies to: SEC-registered entities using AI models.

    conducting adequate due diligence on the data sets used to train their models
  11. #11ImportantTechnological Focus: Artificial Intelligence

    Applies to: SEC-registered entities using AI.

    Firms are expected to maintain detailed documentation of their AI testing protocols and the results of their ongoing monitoring efforts.
  12. #12ImportantCybersecurity and Data Protection

    Applies to: All SEC-registered entities.

    the SEC expects firms to provide regular cybersecurity training to their employees

© Regulations.AI — created on 12-Feb-2026 using Gemini 3 Flash Preview