When Compliance Policies and Practices Don’t Match
Investment advisers spend significant time developing policies and procedures designed to address the regulatory risks associated with their business. However, having appropriate policies in place is only part of an effective compliance program. Firms also need to ensure that employees follow those policies and that written procedures continue to reflect how the business actually operates.
This can become more challenging as hedge fund, private equity and other private investment firms grow. New employees join, investment strategies evolve, technology changes and teams develop new ways of working. Over time, day-to-day practices can begin to differ from the procedures outlined in the compliance manual and the code of ethics.
The differences are not always obvious. A procedure may appear to be followed while the underlying records tell a different story. In other cases, employees may follow a required process consistently, but the process itself may no longer address the risk it was designed to manage. Identifying these gaps requires firms to look beyond whether a policy exists and evaluate how it operates in practice.
Where Operational Gaps Commonly Occur
A compliance policy may be well written and still fail to reflect what happens in practice. For private fund managers, several areas can be particularly susceptible to gaps between written requirements and day-to-day activity.
Electronic communications: Firms may require employees to conduct business through approved and monitored communication channels. However, employees may use personal text messages, messaging applications or other unapproved platforms when communicating with colleagues, portfolio company executives, investors or other business contacts. Firms should consider not only whether off-channel communications occur, but also what happens when they are identified. Are the communications captured and retained? Is repeated activity escalated? Does the firm’s testing provide a reasonable way to identify communications taking place outside approved systems?
Personal trading: A firm's Code of Ethics may require employees to disclose brokerage accounts, pre-clear certain transactions and submit periodic holdings and transaction reports. Testing may identify unreported accounts, late certifications or transactions that were completed without required pre-clearance. Completed certifications alone may not demonstrate compliance if employees misunderstand which accounts, securities or transactions must be reported. Comparing certifications and pre-clearance records with underlying account information can provide a more complete picture.
Expert networks and outside research: Hedge fund managers frequently maintain procedures governing expert network consultations and other interactions that could present material nonpublic information concerns. A firm may have a clear approval process for formal expert network calls, while employees have separate conversations with industry contacts, consultants or other sources that do not go through the same process. Testing should consider how investment professionals actually gather information, including activity that may fall outside the firm's formal research channels.
Expenses and allocations: Private equity firms often maintain policies governing how expenses are allocated among funds, the management company, portfolio companies and co-investment vehicles. As new expenses arise, employees may make allocation decisions based on past practice rather than the firm's written procedures. A practice can be applied consistently and still create a compliance issue if it differs from the methodology described in fund documents or disclosures. Testing should therefore consider both consistency and whether the allocation methodology matches the firm's governing documents and stated practices.
Marketing and investor communications: Firms may require compliance review of marketing materials and investor communications before they are distributed. In practice, presentations, pitchbooks, due diligence responses, website content or other materials may be updated outside the established review process. A document may even receive the required compliance approval and then be modified before it reaches investors. Testing the process therefore means looking beyond whether an approval exists and confirming that the version distributed is the version that was reviewed.
Technology and artificial intelligence: Employees increasingly use new technology to support research, communications and other business activities. A firm's policies may address cybersecurity, privacy and approved systems without reflecting newer tools employees have begun using. This can include AI capabilities embedded within software the firm has already approved. Employees may believe they are using an approved platform while new functionality introduces uses or data considerations that were never evaluated as part of the original review.
The Harder Gaps to Spot
Not every compliance gap involves an employee clearly violating a policy. Some of the harder issues to identify occur when the required procedure takes place but does not produce the result the firm expects. For example, an employee may complete every required certification but misunderstand what needs to be disclosed. A marketing piece may receive compliance approval but be changed before distribution. An expense allocation may follow years of established practice but differ from the methodology described in fund documents. A restricted list may be maintained as required, but the people responsible for updating it may not receive information quickly enough to keep it current.
Firms should also consider whether information is consistent across their compliance manual, Form ADV, fund documents, side letters, investor communications and actual operating procedures. Each may appear consistent when reviewed individually, while comparing them can reveal differences in how the firm describes or carries out a particular practice. One way to approach testing is to compare three things: what the policy requires, what employees say they do and what the underlying records show actually occurred. A difference among the three can identify an area that warrants further review.
Practical Steps Firms Should Take
Identifying these gaps requires firms to look beyond whether a policy is appropriately written and test whether the underlying procedures are actually being followed. Sampling transactions, communications, approvals and employee certifications can help determine whether controls are operating as intended and identify patterns that may point to a broader weakness.
Firms should periodically compare their written compliance program with their actual business practices rather than waiting for an SEC examination to identify inconsistencies. This review can include:
Testing employee compliance with personal trading, political contribution and outside business activity requirements.
Reviewing the use of electronic communications and confirming employees are using approved channels.
Comparing approved marketing materials with the versions ultimately distributed to investors or prospects.
Sampling marketing and investor communications to confirm required compliance reviews occurred.
Reviewing expense allocation practices against written policies and governing documents.
Evaluating expert network and research practices, including activities that occur outside formal third-party platforms.
Identifying new technology and AI tools being used by employees and determining whether existing policies appropriately address them.
Comparing relevant provisions across the compliance manual, Form ADV, fund documents, side letters and other disclosures for inconsistencies.
Speaking with employees across investment, operations, finance and investor relations to understand how established procedures work in practice.
When testing identifies a difference, the next step is determining why it occurred. An isolated employee error may require training or follow-up, while repeated exceptions may indicate that a control is ineffective, a process has changed or the written policy no longer reflects the firm's operations. The appropriate response depends on the underlying cause, not simply the fact that an exception occurred.
Keeping Policies and Practices Aligned
Pillar Compliance Group works with investment advisers to test whether compliance policies and procedures are operating as intended. This can include reviewing records, sampling transactions and approvals, speaking with employees and comparing written requirements with actual business practices. Identifying inconsistencies before an examination gives firms an opportunity to determine whether an issue requires additional training, stronger controls, updated policies or changes to the underlying process. To learn more about how Pillar Compliance Group partners with investment management firms on their regulatory compliance programs, reach out to a member of our team.