Insights

What To Know About Compliance Before You Start an RIA

0
 min read
October 5, 2026

A few weeks after an advisor files to register a new RIA, the SEC writes back. The reply is titled a “deficiency letter,” and more than one founder has read that heading and assumed the firm was finished before it started. It wasn’t. That’s simply what the SEC calls its standard response.

That gap between how compliance looks from the outside and how it works in practice ran through “Cleared for Launch: Compliance 101 for New RIAs,” our recent webinar with Giovanni Corrado, founder and CEO of compliance consultant NextReg, and Antoine Lena, founder and managing partner of Twenty Five Capital Partners, an RIA that runs its compliance program with NextReg on Hadrius. Giovanni walked through the full path from forming an entity to sitting across from an examiner. Antoine described what that path looked like for a former UBS advisor who wanted his own firm.

EMBED

Three lessons stood out:

1. You have to be compliant from day one

Most advisors picture registration as the finish line. File the Form ADV, answer the SEC’s questions, receive the order granting registration, and then get to work. 

Not the case. 

“There is no grace period to be compliant,” says Corrado. “Approval is the start date.”

On the day the SEC approves the firm, the brochure and Form CRS need to be ready for every new client, and the website needs to meet the Marketing Rule. Books and records need to be running, including email and message retention, code of ethics administration and personal trade surveillance. A compliance calendar should already be laid out at least 12 months ahead. The first examination typically arrives within a year of registration, so the program an examiner reviews is the one you switched on at launch.

The practical consequence is that most of the compliance build happens before you file. Giovanni's process puts the policies, procedures and code of ethics in place first, alongside the technology to run them, so that approval flips a switch instead of starting a scramble.

2. Your policies have to describe a program you actually run

Here’s a problem Corrado sees often: A new RIA writes its policies and procedures before it has a single client. Then the business starts to operate, and within a few weeks, starts to deviate from the plan it has laid out.

Corrado was candid about it. Once a firm is live, NextReg runs a readiness review that checks whether custody arrangements match what was filed and whether the written policies match how the firm has started to operate. “Many times those things may not match at the beginning,” he said, so amendments follow.

3. Compliance shouldn’t stop you from launching an RIA

Before launching Twenty Five Capital Partners, Antoine spent his entire career at a large bank. He was used to compliance being a constant presence: reviewing every message, every LinkedIn post, every email and every trade. He heard from compliance roughly every other day.

So when he decided to go independent, he assumed the work would follow him, with the added weight of being responsible for all of it himself. Trade monitoring, keeping employees from emailing out sensitive data, putting guardrails in place and fixing mistakes when they surfaced. He described the prospect as grueling.

But that’s not how it turned out. Today his compliance routine is a weekly Hadrius report, plus one monthly call with NextReg to work through open items. “It's not that much time,” he said. “I know I have good backing.”

The change he values most is in the tone of the relationship. Before, compliance was the team that made the business harder to run. Now it’s the team he brings new ideas to, including the firm’s registration path, which has moved from the SEC to the state level and, he hopes, back again. “Now it’s easier,” he said, “and not a worry at all anymore.”

‍

Read the full transcript of “Cleared for Launch” below, and read how Twenty Five Capital Partners runs its program in our customer case study here.

‍

Transcript

Leonard DeFranco:

Hello and welcome to “Cleared for Launch: Compliance 101 for New RIAs.” My name is Leonard DeFranco, and I’m the editorial lead at Hadrius. Today we're talking about compliance for anyone considering starting their own RIA. It's a daunting obligation if you haven't gone through it before. In this session, we hope to show you a path that combines the right technology with the right partners, so that anyone considering launching an RIA has a clearer idea of how to meet this obligation and keep it from becoming a barrier to success.

As an introduction to Hadrius: we provide agentic compliance for financial services firms. We serve RIAs, broker-dealers and private wealth firms regulated by the SEC and FINRA. It's an end-to-end compliance platform that covers everything from marketing review to communications archiving, and even branch management once you're large enough to have multiple branches whose testing programs need oversight.

Today I'm joined by Giovanni Corrado, the founder, managing partner and CEO of NextReg, a compliance expertise firm, and Antoine Lena, a mutual customer of Hadrius and NextReg, who is the founder, managing partner and portfolio manager of Twenty Five Capital Partners in California. Gentlemen, thank you for joining me. 

I'll set the table for what we're going to talk about, and then pass it over to Giovanni.

RIAs carry a sizable burden. If compliance isn't handled well, RIAs spend about 100 hours preparing for upcoming exams, and they can spend an inordinate amount of time keeping compliance aligned, overseeing outgoing marketing materials, and archiving communications. It also tends to be costly. Of course, that cost doesn't compare with the potential damage of a finding, or a costly penalty from a regulator.

Many advisors considering going out on their own, to keep the full benefit of being an advisor and owning their book of business, see this as an intimidating barrier to entry. However, firms like NextReg, run by Giovanni Corrado, are here to help, which is why we want to tell you today why compliance shouldn't stop you from launching on your own. Giovanni, would you like to introduce yourself?

‍

‍Giovanni Corrado:

Of course. I'm Giovanni Corrado, managing partner at NextReg. We're a group of AI-powered chief compliance officers dedicated, through our partnership with Hadrius, to turning compliance from a pure burden and cost center into a strategic advantage: something you can leverage to launch faster and stay ahead of your competitors.

Launching an RIA compliance program

The path to registration

Some of you may be thinking about launching your RIA. You might be in the middle of it, or you may have already registered. Let's walk through it end to end.

The first step is registration: where we're going to register and how we're going to build that application. Are we coming into this with at least $100 million in assets under management, transferable within the first 120 days? If so, we go directly the SEC route. Not quite there yet? Then we evaluate a state-by-state approach. Are we launching a purely digital wealth offering? Then maybe we evaluate the internet adviser exemption.

Whatever the route, we eventually submit the Form ADV package to the applicable regulator, either a state or the SEC. Then there's a back-and-forth with that regulator until approval.

Once it's approved, and this is the important message, that's when the work really starts. We need to set up a compliance program, make sure our policies and procedures reflect the firm's actual day-to-day processes, and then run it for as long as you have your firm. An important milestone is your first examination, which you should expect within 12 months of registration. That's where all of that work shows up in practice in front of the regulator.

Now let's talk about what it takes to set up, build, file, get through review and go live, and why this doesn't have to be the blocker it so often becomes for people thinking about launching their own firm. Let's demystify it, go into the details, and look at what needs to happen and how we can help.

From setup to go-live

The first stage is setting up the entity that will be the registered investment adviser. We gain access to the applicable systems, such as IARD and FINRA Gateway, to start completing the application.

Then we move into the second phase, the build phase, before we file. This is where we craft the policies, procedures, code of ethics and so on that will accompany the firm and really dictate how it operates day to day.

Once those two things are in place, we get to step three on the screen: we file, either with state regulators or the SEC, and we await their response. When firms receive that response, they can have a panic attack, because it's titled a "deficiency letter." If we ever get to that point together, please don't panic. Antoine can attest that we prepared them for it. That's just what they call their standard response. Regulators can be a little dramatic at times.

That brings us to phase four: full review by the SEC. By law, they have 45 days to act, and the states follow the same parameter. Once the deficiency letter arrives, we put together a response, which has to follow very particular formats for these regulators, and we go back and forth with them until they approve the application. End to end, that timeline can run anywhere from 45 days up to 90 to 120 days, depending on the regulator.

And then we're live. In terms of regulatory fees, you'll pay $40 to $225 per year to stay active. There's no filing fee for the ADV itself. You'll also pay about $200 per year for each state where you have more than five clients, because that triggers a notice filing in that state. For an SEC-registered firm, it's a notice filing, not a full registration, with a simple fee.

State vs. SEC registration

If you're evaluating starting your own firm, this is the first question, and it's where we start: will we have $100 million in assets within the first 120 days, or not? There's no right or wrong answer. Of course we'd all like to have more, but this is the starting point.

If we don't have 80–90% certainty that we'll reach $100 million within 120 days of submission to the SEC, we go the state route and register state by state. What does that look like? First, by default, we register in the state where your principal place of business is; say Florida, New York or Texas. Where else do we register if we can't go SEC right away? In any other state where five or more of your clients are residents, with some exceptions, such as Texas, where a single client triggers registration. Everything else holds equal.

If we're more than 80% confident we'll reach $100 million or more in transferred assets under management, discretionary or non-discretionary, we go straight to the SEC through the 120-day exemption.

A quick note: if we had a reasonable basis to reach $100 million, but the 120-day mark after submission is approaching and we're not there yet, we can always drop down to the state level. It's not a super easy process, but it's definitely doable, and we've done it before.

What the Form ADV is

Many people view the ADV as a long, daunting government document written in a foreign language somewhere in Washington, D.C. It can be demystified and handled in different ways. But it is a disclosure document, not a form.

ADV Part 1A looks like a form, but in reality it's asking for your disclosures: your conflicts, how you handle marketing, how you charge fees, your assets under management and so on. But the core of the application is ADV Part 2A, the so-called brochure. It's a long, descriptive narrative document, unfortunately also written in regulatory language, where you describe your business. How do you charge? How do you invest? How will you put your clients' interests ahead of your own? How will you supervise the compliance program? Everything is in narrative format.

Your audience there is the regulator, yes, because they need to approve you. But it's also the client. Clients receive these documents at the start of the relationship and every year after.

So we work through it together and end up with a polished ADV Part 1A and a Part 2A brochure. We craft the ADV Part 2B, which is specific to the investment adviser representatives associated with the firm, so it's an individual-level filing. And we craft Form CRS, a one- to two-page summary of the 2A for your clients.

Another important component is preparing Form U4s for associated persons. While the SEC reviews your application, we want to be ready to associate you, the advisor, with the firm at the state level through a U4 filing.

What has to exist before you file

You need your entity and your incorporation documents. You need IARD and FINRA Gateway accounts. You need a named chief compliance officer, which is actually the only position the SEC requires you to list. And you need a technology tool that covers obligations such as code of ethics administration, marketing compliance, testing and communications surveillance. That's where a player like Hadrius comes in.

Submission through approval

Once all of this is in place and submitted, the journey to going live begins. As I mentioned, our average time to submission is about 30 days. The SEC has 45 days by federal statute to review the application and reply with a deficiency letter. That's 45 days to reply, not to approve: they have no legal deadline for approval, but they do have one to reply.

In this day and age, we're seeing a pretty fast turnaround from the SEC after submission. Our average from submission to approval is 30 to 45 days. So you can plan on 60 to 75 days, potentially 90, from beginning to end to go live.

Review with the SEC is iterative. They send a deficiency letter, we reply, they may send another, and we reply until it's done. Recently we've been getting to approval with zero, one or at most two deficiency letters.

After approval: compliant from day one

Approval is a start date. There's no grace period to be compliant; you need to be compliant from day one. That's why all those other pieces need to be in place the day the SEC issues its official order granting registration.

What happens at that point? With our final ADV, we deliver the brochure and supplements to every new client, along with Form CRS. We publish them on the website and make sure the site complies with the SEC Marketing Rule or the applicable state marketing rules.

Then, everybody's favorite part: we sign on clients. We have advisory agreements in place, which we help you draft alongside counsel. We help you deliver those agreements, onboard clients and bring the assets in. Then we start running the practice, making sure the fee schedule matches the brochure and the advisory agreement, and that the privacy notice goes out to every client.

Now we switch on the machine: books and records, which is where Hadrius really comes in, including email and instant message retention, code of ethics administration and personal trade surveillance. We launch the compliance calendar with owners and due dates, organized at least 12 months out, and turn on code of ethics reporting obligations for everyone at the firm.

Then we move into a compliance readiness audit to confirm all of this is in place. We run a small test to make sure custody arrangements match what was filed, and we compare the policies against how you've started running the firm. Those often don't match at the beginning, so amendments are needed. We also deliver the required training. And all of a sudden, you're running your own firm.

Running the program

Now we're live, clients are in and we have our own practice. What needs to happen from there? This is where the Hadrius and NextReg partnership really comes in. Some tasks happen daily, some weekly, some quarterly, some yearly and some ad hoc. You can see them on the screen. In our methodology, they're all laid out in a compliance calendar and carried out with the help of technology and the outsourced support we provide.

It's continuous work. In the moment it can feel trivial, like paperwork being pushed. But the moment the SEC or the state comes in, everything changes.

Examinations

Let's move to the last stage: what happens during an examination. Before the exam, we'll have the program running. But what actually occurs?

These are surprise examinations. That's how state regulators and SEC examiners work. You get a phone call, followed by a lengthy production list, and the conversation starts. Everything on that production list is what we'll have been taking care of daily, weekly, monthly, quarterly and ad hoc, over and over again. That's when you see the fruits of that labor: you'll be standing in front of an SEC or state examiner with an answer and the proper documentation in place. It all shows up at that moment, and the continuous work is for that one goal.

How do examinations work? There's an initial phone call, then a production list, then the production, which we help you deliver to the regulator, followed by interviews. Interviews can be on site, which the SEC recently picked back up in its regional offices, or remote, though remote is fading away. The SEC will either require you to come to them or come to your office. We assist with every item of the examination: the response to the production list, delivering the production, preparing for interviews with the regulator and any follow-ups afterward.

Then what are the outcomes?

The ideal outcome: you never hear from them again, which happens all the time. There's no "audit complete" notification from the regulator. They may simply never show up again, which is good news.

The more likely outcome is that they close the exam with a deficiency letter. It tells us what's working and what isn't, and that they expect improvements by the next exam cycle. How that first exam goes determines when they come back. If it goes well and the letter flags mild areas for improvement, you may be on a three-, five- or seven-year exam cycle.

If not, that leads to the other two possible outcomes. The first is that, if the deficiencies are significant, they'll monitor your firm continuously. You'll spend a lot of time fielding regulatory scrutiny and questions until those deficiencies are fixed. That's not ideal and it disrupts the business, but it's still not the worst case.

The worst case is that, for some firms, the deficiencies are so numerous and negligence is involved, that the Division of Examinations refers the case to the Division of Enforcement. If that referral happens, we're in lawsuit and penalty territory, which can be life-threatening for your firm and your reputation. Of course, our job is to make sure we never get to that point.

I hope this was helpful, Lenny. I'll turn it back over to you to bring in a tangible example.

Customer perspective: Twenty Five Capital Partners

Leonard DeFranco

Thank you for going through all that, Giovanni. 

What really stands out from your presentation is that this is an intimidating obligation to meet on your own. That's why very smart people like Antoine Lena have chosen to work with partners like NextReg, which runs the compliance program for Twenty Five Capital Partners on Hadrius.

Antoine, can you walk me through how you decided to meet the compliance obligation once you chose to go out on your own as an advisor?

‍

Antoine Lena

First of all, thanks for having me. 

I came from a wirehouse. I was at UBS for my entire career before launching Twenty Five Capital Partners. Compliance is a big piece of the business there. Compliance is always on your back, reading every message you send, every post on LinkedIn, every email, every trade.

So it was a little overwhelming when I was thinking about launching Twenty Five Capital to figure out how I'd run a business and also handle all of these things: trade monitoring, making sure none of my employees leak sensitive data through their emails, having the guardrails in place first, and then resolving the mistakes we do find. For me, it was grueling. 

I started doing some research and came across Hadrius, which referred me to NextReg. We started talking, and they helped me understand the lay of the land when it comes to compliance as a small startup RIA.

‍

Leonard DeFranco

You were considering joining an aggregator, and you decided against it. What would you tell an advisor who's weighing whether to go out on their own or join a wirehouse or an aggregator about what it's like to actually run your own firm?

‍

Antoine Lena

A big part of our business is how we communicate with our clients: what we can send out as newsletters, blog posts, and social media posts. Another is the way we manage money. We have a very customizable strategy. We're stock pickers, we like to invest in direct deals, we're true investors.

Coming from a wirehouse and talking to a lot of aggregators and other big RIAs, we found that you technically run your own business, but you abide by their rules, and you don't have the flexibility and freedom you think you have. For us, that was a big piece. We wanted as much freedom as possible and to be in control of what we can and can't do. It was important to find someone who could help us stay within the guidelines but still let us express ourselves the way we wanted to.

‍

Leonard DeFranco

Now that you're working with NextReg, the time you devote to compliance is basically one review session per month. Can you talk about what happens in those sessions, and how much time per week you actually spend thinking about compliance?

‍

Antoine Lena

It's not that much time. Probably should be a little more, but I know I have good backing. Every week we receive a report from Hadrius about our trades and our email: was any sensitive information sent out to clients in our emails? That gives me a pretty good idea of where we stand and whether we're doing things right.

On top of that, every month we have a conversation with our partner at NextReg and go over specific items. Do we have anything outstanding on our communications? Are all the trading accounts linked to Hadrius so we're monitoring our trades? If we have a new investment idea that falls outside the traditional RIA realm, what can we do there? How do we amend the ADV to reflect it and not get in trouble?

At UBS, I was thinking about compliance pretty much every other day, with a compliance email every other day. Now, once a month, we can talk about the problem we're trying to solve with a team that's as creative as we are.

‍

Leonard DeFranco

Spending very little time worrying about compliance is what we want to hear. Last question: what would you say to someone who says the compliance obligation is what's keeping them from starting their own RIA?

‍

Antoine Lena

Talk to NextReg. They've solved a lot of our problems. We went through a lot with them: SEC registration, then deregistration and re-registration with the state because we fell short of the $100 million minimum, and hopefully soon another re-registration with the SEC. They've been with us the whole time. They're part of the team, and we really feel like a valued client. The service is great.

When you're with a big aggregator or a big wirehouse, you don't feel like you're on the same team as compliance. More than peace of mind, we feel like we have a true partner that enhances our offering and our work rather than restricting it. That's where we come from: me at UBS, and my business partner at Morgan Stanley. Compliance made the business harder to run. Now it's easier and better, and it's not a worry at all anymore.

‍

Watch the full video recording of “Cleared for Launch” here, and read how Twenty Five Capital Partners runs its program in our customer case study here.

Share this article

Insights that Move Compliance Forward

Explore new ideas, proven strategies, and technology that’s transforming how firms stay compliant.

Enter your email below to opt-in
Unsubscribe anytime. By submitting, I agree to the terms and conditions of Hadrius.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
hadrius logo icon

We are Hadrius.

Hadrius is built for financial services compliance teams that demand more from their technology. Our privacy-first, policy-aware AI compresses review cycles, eliminates noise, and produces regulator-grade evidence on demand.

One vendor. One system of record.