By E.J. Yerzak

Chief Compliance Officers have never faced a broader mandate. As registered investment advisers (RIAs) complement their enhancements to cybersecurity programs for Regulation S-P and address emerging artificial intelligence risks, compliance teams are increasingly expected to oversee areas that extend well beyond traditional regulatory obligations.  

In addition to managing regulatory filings, disclosures, marketing reviews, and Code of Ethics reporting, CCOs are now expected to have visibility into  their firms’ cybersecurity controls and AI governance practices. This has prompted a common question among CCOs. “Am I personally liable if we have a cyber incident or an issue involving AI?”  

The answer, as with most regulatory questions, is it depends.  

CCOs can be personally liable when they are directly involved in violations of federal securities laws or fraudulent behavior, or when they are complicit in efforts to cover up such actions. However, where a CCO can demonstrate reasonably designed controls and effective oversight, personal liability is far less likely.  

Former Commissioner Luis Aguilar previously summed this up well in a 2015 speech, stating that enforcement actions are not typically brought against CCOs “who take their jobs seriously and do their jobs competently, diligently, and in good faith to protect investors.” 

While compliance expectations have expanded and it may seem as if CCOs are facing mounting personal liability, the current SEC administration under Chair Atkins appears to be focused more on misconduct and investor harm, and less on technical violations. SEC enforcement actions have found CCOs personally liable for willfully aiding and abetting misconduct under certain circumstances. Recent cases have involved CCOs who backdated annual compliance reviews, falsified trading pre-clearance forms, or failed to address recidivism for prior deficiencies cited by SEC examiners.  

CCO liability cases tend to involve one or more of the following: 

  • Gross negligence by the CCO (a higher bar than ordinary negligence) 
  • Willful, active participation in a violation or in attempts to hide it through backdating, backfilling, or falsification of records 
  • Careless disregard for a violation (awareness that the violation is occurring but failing to take any action) 
  • Becoming aware of a violation and trying to hide it, sweep it under the rug, or back-date compliance records to obfuscate it 

Rule 206(4)-7 under the Investment Advisers Act of 1940, otherwise known as the Compliance Program Rule, requires RIAs to appoint a qualified and competent Chief Compliance Officer responsible for administering policies and procedures reasonably designed to prevent violation of the Advisers Act and accompanying rules. Rule 204-2, the Books and Records Rule, requires RIAs to maintain accurate records. Both of these as well as the general anti-fraud provisions of Section 206(4) of the Advisers Act are often cited in CCO liability cases.  

RIAs can be cited for failing to follow their own policies and procedures. However, the CCO’s role is generally one of oversight and administration. A CCO is not responsible for physically holding each employee’s hand to complete every task assigned to that employee. Compliance’s function is one of implementing reasonably designed policies, monitoring for compliance, and taking remedial action for violations.  

Although the scope of compliance responsibilities has expanded, it remains unlikely that CCOs will be held personally liable for the failure of other advisory personnel to follow a policy exactly to the letter, provided that the CCO can demonstrate efforts to inform, monitor, and, where appropriate, effect disciplinary actions. And while Rule 206(4)-7 requires a designated CCO to be qualified and competent, that doesn’t equate to competency in everything. Knowing when to delegate tasks or functions and when to bring in outside experts is a key quality of a competent CCO, particularly when it comes to emerging risks like cybersecurity and artificial intelligence that may lie outside a CCO’s core competency .  

Burying one’s head in the sand in the wake of expanding workloads and expectations is not an option. While CCOs are not held to guarantee perfect compliance by all their staff, disregarding known risks and failing to address identified issues remains relevant to the role. The expectation is not perfection, but reasonable oversight, timely escalation, and good-faith action when risks are identified.