RegTech becomes non-negotiable for US investment managers

RegTech

US investment managers are being warned that 2026’s regulatory landscape is not lighter, just sharper, as the SEC narrows its focus to fraud and demonstrable investor harm while raising the bar on what counts as genuine compliance.

According to Leo RegTech, under new SEC chair Paul Atkins, some in the industry have taken the redirection of examination and enforcement resources as a signal to relax. Practitioners, however, note that smaller average fines do not mean reduced scrutiny.

Leo RegTech recently discussed the compliance platform imperative of why investment managers can’t afford to wing it.

The SEC’s Division of Examinations continues to prioritise retail investor protection, RIAs’ fiduciary duties and the strength of their compliance programmes.

The Division’s fiscal year 2026 priorities, published in November 2025, single out marketing, valuation, trading, portfolio management, disclosure and filings, and custody as core risk areas for investment advisers, investment companies and broker-dealers alike. Conflicts of interest and documented standards of conduct sit alongside emerging concerns such as cybersecurity, due diligence and the newly amended Regulation S-P.

AI governance is drawing particular attention. Examiners will assess whether firms’ actual use of AI matches what they tell clients and regulators, meaning managers who claim AI supports portfolio management must show it genuinely shapes investment decisions rather than functioning as background research, backed by documented processes and audit trails.

Regulation S-P adds a hard deadline to the mix. The amendments, updating privacy and data security rules under the Gramm-Leach-Bliley Act, require incident response planning and breach notification, with large firms above $1.5bn AUM already required to comply since December 2025 and smaller firms following by June 2026.

Firms must be ready to produce incident-response programmes, risk assessments, breach logs and vendor-oversight records on short notice, meaning policies parked in a shared drive will not suffice.

The CFTC layer brings its own risks. Managers relying on CPO exemptions under Rule 4.13 or CTA exemptions under Rule 4.14 must complete an annual affirmation via the NFA’s Exemptions Filing System, or risk automatic withdrawal of their exemption. A December 2025 CFTC no-action letter did offer relief, allowing many SEC-registered private fund managers to opt out of CFTC registration, though claiming that relief still demands careful documentation.

Across the SEC, FINRA and CFTC, the message is consistent: compliance programmes must be demonstrably effective, not just written down. Fragmented approaches, and reliance on spreadsheets, checklists and institutional memory, are increasingly viewed as exposure rather than flexibility.

Firms are being pushed toward integrated platforms capable of monitoring, detecting, escalating and evidencing compliance activity in real time, as good infrastructure becomes as essential to compliance as good intentions.

Read the full Leo RegTech post here.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.