Ask ten registered investment advisors about email marketing and most will describe one of two positions: either they avoid it almost entirely because compliance feels like a minefield, or they send emails through a personal Gmail account with no real recordkeeping plan at all. Both positions come from the same gap: nobody at the firm has translated the SEC Marketing Rule into a specific, repeatable email process. The rule itself is not vague. What is missing is usually the workflow.
What the SEC Marketing Rule Actually Requires for Email
The Marketing Rule (Rule 206(4)-1 under the Investment Advisers Act) treats email the same as any other advertisement once it goes to more than one recipient or is a template used repeatedly, meaning it falls under the same recordkeeping, review, and prohibition rules as a printed ad or a website page. The specific obligations that trip up advisors most often:
| Requirement | What It Means in Practice |
|---|---|
| Recordkeeping (Books and Records Rule) | Every marketing email, including the send list, subject line, and any performance claims, must be retained, generally for five years, with the first two years in an easily accessible location |
| Testimonial and endorsement disclosures | Any client quote or referral mention in an email needs the same disclosures required elsewhere: whether compensation was involved, and any material conflicts |
| Performance claims | Any mention of returns or results in an email must meet the same net-of-fees, time-period, and comparability standards required in any other advertisement |
| Pre-review and approval | A designated compliance reviewer needs to sign off on template emails before they go out, and that approval itself should be documented and retained |
The Approval Gap That Actually Causes Violations
The most common failure is not a knowingly non-compliant email. It is a template built once, approved once, and then edited by a junior team member six months later without a second compliance review, because nobody built a process requiring one. A rule-compliant email program treats every edit to a template, not just the original send, as a new advertisement that needs the same review it got the first time.
CLIENT WORK: 360 Financial
BSPKN manages digital marketing for 360 Financial, an RIA whose team cannot risk a compliance gap in a single email send or social post. Every campaign for that engagement is built with the recordkeeping and disclosure requirements in mind from the first draft, not added as a review step after the copy is already written.
Building an Email Program That Survives an Exam
1. Store Every Send With Its Recipient List and Approval Record Together
An exam request is rarely just “show me the email.” It is “show me who received this, when, and who approved it.” An email platform or archive tool that captures the send list and the approval trail in one place removes the need to reconstruct that history under time pressure.
2. Route Every New Template and Every Edit Through the Same Reviewer
A single designated compliance reviewer, even if that is the advisor themselves at a small firm, should approve every net-new template and every material edit to an existing one. Minor copy fixes still count if they touch a performance claim, a testimonial, or a call to action.
3. Build a Standard Disclosure Block for Any Client Story or Quote
Rather than deciding disclosure language fresh each time a client story appears in an email, a pre-approved disclosure block that compliance signs off on once can be reused across every email that includes a testimonial, cutting review time without cutting the required protection.
4. Separate Educational Content From Promotional Content Clearly
Purely educational emails, market commentary with no specific product or performance claim, carry lower compliance risk than promotional sends. Building two clearly separated email tracks, one educational and one promotional, makes the review burden proportional to the actual risk of each email rather than treating every send the same way.
Third-Party Email Platforms Do Not Make You Compliant
A common misconception among smaller RIAs is that using a reputable email marketing platform, Mailchimp, Constant Contact, or a CRM’s built-in send tool, satisfies the recordkeeping requirement automatically. It does not. Those platforms retain send logs and open rates, which is useful data, but they do not track who approved the content, whether a testimonial disclosure was attached, or whether a performance claim was reviewed against the required standards before it went out. The compliance layer has to be built on top of the platform, not assumed to come with it.
What an Exam Request Actually Looks Like
When the SEC or a state regulator asks for marketing records during an exam, the request is rarely narrow. A typical request asks for every advertisement disseminated in a given period, the approval record for each, and the recipient list for each send. Firms that store emails in one place, approvals in another, and recipient lists in a third system routinely spend days reconstructing what should be a single export. Firms with an integrated archive can usually produce the full package within hours, which itself signals a mature compliance program to the examiner before they have reviewed a single email’s content.
A Realistic Timeline for Building This Out
A firm starting from no formal email compliance process should not expect to build a fully mature program in a week. A realistic path runs in three phases: first, designate a compliance reviewer and stop sending any new template without their sign-off, which can happen immediately. Second, within 30 to 60 days, move email sending into a platform that can archive send lists and approvals together, rather than in separate tools. Third, over the following quarter, build the standard disclosure blocks and separate the educational and promotional tracks described above, so future content can move through review faster without cutting corners.
Frequently Asked Questions
Does every email an advisor sends count as an advertisement under the Marketing Rule?
Generally, a one-to-one email to a single existing client discussing their specific account does not count. A template sent to more than one recipient, or any email promoting the advisor’s services or performance, does count and falls under the Rule’s advertising requirements.
How long does an advisor need to keep marketing emails?
The general books and records requirement is five years from the end of the fiscal year in which the advertisement was last disseminated, with the first two years in an easily accessible place. Firm-specific retention policies can extend beyond that minimum.
Can a financial advisor include a client testimonial in a marketing email?
Yes, since the 2021 amendments to the Marketing Rule, but only with specific disclosures about compensation and material conflicts, and the testimonial itself needs to meet the same standards required for a testimonial on a website or in a printed ad.
Read more on the compliance side of financial marketing in can financial advisors use client testimonials under the SEC Marketing Rule and why Google Ads for financial advisors burns budget without a compliance-built landing page, or explore BSPKN’s financial marketing services and the Propel system behind them.
Market Without Guessing at the Compliance Line.
Book a 15-minute strategy call with BSPKN. We will show you what a defensible, SEC Marketing Rule aligned email and content program looks like for an RIA, without slowing your marketing down to a crawl.
