Broker-Dealer Compliance Requirements: What Firms Must Maintain

Operating a broker-dealer requires considerably more than obtaining FINRA membership and maintaining a Written Supervisory Procedures manual.

A broker-dealer must actively manage, implement and test a supervisory and compliance framework that reflects the business the firm actually conducts. Depending on the firm, that includes supervisory procedures, supervisory controls testing, office inspections, Anti-Money Laundering requirements, books and records, regulatory filings, financial responsibility requirements, communications review, continuing education, registration oversight, privacy and information security requirements, and obligations tied to particular products or customer types. And that's just the short list.

There is no single compliance program that is appropriate for every broker-dealer. A small private placement firm should not have the same compliance program as a retail introducing broker-dealer, and neither should look like a clearing firm or market maker. The firm's customers, if any, services and products, compensation arrangements, office structure, handling of customer funds or securities, and role in transactions all affect what the compliance program needs to address.

One of the first questions is whether the firm's compliance structure actually matches its business. The procedures need to address the applicable requirements, the required reviews and testing need to occur, and the firm needs to be able to demonstrate what it did. If you are new to the regulatory world, a useful way to think about this is simple: if there is no evidence that an activity occurred—documentation or some other memorialization—a regulator may treat it as though it did not.

The Supervisory System Is the Starting Point

FINRA Rule 3110 requires every member firm to establish and maintain a supervisory system reasonably designed to achieve compliance with applicable securities laws, regulations and FINRA rules. It also requires written procedures to supervise the firm's business and the activities of its associated persons.

A useful WSP explains how the firm complies with a requirement in practice. Depending on the subject, that may mean identifying who performs the review, what is reviewed, how often it occurs, what evidence is retained, what constitutes an exception, and how an exception is escalated or resolved.

A procedure may state, for example, that a designated principal reviews a particular report each month. During an examination, the more important questions are whether the review actually occurred, whether exceptions were investigated, and whether the firm retained evidence of the review.

WSPs also need to change when the business changes. A new product, new office, new compensation arrangement, change in clearing relationship, expansion of retail activity or other significant change may require changes to the supervisory process itself, not simply another paragraph in the manual.

While the WSP is the foundation of the supervisory system, an experienced compliance officer knows that a clear and accurate manual is only the starting point. Even an excellent WSP is of limited value if the people responsible for carrying out the procedures do not understand or follow them. The firm needs to communicate relevant procedures to the supervisors and associated persons whose activities they govern and have a way to determine whether those procedures are actually being followed.

This is where supervisory controls testing, office inspections and other reviews begin to tie together. The point is not simply to establish what the firm says it will do. The firm also needs processes designed to determine whether it is actually doing it.

There Is More Than One Annual Review

Broker-dealer compliance includes several annual requirements that are sometimes grouped together as an “annual compliance review.” That shorthand can be misleading because the requirements are different.

FINRA Rule 3110(c) requires a review, at least annually on a calendar-year basis, of the businesses in which the firm engages. The review must be reasonably designed to assist the firm in detecting and preventing violations and achieving compliance with applicable securities laws, regulations and FINRA rules.

Rule 3120 addresses supervisory controls. A firm must designate one or more principals to establish, maintain and enforce supervisory control policies and procedures that test and verify that the firm's supervisory procedures are reasonably designed. When testing identifies a need for additional or amended procedures, the firm is required to address it.

The designated principal or principals must also provide senior management, no less than annually, with a report detailing the supervisory control system, a summary of test results, significant identified exceptions, and additional or amended supervisory procedures created in response to the testing. Firms meeting the $200 million gross-revenue threshold in Rule 3120(b) have additional annual-report content requirements.

Rule 3130 imposes a separate annual requirement. The firm's CEO or equivalent officer must certify that the firm has processes in place to establish, maintain, review, test and modify its written compliance policies and WSPs. The CEO must also have conducted one or more meetings with the CCO during the preceding 12 months to discuss those processes and the other matters specified by the rule. The processes supporting the certification must be evidenced in a report reviewed by the CEO and CCO.

These requirements are related, but they are not interchangeable.

In practice, a well-run compliance program coordinates the Rule 3110 annual review, Rule 3120 testing and report, and Rule 3130 certification while also maintaining a calendar for branch and other office inspections, AML testing and other recurring requirements according to the schedules that actually apply to each of them.

Branch and Office Inspections

Office inspections are another important part of Rule 3110.

The inspection cycle depends on the type of location. Every OSJ and any branch office that supervises one or more non-branch locations must be inspected at least annually on a calendar-year basis. A branch office that does not supervise one or more non-branch locations must be inspected at least every three years. Non-branch locations must be inspected on a regular periodic schedule, which FINRA presumes to be at least every three years. The firm's risk assessment may warrant more frequent inspections.

Remote work has made office classification more important, not less.

FINRA's Residential Supervisory Location framework permits certain qualifying supervisory residences to be treated as non-branch locations if the applicable conditions are met. Before designating a location as an RSL, the firm must satisfy the eligibility requirements of Rule 3110.19, conduct and document the required risk assessment, and comply with the applicable reporting requirements. An RSL is then subject to the inspection requirements applicable to non-branch locations rather than the annual inspection requirement that would otherwise apply to an OSJ or supervisory branch office.

There is another layer to consider. Not every state jurisdiction has necessarily adopted the FINRA RSL classification for its own branch registration purposes. FINRA's Form BR functionality specifically accommodates situations in which FINRA treats a qualifying location as an RSL while a jurisdiction continues to require the location to be registered or notice-filed as a branch. Firms therefore need to consider both FINRA's classification and the requirements of each applicable jurisdiction rather than assuming that an RSL designation resolves the issue everywhere. Depending on the state, a location that is designated an RSL everywhere else may have an obligation to classify as an OSJ in that particular state, thereby potentially changing your inspection obligations.

Firms should also understand the distinction between inspection frequency and inspection method. FINRA's Remote Inspections Pilot Program under Rule 3110.18 currently permits eligible participating firms, subject to the rule's conditions, to conduct qualifying inspections remotely through June 30, 2027. A firm that does not participate in the Pilot Program generally must satisfy its Rule 3110(c) inspection obligations through on-site inspections. The Pilot Program does not change the underlying inspection cycles.

A branch or other office inspection should test how the location is actually operating. The inspection should help determine whether the firm's supervisory requirements are being followed and whether identified issues need corrective action.

A finding by itself is not unusual. The more important issue is what the firm does with it. Repeat findings, incomplete remediation or a lack of documented follow-up can tell a regulator much more about the supervisory system than the inspection report itself.

Anti-Money Laundering Requirements

FINRA Rule 3310 requires each member firm to develop and implement a written AML program reasonably designed to achieve and monitor compliance with the Bank Secrecy Act and its implementing regulations.

The program must be approved in writing by senior management and include required policies and internal controls, designated AML responsibility, ongoing training for appropriate personnel and applicable customer due diligence procedures.

Rule 3310 also has its own independent testing requirement.

For most firms, independent AML testing must be performed annually on a calendar-year basis. A firm that does not execute transactions for customers, otherwise hold customer accounts, or act as an introducing broker with respect to customer accounts may conduct the independent test every two years. FINRA gives firms engaged solely in proprietary trading or conducting business only with other broker-dealers as examples of firms that may qualify for the two-year cycle. More frequent testing may be appropriate when circumstances warrant.

Independent testing should evaluate whether the program is working. The appropriate scope depends on the firm's business and risks and may include customer identification and due diligence, transaction monitoring and escalation, suspicious activity reporting, training, required records and remediation of prior findings.

Simply confirming that the firm has an AML manual is not independent testing.

Books and Records

Broker-dealer recordkeeping requirements are extensive and arise under both SEC and FINRA rules.

Exchange Act Rules 17a-3 and 17a-4 establish many of the records broker-dealers must create and preserve. FINRA Rule 4511 requires firms to make and preserve books and records required by FINRA rules, the Exchange Act and applicable Exchange Act rules.

The practical issue is not simply whether records exist somewhere in an electronic system.

A broker-dealer should know which records it is required to maintain, where those records reside, how long they must be retained, whether the method of preservation satisfies applicable requirements, and how they will be produced in response to a regulatory request.

The same applies when records are maintained through a vendor or another third party. The technology may be outsourced. The broker-dealer's regulatory responsibility is not.

Recordkeeping also overlaps with supervision. If a firm says that a review occurred but cannot produce evidence of it, that quickly becomes more than a records issue.

Registration, Qualification and Regulatory Reporting

Registration is an ongoing compliance function. It does not end when an individual passes an examination or the firm completes its initial membership process.

Broker-dealers need procedures to maintain appropriate firm, branch and individual registrations and to identify changes requiring amendments to Forms BD, BR, U4 or U5. Firms also need to determine whether associated persons hold the registrations required for the functions they perform.

Rule 3110 includes requirements concerning the investigation of applicants for registration and verification of information reported on initial or transfer Forms U4. Onboarding a registered person therefore involves more than processing paperwork.

Regulatory reporting presents a separate set of issues.

FINRA Rule 4530 requires firms to report specified regulatory, disciplinary, criminal, civil and other events promptly and, for the events covered by paragraphs (a) and (b), no later than 30 calendar days after the applicable knowledge or determination standard is met. Certain written customer complaints, including complaints alleging theft or misappropriation of funds or securities or forgery, are included in those event-reporting requirements. Separately, Rule 4530(d) requires firms to report statistical and summary information concerning written customer complaints by the 15th day of the month following the calendar quarter in which the complaints were received.

The same event can trigger more than one compliance obligation. A customer complaint may need to be retained in the complaint file, evaluated for Rule 4530 reporting, reviewed for possible Form U4 or U5 disclosure, and investigated from a supervisory standpoint.

Those decisions need to connect.

Financial and Operational Compliance

Financial responsibility is a core part of broker-dealer compliance, although the applicable requirements differ substantially based on the firm's business.

Exchange Act Rule 15c3-1 establishes broker-dealer net capital requirements. Rule 17a-5 contains financial reporting requirements, including FOCUS reporting and annual financial reporting obligations. Firms subject to Exchange Act Rule 15c3-3 also have customer protection requirements involving, among other things, possession or control of customer securities and reserve computations.

A carrying broker-dealer operates under a very different financial and operational framework from a limited-purpose firm that does not hold customer funds or securities.

Limited activity, however, does not eliminate financial responsibility requirements. It changes which requirements apply.

That distinction becomes particularly important when a firm changes its business. A new activity can affect net capital requirements, customer protection obligations, financial reporting, supervisory procedures or the scope of the firm's FINRA membership. Depending on the change, FINRA approval may also be required before the firm begins the new activity.

Those questions are much easier to address before the activity begins than after it is already underway.

Communications With the Public

FINRA Rule 2210 divides communications into correspondence, retail communications and institutional communications, with different review, approval, filing and recordkeeping requirements depending on the type of communication and the circumstances.

For that reason, a communications program should be more specific than “advertising requires principal approval.”

The firm needs to understand what types of communications it produces, who receives them, which require principal approval, what exceptions apply, whether FINRA filing requirements are triggered, and how the communications are retained.

The process also needs to reflect the way the firm's personnel actually communicate. Websites, email, social media, presentations, pitch books, text messages and other electronic communications can implicate both communications rules and books-and-records requirements.

Retail Business Creates Additional Obligations

A broker-dealer that makes recommendations of securities transactions or investment strategies involving securities to retail customers also needs to incorporate Regulation Best Interest (“Reg BI”) into its compliance and supervisory framework.

Reg BI includes Disclosure, Care, Conflict of Interest and Compliance Obligations in connection with covered recommendations to retail customers.

The definition of retail customer is important. It is not limited to unsophisticated or lower-net-worth investors. A natural person may qualify as a retail customer for Reg BI purposes even if the person is also an accredited investor. The SEC staff has specifically confirmed that Reg BI can apply to a limited-purpose broker-dealer recommending private offerings to accredited investors when the investor meets the rule's definition of retail customer.

That can make Reg BI relevant to firms that do not think of themselves as traditional retail broker-dealers, including some firms engaged in private placements.

The firm's procedures should address how recommendations are actually made, what conflicts exist, how those conflicts are addressed, what disclosures are provided, what documentation is maintained and how the activity is supervised.

A generic Reg BI policy does little good if it does not match the firm's actual sales process. More importantly, the firm needs to evaluate what the individuals engaged in sales are actually saying and doing, not simply what the procedures say they should be doing. That includes identifying where recommendations are being made and whether the firm's disclosures, treatment of conflicts and supervisory process match what is actually happening.

Form CRS requires a separate analysis. A broker-dealer can have Form CRS obligations even when Reg BI is not triggered because no recommendation was made. As an example, SEC staff has specifically addressed private placement broker-dealers that interact directly with retail investors in the subscription process. Depending on the facts and circumstances, those firms may be considered to be offering services to retail investors and therefore subject to Form CRS filing and delivery requirements even when they do not make recommendations or offer traditional brokerage accounts. The SEC has also cautioned firms in that situation to consider carefully whether their communications with investors may in fact rise to the level of a recommendation.

Privacy and Information Security

Privacy and information security are also part of the broker-dealer compliance framework.

The SEC's amended Regulation S-P expanded the requirements applicable to broker-dealers and other covered institutions. Among other things, firms must maintain written incident response policies and procedures addressing unauthorized access to or use of customer information and, when required, provide notice to affected individuals.

The compliance dates have passed for both larger and smaller covered institutions: December 3, 2025 for larger entities and June 3, 2026 for smaller entities. These are current requirements that should already be reflected in the firm's compliance framework where applicable.

Information security also cuts across multiple functions. Compliance, technology, vendor management and incident response need to work together. An incident response plan that exists only in the compliance manual will be of limited value if the people expected to use it do not understand their responsibilities when an incident actually occurs.

Business Continuity Planning

FINRA Rule 4370 requires every member firm to create and maintain a written business continuity plan addressing emergencies and significant business disruptions. The plan must be updated when there is a material change to the firm's operations, structure, business or location and must be reviewed annually to determine whether changes are necessary. A registered principal who is a member of senior management must approve the plan and is responsible for the annual review.

The required plan is flexible enough to reflect the firm's size and business, but the rule identifies specific areas that must be addressed to the extent applicable. For firms that depend heavily on clearing firms, technology providers and other vendors, the business continuity analysis also needs to consider those dependencies rather than simply assuming the vendor's own plan solves the problem.

Continuing Education and the Annual Compliance Meeting

Rule 1240 establishes the Regulatory Element and Firm Element requirements. Registered persons subject to the Regulatory Element generally complete it on an annual calendar-year schedule under the timing provisions of the rule. Firms must also maintain a continuing and current Firm Element program, evaluate and prioritize their training needs at least annually, and develop a written training plan based on their business, regulatory developments and the responsibilities of their registered persons.

Separately, Rule 3110(a)(7) requires registered representatives and principals to participate, no less than annually, in an interview or meeting at which compliance matters relevant to their activities are discussed. This is commonly addressed through the firm's Annual Compliance Meeting.

The requirements can overlap. Rule 1240 expressly permits a firm to consider an individual's participation in AML training and the Annual Compliance Meeting toward satisfying that person's Firm Element requirement. They should not, however, simply be treated as different names for the same requirement.

Where Broker-Dealer Compliance Programs Tend to Break Down

Most compliance problems do not begin because a firm has no compliance program. More often, the program exists, but some part of it no longer matches the business or is not operating the way management believes it is.

Common examples include:

  • a WSP assigns a review, but the firm cannot demonstrate that it was performed;
  • the firm's business changes without a corresponding change to the supervisory process;
  • testing confirms that a control exists without determining whether it works;
  • an office inspection identifies a deficiency, but there is no documented remediation;
  • required reviews are performed inconsistently or the supporting records cannot readily be produced;
  • registration, compliance and operational records describe an individual's responsibilities differently;
  • a vendor performs a regulatory or operational function, but the firm exercises little meaningful oversight of the vendor;
  • an annual requirement becomes a document-completion exercise instead of a meaningful review; or
  • the same exception appears repeatedly without the firm addressing the underlying cause.

None of these problems requires a dramatic compliance failure. Small inconsistencies accumulate. Procedures drift away from actual practice. A control that worked when the firm had ten people may no longer be adequate when it has fifty. A process developed for one business line may not address another.

That is why a compliance program has to be maintained, not merely created.

Building the Compliance Program Around the Firm

Building a compliance program starts with inventorying and understanding the firm's actual business.

What does the broker-dealer do? Who are its customers, if any? What products and services does it offer? How are transactions originated and processed? Who supervises each activity? Where are associated persons located? Does the firm handle customer funds or securities? What vendors perform regulatory or operational functions? What changes are being considered?

Those questions define the regulatory analysis.

From there, the firm can determine which supervisory reviews, testing, filings, inspections, records, financial controls and other processes apply and assign responsibility for them.

The same analysis should occur whenever the business is contemplating a change, and the timing matters: it should happen before the change is implemented. A new product, office, registered person, customer type or business line can change more than one regulatory requirement at the same time. It may also trigger the need to seek FINRA approval before the change is implemented.

It is considerably easier to identify those issues while the business change is being considered than to discover them after the firm has already begun conducting the activity.

How DFP Partners Can Help

DFP Partners works with broker-dealers in several different capacities.

For some firms, we serve in an outsourced role, including as the firm's CCO or FinOp. Many of our clients, however, maintain their own CCO, FinOp, supervisors and compliance personnel and use DFP as a consulting resource.

Our broker-dealer consulting work includes ongoing CCO support, FINRA Rule 3120 reviews and supervisory control testing, full branch office inspections, independent AML testing, WSP development and updates, mock FINRA examinations, Annual Compliance Meeting preparation and delivery, marketing and electronic communications reviews, registration support, regulatory remediation, and assistance with new products, business lines and regulatory requirements.

The scope depends on what the firm needs.

A broker-dealer with an experienced internal compliance department may want an independent Rule 3120 review, assistance with branch inspections or additional resources for a particular project. Another firm may need ongoing support across several areas. A firm that wants to outsource a designated function may determine that an outsourced CCO or FinOp arrangement makes sense.

The objective is not to impose unnecessary compliance infrastructure on a firm. It is to make sure the compliance framework fits the firm's business, the requirements that apply to that business are being addressed, and the firm can demonstrate that its supervisory and compliance processes are functioning as intended.

More from the blog