Show year:
Priority 20222023202420252026
Financial Crimes Prevention
Cybersecurity and Cyber-Enabled Fraud105436
Exam Findings
Ransomware & Extortion Events637
Data Loss Prevention Programs/Data Breaches116737
Phishing, Smishing or Quishing37
New Account Fraud37
Account Takeovers37
Account Impersonations7
Imposter Websites637
Relationship Investment Scams7
Insider Threats637
Account Access Authentication67
New Account Opening Identity Validation67
Identity Theft Prevention Program67
Inadequate Risk Assessment Process11
Insufficient Branch Policies, Controls and Inspections1167
Insufficient Training11
Insufficient Vendor Controls1167
Insufficient Access Control Management12
Inadequate Change Management Supervision12
Limited Testing and System Capacity12
Digital Transformation and the Adoption of Cloud77
Log Management Practices77
Updating WSPs77
Suspicious Activity Report (SAR) Filings77
New SEC Cybersecurity Rules4
Emerging Risks
Vendor Risk126
Generative Artificial Intelligence (GenAI)-Enabled Fraud1047
Quasi-Advanced Persistent Threats (Quasi-APTs)4
Cybercrime-as-a-Service47
Anti-Money Laundering, Fraud and Sanctions591169
Exam Findings
Misconstruing Obligation to Conduct CIP and CDD1113713
Unestablished/Implemented Policies and Procedures for CIP and CDD713
Inadequate Verification of Customer Identities1113713
Inadequate Due Diligence on Correspondent Accounts of Foreign Financial Institutions14
Inadequate Due Diligence1113814
Inadequate Detection and Responses to Red Flags13713
Inadequate Ongoing Monitoring and Reporting of Suspicious Transactions71113813
Insufficient Staff and Resources14
Inadequate Handling of FinCEN Information Requests1113
Inadequate Training914
Insufficient Independent Testing713814
Insufficient Compliance With Certain Requirements of the BSA7
Emerging Risks
Manipulative Trading in Small Cap IPOs11
Sanctions Evasion12
ACATS Fraud13
New Account Fraud15
Investment Fraud by Bad Actors Targeting Investors Directly6
Continuing Risk: ACH Fraud9
Adversarial Use of Generative Artificial Intelligence1215
Manipulative Trading15181319
Exam Findings
Inadequate WSPs16191420
Non-Specific Surveillance Thresholds16191420
Surveillance Deficiencies16191420
Emerging Risks
Manipulative Trading in Small Cap IPOs1521
Targeted Exam
Firms participating in small-cap offerings with business operations in foreign jurisdictions22
Crypto Asset Developments
Crypto Asset-Related Market Abuse23
Targeted Examination on Crypto Asset Retail Communications23
Firm Operations
Outside Business Activities and Private Securities Transactions1318262332
Exam Findings
Incorrect Interpretation of Compensation1418262332
Inadequate Approval Process19262332
Inadequate Consideration of Need to Supervise14
No Documentation1419272332
No or Insufficient Notice and Notice Reviews1419272333
No PST Monitoring/Inadequate Controls1419272333
No Review and Recordkeeping of Digital Asset Activities14192723
Books and Records1620292534
Exam Findings
Misinterpreted Obligations162230
Failure to Maintain Email Correspondence223026
Failure to Maintain Non-Email Electronic Communications2635
Failure to Maintain Electronic Correspondence of Part-Time CCOs or FINOPs35
Failure to Maintain Converted Records22312635
No ESM Notification16
Inadequate Due Diligence of Third-Party Vendors2635
Inadequate Supervision of Third-Party Vendors27
Inadequate Supervision2635
Inadequate WSPs2635
Contacting Customers Through Off-Channel Communications302735
Inadequate Reviews2735
Emerging Risks
Direct Mutual Fund Business Risk17
Regulatory Events Reporting182231
Exam Findings
No Reporting to the Firm182332
Inadequate Surveillance182332
No Reporting to FINRA182333
Incorrect Rule 4530 Product/Problem Codes182333
Senior Investors and Trusted Contact Persons2026342837
Exam Findings
No Reasonable Attempt to Obtain TCP Information2026342838
No Written Disclosures2126352838
No Documented Training26352838
No Documented Internal Review26352838
Attempted Circumvention of FINRA Rule 3241352838
Emerging Risks
Customer Account Information Risks22
Senior Investors2829
Crowdfunding Offerings: Broker-Dealers and Funding Portals~22283630
Exam Findings
Failure to Obtain Attestation23293731
Inadequate Supervision31
Missing Disclosures23293731
Failure to Report Customer Complaints23293731
Untimely Required Filings23293731
Not Filing CMAs23293731
Offering Investment Advice or Recommendations293731
Misleading Statements293732
Failing to Transmit Funds303732
Failing to Take Measures to Reduce Risk of Fraud303732
Issues Regarding Maintenance and Transmission of Funds32
Member Firms' Nexus to Crypto
Exam Findings
Communications with the Public3341
Supervision3342
Private Securities Transactions of an Associated Person42
Outside Business Activities of Registered Persons42
Anti-Money Laundering (AML) Compliance Programs3342
Customer Account Transfer Contracts42
Standards of Commercial Honor and Principles of Trade42
Emerging Risks
Crypto Asset-Related Market Abuse35
Communication and Sales
Communications with the Public3039393745
Exam Findings
False, Misleading, Inaccurate or Unbalanced Information in Mobile Apps3241403744
Inadequate Supervision of Firms' Social Media Influencers and Failure to Retain Records3745
Inadequate Reviews of Electronic Communications46
Deficient Digital Assets Communications33414040
Municipal Securities Advertisements414141
Communications Promoting ESG Factors414141
Misrepresentations in Cash Management Accounts Communications33
Insufficient Supervision and Recordkeeping for Digital Communication33
No WSPs and Controls for Communication That Use Non-Member or OBA Names (so-called “Doing Business As” or “DBA” Names)33
Municipal Securities Advertisements33
Emerging Risks
Retail Communications Focused on Registered Index-Linked Annuities37
Targeted Exam Letter on Crypto Asset Retail Communications43
Reg BI and Form CRS2431433947
Exam Findings
WSPs That Are Not Reasonably Designed to Achieve Compliance with Reg BI and Form CRS26
Inadequate Staff Training26
Failure to Comply With Care Obligation2734473947
Failure to Comply with Conflict of Interest Obligation34474048
Not Identifying and Addressing All Potential Conflicts of Interest35
Failure to Comply with Disclosure Obligation35484048
Failure to Comply with Compliance Obligation35484049
Improper Use of the Terms "Advisor" or "Adviser"27
Insufficient Reg BI Disclosures27
Deficient Form CRS Filings2736484150
Failing to Properly Deliver Form CRS36494150
Form CRS Not Posted Properly on Website2736494150
Inadequate Form CRS Amendments2736494250
Misconstruing Obligation to File Form CRS28364942
Private Placements3544514453
Exam Findings
Inadequate Filings Procedures3645524454
Failing to Conduct Reasonable Investigation3645524554
Failure to Evidence Due Diligence534554
Improper Discharge of Reg BI Obligations54
Failure to Comply with SEC Rules Regarding Contingency Offerings4554
Concerning Third-Party Due Diligence36
Emerging Risks
Private Placements Offerings of Pre-IPO Securities4555
Conservation Donation Transactions Risks38
Annuities Securities Products3946554656
Exam Findings
WSPs4756
Exchanges4857
Reg BI Care Obligation Violation4857
False or Misleading Documentation4857
Not Addressing Buyouts404756
Unsuitable Exchanges404756
Inadequate Surveillance56
Insufficient Training404756
Poor and Insufficient Data Quality4047564857
Additional Deposits4856
Reasonably Available Alternatives48564857
Emerging Risks
RILAS47
Market Integrity
Consolidated Audit Trail (CAT)4250595161
Exam Findings
Incomplete Submission of Reportable Events51605162
Failure to Repair Errors Timely605162
Inaccurate or Incomplete Reporting of CAT Orders4251605162
Late Resolution of Repairable CAT Errors4351
Failure to Submit Corrections51605162
Inadequate Vendor Supervision435160
Unreasonable Supervision5162
Recordkeeping51605162
Emerging Risks
Data Integrity and Timeliness Issues in Municipal Underwriting Filings53
Customer Order Handling: Best Execution4353625363
Exam Findings
No Assessment of Execution in Competing Markets4454635464
No Review of Certain Order Types4554635464
Unreasonable "Regular and Rigorous Reviews"54635464
Securities with Limited Quotations or Pricing Information5464
No Evaluation of Required Factors45
Conflicts of Interest455463
Emerging Risks
Targeted Review of Wholesale Market Makers45
Customer Order Handling: Order Routing Disclosure4655645463
Exam Findings
Inaccurate Quarterly Reports4656655464
Incomplete Disclosures4757665564
Incomplete Disclosure When Incorporating by Reference576655
Deficient Communications47576655
Not Held Customer Reports576655
Insufficient WSPs4757665564
Fixed Income Fair Pricing58686068
Exam Findings
Incorrect PMP Determinations59696068
Outdated Mark-Up/Mark-Down Grids59696069
Failure to Consider Impact of Mark-Up on Yield to Maturity696069
Unreasonable Supervision696069
Exception Reports59
Market Access Rule48736370
Exam Findings
Insufficient Controls48736370
Failure to Consider Additional Data746371
Impermissible Exclusions746371
Inadequate Financial Risk Management Controls48746371
Reliance on Third-Party Vendors48746371
Inadequate Post Trade Surveillance6471
Failure to Document Annual Review of Effectiveness746471
Extended Hours Trading6573
Exam Findings
Inadequate Supervision6674
Reporting Failures6674
Financial Management
Net Capital5063766775
Exam Findings
Inadequate Supervision of Net Capital Compliance6876
Inadequate Processes or Supervision of Net Capital Deductions6876
Inaccurate Classification of Receivables, Liabilities and Revenue50
Failed to Deliver and Failed to Receive Contracts (Fails)50
Inadequate Processes or Supervision for Capital Charges for Underwriting Commitments5163776876
Inaccurate Net Capital Deductions and Concentration Charges637768
Inadequate WSPs6377
Inaccurate Recording of Revenue and Expenses5164776876
Late or Inadequate Filings6876
Insufficient Capital for Underwriting Participation6876
Inaccurate OCC Charges6876
Insufficient Documentation Regarding Expense-Sharing Agreements51
Liquidity Management5264786979
Exam Findings
Insufficient Stresses on Clearing Deposit Requirements69
Unreasonable Stress Test Assumptions69
Inadequate Supervision70
Establishing Inaccurate Clearing Deposit Requirements526579
Not Extending the Stress Test Period65
Not Modifying Business Models5265
No Liquidity Contingency Plans52657970
Inaccurate or Incomplete SLS Reporting797080
Credit Risk Management536781
Exam Findings
No Credit Risk Management Reviews546781
No Credit Limit Assignments5467
No Monitoring Exposure546781
Inadequate Systems to Monitor Customer and Counterparty Limits67
Customer Asset Protection5570847182
Exam Findings
Inadequate Supervision7183
Treatment of Free Credit Balances – Transfers to Another Account/ Institution83
Inconsistent Check-Forwarding Processes5671
Inaccurate Reserve Formula Calculations5671847183
Improper Withdrawals from Reserve Bank Account84
Inaccurate Segregation of Customer Securities71847283
Inadequate FINOP access to books and records to fulfill required duties83
Inadequate external reconciliations of books/records for customer asset location/custody83
Inadequate Handling of Customer Checks72
Omitted or Inaccurate Blotter Information56
Emerging Risks
FINRA Reminds Firms of Their Obligations to Designate FINOPs7383
Portfolio Margin and Intraday Trading566882
Exam Findings
Inadequate Recordkeeping83
Incorrect Account Equity83
Accounts Below Minimum Equity83
No Internal Audit Review of Portfolio Margin Process83
Inadequate Monitoring Systems5769
Not Promptly Escalating Risk Exposures5769
Insufficient WSPs5769
Non-Eligible Products Included in the Portfolio Margin Methodology69
Sub-section (with page numbers)
Not a stated priority that year
Source: 2026 FINRA Annual Regulatory Oversight Report. Values represent page numbers in each year's source report. Bates Group Research.