Securities Regulatory Roundup | August-September 2026

August and early September brought renewed focus to several of the most consequential securities compliance themes of 2026: fraud prevention, cybersecurity, anti-money laundering enforcement, digital assets, and the continued modernization of supervisory and operational requirements. FINRA proposed broader tools for responding to suspected financial exploitation, issued new cybersecurity guidance and a targeted technology alert, and imposed a significant AML fine. At the same time, the SEC and CFTC continued to shape the regulatory agenda for digital assets, market structure, reporting, and intermediary oversight.

For broker-dealers, investment advisers, and other regulated firms, the throughline is increasingly operational. Regulators are examining whether policies are supported by effective escalation procedures, documented supervisory decisions, reliable technology controls, current training, and evidence that compliance processes work as intended. The sections below highlight where August and early September activity was concentrated and what firms should be preparing for next.

FINRA · Investor Protection

FINRA Proposes Broader Protections Against Financial Fraud

FINRA proposed amendments to Rules 2165 and 4512 and proposed new Rule 2166, which would expand the tools available to member firms when they reasonably believe a customer is being targeted by fraud. The proposal would modernize trusted-contact practices, expand the potential duration of holds in certain suspected financial-exploitation matters, and establish a framework for temporarily delaying transactions or disbursements when any adult customer may be the target of fraud.

Current Rule 2165 focuses on temporary holds involving specified adults, including seniors and other vulnerable adults. The proposed framework would broaden the circumstances in which a firm could intervene, reflecting the growth and increasing sophistication of scams targeting customers across age groups.

What this means for firms

If adopted, the proposal could require changes to supervisory procedures, escalation protocols, customer communications, documentation standards, training, and technology workflows. Firms may need to define more clearly who can authorize a temporary delay, how suspected fraud is investigated, when a trusted contact must be notified, and what evidence must be retained — and to distinguish temporary holds under the existing financial-exploitation framework from delays involving other forms of suspected fraud.

FINRA · Cybersecurity

FINRA Highlights Effective Cybersecurity Practices

FINRA released guidance highlighting effective cybersecurity practices built around principles that can be scaled to firms of different sizes and business models. The guidance reinforces the importance of risk-based governance, access controls, incident preparedness, employee awareness, third-party oversight, and documentation. Cybersecurity continues to be both a technology and supervisory concern — firms must not only implement appropriate safeguards but also demonstrate how risks are identified, assigned, monitored, escalated, and remediated.

What this means for firms

Broker-dealers should assess whether cybersecurity policies accurately reflect current systems, vendors, access arrangements, and operational risks, and whether annual training addresses current threats and employees’ reporting responsibilities. Reviews should connect to broader compliance and operational-risk programs, with findings from testing, incidents, and vendor assessments resulting in documented remediation and follow-up rather than remaining isolated within information-security functions.

FINRA · Technology Alert

FINRA Warns Firms About Power Pages Configuration Risk

FINRA warned firms that improperly configured Microsoft Power Pages portals could expose information stored in Microsoft Dynamics 365 environments, including customer and employee personally identifiable information. The alert demonstrates how a technical configuration issue can develop into a regulatory, privacy, and supervisory risk: internet-facing portals may create unintended exposure when access controls, permissions, or data connections are not configured and tested appropriately.

What this means for firms

Firms using internet-facing portals should evaluate whether sensitive information can be accessed by unauthorized users and whether adequate controls exist around portal configuration, testing, deployment, and ongoing monitoring. Compliance, information security, privacy, and vendor-management teams may need to coordinate these reviews and confirm that configuration risks are addressed through change-management procedures, incident-response plans, third-party assessments, and employee training.

FINRA · AML Enforcement

FINRA AML Enforcement Highlights Program and Supervisory Failures

FINRA imposed a $20 million fine involving failures to establish and implement an AML program reasonably designed to detect and cause the reporting of suspicious transactions involving foreign-currency wires. The matter also involved customer due diligence failures and the untimely detection and reporting of suspicious customer activity, reinforcing the expectation that AML programs account for the specific customers, products, transactions, and geographic risks present in a firm’s business.

What this means for firms

Written procedures alone are insufficient when transaction-monitoring parameters do not reflect actual risks, customer due diligence is incomplete, or alerts do not result in timely escalation and reporting. Firms should assess whether monitoring covers relevant transaction types, whether customer risk profiles are sufficiently detailed and current, and how alert disposition, escalation timelines, SAR filing, supervisory accountability, and quality assurance are documented. The matter also provides useful scenario-based material for annual AML training.

FinCEN · BSA Enforcement

FinCEN Imposes Significant Broker-Dealer Penalty

FinCEN separately imposed a $125 million penalty for willful Bank Secrecy Act violations, described as its largest penalty against a broker-dealer to date. Together with the FINRA matter, the action demonstrates continued regulatory scrutiny of whether broker-dealer AML programs operate effectively in practice — deficiencies involving customer due diligence, monitoring, escalation, written procedures, and supervisory oversight can become interconnected rather than remaining isolated compliance issues.

Firms should use recent enforcement activity to evaluate whether their AML risk assessments, monitoring systems, investigation processes, staffing, training, and governance structures remain appropriate for their current business.

SEC · Rulemaking Agenda

SEC Rulemaking Agenda Identifies Future Priorities

The SEC released its 2026 rulemaking agenda, identifying regulatory initiatives that could materially affect broker-dealers, investment advisers, investment companies, issuers, and market-infrastructure participants. Areas identified for potential action include:

  • Digital assets and crypto-asset regulation
  • Broker-dealer and market-structure modernization
  • The Consolidated Audit Trail
  • Investment-adviser custody and recordkeeping
  • Form PF
  • Transfer Agent regulation
  • Corporate disclosure and capital formation
  • Executive compensation and shareholder proposals

The agenda includes both pre-rule and proposed rulemaking activity. It therefore identifies areas in which future change may occur, rather than establishing immediate compliance obligations.

What this means for firms

Compliance teams should monitor the agenda and identify which initiatives could affect their products, customer relationships, systems, data, records, and supervisory processes. Early impact assessments can help firms understand dependencies before final requirements and implementation dates are established.

SEC · Digital Assets

SEC Proposes Tailored Crypto-Asset Offering Framework

The SEC proposed a tailored offering framework for certain crypto-asset investment contracts and continued considering broader regulatory questions involving digital-asset custody, disclosures, trading activity, intermediary obligations, and investor protection. The proposal reflects the SEC’s continuing effort to determine how existing securities-law principles should apply to digital assets while considering whether more tailored registration and disclosure requirements are appropriate for certain offerings.

Firms engaged in digital-asset activity should continue monitoring developments that may affect product governance, disclosures, supervision, custody, recordkeeping, communications, and registration.

SEC · Transfer Agents

SEC Proposes Transfer-Agent Modernization

The SEC proposed comprehensive modernization of transfer-agent requirements, addressing registration, reporting, books and records, account servicing, and operational requirements. Transfer-agent regulation has remained largely unchanged despite substantial changes in technology, market structure, and account-administration practices; the proposal signals an effort to establish a more current framework for recordkeeping, safeguarding assets, processing transactions, and supporting issuer and investor accounts.

Transfer agents and firms that rely on their services should evaluate the proposal’s potential impact on systems, data, operational controls, vendor relationships, reporting, and books and records.

SEC · Investment Advisers

SEC Proposed to Rescind the Investment Adviser Pay-to-Play Rule

The SEC proposed rescinding Rule 206(4)-5 under the Investment Advisers Act and its associated recordkeeping requirements. The rule generally prohibits an investment adviser from receiving compensation for providing advisory services to certain government clients for two years after certain political contributions are made. The SEC currently seeks public comment on this proposal.

CFTC · Emerging Markets

CFTC Activity Signals Continued Focus on Emerging Markets

The CFTC continued developing policy involving digital assets, prediction markets, event contracts, AI-related compute derivatives, affiliate conflicts, and registration exemptions. It also exercised emergency authority in connection with KalshiEX, LLC following litigation involving event contracts and prediction markets — a matter that reflects continued disagreement between federal and state authorities concerning the oversight of these products.

Although much of this activity remains developmental, firms should monitor how future rulemaking or litigation could affect product governance, conflicts management, disclosures, supervision, intermediary registration, and training.

NFA · Business Continuity

NFA Updates Business-Continuity Requirements

The NFA amended its business-continuity requirements to permit cloud-based applications to serve as primary or backup recovery sites. The amendment recognizes the expanded role of cloud services in business-continuity and disaster-recovery programs and gives firms an occasion to review whether written plans accurately reflect their current technology infrastructure, vendors, data dependencies, and recovery arrangements.

What this means for firms

The use of cloud services does not eliminate the need for documented recovery planning and testing. Firms should consider whether business-continuity plans address vendor oversight, employee access, data availability, testing, communications, system dependencies, and governance during a disruption — and whether written plans align with the recovery methods the firm actually intends to use.

SEC + CFTC · Form PF

Form PF Compliance Date Moves to July 2027

The SEC and CFTC moved the compliance date for amendments to Form PF to July 1, 2027. The additional implementation period gives affected private fund advisers more time to assess data requirements, reporting processes, controls, systems, and governance. Firms should use the extended timeline to evaluate data availability, assign implementation responsibility, conduct testing, and address reporting dependencies.

Form PF compliance date: July 1, 2027
FINRA + MSRB · 2027 Implementation

FINRA and MSRB Changes Create an August 2027 Implementation Cluster

FINRA’s expanded TRACE affiliate-principal indicator becomes mandatory on August 2, 2027. Amendments to MSRB Rule G-12 become effective one day earlier, on August 1, 2027. Firms affected by both developments should incorporate the dates into a consolidated implementation calendar and identify the systems, procedures, testing, and training required for each change.

MSRB Rule G-12 amendments effective August 1, 2027 TRACE affiliate-principal indicator mandatory August 2, 2027
FINRA · Annual Renewals

FINRA Publishes 2027 Annual Renewal Program Timeline

FINRA published its 2027 Annual Renewal Program timeline. FINRA systems are scheduled to shut down for renewal processing at 6:00 p.m. on December 27, 2026. Filings submitted during the shutdown will not be processed until the system resumes operations on January 2, 2027. Broker-dealers and investment advisers should coordinate registration filings, terminations, amendments, continuing education and internal approval processes around the shutdown period and ensure licensing and registration teams understand year-end deadlines and dependencies.

Renewal processing shutdown begins December 27, 2026 Processing scheduled to resume January 2, 2027
NASAA · Qualification Exams

Qualification-Exam Retake Requirements Continue to Evolve

NASAA announced that the waiting period following a third or subsequent failure of NASAA qualification examinations will decrease from 180 days to 60 days. NASAA has not reduced the waiting period following first and second failures to 15 days, as contemplated by FINRA’s separate proposal. The different approaches mean firms may need to account for examination-specific waiting periods when managing candidate eligibility and testing schedules. The MSRB had not issued a comparable proposal as of the August update.

How RegEd Can Help

Connect regulatory change to supervisory action

August and early September activity shows how quickly regulatory developments translate into operational demands. Fraud proposals may require new escalation and documentation workflows. Cybersecurity guidance must be reflected in controls and training. AML enforcement continues to test whether written programs produce timely detection, investigation, and reporting. And future reporting and market-structure changes require coordinated planning well before their compliance dates.

RegEd helps firms connect regulatory intelligence with policies, procedures, training, supervisory workflows, and documentation. Solutions spanning Regulatory Change Management, compliance case management, Firm Element training, branch audit management, and licensing and registration can help firms assign responsibility, manage implementation, and maintain evidence across the compliance lifecycle.

Scroll to top