Practical IT Change Management, the CCO’s Best Friend: Utilizing Change Management to Evidence Monitoring

Utilizing Change Management to Evidence Monitoring

As the SEC arrives to the technology party in a very public manner, investment advisers and broker dealers, who have already been operating in a needs-driven and best practice environment, must now open their programs for scrutiny. Current SEC and FINRA exams are already extending the interview and examination process into the technology arena, starting with the Chief Compliance Officer’s methods for touching base with and monitoring tech processes with regulatory ramifications. There are very few tech processes without direct ramifications for the compliance function. Consider Rule 204-2 and the maintenance and archiving of firm records on systems, file servers, and in the cloud; Regulation S-P and the protection of client information through secure networks, VPN’s, and the utilization of encryption; FINRA Notice to Members 11-39 (August 2011) in conjunction with Rule 17a-4 regarding the retention of business communications extending to personal devices like phones and tablets. The list goes on indefinitely as all of our business models have become intertwined with enabling technology. The registered adviser’s fiduciary responsibility to clients has been inextricably snared in the ability to manage, maintain, and deliver services through systems, networks, outsourced applications, and third parties.

Perhaps equally important to the potential for regulators connecting your compliance monitoring duties to technology, investors, both private and institutional, expect evidence of your firm’s ability to secure data and provide continuous services. The final critical consideration in vetting your technology program in general is the growing threat of breach and corresponding business risk. I have heard the words many times “our perimeter is secure.” Industry surveys, daily reports in the media, and our own experience teaches that this is a special form of hubris.1 Are you, the Chief Compliance Officer, working to validate such statements?

Fill in the form below

Loading form...
Category: Tags: ,

Cart

Latest Content

Custody Concerns Continue

You timely filed your Form ADV within 90 days of fiscal year end, but did you properly answer all the questions related to custody? Not surprisingly, the Form remains confusing for many advisers, as does application of the Custody Rule itself. The SEC has issued guidance, letters to the industry, alerts and FAQs, but things … Continued

Blockchain Isn’t Hot Sauce

Guest post by Samson Williams, Partner – Axes & Eggs and Keynote Speaker – Ascendant CSS Spring 2019 Conference  I started telling people that blockchain isn’t hot sauce in mid-2017 to help explain why initial coin offerings (ICOs) were just the latest form of unregulated, online gambling. In November 2017, with Bitcoin nearing a high … Continued

The Importance of Effective ADV Disclosure: Staying Ahead of the Regulators

This ComplianceCast will discuss how firms can mitigate risk by having effective disclosure in their Form ADV Brochure. Our panelists will be CSS Ascendant Senior Consultant Ariana Monchick and Jessica Matelis, Partner at Foley & Lardner and former Senior Counsel at the SEC Division of Enforcement. They will discuss: Required disclosures The types of conflicts … Continued

Regulation Best Interest, Cybersecurity Top Concerns at IAA 2019 Compliance Conference

The Investment Adviser Association (IAA) represents the interests of investment advisers in Washington D.C., and the IAA Investment Adviser Compliance Conference 2019 was a forum for the discussion of future potential rulemaking. Cybersecurity and Fiduciary Rule considerations were headline topics, with custody and marketing right behind. The following is a summary of key issues discussed … Continued

The Challenges of Building a Global Compliance Program

Compliance programs face challenges in balancing global requirements with local exceptions while incorporating the fast pace of regulatory change, addressing critical business needs and obtaining the necessary resources necessary to manage the program. Trends and thinking on the subject were center stage at the recent CSS London event “Looking at the Year Ahead – Global … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.