Practical IT Change Management, the CCO’s Best Friend: Utilizing Change Management to Evidence Monitoring

Utilizing Change Management to Evidence Monitoring

As the SEC arrives to the technology party in a very public manner, investment advisers and broker dealers, who have already been operating in a needs-driven and best practice environment, must now open their programs for scrutiny. Current SEC and FINRA exams are already extending the interview and examination process into the technology arena, starting with the Chief Compliance Officer’s methods for touching base with and monitoring tech processes with regulatory ramifications. There are very few tech processes without direct ramifications for the compliance function. Consider Rule 204-2 and the maintenance and archiving of firm records on systems, file servers, and in the cloud; Regulation S-P and the protection of client information through secure networks, VPN’s, and the utilization of encryption; FINRA Notice to Members 11-39 (August 2011) in conjunction with Rule 17a-4 regarding the retention of business communications extending to personal devices like phones and tablets. The list goes on indefinitely as all of our business models have become intertwined with enabling technology. The registered adviser’s fiduciary responsibility to clients has been inextricably snared in the ability to manage, maintain, and deliver services through systems, networks, outsourced applications, and third parties.

Perhaps equally important to the potential for regulators connecting your compliance monitoring duties to technology, investors, both private and institutional, expect evidence of your firm’s ability to secure data and provide continuous services. The final critical consideration in vetting your technology program in general is the growing threat of breach and corresponding business risk. I have heard the words many times “our perimeter is secure.” Industry surveys, daily reports in the media, and our own experience teaches that this is a special form of hubris.1 Are you, the Chief Compliance Officer, working to validate such statements?

Fill in the form below

Loading form...
Category: Tags: ,

Cart

Latest Content

OCIE Examined 15% of RIAs in 2017

In 2017, the SEC examined 2,114 investment advisers, approximately 15 percent of the 14,000+ registered investment advisers, the SEC confirmed in its Fiscal Year 2019 Congressional Budget Justification Annual Performance Plan. In the same report, the SEC said the staff will continue to improve its efforts of RIAs, noting that nearly 35 percent of all … Continued

Ascendant’s Adam DiPaolo Discusses Hypothetical & Model Performance Marketing Pitfalls

A Jan. 12 article in HFMCompliance titled “Best practice for hedge funds using hypothetical and model performance” outlines best practices for hedge fund managers when using hypothetical performance or model data in marketing efforts, and how managers relying on such data can avoid enforcement actions. Adam DiPaolo, Senior Consultant in Ascendant’s Private Funds group, is quoted in the … Continued

SEC’s Exam Priorities Offer Insight Into National Exam Program

On February 7, 2018, the SEC’s Office of Compliance Inspections and Examinations (“OCIE”) issued their 2018 Examination Priorities (see Ascendant’s summary here). In addition to defining their examination priorities for the year, the OCIE staff offered some insight into the National Exam Program.  Specifically, they defined the following five principles in executing their exam priorities: … Continued

SEC Updates: ICO Gatekeeper Standards, SEC/CFTC Swap Rules

SEC Chairman Jay Clayton had some stern advice for market professionals, especially gatekeepers, who he said need to act responsibly and hold themselves to high standards. Speaking via videoconference during Securities Regulation Institute’s recent annual conference, he said, “To be blunt, from what I have seen recently, particularly in the initial coin offering (“ICO”) space, they … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.