Compliance Check-In: Is Your Compliance Program Working?

For registered firms, having a compliance manual is only the starting point. The more important question is whether a firm can demonstrate that its policies, procedures and controls are actually operating in practice.
Recent CSA and OSC examination findings and guidance have highlighted recurring concerns relating to compliance systems, documentation, KYC, KYP and suitability, training, conflicts of interest, cybersecurity and oversight of third-party service providers.
For Portfolio Managers (PMs), Exempt Market Dealers (EMDs) and Investment Fund Managers (IFMs), this provides a useful opportunity to take a fresh look at their compliance programs to confirm that required policies exist, and to assess whether those policies are appropriately tailored to the firm, understood by employees, consistently followed and supported by documentation.
From Policies to Evidence
Under section 11.1 of National Instrument 31-103 Registration Requirements, Exemptions and Ongoing Registrant Obligations (NI 31-103), a registered firm must establish, maintain and apply policies and procedures that establish a system of controls and supervision sufficient to provide reasonable assurance that the firm and individuals acting on its behalf comply with securities legislation and that the firm manages the risks associated with its business in accordance with prudent business practices.
The regulatory expectation therefore extends beyond having policies in place: firms should be able to demonstrate that those policies and procedures are being applied and are operating as intended.
A well-written policy does little to protect a firm if the underlying process is not being followed. Similarly, a firm may have effective informal practices, but if those practices cannot be demonstrated through documentation, testing or other records, it may be difficult to evidence compliance during a regulatory examination.
This continues to be an area of regulatory focus. OSC Staff Notice 33-759, the Registration, Inspections and Examinations Division's 2025 Annual Report, expressly encourages registrants to use examination findings as a self-assessment tool to strengthen their compliance systems, internal controls and supervision.
Recent CSA guidance also reinforces the expectation that policies and procedures be up-to-date, comprehensive and appropriately tailored to the firm's registration categories, business model and client relationships. Joint CSA/CIRO Staff Notice 31-368 notes that the application of the KYC, KYP and suitability requirements will vary depending on those factors and provides examples of practices intended to assist firms in aligning their processes with the requirements of NI 31-103 and its Companion Policy.
For CCOs, this creates a useful starting point for a compliance review.
1. Can You Demonstrate Your KYC, KYP and Suitability Process?
KYC, KYP and suitability remain fundamental registrant obligations.
In December 2025, the CSA and CIRO published Joint Staff Notice 31-368, Client Focused Reforms: Review of Registrants' Know Your Client, Know Your Product and Suitability Determination Practices and Additional Guidance, following compliance reviews of 105 registered firms, including PMs, restricted PMs, EMDs and IFMs.
Staff found that, while many firms had made meaningful progress implementing the Client Focused Reforms, others had not fully updated their processes to reflect the enhanced KYC, KYP and suitability requirements. The Notice provides examples of deficiencies and additional guidance intended to assist firms in improving compliance.
Firms should consider whether they can demonstrate:
that KYC information is sufficiently detailed and kept current;
that risk tolerance and risk capacity are appropriately assessed;
that investment products have been subject to appropriate KYP review and ongoing monitoring;
how investment recommendations or portfolio decisions are assessed against the client's circumstances;
how concentration, liquidity, costs, available alternatives and other suitability factors are considered;
how suitability is reassessed when required and what reassessment triggers are; and
how exceptions or unusual circumstances are identified, escalated and documented.
These areas reflect the guidance in Staff Notice 31-368 and the underlying requirements in sections 13.2, 13.2.1 and 13.3 of NI 31-103. The Notice also emphasizes the importance of maintaining documentation supporting the assumptions, information and analysis underlying suitability determinations.
The processes should also reflect the firm's actual business model. A firm managing customized portfolios may require different controls than a firm using a limited model portfolio or pooled fund structure. The regulatory obligation is the same, but the compliance system used to satisfy it should make sense for the business.
2. Are Material Conflicts Being Identified and Addressed in the Client's Best Interest?
Under section 13.4 of NI 31-103, registered firms and individuals must take reasonable steps to identify existing and reasonably foreseeable material conflicts of interest and address material conflicts in the best interest of the client.
Disclosure is an important component of the conflicts framework, but disclosure alone is not sufficient to address a material conflict.
Joint CSA/CIRO Staff Notice 31-363, Client Focused Reforms: Review of Registrants' Conflicts of Interest Practices and Additional Guidance, followed a review of 172 firms across various registration categories. Staff identified issues including failures to identify material conflicts, inadequate controls to address conflicts in clients' best interests and inadequate or outdated policies and procedures.
This warrants particular attention where a firm's business involves:
proprietary products;
related or connected issuers;
referral arrangements;
compensation or fee arrangements that may influence recommendations; or
other relationships or incentives that may create a conflict between the interests of the firm or its representatives and those of the client.
The CSA's Client Focused Reforms guidance also identifies sales practices, compensation arrangements, incentive practices, referral arrangements, proprietary products and product-shelf development as areas where more detailed conflict documentation may be expected.
CCOs should therefore consider whether the firm's conflicts inventory remains current and, more importantly, whether the controls identified for each material conflict are actually being applied and are effective in addressing the conflict in the client's best interest.
3. Does Your Documentation Tell the Same Story as Your Policies?
Documentation is often where an otherwise reasonable compliance process becomes difficult to demonstrate.
Consider a firm that regularly discusses suitability issues at investment committee meetings but does not record the discussion, considerations or conclusions supporting its investment decisions. Or a CCO who reviews marketing materials but does not retain evidence of approval. The control may be occurring, but demonstrating it later can become unnecessarily difficult.
Firms should ask:
If a regulator reviewed this activity six months from now, would our records show what we did, why we did it and who reviewed it?
This is particularly relevant in light of recent CSA guidance. Staff Notice 31-368 identifies documentation as an important component of demonstrating compliance with KYC, KYP and suitability obligations, while the conflicts guidance under Staff Notice 31-363 similarly emphasizes the importance of records supporting how material conflicts are identified and addressed.
This does not mean creating paperwork for the sake of paperwork. Good compliance documentation should be proportionate to the risk and integrated into normal business processes wherever possible.
4. Is Marketing Review Keeping Pace With the Business?
Websites, social media, newsletters, presentations and other client communications should be part of the firm's compliance framework.
As marketing strategies evolve, firms should consider whether their review procedures continue to capture:
performance information;
statements about expertise, experience or capabilities;
testimonials and endorsements;
descriptions of products and services;
potentially misleading or overly broad claims;
use of social media by registered individuals; and
paid promotions, referral arrangements and relationships with third parties who create or distribute investment-related content.
The growing use of social media and third-party content creators has attracted increased regulatory attention.
In December 2025, the CSA and CIRO published Joint Staff Notice 31-369, Guidance on the Application of Securities Legislation to Finfluencer Activity. The guidance addresses circumstances in which online investment-related activity may engage securities law requirements and provides specific guidance for registrants and issuers working with finfluencers.
Among the risks identified by regulators are misleading or biased information, inadequate disclosure of conflicts, promotion of complex or higher-risk investments and recommendations that may not be suitable for the audience receiving them.
Firms using influencers, referral partners or other third parties to promote their services or investment products should therefore consider the nature of the activity, applicable registration requirements, conflicts and referral-arrangement requirements, compensation and disclosure, and the firm's responsibility for activities conducted on its behalf.
5. Are Third-Party Service Providers Actually Being Overseen?
Outsourcing a function does not necessarily outsource the registrant's regulatory responsibility.
IFMs in particular should pay close attention to oversight of fund administrators, valuation providers, transfer agents and other service providers[LH3] [KF4] . The same principle applies more broadly to registered firms using technology providers, consultants, custodians and other third parties.
Cybersecurity has made third-party oversight particularly important.
In July 2026, the CSA published Staff Notice 33-322, Review of Registered Firms' Cybersecurity Practices and Additional Guidance, following a focused compliance examination sweep of 73 registered firms. The CSA's review examined cybersecurity policies and procedures, employee training, risk assessments and controls, third-party service-provider oversight and incident-response planning.
The Notice reinforces that cybersecurity should form part of the firm's broader compliance and risk-management framework. For CCOs, this means considering not only the firm's own systems but also the risks arising from service providers that have access to confidential information, critical systems or important business functions.
Firms should be able to demonstrate appropriate initial due diligence, ongoing oversight and processes for responding to deficiencies or incidents involving service providers.
The nature and extent of those controls should be proportionate to the firm's size and operations, the importance of the outsourced function and the cybersecurity or operational risks associated with the service provider.
6. Is Training Tailored to the Firm and Being Documented?
Training is an important component of a firm's compliance system under section 11.1 of NI 31-103.
Joint CSA/CIRO Staff Notice 31-368 provides specific guidance on registrant training. Staff identified concerns where training was not sufficiently comprehensive, was not tailored to the firm's business or regulatory obligations, was optional rather than mandatory for relevant registered individuals, or where firms could not adequately demonstrate the content of or attendance at training.
The Notice indicates that training should be tailored to the firm's operations, appropriate for its size and sufficiently comprehensive to address the requirements and processes relevant to its registered individuals.
Depending on the firm's business and the individual's responsibilities, training may include:
KYC, KYP and suitability requirements and the firm's processes for meeting them;
conflicts of interest and the controls established by the firm;
new or complex securities and material changes to existing products;
changes to securities legislation, regulatory guidance or the firm's policies and procedures;
issues or deficiencies identified through compliance reviews or testing; and
other regulatory risks relevant to the individual's role and the firm's activities.
Training does not always need to take the form of a formal annual course.
Product discussions, KYP meetings, compliance updates and training delivered in response to a regulatory development or identified issue may all form part of a firm's training program. Where training occurs through these more informal channels, however, firms should consider documenting the subject matter, materials or discussion and attendance so they can demonstrate the training that occurred[LH5] .
Where new or complex securities are introduced, Staff Notice 31-368 indicates that firms should consider whether additional product-specific training is necessary to support registered individuals in satisfying their KYP and suitability obligations.
7. Is the CCO Testing the Compliance Program?
One of the most useful questions a CCO can ask is:
How do I know this control is working?
Testing does not need to be overly complicated. Depending on the firm's size and business, it may include:
sampling client files;
reviewing KYC updates;
testing suitability documentation;
reviewing personal trading;
checking marketing approvals;
reviewing referral payments;
confirming required filings;
testing fee calculations;
reviewing complaints;
assessing service-provider oversight; and
following up on previously identified deficiencies.
This approach is consistent with the broader regulatory expectation under section 11.1 of NI 31-103 that the firm's compliance system provide reasonable assurance of compliance and appropriately manage the risks associated with its business.
The OSC's 2025 RIE Annual Report similarly encourages firms to use regulatory examination findings as a self-assessment tool to strengthen systems of compliance, internal controls and supervision.
Testing results should feed back into the firm's compliance program and, where appropriate, the CCO's annual report to the board under section 5.2 of NI 31-103.
A Practical Compliance Review
A strong compliance program should evolve with the firm.
Changes in personnel, products, clients, technology, service providers, marketing practices or business strategy can all create new compliance risks even where the underlying securities requirements have not changed.
For a compliance review, CCOs may want to step outside the compliance calendar and ask a broader set of questions:
Are our policies still appropriate for the business we operate today?
Are we actually following them?
Can we demonstrate that we are following them?
Where we identify a problem, do we have a process to correct it and confirm that the solution worked?
Recent CSA guidance reinforces a consistent message: compliance frameworks should not only describe what a firm intends to do. They should reflect the firm's actual business, be implemented in practice and generate sufficient evidence for the firm and its CCO to demonstrate that regulatory obligations are being met.
For many firms, the objective should not be to create more compliance. It should be to make the compliance framework more effective, more demonstrable and better integrated into the firm's operations.
How SGD Compliance Can Help
SGD Compliance Consulting works with Portfolio Managers, Investment Fund Managers and Exempt Market Dealers to assess their compliance frameworks, identify gaps and develop practical solutions tailored to their business models.
Our compliance reviews can assist firms in preparing for regulatory examinations, evaluating existing policies and practices, strengthening compliance testing and providing CCOs and boards with a clearer picture of the firm's regulatory risk.
This article was prepared for informational purposes only and is not intended to provide, and should not be relied upon for, specific legal or regulatory advice. Firms should independently assess the application of securities laws and regulatory guidance to their particular circumstances.



Comments