Skip to main content

Industry Risks and Threats – Resources for Member Firms

FINRA provides extensive resources to assist member firms with managing and addressing risks and threats that could pose harm to their business, compliance programs and investors, including:

  • Highlights on the recent risks FINRA observed in our regulatory programs;
  • Observations from recent targeted exams (sweeps) on emerging industry issues and related regulatory obligations; and
  • Other FINRA resources, including those that represent particularly significant ongoing and emerging threats to firms and investors – such as cybersecurity, fraud, anti-money laundering (AML) and sanctions. 

Member firms may consider using these resources to help them evaluate and enhance their supervisory and compliance programs. However, these resources do not create new legal or regulatory requirements or new interpretations of existing requirements, nor do they relieve firms of any existing obligations under federal securities laws and regulations. Member firms may consider the following information when developing new, or modifying existing, practices that are reasonably designed to achieve compliance with relevant regulatory obligations based on the member firm’s size and business model.


FINRA has recently observed an increase in the frequency, sophistication and variety of threat incidents (i.e., instances where firm employees, advertently or inadvertently, use their access to firms’ systems and data to cause harm to firms, their investors or both).

In response, FINRA summarizes effective controls and practices we have observed firms employ to manage insider threat risks, as well as relevant questions for consideration that firms may use to evaluate their current insider threat programs.

Sweep Updates

FINRA conducts targeted exams, or sweeps, to review firms' conduct relating to certain emerging industry issues and help focus our regulatory responses. 

To support our ongoing goals of transparency with the industry and help firms continually improve their compliance programs, FINRA publishes sweep letters and provides updates to share initial themes from our reviews. Most recently, we provided updates on two of our most significant sweeps, including:

Most Recent Sweep – November 2022

Crypto Asset Communications

In November 2022, FINRA initiated a targeted exam of firm practices regarding retail communications concerning Crypto Asset1 products and services, including:

  • all crypto-asset retail communications made by, or distributed, by firms or their affiliates;
  • all WSPs concerning the review, approval, record keeping and dissemination of communications;
  • any communications-related compliance policies or other written guidance.

FINRA Provides Update on Sweep: Special Purpose Acquisition Companies (SPACs) – NEW IN OCTOBER 2023

The update highlights a number of initial themes from our reviews of firms’ offering of, and services provided to, SPACs and their affiliates (e.g., sponsors, principal stockholders, board members, and related parties) and includes questions for firms to consider as they evaluate whether their supervisory systems are reasonably designed to address risks of their SPAC-related activities, including:

  • reasonable investigation of the issuers and the securities they recommend, including SPACs;
  • underwriting compensation and disclosures;
  • identifying, addressing and disclosing potential or actual conflicts of interest when underwriting or recommending transactions in SPACs; and
  • firms’ supervisory systems, procedures, processes, and controls for underwriting and recommending transactions in SPACs.

FINRA Provides Update on Sweep: Social Media Influencers, Customer Acquisition and Related Information Protection

This update focuses on firms’ practices and supervisory systems regarding their social media influencer and referral programs, such as maintaining:

  • Written supervisory procedures (WSP) that differentiate between social media influencer and referral programs and address firms’ obligations under Regulation S-P;
  • Written policies regarding social media influencer and referral program participants’ compensation and conduct; and
  • Written policies regarding sharing customer information with third parties (including permitting customers to opt out of information sharing).

FINRA Provides Update on Sweep: Option Account Opening, Supervision and Related Areas

This update includes questions for consideration for members – based on FINRA’s observations to this point in its review – to help firms evaluate whether their supervisory systems adequately address risks related to supervising the approval of options accounts and monitoring the trading activity in options accounts, including questions addressing:

  • Processes for collecting and reviewing customer information;
  • Disclosures about options trading; and
  • Supervision of approved options accounts.

Compliance Resources on Key Risks and Threats

The sections below provide select resources on ongoing and emerging risks in areas that may present significant threats to member firms and investors.

2023 Report on FINRA’s Examination and Risk Monitoring Program – New Focus on Financial Crime and Related Risks

The 2023 Report also includes a number of new topics and a new section on Financial Crime, which are focused on helping firms address financial crime and other industry risks and emerging threats:


FINRA has recently seen an increase in the frequency and sophistication of cyberattacks – such as imposter websites and phishing campaigns – that target member firms, their customers and their employees.  FINRA responds to these attacks, in part, by promptly issuing cybersecurity alerts or notices to warn firms.

U.S. Securities and Exchange Commission (SEC) Proposes Amended Cybersecurity Rules

In March 2023, the SEC proposed rules and rule amendments regarding their cybersecurity regulations:

Phishing Campaigns

FINRA has observed and quickly responded to address several phishing campaigns that involve fraudulent emails claiming to be from FINRA, such as those that:

FINRA promptly issued cybersecurity alerts to warn firms, worked with firms to suspend domain names, where applicable, and helped to suspend these phishing campaigns. Member firms should be aware that they may receive similar phishing emails from other domain names.

Alerts About Other Cybersecurity Risks

In certain situations, FINRA also shares alerts issued by other government and non-governmental organizations that concern potential cybersecurity attacks relevant to member firms:

Other Cybersecurity Compliance Resources

  • Core Cybersecurity Threats and Effective Controls for Small Firms 
    This tool helps small firms enhance their customer information protection, and cybersecurity WSPs and related controls by (1) highlighting common categories of cybersecurity threats; (2) providing a summary of core controls; and (3) listing relevant terms and additional resources.  
  • Cybersecurity Checklist
    This checklist helps small firms establish and evaluate their data protection policies and controls.
  • Firm Checklist for Compromised Accounts
    This checklist includes practices and steps firms may consider if they learn that an unauthorized person may have gained access to customers’ accounts.

Recent Cybersecurity Threat Alerts and Notices – Phishing and Imposter Domain Names


Regulatory Notices

  • Regulatory Notice 22-29 (FINRA Alerts Firms to Increased Ransomware Risks)
    This Notice provides questions firms can use to evaluate their cybersecurity programs in light of the increased ransomware threat, lists possible additional firm controls and provides relevant resources.
  • Regulatory Notice 22-18 (FINRA Reminds Firms of Their Obligation to Supervise for Digital Signature Forgery and Falsification)
    This Notice addresses the risks presented by signature forgeries and falsifications by identifying the relevant regulatory obligations, and describing the scenarios member firms reported to FINRA in which representatives forged or falsified customer signatures, as well as the methods firms used to identify the forgeries or falsifications.
  • Regulatory Notice 21-29 (FINRA Reminds Firms of their Supervisory Obligations Related to Outsourcing to Third-Party Vendors)
    This Notice reminds firms about applicable regulatory obligations for vendor management; summarizes recent trends in examination findings, observations and disciplinary actions; and provides questions member firms may consider when evaluating their systems, procedures and controls relating to Vendor management.
  • Regulatory Notice 21-18 (FINRA Shares Practices Firms Use to Protect Customers From Online Account Takeover Attempts)
    This Notice outlines the increase in ATO incidents observed in 2021; reiterates firms’ regulatory obligations to protect customer information; and discusses common challenges firms identified in safeguarding customer accounts against ATO attacks, as well as practices they find effective in mitigating risks from ATOs—including recent innovations—which firms may consider for their cybersecurity programs.
  • Regulatory Notice 21-14 (FINRA Alerts Firms to Recent Increase in ACH “Instant Funds” Abuse)
    This Notice warns member firms of a sharp increase (as of March 2021) in new customers opening online brokerage accounts and engaging in Automated Clearing House (ACH) “instant funds” abuse to effect securities trading, and urges firms to evaluate and, as appropriate, mitigate the potential financial risk they face in light of the increase in “instant funds” abuse.
  • Regulatory Notice 20-32 (FINRA Reminds Firms to Be Aware of Fraudulent Options Trading in Connection With Potential Account Takeovers and New Account Fraud)
    This Notice provides member firms and associated persons with information regarding options transactions in connection with these account takeover and new account fraud schemes to help identify, prevent and respond to such activity.
  • Regulatory Notice 20-30 (Fraudsters Using Registered Representatives Names to Establish Imposter Websites)
    This Notice describes certain common characteristics of imposter websites and actions firms and registered representatives can take to monitor for and address these sites.

AML, Fraud and Sanctions

Moving Forward: FINRA's Anti-Money Laundering Actions in 2023

New account fraud, Russia-related sanctions and cyber-enabled fraud aren’t the only threats that FINRA’s Special Investigations Unit (SIU) keep their eye on. Read more about how the SIU flagged a host of emerging threats, and their proactive work with other units across FINRA’s regulatory operations and member firms.

Select Compliance Resources

  • Anti-Money Laundering (AML) Template for Small Firms
    This template provides text examples, instructions, relevant rules, websites and other resources that help small firms develop an AML compliance program plan.
  • Frequently Asked Questions (FAQ) regarding Anti Money Laundering (AML)
    This page provides answers to FAQs regarding FINRA Rule 3310 and firms’ AML requirements, including the required elements of firms’ AML compliance programs; whether firms’ AML compliance personnel have to be registered principals; how the Customer Identification Program (CIP) defines “account” and “customer”; and whether there are any exceptions from the Suspicious Activity Reporting (SAR) reporting requirement.



Regulatory Notices

  • Regulatory Notice 22-25 (Heightened Threat of Fraud: FINRA Alerts Firms to Recent Trend in Small Capitalization (“Small Cap”) IPOs)
    This Notice alerts firms to a recently observed, emerging threat to customers and member firms, where FINRA, NASDAQ and NYSE have observed initial public offerings (IPOs) for certain small capitalization (small-cap) issuers listed on U.S. stock exchanges that may be the subject of pump-and-dump-like schemes.
  • Regulatory Notice 22-21 (FINRA Alerts Firms to Recent Trend in Fraudulent Transfers of Accounts Through ACATS)
    This Notice provides an overview of how bad actors effect fraudulent transfers of customer accounts using ACATS (referred to as ACATS fraud), lists several existing regulatory obligations that may apply in connection with ACATS fraud, and provides contact information for reporting the fraud.
  • Regulatory Notice 22-06 (U.S. Imposes Sanctions on Russian Entities and Individuals)
    This Notice provides member firms with information regarding the sanctions the U.S. government imposed in February 2022 in response to Russia’s actions in Ukraine.
  • Regulatory Notice 21-36 (FINRA Encourages Firms to Consider How to Incorporate the Government-Wide Anti-Money Laundering and Countering the Financing of Terrorism Priorities Into Their AML Programs)
    This Notice informs member firms of the Financial Crimes Enforcement Network’s (FinCEN) government-wide priorities for anti-money laundering and countering the financing of terrorism policy, which was mandated by the Anti-Money Laundering Act of 2020 (AML Act).
  • Regulatory Notice 21-03 (FINRA Urges Firms to Review Their Policies and Procedures Relating to Red Flags of Potential Securities Fraud Involving Low-Priced Securities)
    This Notice provides information that may help FINRA member firms that engage in low-priced securities business assess and, as appropriate, strengthen their controls to identify and mitigate their risk, and the risk to their customers, including specified adults and seniors, of becoming involved in activities related to fraud involving low-priced securities.
  • Regulatory Notice 20-13 (FINRA Reminds Firms to Beware of Fraud During the Coronavirus (COVID-19) Pandemic)
    This Notice outlines four common scams to which firms and their customers were exposed during the COVID-19 pandemic: (1) fraudulent account openings and money transfers; (2) firm imposter scams; (3) IT Help Desk scams; and (4) business email compromise schemes—and describes measures that firms and associated persons may take to mitigate related risks.
  • Regulatory Notice 19-18 (FINRA Provides Guidance to Firms Regarding Suspicious Activity Monitoring and Reporting Obligations)
    This Notice provides guidance to member firms regarding suspicious activity monitoring and reporting obligations under FINRA Rule 3310 (Anti-Money Laundering Compliance Program).