Platform Why Features Security Score AI Engine AI Coding KYP Hub Pricing Company About Buckler News Contact Français Book Demo →
Regulatory Basis

The Obligation

No rule in either country is titled "monitoring data quality." The obligation comes from the duty to supervise, the duty to monitor products, and the expectation that firms can evidence what they did. Each one fails if the underlying data is wrong.

1
Controls, Automated Processes and Evidence
What the rules and the joint staff notice say about the systems behind KYP

CIRO's Rule 3301 requires a dealer to monitor what it makes available for significant changes.[1] Section 11.1 of NI 31-103 and CIRO Rule 3904 require a system of controls and supervision sufficient to provide reasonable assurance that the firm complies with securities legislation, including its KYP requirements.[2] Joint CSA/CIRO Staff Notice 31-368 adds four expectations that apply directly to monitoring data.[2]

The notice's list of what KYP policies and procedures should cover includes the division of KYP work between the firm and its registered individuals, and says:

"... all processes used by the firm should be clearly described (e.g., if a firm uses centralized groups or automated systems to assist with aspects of its KYP obligations, the process followed should be set out in detail) and the individuals who are responsible for carrying out and supervising each process should be clearly identified." Joint CSA/CIRO Staff Notice 31-368, p.34 [2]

In its discussion of approvals, the notice addresses firms whose processes are driven by algorithmic models:

"In such cases, firms should document details of the model used, the resulting outputs and evidence of ongoing oversight to ensure it is functioning appropriately." Joint CSA/CIRO Staff Notice 31-368, p.16 [2]

A monitoring system that evaluates every security against coded thresholds is that kind of process. Evidence that it is "functioning appropriately" starts with evidence that it is working on correct data.

Among its monitoring findings, the notice described firms that "maintained up-to-date information on securities (e.g., updated issuer financials) but had no evidence it was reviewed or considered as part of their monitoring process."[2] The reverse problem matters just as much: a firm that can show its system reviewed the data, but can't show the data was right.

On KYP assessments, the notice says: "While third-party reports can support KYP assessments, firms need to document their own analysis."[2] Most monitoring data comes from vendors. The firm can rely on it, but it remains responsible for knowing what it's relying on and whether it's fit for the purpose.

2
Supervision, Vendors and Accurate Information
FINRA's supervisory and outsourcing expectations, and the duty not to rely on inaccurate information

FINRA Rule 3110 requires a supervisory system reasonably designed to achieve compliance.[5] Where that system depends on automated monitoring, its design includes the data feeding it.

FINRA Regulatory Notice 21-29 reminds firms that outsourcing an activity or function to a third-party vendor does not relieve them of their ultimate responsibility for compliance with applicable securities laws and regulations, and describes practices for vendor due diligence and ongoing monitoring, including reviewing the accuracy of vendors' work product and overseeing system changes that affect critical functions.[6] Market data, fund data and monitoring platforms are all vendor services that firms commonly rely on for KYP.

The SEC's 2019 interpretation of the adviser standard of conduct requires a reasonable investigation into an investment "sufficient not to base its advice on materially inaccurate or incomplete information."[4] Reg BI's Care Obligation requires a broker-dealer to understand the risks, rewards and costs of what it recommends.[3] Both depend on the information about the product being correct and current.

Expectation Canada United States
System of controls NI 31-103 s.11.1 and CIRO Rule 3904 FINRA Rule 3110
Automated processes Set out in detail in policies; responsible individuals identified Part of a reasonably designed supervisory system
Algorithms and models Document the model, its outputs and evidence of ongoing oversight Covered by supervisory and vendor oversight expectations
Third-party data and vendors Third-party material can support KYP; the firm documents its own analysis Outsourcing does not relieve the firm of responsibility (Notice 21-29)
Information quality Evidence that information was obtained and reviewed Advice not based on materially inaccurate or incomplete information
Inputs

The Data

Before a firm can audit its monitoring data, it has to know what that data is. Most monitoring systems depend on more sources than the people who rely on their alerts realize.

1
The Data Inventory
Every input a KYP monitoring system depends on
Data Set What It Holds Typical Source What Goes Wrong
Monitored population Every security on the shelf and every security held in client accounts Product management records, custody and account systems Transfers-in and delisted or closed securities left out
Security master Identifiers, security type, classification, issuer and fund links Internal reference data, vendor reference feeds Identifier changes and reclassifications break the link to monitoring data
Market data Prices, returns, volatility, spreads Market data vendors Stale prices, corporate-action errors, gaps
Fundamental and fund data Financial ratios, ratings, MERs and fees, holdings, flows, manager names Fund data vendors, filings, rating agencies Fields that stop updating; methodology changes; lag
Events and documents Fund amendments, issuer notices, rating actions, regulatory actions Regulatory filing systems, issuer and manager notices, news Events not captured, or captured late
Material change registry The metrics, thresholds, frequencies and severities the system applies Internal - owned by the product committee Coded thresholds differ from the approved policy
Output records Evaluations, alerts, reviews, decisions and notifications The monitoring system and workflow tools Records overwritten rather than versioned; missing no-breach evaluations

For each data set, the inventory should record an owner, the source, how often it updates, and which material change definitions depend on it. That last link matters most: when a vendor field changes, the firm needs to know immediately which monitoring rules are affected.

2
Six Dimensions of Quality
What "good" means for monitoring data, and how each dimension can be tested
Dimension The Question Example Test
Completeness Is every security in the monitored population covered, with every field each of its rules needs? Reconcile the monitored list against shelf and holdings; count missing fields per rule
Accuracy Do the values match the primary source? Re-derive a sample of values from fund documents, filings or financial statements
Timeliness Is each value as current as the rule's evaluation frequency assumes? Compare each field's last-update date with its expected update cycle
Consistency Do the same facts agree across sources and systems? Compare vendor fees and ratings with the firm's own KYP records and client reporting
Lineage Can each value be traced to its source and every transformation applied to it? Trace a sample of alerts back to the raw source record
Point-in-time reproducibility Can the firm show what the data said on a past date, not just what it says now? Reproduce a past evaluation from stored data and confirm the same result

The last dimension is the one most often missing, and the one an examiner is most likely to test. A monitoring record has little evidentiary value if the data behind it has since been overwritten and the firm can't show what the system actually saw when it made the call.

3
How Monitoring Data Fails
The quiet errors that produce clean-looking logs

Monitoring data rarely fails loudly. The common failures produce no alert at all, which looks exactly like a security with nothing to report.

  • The unmapped security. A new fund series, a transferred-in position or a security with a changed identifier never gets linked to its data. It sits in client accounts and is never evaluated.
  • The frozen field. A vendor stops updating a field after a fund merger or a data licence change. The last value carries forward and passes every check.
  • The null that passes. A missing value is treated as zero or as "no breach" rather than as a failure to evaluate.
  • The silent methodology change. A vendor reclassifies funds into new categories, changing every peer-relative threshold without any change in the funds themselves.
  • The corporate action break. A split, merger or distribution is recorded wrongly and produces a false price move, or hides a real one.
  • Registry drift. The thresholds coded in the system no longer match the definitions the product committee approved.
  • The overwritten history. Data is refreshed in place, so past evaluations can no longer be reproduced.
Design principle: a check that can't run should fail loudly. The single most useful control is to treat "could not evaluate" as its own outcome, distinct from "evaluated, no breach," and to route it to someone. A monitoring system that reports coverage gaps is more trustworthy than one that reports none.
Assurance

The Audit

Auditing monitoring data is ongoing work, not an annual exercise. Some tests run automatically every day; others are periodic samples and reviews.

1
Responsibilities
What the firm and the individual advisor each need to do
What the Firm Needs to Do
  • Maintain a data inventory. Every data set, its owner, source, update cycle and the rules that depend on it.
  • Describe the automated process. In the firm's written policies, in detail, with named people responsible for running and supervising it.[2]
  • Test data quality continuously. Automated completeness, timeliness and consistency checks, with exceptions routed and resolved.
  • Oversee vendors. Due diligence before relying on a data source, and ongoing review of accuracy and change notices.[6]
  • Reconcile the registry. Confirm the thresholds in the system match the approved material change definitions.
  • Preserve history. Store data and results so any past evaluation can be reproduced.
  • Evidence oversight. Keep records that the system was tested and functioning appropriately.[2]
What the Individual Advisor Needs to Do
  • Treat the system as a tool. Use monitoring output as an input to their own product understanding, not a replacement for it.
  • Report discrepancies. Flag data that conflicts with what they see in fund documents, issuer notices or client statements.
  • Report missing coverage. Tell the firm when a security they deal in doesn't appear in monitoring.
  • Know the limits. Understand which facts about a product come from vendor data and how current they are.
2
Audit Tests
A test program that covers inputs, processing and outputs
Test What It Proves Suggested Frequency
Coverage reconciliation Every security on the shelf and in client accounts is in the monitored population and mapped to its data Daily, automated
Field staleness check Each field has updated within its expected cycle Daily, automated
Could-not-evaluate report Every rule that failed to run is identified, not counted as a pass Daily, automated
Source re-performance A sample of values matches primary documents Monthly sample
Registry reconciliation Coded thresholds match approved definitions On every registry change, and quarterly
Known-event back-test The system caught real events it should have caught - for example, fee changes or manager departures found in filings Quarterly
Point-in-time reproduction A past evaluation can be rebuilt from stored data with the same result Quarterly sample
Vendor change review Vendor methodology and field changes were assessed for their effect on monitoring rules On every vendor notice, and annually

The known-event back-test is the most revealing. Take a set of significant changes the firm can find independently - a fee increase in a fund amendment, a manager change announced by the fund company, a rating downgrade - and check whether the monitoring system flagged each one, and when. Misses point directly to gaps in coverage, data or rules.

3
Documentation
A written process for monitoring data assurance

The example below shows what a written process might cover. It is illustrative; each firm's process should reflect its systems, vendors and business model.

Example: Written Process for KYP Monitoring Data Assurance
Illustrative
1
Scope. Applies to all data used in KYP monitoring: the monitored population, security master, market data, fundamental and fund data, event and document feeds, the material change registry, and monitoring output records.
2
Ownership. Each data set has a named owner recorded in the data inventory. The Head of Product Oversight is responsible for the monitoring process; Compliance supervises it.
3
Process description. The firm's KYP policies describe the automated monitoring process in detail: data sources, evaluation logic, frequencies, exception handling and the individuals responsible for each step.
4
Daily controls. Coverage reconciliation, field staleness checks and a could-not-evaluate report run daily. Exceptions are assigned to the data owner and resolved or escalated within three business days.
5
Periodic testing. Source re-performance is run monthly on a sample; registry reconciliation, known-event back-testing and point-in-time reproduction quarterly. Results are reported to the Product Committee.
6
Vendors. Before a data source is used, the firm documents vendor due diligence. Vendor change notices are assessed for their effect on monitoring rules before the change takes effect, and each vendor is reviewed annually.
7
Change control. Changes to evaluation logic or the material change registry are approved, tested and logged with the date and version before deployment.
8
Retention. Source data, evaluation results and registry versions are retained so any evaluation can be reproduced for the firm's record retention period.
Five Questions to Test Monitoring Data
  1. Can the firm list every data source its monitoring depends on, with an owner for each?
  2. Does the system report securities and rules it could not evaluate, separately from those it evaluated and cleared?
  3. Has the firm checked recently whether its monitoring caught real events it could find independently?
  4. Do the thresholds in the system match the definitions the product committee approved?
  5. Could the firm reproduce exactly what its monitoring system saw on any given date last year?
A note on scope: This paper covers the data that supports Know-Your-Product monitoring, under regulatory requirements and published guidance in Canada and the United States as of its publication date. It is general information, not legal, compliance or audit advice. The inventory, quality dimensions, tests, frequencies and example process are illustrations, not prescribed requirements. Where rules and guidance are quoted, the quotation is from the source cited.
References
  1. CIRO. Investment Dealer and Partially Consolidated Rules, Rule 3300 series (Product Due Diligence and Know-Your-Product), including Rule 3301(1)(iii). Source document (PDF)
  2. Joint CSA/CIRO Staff Notice 31-368, Client Focused Reforms: Review of Registrants' Know Your Client, Know Your Product and Suitability Determination Practices and Additional Guidance, December 10, 2025. KYP firm assessments, pp.10-13; approval, pp.15-16; monitoring for significant changes, pp.16-18; compliance system and KYP policies, pp.32-34. Source document (PDF)
  3. U.S. Securities and Exchange Commission. Regulation Best Interest: A Small Entity Compliance Guide. Source document
  4. U.S. Securities and Exchange Commission. Commission Interpretation Regarding Standard of Conduct for Investment Advisers, Release No. IA-5248, June 5, 2019. Source document (PDF)
  5. FINRA. FINRA Rules, Rule 3110 (Supervision). Source document
  6. FINRA. Regulatory Notice 21-29, FINRA Reminds Firms of their Supervisory Obligations Related to Outsourcing to Third-Party Vendors, August 13, 2021. Source document