On December 10, 2025, the Canadian Securities Administrators and the Canadian Investment Regulatory Organization published Joint Staff Notice 31-368, Client Focused Reforms: Review of Registrants' Know Your Client, Know Your Product and Suitability Determination Practices and Additional Guidance. It's the first formal accounting of how firms have actually implemented the Client Focused Reforms (CFRs) - the enhanced KYC, KYP, and suitability determination obligations that came into force on December 31, 2021.
The CSA and CIRO conducted compliance reviews of 105 registered firms - investment fund managers, portfolio managers, restricted portfolio managers, exempt market dealers, investment dealers, and mutual fund dealers - against the requirements in NI 31-103, CIRO's Investment Dealer and Partially Consolidated Rules, and the Mutual Fund Dealer Rules. Some firms had invested real resources in adapting their processes. Others had not meaningfully updated anything since the CFRs took effect, more than three years before this Notice was published.
This page is a review of that Notice, organized the way the Notice itself is organized: Know Your Client, Know Your Product, Suitability Determination, and Compliance System and Training. Each section below breaks out the issues Staff identified in their reviews, the guidance Staff gave in response, and - where the Notice provides them - examples of practices Staff found acceptable.
The throughline across all four sections is the same: firms had processes, but not evidence. Committees discussed things, individuals reviewed things, reassessments happened - but without documentation showing who did what, when, and on what basis, none of it satisfies the obligation. Staff were explicit that a firm's specific application of these requirements will vary by registration category, business model, and client relationships - there's no single correct process. What's non-negotiable is that whatever process a firm runs, it has to produce a retrievable record.
For a firm that hasn't kept pace, this Notice isn't a warning shot - it's the exam checklist. Staff spelled out, category by category, exactly what they looked for across 105 firms and exactly where most of them fell short. What follows is what that means in practice: what firms actually need to build, what it costs them not to, and what happens when a regulator - or a client's lawyer - comes looking for the record.
Nearly every issue Staff identified traces back to the same root cause: a process existed, but nothing could prove it ran. Closing that gap means building a system of record across KYC, KYP, and suitability - not a policy binder, an operating system - with, at minimum:
| Issue | What It Means | Reference |
|---|---|---|
| Risk-profile methodology | Document how risk tolerance and risk capacity are each assessed, reconcile conflicts between them, and capture client confirmation - not a single blended checkbox. | Know Your Client, §1 |
| Material change definitions | Define, per security type, the metric tracked, the breach condition, the evaluation frequency, and the severity level - with a defined owner and review cadence. | Know Your Product, §4 |
| Approval and KYP assessment trail | Show meaningful consideration behind every approval and assessment, not just its outcome, with clear ownership at each step. | Know Your Product, §1 & §3 |
| Suitability determination process | Capture every required factor - KYC, KYP, account impact, cost impact, and a reasonable range of alternatives - for each investment action, tied to the underlying data rather than reconstructed afterward. | Suitability Determination, §1 |
| Reassessment triggers | Wire reviews to KYC updates, KYP changes, and changes in the responsible individual, so reassessment happens on schedule rather than by exception. | Suitability Determination, §5 |
| Firm-specific policies and procedures | Describe how the firm actually meets each obligation in practice, not a restatement of the rule text. | Compliance System and Training, §1 |
| Mandatory, tracked, tested training | Require training for every registered individual, and keep records of content, attendance, and completion. | Compliance System and Training, §2 |
The common thread across all seven: every one of them has to produce something retrievable on demand. A process that exists only in a compliance officer's head, or in a spreadsheet nobody else can find, doesn't meet the bar Staff just described in writing.
Every one of the factors in a suitability determination - KYC, KYP, account impact, cost impact, a reasonable range of alternatives - exists because it's also what a client's lawyer, or an OBSI investigator, will ask for after a loss. A firm that can't produce the documentation behind a recommendation has no way to show the recommendation was reasonable at the time it was made, whatever the outcome turned out to be. That's the exposure this Notice makes explicit: undocumented suitability determinations don't just fail a compliance review, they fail a defense.
That exposure compounds where the gap is systemic rather than isolated. A firm using the same undocumented process across its entire book - a generic risk questionnaire, no defined significant-change monitoring, no reasonable-range-of-alternatives process - isn't looking at one client complaint. It's looking at every client who was recommended a security under that same process, which is the fact pattern that turns individual complaints into arbitration claims at scale and raises E&O insurance costs firm-wide.
Where Staff found deficiencies in this review, firms were required to take corrective action within a reasonable time frame; where the gaps were significant, Staff indicated they warranted further regulatory action. In CIRO's enforcement framework, that range runs from terms and conditions imposed on a firm's registration, through monetary sanctions and suspension, to registration revocation in the most serious cases - and because Chief Compliance Officers and Ultimate Designated Persons carry personal responsibility for a firm's compliance system under NI 31-103, individual accountability sits alongside firm-level exposure, not instead of it. CIRO also publishes its enforcement decisions, so the reputational cost of a finding tends to outlast the sanction itself.
Yes - and firms should plan on that basis. This is a read of where things are headed, not a claim about CIRO or the CSA's internal plans, but it's grounded in what the Notice itself says. Staff stated plainly that they "will continue to review and evaluate firms' compliance with securities legislation, including all CFR requirements, during regular compliance examinations," and that they'll draw on the observations in this Notice - a systematic review of 105 firms - to do it. That's a different posture than a one-off report: it reads as the new baseline for what an examiner walks in already expecting to find, and what they'll flag immediately if they don't.
Two things point the same direction. First, CIRO has said further KYC, KYP, and suitability guidance is coming, tied to both ongoing member examinations and the incoming Consolidated Rulebook - this Notice is a checkpoint in an active process, not the end of one. Second, the findings themselves were widespread enough - gaps identified across a 105-firm sample spanning nearly every registration category - that regulators have little reason to treat any individual firm's gaps as isolated or excusable going forward. A firm that hasn't closed what's described in this Notice by its next routine exam shouldn't expect the benefit of the doubt it might have gotten before this Notice existed.
Registrants must take reasonable steps to obtain and periodically update KYC information sufficient to support suitability determinations. How much detail is required scales with the complexity of the securities and services a firm offers - but most of the 105 firms reviewed had gaps somewhere in the collection, verification, or currency of that information.
A client's risk profile has two distinct components: risk tolerance (a client's subjective willingness to accept risk) and risk capacity (a client's objective ability to endure financial loss, given their full financial picture). Firms must determine and document both, and the overall risk profile should reflect the lower of the two unless the registrant documents why it's reasonable to determine otherwise.
Risk tolerance and risk capacity must be assessed separately, with specific client input on both, and the overall risk profile should reflect the lower of the two absent a clearly documented rationale otherwise. Firms should have a consistent, documented process with clear criteria for arriving at an overall risk profile, and should reconcile any inconsistency between the stated risk profile and other KYC information - discussing it with the client and documenting the resolution. Where questionnaires are used, they should include separate questions for tolerance and capacity, weighted to avoid outcomes like a low-capacity, high-tolerance client being assigned a high overall risk profile. Risk profile determinations, like all KYC information, must be confirmed by the client.
The CFRs clarify the financial information registrants must consider to support suitability determinations: annual income, liquidity needs, financial assets, net worth, and whether the client is using leverage or borrowing to finance securities purchases. Registrants must take reasonable steps to collect and document sufficient detail on each.
Firms should gather sufficiently detailed information on annual income, liquidity needs, financial assets, net worth, and leverage use, and make further inquiries or obtain corroborating details where client-provided information appears unclear or inaccurate. A breakdown of financial assets gives a clearer picture of a client's circumstances; firms offering illiquid or sector-specific products should assess whether they also need to understand investments the client holds outside the firm to make an adequate suitability determination.
Registrants must take reasonable steps to keep KYC information current, updating it within a reasonable time after becoming aware of a significant change, and on defined minimum schedules regardless: no less than every 12 months for managed accounts, within 12 months before a trade for exempt market dealers, and no less than every 36 months in any other case. More than 36 months have elapsed since the CFRs' effective date, so by the time of this Notice every firm's KYC information should already reflect the full CFR standard.
Registrants must review and update KYC information at the required frequency or sooner if they learn a client's circumstances have significantly changed, and periodic updates should evidence that the registrant turned their mind to reviewing all elements of the client's KYC after a meaningful interaction. A note stating only "no update" or "no changes" is insufficient without other evidence a meaningful interaction took place. Changes to significant KYC and account information - name, address, banking details, or anything posing a heightened account-security risk - should be formally documented with the client's written confirmation. Where clients are unresponsive to update requests, registrants should document their reasonable efforts to reach them and, for prolonged non-response, consider account restrictions such as limiting new trades outside of redemptions until KYC is updated.
Registered firms must take reasonable steps to assess, approve, and monitor the securities they offer - product due diligence, in CIRO's terms - while registered individuals must take reasonable steps to understand the securities they transact in or recommend, in enough detail to meet their own suitability obligations. Staff found firms using every division of labour between the two, but common gaps in documentation regardless of the model chosen.
Registered firms must take reasonable steps to assess the key aspects of securities offered to clients - structure, features, risks, initial and ongoing costs, and the impact of those costs.
All securities offered to clients - including those in model portfolios and those of related or connected issuers - must be subject to an appropriate KYP assessment by the firm itself. The depth of review should scale with a security's structure, complexity, risk level, and transparency: a streamlined review may suit less complex, lower-risk securities, while novel, leveraged, illiquid, or opaque securities warrant more in-depth review. It may be reasonable to group KYP assessments for similar, non-complex securities (e.g., non-complex mutual funds from the same manufacturer), provided the process is well-defined. Firms should retain supporting documentation - issuer financial statements, prospectuses, fund facts, due diligence reports, and filings - and keep records of the analysis conducted for every security made available to clients.
Registered individuals must take reasonable steps to understand every security, and every model portfolio, that they purchase, sell, or recommend for a client - a separate obligation from the firm's own KYP assessment.
Individuals must understand a security's structure, features, risks, costs, and how those costs affect performance, with more complex or higher-risk securities warranting more detailed consideration. Where a firm offers model portfolios, its client-facing individuals need to understand how the models are composed, their features and risks, and the client types they suit; individuals responsible for selecting securities within a model must understand the underlying securities themselves. Firms should give individuals access to the information gathered through the firm's own KYP process, along with any necessary training and tools, and maintain documentation demonstrating individuals took reasonable steps to understand what they recommend.
Firms must ensure every security they make available to clients is approved, and registered individuals must not purchase, sell, or recommend a security to a client unless the firm has approved it.
Firms must establish approval processes for the securities and model portfolios they make available, with processes and criteria that vary by business model and the complexity and risk of what's offered. Approval responsibility can sit with a committee (investment or product review committees) or an individual (CIO, CCO, UDP, senior or individual advising representatives), depending on the firm's size and shelf. Portfolio managers using algorithmic models should document the model used, the resulting outputs, and evidence of ongoing oversight to confirm it functions appropriately. Approval documentation should show meaningful consideration by whoever approved it - simply stating a security is "approved" or adding it to an "approved list" without evidence of a reasonable review process is not sufficient.
Firms must take reasonable steps to monitor securities for significant changes - both securities currently available for purchase and, where a firm has an ongoing relationship with clients and completes periodic suitability reassessments, all securities still held in client accounts, even if no longer offered.
Firms should define what constitutes a significant change for the types of securities they offer, and implement a monitoring process specifying how and how often monitoring occurs - reflecting the nature of the securities, the firm's business model, and its investment strategy. Examples of significant change identified by firms include a change in a security's risk rating, its costs or fees, its liquidity, distribution or redemption privileges, an issuer's operations, management, or significant ownership, an issuer's credit rating, financial ratios, the geopolitical situation, or macroeconomic factors. Annual monitoring alone was generally not found sufficient. Where a significant change is identified, firms should document their assessment and consider appropriate responses - notifying registered individuals, reassessing suitability and taking corrective action in client accounts, revisiting the firm's approval, or implementing additional sale controls.
KYP assessment and monitoring requirements apply to securities transferred into a firm or acquired through a client-directed trade, even where the firm isn't required to formally approve them because they aren't otherwise made available to clients. Firms must assess these securities within a reasonable time and include them in ongoing significant-change monitoring.
Registrants must assess securities transferred into the firm or resulting from client-directed trades within a reasonable time, though the depth of that assessment can vary based on the nature of the security, how long it's expected to be held, the client's circumstances and objectives, and the client relationship. Firms must not exclude these securities from their KYP assessment and monitoring processes. The assessment performed, and the steps taken by the registered individual to understand the security, should be adequate to support suitability determinations - including any decision to continue holding or to divest - and should be documented.
Before taking any investment action, registrants must assess and determine whether that action is suitable for the client, considering specific factors that draw on the client's KYC information and the registrant's KYP assessment, and must determine that the action puts the client's interest first. The same provisions govern periodic reviews of account suitability and the handling of client-directed trades and unsolicited orders. Staff found that many firms hadn't updated their suitability processes to reflect the enhanced CFR obligations.
Before taking an investment action, registrants must assess and determine its suitability considering: the client's KYC information; the registrant's KYP assessment or understanding of the security; the impact of the action on the client's account, including concentration and liquidity; the potential and actual impact of costs on the client's return; and a reasonable range of alternative actions available through the firm. Registrants must also determine that the action puts the client's interest first.
Not every factor will be equally relevant in every case, but registrants must have processes to reasonably consider each factor's relevance to the specific investment action, always prioritizing the client's interest over their own or other competing considerations. Documentation should be detailed enough to illustrate a reasonable basis for the determination that the action is suitable and puts the client's interest first - reflecting understanding of the product, its risk, complexity, and uniqueness, and enabling robust supervisory review. Where firms offer model portfolios, suitability determinations are expected at both the model-construction level and the client-facing level, including for any substitutions or deviations. Firms that maintained well-defined investment policy statements considering all of a client's accounts, combined with automated pre- and post-trade compliance tools, were generally better positioned to demonstrate compliance.
Registrants must assess how an investment action affects concentration and liquidity within a client's account and, where a client holds multiple accounts at the firm, across the client's overall portfolio.
Registrants should have appropriate controls to calculate, monitor, and manage concentration in client accounts and portfolios, tailored to their business model and securities offered - the higher the concentration in a particular security, sector, or industry, the more the registrant should document to demonstrate suitability and client-interest-first. Where a holding exceeds internal thresholds but remains suitable, registrants must document the rationale in detail. Firms with narrower or higher-risk offerings should gather thorough financial circumstances information, including external holdings, sector, and overall exempt-product exposure. Firms maintaining multiple client accounts need processes to assess and monitor concentration and liquidity across the full portfolio those accounts comprise.
As part of assessing suitability and putting the client's interest first, registrants must consider the actual and potential impact of costs associated with an investment action on the client's return.
Registrants should have processes to assess all direct and indirect costs, fees, commissions, and compensation associated with an investment action and compare them against other available options. Because costs significantly affect client returns, individuals should consider relative costs, including compensation paid directly or indirectly to the firm or individual, put the client's interest first when choosing among suitable options, and document the rationale when recommending a higher-cost product. The relevance and documentation burden vary by circumstance: uniform-commission listed securities generally require minimal documentation, while a choice among multiple series with different costs must be documented as part of the suitability determination for the series selected.
When assessing a proposed investment action, registrants must consider a reasonable range of alternative actions available through their firm at the time.
Firms must have processes to ensure a reasonable range of alternatives is considered, clearly defining who is responsible for identifying and assessing alternatives and when, the scope of products to be considered in defining a "reasonable" range, and what documentation the process requires. Firms with broad product shelves may design efficient centralized processes while still giving individuals enough flexibility to evaluate alternatives and make personalized recommendations; documentation should reflect the complexity of the security. Evaluating alternatives requires assessing cost structures and returns, including lower-cost options available through the firm, with the basis for the determination documented.
Registrants must reassess a client's account and holdings to ensure they remain suitable and continue to put the client's interest first. At minimum, this must occur when the registrant conducts its periodic KYC review; other triggers include a change to the registered individual responsible for the account, or the registrant becoming aware of a KYP or KYC change that could affect whether the suitability determination criteria are still met.
Reviews must assess whether the account and its securities continue to be suitable and put the client's interest first, considering whether alternative securities would better serve the client and any potential concentration or liquidity issues arising from market movements. The reassessment process should align with the firm's business model - a detailed periodic reassessment is critical for firms following a buy-and-hold, minimal-trading strategy. Generic notes like "no changes" are insufficient; records should show a meaningful reassessment took place. Exempt market dealers with only a transactional relationship to clients (no ongoing account) aren't subject to the reassessment requirement, since there's no ongoing client relationship or account to reassess.
Registrants must assess whether a client-directed trade is suitable and puts the client's interest first. If it isn't, the registrant must inform the client of the determination and its basis, recommend a suitable alternative action, and, if the client still wishes to proceed, confirm and document the client's instruction to do so.
When a client-directed trade instruction is received, the registrant must first assess suitability with consideration of all criteria in subsection 13.3(1). If the action isn't suitable or doesn't put the client's interest first, the registrant must follow the required steps - inform the client, recommend a suitable alternative, and document confirmation if the client proceeds anyway. Simply noting that the client directed the trade is not sufficient documentation. If the proposed action is unsuitable and no suitable alternative is available through the firm, the registrant should recommend the client not make the investment.
Section 11.1 of NI 31-103 requires firms to establish, maintain, and apply policies and procedures that give reasonable assurance the firm and every individual acting on its behalf complies with securities legislation - including KYC, KYP, and suitability determination requirements - and explicitly requires firms to train registered individuals on that compliance. Staff identified issues with both across the review.
Issues identified with KYC, KYP, and suitability determination policies and procedures included outdated policies that had not been updated to reflect the CFRs, and policies that were generic and not tailored to the firm's own operations - some simply repeated the rule text without any detail on how compliance is actually achieved at that firm, or what level of documentation is required as evidence of it.
Policies and procedures should be comprehensive, current, and tailored to the business. At minimum, Staff expect them to cover:
Training should be tailored to the firm's operations and appropriate to its size, comprehensive, and cover all key elements of the requirements with relevant examples. It should be mandatory for all registered individuals, and firms should keep records of both content and attendance. Where training is outsourced, the firm remains responsible for assessing the third party's training for adequacy, accuracy, and fit to its own operations. Firms should consider whether product-specific training is necessary for new or complex securities, and should assess whether individuals actually understood the training provided - one effective practice Staff observed was requiring a quiz at the end of training, with a minimum passing mark (e.g., over 75%) as evidence of successful completion.