The following is an outline of what wealth management firms in Canada and the United States need to have in place to meet regulatory requirements for Know-Your-Product (KYP): the ongoing monitoring, due diligence, and audit trail that CIRO and the CSA expect north of the border, and that the SEC and FINRA expect south of it, for every security on the shelf and in every client account. The obligation doesn't end at initial approval - it's continuous, and it has to hold up the same way for every advisor, every time.
That consistency is the actual requirement. A firm needs one defined process - not individual judgment - for what belongs on the product shelf, how it's monitored once approved, what happens when something changes, and how the resulting alert gets resolved. That process has to run identically across every advisor and every account, and it has to leave a record: what was decided, when, by whom, and why - retrievable on demand, not reconstructed after a regulator asks.
The obligation splits across three groups, and KYP frameworks on both sides of the border assign it the same way. Product management (a head office committee, typically) decides what belongs on the shelf and monitors it at the product level. Each advisor decides what belongs in a client's account and monitors it at the position level. Supervision proves, for any security at any time, that both happened - the record CIRO, the CSA, the SEC, or FINRA will ask for in a review or a sweep. Most firms run these three jobs on disconnected tools - a watchlist here, a spreadsheet there, a quarterly sample of ten names out of four hundred. That's a structural gap, not a discipline problem: all three teams are asking the same question - has anything changed about this security that changes the conclusion already reached? The data and monitoring behind that question should be built once, shared across all three teams, and documented in a single auditable record, not rebuilt three times and reconciled after the fact.
This page is that outline. It covers what Product Management does to approve and monitor the shelf, what Advisors are responsible for once a security is in a client's account, and what Supervision has to prove to any of the four regulators above. All three run on the same underlying material change definitions and monitoring data, apply the same severity-scaled workflow - Critical, Important, Watch - when an alert fires, and close it through a defined, auditable process. Together, that's what makes Know-Your-Product a continuous, firm-wide discipline instead of a point-in-time check.
Two things are worth defining before the rest of this page makes sense. What counts as a material change, and the process for approving a product in the first place, are product decisions - specific to each asset class, and defined in advance by Product Management, Section 1 and Section 2. What happens once a material change fires an alert, by contrast, is a regulatory requirement, not a product one - it has to be identical whether the alert lands on the shelf side or in an advisor's book. That workflow is defined once, under Supervision, Section 1, and both Product Management and Advisors follow it rather than each defining their own.
At a wealth management firm, investment dealer, or broker-dealer, a head office committee of product specialists, market specialists, and compliance officers decides what goes on the product shelf. Under Know-Your-Product obligations that apply across Canada and the US,[1] its job doesn't end at approval - it carries five ongoing responsibilities.
In the KYP HubStep by step: Product Approval.
The product team sets baseline eligibility parameters across every category on a full-service shelf: equities, mutual funds, exchange-traded funds (ETFs), bonds, principal-protected notes, municipal bonds, and private equity. Equities are screened on minimum share price or market capitalization, ruling out illiquid or highly speculative names. Mutual funds and ETFs require a minimum fund size or track record for a new fund family, and a minimum AUM threshold within an approved family. Bonds and municipal bonds are screened on issuer credit quality and minimum rating; principal-protected notes on the structuring counterparty's creditworthiness and guarantee terms; private equity and other exempt-market products get the most intensive review, given their illiquidity and thinner disclosure. Most firms run an open-architecture model - once a fund family or equity class clears the baseline, new products inside it are added routinely. Scrutiny concentrates on the higher-risk edge of each category: leveraged and inverse ETFs, crypto and Bitcoin funds, hedge funds, thinly traded or micro-cap equities, complex structured notes, and private placements. The standard doesn't change with what a firm trades - a full-shelf dealer and a fund-only shop face the same bar for whatever they carry.
Approval isn't a formality anywhere in North America: regulators on both sides of the border require an approval decision to be documented, analytically grounded, and defensible on demand - not just recorded.
CIRO, the CSA, and the OSC treat approval the same way. Their joint review of 105 registered firms found many with approvals that lacked supporting KYP assessment rationale, or that leaned on an affiliate's work instead of the firm's own analysis.[5] CIRO's bar is documented, meaningful consideration with supporting analysis behind every approval - whether it comes from a committee or a single reviewer - scaled to the shelf's complexity.[3]
The bar doesn't drop under US rules. The SEC's Regulation Best Interest requires reasonable diligence, care, and skill to understand a security's risks, rewards, and costs before recommending it.[6] Registered investment advisers carry the same fiduciary duty directly under the Investment Advisers Act. FINRA Rule 3110 goes further on the shelf itself: a broker-dealer's written supervisory procedures have to cover every product line it offers, which in practice means a documented new-product review process before anything is added to the shelf, and ongoing supervision of what's already on it - not just a one-time sign-off.[7] Whichever regulator - CIRO, the SEC, or FINRA - the question is the same: can the firm produce the analysis behind the decision, not just the decision itself.
Approval isn't a one-time event. Once a security is on the shelf, the same committee keeps reviewing it against three inputs: whether the original investment thesis still holds, the firm's current exposure, and how it has performed against its defined material change thresholds over time (Section 2). None of that holds up in isolation - it's measured against comparable securities in the same segment and market.
That process is defined once, not reassembled by hand for each review. Four categories of information feed every decision:
Reviews run on a defined schedule: opened immediately by a qualifying alert (Section 3), or on a regular 12-to-18-month cadence otherwise. Either path closes only with a formal, attributed sign-off.
In the KYP HubStep by step: Material Change. The rule behind it: Material Change: When to Reopen a KYP Assessment. Triggers by security type: equities, mutual funds and ETFs, structured products, segregated funds and annuities, model portfolios and alternatives and private markets.
Monitoring can't start until the firm has written down, in advance, what counts as a material change to a security's fundamentals - specific to the product type, not one generic rule across the shelf. Skip this step and "monitoring" is just a word: there's nothing concrete to check against.
The terminology has shifted over time, but the obligation hasn't. CIRO's foundational guidance calls this a "material change":[3]
The December 10, 2025 findings[5] use "significant change" for the same obligation, and flagged this gap as widespread: most of the 105 firms reviewed had no written definition of what a significant change meant for a given security type. A firm without a documented threshold can't demonstrate it was looking for the right thing. This document treats "material change" and "significant change" as the same requirement.
Neither the SEC nor FINRA defines a single term the way CIRO does, but the expectation lands in the same place. FINRA's suitability rule[8] requires a reasonable basis to believe a recommendation is suitable, built on genuine understanding of the product - understanding that can't stay frozen at the moment of the original recommendation. The SEC's Regulation Best Interest goes further: a recommendation compliant at one point in time doesn't stay compliant if the facts underneath it change,[6] and examiners have flagged firms with no written process for catching that. In practice, every firm - Canadian dealer or US broker-dealer - needs the same thing: a documented, product-specific definition of what change forces a fresh look.
That definition can't live only in a policy document or training deck - it has to sit in a system the firm can produce on demand, the same standard as the approval documentation in Section 1. A material change definition that exists only as a compliance officer's verbal understanding, or an analyst's personal spreadsheet, doesn't meet that bar, even if it's being followed faithfully.
For each material change definition, the system of record needs to capture, at minimum:
The registry itself has to stay current, not just get defined once and filed away. The December 10, 2025 findings criticized firms with no defined threshold at all; a stale one has the same effect if never revisited as products, markets, and risk tolerance change. The registry should have a defined owner - the same committee responsible for shelf approval in Section 1 - and a defined cadence for reassessing whether each material change definition's metric, condition, frequency, and severity still reflect current conditions, with changes logged and dated rather than edited in place.
The tables below show a representative material change definition, organized by severity rather than product type - six Critical, six Important, five Watch - mixing equities, mutual funds, and ETFs, the way a firm prioritizes response: by significance, not security type.
| Alert | Asset Class | Security Type | Metric | Breach Condition |
|---|---|---|---|---|
| Dividend Cut | Equity | All equities (flat rule) | Declared dividend per share | Current period's DPS is below the prior period's. |
| Earnings Miss | Equity | All equities (flat rule) | Reported EPS vs. consensus estimate | Actual EPS comes in below consensus estimate. |
| Quartile Ranking Drop | Mutual Fund | Category-relative (peer category) | Peer-category quartile ranking, trailing 3-year | Any quartile-boundary drop (1st to 2nd, 2nd to 3rd, or 3rd to 4th). |
| Alpha Turns Negative | Mutual Fund | Self-relative (fund's own trailing history) | Trailing alpha vs. benchmark | Trailing alpha crosses from positive to negative. |
| Net Outflow Alert | Mutual Fund | All fund categories (flat rule) | Monthly net flow, % of total net assets | 6 consecutive months of negative net flow, each month's outflow at least 1% of total net assets. |
| Fund Status Change | ETF | All ETFs (flat rule) | Fund status field | Any status change event (closed to new investors, or terminated). |
| Alert | Asset Class | Security Type | Metric | Breach Condition |
|---|---|---|---|---|
| Volatility Spike | Equity | Self-relative (security's own trailing history) | 30-day realized volatility | Exceeds a defined multiple of its own 1-year average. |
| Margin Compression | Equity | All equities (flat rule) | Operating / profit margin | Declines by 2 or more points quarter-over-quarter or year-over-year. |
| Free Cash Flow Decline | Equity | All equities (flat rule) | Free cash flow | Declines by a defined percentage year-over-year. |
| Management Fee / MER Increase | Mutual Fund | All fund categories (flat rule) | Management fee / MER | Any increase versus the prior period. |
| Underperformance vs. Category | Mutual Fund | Category-relative (peer category) | Trailing return vs. peer category | Underperforms peer category average by a defined margin over a trailing period. |
| AUM Decline | ETF | All ETFs (flat rule) | Total assets under management | Declines by a defined percentage over a trailing period. |
| Alert | Asset Class | Security Type | Metric | Breach Condition |
|---|---|---|---|---|
| Drawdown from Peak | Equity | All equities (flat rule) | Price vs. rolling peak | Percentage decline from the security's rolling price peak, past a defined threshold. |
| P/E, EV/EBITDA, P/B Deviation | Equity | Sector-relative (GICS sector) | Valuation multiples vs. sector | Deviates from the security's own sector average by a defined margin. |
| Turnover Spike | Mutual Fund | Self-relative (fund's own trailing history) | Portfolio turnover ratio | Exceeds a defined multiple of its own historical average. |
| Valuation Drift vs. Category | Mutual Fund | Category-relative (peer category) | Portfolio valuation multiples vs. peer category | Drifts from peer category average by a defined margin. |
| Tracking Error Increase | ETF | Category-relative (fund's own benchmark) | Fund return vs. benchmark return | Standard deviation between the two widens beyond a defined tolerance over a trailing period. |
Each threshold should tie back explicitly to the regulatory obligation it satisfies, rather than leaving the connection implicit.
In the KYP HubWhen an alert fires: From Alert to Decision. Testing the data behind monitoring: Auditing KYP Monitoring Data.
Once thresholds are documented, every security on the shelf has to be evaluated against them continuously, not through periodic sampling. The December 10, 2025 findings[5] are direct on this: annual review alone was judged insufficient for complex or risky products, and passively waiting for an issuer to announce a change was flagged as a deficiency in its own right. A quarterly check of the shelf's higher-profile names will always miss a change between checks. Monitoring frequency should be calibrated to each security's risk and complexity, not applied on one blanket schedule.
Ongoing monitoring should also account for a condition that stays flagged over time. If the same issue keeps re-opening a fresh review, reviewers tune out - which defeats the purpose. Firm policy should define, in advance, how long a reviewed condition stays "settled" before it warrants re-review, and what breaks that window immediately, such as the condition getting materially worse. That's decided once, up front, not left to individual judgment.
Mechanically, that evaluation runs as a continuous loop across the whole shelf, with one decision at its center: does the cycle end quietly, or open an alert?
When a security crosses its defined threshold, the response that follows - who has to act, what they have to produce, and by when - is the workflow defined once, at the regulatory level, in Supervision, Section 1, scaled to the severity already assigned to that material change in the registry (Section 2). What belongs to Product Management is the shelf-level piece of that workflow: the review below, which closes with the firm recording one of three outcomes:
A Critical breach opens a defined product management workflow: the committee reviews the security, records a status decision, and notifies every advisor holding it - whose own review is covered in the Advisors section.
This is the mechanism behind the timeframe and ownership questions above: a Critical material change breach opening a defined, three-step product management workflow that closes with every affected advisor notified.
Every step above has to leave a record - whether the standard is CIRO's in Canada or the SEC and FINRA's in the US[6][7], the test is the same: can the firm produce evidence, not just assert the work happened. Each review opened by a material change breach must capture: the date the threshold was crossed, who reviewed it and when, what was reviewed, the rationale for the outcome, and, where an advisor-level review was opened, what the advisor concluded.
That documentation needs to be stored somewhere retrievable on demand, not scattered across email or individual notes. For a Wind-Down decision, documentation tracks progress through to completion - the unwind, not the decision, is the end of the record. This is what a firm hands a regulator or auditor to show the monitoring obligation was met, not just asserted.
Concretely, once material change is defined (Section 2), the firm has to be able to produce five categories of record on demand:
Two further record types make this trustworthy, not just complete. Entries should be appended, never edited: a correction is a new, dated entry referencing the one it corrects, preserving the history of what was known and when - the same discipline this document applies to the material change registry (Section 2). And every breach and evaluation record needs to reference the specific material-change-definition version in effect when it was created; a record has no evidentiary value if it can't show which threshold and severity level applied on the date it was breached.
| Record | What It Proves | Captured | Granularity |
|---|---|---|---|
| Material Change Breach Log | A specific material change was breached for a specific security. | At the moment of evaluation | Per security, per material change, per event |
| Breach Frequency Rollup | How often a given material change has been breached across the whole shelf. | Derived from the Material Change Breach Log | Per material change, aggregated across securities |
| Evaluation (No-Breach) Log | The security was checked and cleared, not simply left unchecked. | Every scheduled evaluation, whether or not it fires | Per security, per evaluation cycle |
| Alert Delivery Record | Every advisor holding the security received the resulting alert. | At time of alert dispatch | Per alert, per recipient advisor |
| Critical Workflow Timeliness Record | The product-level Critical workflow was completed within its required timeframe. | At each workflow milestone (opened, decision, closed) | Per Critical material change event |
| Shelf Coverage Completeness | Every security on the shelf was evaluated on its defined cadence - a full sweep, not a sample. | Rolled up over a reporting period | Firm-wide, across the full shelf |
| Material Change Version Linkage | Which threshold and severity level was in effect when a given record was created. | At the moment each record is written | Per record, referencing the registry version (Section 2) |
That monitoring obligation doesn't depend on ownership. A security with no advisor currently holding it still has to be evaluated on the same schedule as everything else on the shelf (Section 3) - the shelf, not any advisor's book, defines the monitored population. The only difference is on alert delivery: with no advisor of record, there's no one to route an alert to. The evaluation itself, and the proof of it, still has to exist.
All of this needs to be retrievable as more than disconnected logs - an audit trail a product management team can generate on demand, for any material change or any security, rather than reconstructing it by hand each time an auditor asks:
Because that data is captured as it happens rather than assembled after the fact, none of this is new reporting work - it's the same records above, filtered and rolled up on demand.
Product Management covers how the shelf is defined and monitored - what belongs on it, what counts as a material change, and how the firm responds when one crosses a threshold. This section covers what an individual advisor is responsible for, on a purely know-your-product basis, once a security from that shelf is in a client's account.
An advisor shouldn't be re-litigating the shelf-level approval - that's the product team's job. An advisor answers a narrower question about their own book: has anything changed about a security they hold that changes whether the advisor still genuinely understands it the way KYP requires, and if fundamentals have shifted, is there now a better alternative on the shelf. That question runs through the same material change and alert infrastructure the product team uses, not a separate one.
This section covers what an advisor configures on their own book, and what the platform requires the moment an alert reaches them: a documented, product-level review of the security itself - not a review of any client's account, and not a determination that turns on client-specific facts like risk tolerance or investment horizon.
An advisor's know-your-product obligation[1] sits one level below the shelf: everything below applies the material change definitions and severities the product team has already defined (Product Management, Section 2) to the securities an advisor actually holds. Under CIRO's rules, this is a distinct, standalone obligation[1] - it sits with the individual advisor, not just the committee, and it applies regardless of who any given client is:
South of the border, the same review sits inside the broker-dealer's Care Obligation under Regulation Best Interest[6]: before a registered representative can recommend a security at all, the firm has to have a reasonable basis to believe it understands that security's features, costs, and risks - a product-level, standalone requirement that exists independently of any individual client's circumstances. Whether the standard is CIRO's or the SEC's, the review below asks the same question: does the firm still genuinely understand this security, not whether it's still right for a particular client.
Monitoring and alerts are two distinct things, and the platform keeps them distinct. Monitoring is the ongoing tracking of a security's metrics for material change - all of them, whether or not any currently carries an alert threshold. An alert is a threshold set on one of those monitored metrics that generates a notification when it's crossed. A security can be monitored on twenty metrics with only one or two of them alert-worthy; the advisor should still have visibility into all twenty, not just the ones configured to fire.
What gets monitored is itself layered:
Alerts are a threshold layered on top of a subset of those metrics, not a separate tracking system. The same three layers apply to thresholds: firm-level alert thresholds are mandatory across the shelf; an advisor can add or tighten thresholds across their book, or for one security specifically, on top of whatever the firm already monitors. An advisor can toggle any alert on or off, including mandatory firm-level ones - the underlying metric stays monitored either way; only the notification stops.
Beyond configuration, advisors should have visibility into a security's full monitoring history, not just what it's alerted on:
In short, the view should work in both directions:
Monitoring itself sits at the firm level (Section 1) - it runs continuously against every security an advisor holds, whether or not anything ever breaches. The moment a material change is breached and an alert generates, that changes: responsibility shifts to the advisor holding the security, who now owns conducting the resulting due diligence review. What that review actually requires - and how quickly - depends on the alert's severity, and that scaling shouldn't be the advisor's call to make case by case. Supervision should define the workflow once, for every severity level, and both the shelf-level and advisor-level response follow it (Supervision, Section 1).
For a Critical alert specifically, that firm-defined workflow is what triggers the investment review automatically - it shouldn't be a judgment call the advisor makes on receiving the alert. If Supervision has defined, ahead of time, that a Critical alert on a held security requires a review within a set window - ten business days, for example - the advisor is notified the moment the alert generates and guided directly into that review, rather than deciding independently whether the alert warrants one. When that notification reaches the advisor, it should carry full context, not just the fact that something happened: what alert and material change condition fired, the specific metric and the data behind the breach, when it happened, and whether the same alert has occurred on that security before.
The response required scales with severity, and the table below shows what each level looks like in practice, from the alert opening through to how it closes:
| Severity | Example | Lifecycle |
|---|---|---|
| Critical | A dividend cut on a held equity, or a mutual fund's fund status changing to closed or terminated. | Opens automatically on the security and routes to every advisor holding it. Triggers the investment review below, due within the timeframe Supervision has defined for Critical alerts. Closes once the review is completed and filed. |
| Important | Margin compression on a held equity, or a management fee increase on a held mutual fund. | Opens on the security. The advisor acknowledges it and documents notes directly on the alert. Closes on acknowledgment - unless two or three Important alerts recur on the same security within a defined window, in which case the pattern escalates into a full investment review. |
| Watch | A drawdown from peak price, or a valuation drift against peer category. | Opens on the security. Eligible for bulk close alongside other open Watch alerts, within its own designated timeframe, without an individual write-up unless the advisor chooses to document one. |
CIRO and the CSA are direct about why the Critical-level review can't be optional once a security is flagged:
That review runs in parallel with the shelf-level review the product team conducts on the same material change (Product Management, Section 4) - the shelf-level status decision feeds directly into what the advisor sees, but neither side waits on the other to start. The review itself breaks into four steps, each of which becomes part of the permanent record rather than a private working note:
| Step | What It Covers |
|---|---|
| 1. Investment Review | A review of the security's fundamentals, paying specific attention to the material change that generated the alert, and drawing on any due diligence notes already captured at the firm level for that security. |
| 2. Comparable Securities Review | A review of comparable securities in the same segment, so the decision isn't reached in isolation from what else is available on the shelf. |
| 3. Written Decision | The advisor's decision on the security, confirmed in writing: hold and maintain, or initiate a transition out and identify replacement positions, drawing on a documented, reasonable range of alternatives rather than a single default choice - the December 2025 findings flagged firms with no documented process for assessing alternatives at all.[5] |
| 4. Documentation and Audit Trail | Everything above, documented in an auditable format accessible to the supervision team, so completion of every step can be confirmed without asking the advisor directly (Section 4). |
The review shouldn't be a rigid checklist. It's non-delegable - it has to be completed directly by the advisor, which is exactly why it should stay efficient rather than layered with unnecessary steps - but within that, it draws on the advisor's own judgment and analysis of the security, not a mechanically filled-in form. What matters for the record is that the fundamentals were genuinely reconsidered, that a snapshot of the data as of the review is captured rather than a live reference that can drift afterward, and that the reasoning behind the decision is written down, not just the conclusion. When more than one review is open at once, Critical takes priority, followed by Important, then Watch.
Once the review is completed and the review record is filed, the alert is closed. If the outcome also calls for a suitability review of specific clients holding the security, that has to be completed too - but it's a separate process from the one above, run against a different set of inputs entirely: client-specific facts like KYC profile, risk tolerance, and investment horizon, rather than the security itself. Suitability is evaluated per client;[2] KYP is evaluated per product[1] - the joint CSA/CIRO reform work draws that line explicitly[5] - and closing the KYP-level review above doesn't wait on it.
A Suspend or Wind-Down decision reached on the shelf side (Product Management, Section 4) becomes information the advisor's review has to account for, though here too, neither workflow waits on the other to start.
In the KYP HubStep by step: Advisor Due Diligence.
An advisor's due diligence obligation starts before any ongoing monitoring does. Adding a security to a client's account - by transfer-in or a new transaction - requires its own due diligence review at that point, independent of anything the monitoring record captures afterward.
From there, ongoing due diligence for an advisor runs on one of two tracks: it's opened by an alert, or it runs on a periodic cadence when nothing has fired. Both tracks, and the specific conditions that open a review, are defined once at the firm level as a minimum standard - not something each advisor sets for themselves.
Absent a triggering alert, the advisor still conducts a periodic review on a defined cadence - typically every 12 to 18 months per firm policy - as a separate, calendar-driven workflow that runs alongside the alert-driven one. That obligation to keep checking, not just to have checked once, isn't unique to either side of the border: it mirrors the ongoing suitability obligation under CIRO's suitability determination rule[2] in Canada, and it sits inside FINRA's supervision rule[7] and the SEC's Care Obligation under Regulation Best Interest[6] in the US - a recommendation that was compliant when it was made doesn't stay compliant on its own; someone has to keep checking.
Ongoing due diligence isn't just a scheduled check-in - it requires the advisor to build and maintain notes and documentation supporting the position over time: manager commentaries, analyst reviews, annual reports, or other supporting content. The bar is substantive, not perfunctory, on either side of the border. Canada's December 2025 findings singled out firms where "a note stating only 'no update' or 'no changes' in the client file...was insufficient without other evidence that a meaningful interaction took place,"[5] and firms that broadly "failed to properly document periodic suitability reassessments or demonstrate that a full suitability review of the account and holdings had been conducted."[5] FINRA's own supervision rule sets the same bar in the US: written procedures and the records to show they were actually followed, not just that they exist.[7]
Concretely, three conditions open a review, and each resets the periodic clock the same way a completed review does - the table below shows what triggers each one and the process that follows:
| Trigger | Example | Resulting Process |
|---|---|---|
| Critical Alert | A dividend cut on a held equity, or a mutual fund's status changing to closed or terminated. | Opens a due diligence review - the investment review of that security defined in Section 2 - at the advisor level, completed within the timeframe Supervision has set for Critical alerts. |
| Repeated Important Alerts | Three Important alerts on the same security within a 90-day period, for example - the specific count and window are set by firm policy, not fixed by regulation. | The pattern itself opens a full investment review, even though no single Important alert in the group would have on its own. |
| Periodic Review (No Alerts) | No Critical or Important alert on the security within the past 18 months. | Opens a periodic review on schedule: the advisor determines whether better alternatives are now available, or whether the security still meets their requirements, even though nothing has fired. |
Whichever of the three opens it, completing the review resets the clock: the 12-to-18-month cycle restarts from the date of that review, not from the date of the last one, regardless of which condition actually opened it.
All three conditions, and the cadence itself, are a firm-defined floor, not a ceiling. Supervision sets them as the minimum that applies to every advisor and every security; individual advisors can layer on additional review triggers or a tighter cadence of their own, based on how they manage their own book, the same way they can add monitoring metrics and alert thresholds on top of the firm's own (Section 1). What an advisor adds is theirs to define, but it doesn't lower the floor, and none of it sits outside view: supervision needs visibility into whether the firm-level minimum itself is being met for every advisor and every security, independent of whatever an individual advisor has added on top (Section 4).
Each security's monitoring history - every alert: material change, direction, severity, date breached, status, and who acted and when (Product Management, Section 5) - should surface automatically alongside the due diligence review. That pairs the advisor's point-in-time judgment with the full paper trail, so a review reflects how the security behaved over the period, not just how it looks on the day it's reviewed.
The same principle applies at the book level. An advisor - and, firm-wide, compliance - should have a rolled-up view across the whole book: every material change in effect and every alert against it, filterable by type, security, and date, prioritized by dollar AUM exposure rather than raw count. That view lets an advisor tell, before opening a single account, whether an issue is isolated or systemic across their book - a handful of unacknowledged Critical alerts with real AUM behind them is a different problem than the same count spread across Watch alerts on small positions.
When a regulator evaluates whether an advisor's know-your-product obligation is actually being met, the question comes down to two components, and both have to be answered yes. First: does a documented process exist at all - not tribal knowledge, not a training deck, but a written, followable process. Second: is that process actually being followed, provably, not just described on paper. Sections 1 through 3 above establish the process itself - what gets monitored, how an alert routes into a review, and when a periodic review opens absent one. None of that survives contact with a regulator, though, unless it's documented as it happens.
Documentation here doesn't mean producing a PDF after the fact. It means an audit trail that shows the process was actually followed over time, not reconstructed after the fact to look like it was. Concretely, that audit trail has to include:
Together, that's what documentation means for an advisor, and it's fundamental: a firm with a well-designed process but no way to prove it was followed fails the same way a firm with no process at all does - the whole framework falls apart without it. It's critical that an advisor can consistently generate and store due diligence review documentation, proof of ongoing monitoring, and proof that alerts were processed and closed - not occasionally, and not only for the securities that happen to draw attention, but as a matter of course for everything they hold.
That consistency requirement isn't a design preference - it's written into CIRO's own rules. A Dealer Member must establish, maintain, and apply written policies and procedures that provide reasonable assurance the firm, its employees, and its Approved Persons all comply with CIRO's requirements[9] - one process, applied the same way across every advisor, not left to individual discretion. The same section of the rulebook requires the firm to maintain evidence that those procedures are actually being followed[9] - the audit-trail obligation above, in other words. An advisor can't meet a documentation standard that varies from one advisor to the next; the process and the proof of it have to be the same, whoever is holding the security.
The December 2025 findings were pointed about firms that fell short of that bar:
The per-security audit log exists specifically to close that gap. Every acknowledgment, comment, closure reason, and know-your-product confirmation an advisor records feeds the same enterprise registry Product Management establishes for the shelf, rendered for each held security as a log specific to that security - reviews and their documentation, the complete monitoring record, alert history, and scheduled reviews still to come, all in one place, so a reviewer can see why a decision was reached, not just that one was made.
An advisor's actions complete two of the record types that registry requires (Product Management, Section 5): the Alert Delivery Confirmation - proof the advisor received and acted on the alert, not just that it was sent - and the Critical Workflow Timeliness Record, on the advisor-level side. That's what makes the record complete: a regulator or auditor reviewing one security sees both halves of the response, the shelf-level decision and the advisor-level review, without reconstructing either from separate systems.
Supervision covers how compliance consumes that combined record to demonstrate the monitoring obligation was met - at the shelf level, and at the level of every individual advisor action.
Compliance's job is different from the other two. Product Management covers what belongs on the shelf and how it's monitored; Advisors covers what an individual advisor does once a security is in a client's account. Compliance shouldn't need to run a third, separate monitoring process - its job should be proving, after the fact, that both of the others happened, for every security, every time.
Compliance shouldn't need to maintain its own independent log. It should consume the enterprise registry the product team establishes at the shelf level (Product Management, Section 5) and the per-security audit trail advisors feed at the position level (Advisors, Section 4), and should be able to produce both, for any security, on demand - to an internal auditor or to CIRO directly.
This section covers what that combined record needs to show, and how it gets produced when someone actually asks for it.
In the KYP HubStep by step: Supervising a KYP Program. What the file must show: KYP Documentation: What Your File Must Show.
Product Management, Section 2 defines what counts as a material change and the condition that breaches it - that definition is a product decision. What happens once a material change is breached - who acts, what they produce, and by when - is a firm-defined workflow: each firm sets it based on how it wants its advisors and product team to respond. That a documented workflow needs to exist at all, and needs to be followed the same way every time, is the regulatory requirement - it's what CIRO and the CSA actually examine when they assess whether a firm's monitoring obligation was met,[5] and the same expectation holds under FINRA's supervision rule[7] and the SEC's Regulation Best Interest[6] in the US. Supervision needs to define that workflow once, for the firm, and both Product Management, Section 4 and Advisors, Section 2 follow whatever Supervision has set.
A material change is a documented condition that, once breached, generates an alert carrying its assigned severity (Product Management, Section 2). What follows below is one example of how a firm might scale that response by severity - the specific timeframes, review scope, and closure mechanics are illustrative, not prescribed by regulation; each firm defines its own. The two tables below show the same three severities from each side of the workflow: what the product team's review covers at the shelf level, and what an advisor's review covers once it reaches their book.
| Severity | Trigger | Review & Outcome | Timeframe | Downstream Impact |
|---|---|---|---|---|
| Critical | Critical alert on a shelf security. | Formal investment review - fundamentals, financial ratios, costs, risks, and other changes, benchmarked against comparables. All supporting data is captured and saved. Resolves to Maintain, Hold (no new buys, sells only), or Exit/Wind-Down (reduce client positions). | 10 business days from alert generation (example). | A Hold or Exit/Wind-Down status pushes to every advisor holding the security, triggering the advisor-level workflow below. |
| Important | Important alert on a shelf security. | Acknowledged with notes. Escalates to the same formal investment review as Critical if more than two Important alerts recur on the same security within 90 days. | Firm-defined for acknowledgment; an escalation review follows the Critical timeframe. | Escalation triggers the same status push and advisor-level workflow as Critical. |
| Watch | Watch alert on a shelf security. | No individual review - eligible for bulk closure. | Firm-defined; every alert still closes within its own window - it shouldn't be left open indefinitely. | None. |
| Severity | Trigger | Review & Outcome | Timeframe | Suitability / Client Impact |
|---|---|---|---|---|
| Critical | Critical alert on a held security, or a Hold / Exit-Wind-Down status pushed down from Product Management. | Investment review of the security as held in the advisor's book - the same fundamentals, comparables, and cost/risk analysis as the shelf-level review, focused on whether it still belongs in the accounts holding it. Resolves to Maintain, Hold (no further buys), or Exit/Wind-Down (reduce or close client positions). | 10 business days from alert generation (example, matching the firm's Critical window). | A Hold or Exit/Wind-Down outcome flags every client account holding the security for a suitability follow-up - confirming the position, or its wind-down, still fits each client's KYC profile and risk tolerance. A separate, client-specific process, run against different inputs than the KYP review itself. |
| Important | Important alert on a held security. | Acknowledged with notes. Escalates to the same investment review as Critical if more than two Important alerts recur on the same security within 90 days. | Firm-defined for acknowledgment; an escalation review follows the Critical timeframe. | No suitability trigger on a routine acknowledgment. An escalation that produces a Hold or Exit/Wind-Down outcome carries the same client-level follow-up as Critical. |
| Watch | Watch alert on a held security. | No individual review - eligible for bulk closure. | Firm-defined; every alert still closes within its own window - it shouldn't be left open indefinitely. | None. |
The two tables above are illustrative, not prescriptive: what a regulator examines isn't whether the response matches these specific numbers, but whether Product Management and Advisors both consistently follow whatever workflow Supervision has actually defined for the firm.
Consolidated reporting is the aggregation of everything the firm has generated at the shelf level and the advisor level, across every security and every advisor, into one continuous record rather than two disconnected ones. Compliance shouldn't need to build that aggregation as a separate system - it should be assembled from the records Product Management and Advisors are already required to produce. For any security, at any time, that record needs to cover the following - and be able to confirm, not just capture, each one:
| Level | Record Component | What It Captures & Confirms | Established In |
|---|---|---|---|
| Shelf | Shelf Approval | The documented, analytically grounded decision behind adding the security to the shelf - the approval rationale and ongoing review documentation on file. | Product Management, Section 1 |
| Shelf | Material Change Definition | The metric, condition, and severity that define a material change for that security, and the version in effect on any given date. | Product Management, Section 2 |
| Shelf | Monitoring & Breach History | A continuous log of monitoring activity against the security relative to that definition - evaluations that clear as well as ones that breach - with breach frequency and proof of ongoing evaluation current at all times. | Product Management, Section 3 & 5 |
| Shelf | Alert Trigger | Identification of exactly when an alert was triggered, which material change condition fired, and at what severity. | Product Management, Section 2 & 5 |
| Shelf | Evaluation Cadence | Every security on the shelf evaluated on its defined cadence - a full sweep, including securities no advisor currently holds. | Product Management, Section 5 |
| Shelf | Shelf-Level Workflow | The workflow triggered once a material change was breached - how it was initiated, the sequence followed, the output reached, and the documentation behind it - and whether any Critical workflow closed within its required timeframe. | Product Management, Section 4 & 5; Supervision, Section 1 |
| Both | Alert Delivery | Where the alert was sent and when it was received, at both the shelf level and the advisor level - and confirmation that every advisor holding the security received it and acted on it. | Product Management, Section 5; Advisors, Section 4 |
| Advisor | Advisor-Level Workflow | The investment review triggered on the advisor's book - how it was initiated, the sequence followed, the output reached, and the documentation behind it - a documented review for the outcome reached, not just the conclusion. | Advisors, Section 2 |
| Advisor | Suitability Follow-Up | A client suitability follow-up completed wherever the outcome required one. | Advisors, Section 2 |
| Advisor | Periodic Review Cadence | The periodic due diligence review run on cadence, or correctly reset by a qualifying material change breach. | Advisors, Section 3 |
| Advisor | Know-Your-Product Confirmation | A know-your-product confirmation recorded for the security. | Advisors, Section 1 & 2 |
| Both | Downstream Workflows | Any workflow triggered off the back of the initial one - a firm-level decision to place a security on Hold, for example, and the advisor-level workflow that decision in turn triggers. | Product Management, Section 4; Advisors, Section 2 |
None of this is a separate checklist maintained on the side - every row above reads against a record Product Management or Advisors is already required to produce. Compliance should confirm the record exists and is complete; it shouldn't need to generate new data.
Aggregated this way, the record does more than answer questions about a single security. It gives supervision one continuous view of the entire firm - not just what happened, but whether the firm's own defined process was actually followed, security by security and advisor by advisor. Held up against that same defined process, the aggregated record surfaces exactly where it wasn't, including patterns like:
Supervision needs the ability to see the firm's activity in aggregate against that predefined, documented process - not security by security, but across the whole business at once. That aggregate view is what a regulator is actually looking for[5][9]: a defined process, documentation that the process is being followed, and evidence of the follow-up taken when it isn't - a practice-management response, not necessarily a disciplinary one, showing the firm actively manages adherence rather than assuming it. Structured this way, consolidated reporting gives supervision as clear a picture as possible of those processes and how they're being managed across the business.
The mechanism for producing all of this is an audit log a compliance officer or examiner can generate on demand, for a single security or for a reporting period across the shelf - drawing on the records Product Management defines (Product Management, Section 5) and the per-security audit log Advisors maintains (Advisors, Section 4), joined so the shelf-level decision and the advisor-level response can be reviewed side by side rather than pulled from separate systems.
Why that matters on demand, not reconstructed after the fact, is spelled out in the same December 2025 findings[5]: as noted in Product Management, Section 1, many firms CIRO reviewed couldn't produce documentation showing the analysis behind a decision - not because the work hadn't happened, but because there was no single, retrievable record to confirm it had. A firm that has to manually reconstruct a security's history each time doesn't have a supervision record; it has raw material for one. The same expectation holds under the SEC and FINRA's supervision and suitability rules[6][7][8] in the US: a firm has to be able to show its process was followed, not just assert that it was.
At bottom, an audit log generated on demand has to answer three things: what the rules are, what happened, and whether the rules were followed. Concretely, that means it has to be able to produce, for any security, advisor, or reporting period, without further digging:
Put together, that's a summary of the rules and the process, backed by documented proof that both have been followed consistently - not a single conclusion, but the evidence a regulator can trace decision by decision.
Beyond producing a record on request, supervision needs the same visibility applied proactively - surfacing risk before someone has to go looking for it, not only confirming it after the fact.
At the advisor population level, that means confirming, across every advisor, who is and isn't following the documented process - and flagging those who aren't. It also means seeing the risk behind outstanding alerts specifically: how much monetary exposure sits behind them, and how many positions are involved. That view should be available at both the branch and national level.
At the shelf level, the same visibility applies to positions actually generating breach alerts. Supervision has to satisfy a regulator on three points: an end-to-end process exists for monitoring the shelf's material change definitions, the shelf is actively managed rather than left to run on its own, and advisors follow a defined, consistent review process rather than each handling alerts their own way. On that basis, supervision confirms that everything in an advisor's book is monitored and reviewed - on a periodic cadence or a predefined material change breach - with nothing falling outside either path.
The final step sits at the client level: confirming that suitability requirements tied to that client's KYC profile are met and optimized against the KYP conclusions reached upstream. That closes the loop the Introduction opened with - the shelf-level decision, advisor-level review, and client-level suitability outcome all trace back to the same documented process, so supervision can demonstrate the system as a whole is working, not just that one security looks fine in isolation.
All three levels above draw from the same audit log, available to Supervision at the branch and national level alike - not three separate views, but the same underlying record filtered to whoever is looking for risk in the system.
That's the same standard this document opened with: not whether the work happened, but whether anyone can show it.