Platform Why Features Security Score AI Engine AI Coding KYP Hub Pricing Company About Buckler News Contact Français Book Demo →
Regulatory Basis

The Obligation

Before defining triggers, it's worth being precise about what the rules require. Canada writes a product monitoring duty into its rules. The US gets to a similar place less directly, through the obligation to understand a product before recommending it.

1
Two Linked Rules: The Firm Monitors, the Individual Understands
A monitoring duty at the firm level, and an understanding duty at the individual level that depends on it

Canada's framework is explicit, and it comes in two parts. The first sits with the firm. Under CIRO's Rule 3301 (mirrored for other registrants in NI 31-103, paragraph 13.2.1(1)(c)), a dealer can't make a security available to clients unless it has taken reasonable steps to assess it, approve it, and:[1]

"(iii) monitor the securities or derivatives for significant changes." CIRO IDPC Rule 3301(1)(iii) [1]

The second sits with each registered individual. Rule 3302 bars an Approved Person from buying, selling or recommending a security unless they take steps to understand it:[1][2]

"... including the securities' or derivatives' structure, features, risks, initial and ongoing costs and the impact of those costs." CIRO IDPC Rule 3302(1) [1]

Read together, the two rules form a chain. The firm's monitoring (3301) is how it learns a security has changed; that knowledge is what keeps each individual's understanding (3302) accurate. An individual can't understand a security's current features and risks if the firm hasn't noticed they changed. A firm with no defined trigger breaks the chain in the middle: it may be collecting information, but it has no reliable point at which a change becomes something anyone must act on. The joint staff notice makes the same point directly - some firms kept up-to-date issuer financials on file but had no evidence anyone had reviewed them as part of monitoring.[3]

Joint CSA/CIRO Staff Notice 31-368 grouped the monitoring deficiencies into four issues:[3]

  • No definition of significant change. Firms had monitoring processes but hadn't defined what constitutes a significant change in a security, or what action it should prompt.
  • Inadequate monitoring frequency. Some exempt market dealers selling risky, illiquid and complex products monitored only annually, which staff found inadequate.
  • Passive reliance on issuers. Some firms waited for issuers or manufacturers to notify them of changes, or asked them to confirm annually that nothing had changed.
  • No process, or no evidence. Some firms had no monitoring process at all, or couldn't show that securities and model portfolios had actually been reviewed.
"The greater the security's risk or likelihood of significant changes, the more frequently and closely it should be monitored. In general, annual monitoring alone was not found to be sufficient." Joint CSA/CIRO Staff Notice 31-368, p.18 [3]

The monitored population is wider than the current shelf. The notice says monitoring applies to securities available for purchase through the firm and, for firms with ongoing client relationships, to securities held in client accounts "even if those securities are no longer available for purchase through the firm."[3] Securities transferred in, or bought through client-directed trades, must be assessed within a reasonable time and brought into the monitoring process too, even though the firm isn't required to approve them for the shelf.[3] A trigger framework that only covers the approved list misses both groups.

2
No Monitoring Rule, but a Duty to Understand That Doesn't Expire
Product-level diligence for broker-dealers and advisers, and FINRA's expectations for product review

There is no US equivalent of Rule 3301(1)(iii) - no single rule that tells every firm to monitor every product for significant changes. The obligation is assembled from product-level diligence duties and supervisory expectations. Being precise here matters, because overstating the US requirement is a common mistake in cross-border material.

The first component of Reg BI's Care Obligation is product-level: a broker-dealer must understand the potential risks, rewards and costs associated with a recommendation, and have a reasonable basis to believe it could be in the best interest of at least some retail customers.[5][6] That understanding is tested at the time of each recommendation. A firm whose understanding of a product is a year out of date can't meet it, which makes ongoing product review a practical necessity even though the rule doesn't prescribe it.

The SEC's 2019 interpretation of the adviser standard of conduct sets a comparable bar at the product level:

"A reasonable belief that investment advice is in the best interest of a client also requires that an adviser conduct a reasonable investigation into the investment sufficient not to base its advice on materially inaccurate or incomplete information." SEC Release No. IA-5248, p.16 [7]

Information about a product that has since changed is exactly the kind of inaccurate or incomplete information the interpretation warns against.

At the firm level, FINRA Rule 3110 requires a supervisory system and written procedures reasonably designed to achieve compliance.[8] FINRA's guidance on new products goes further on the shelf itself. Notice to Members 05-26 describes post-approval review as a best practice: formally reviewing complex or conditionally approved products for a set period after approval.[9] Regulatory Notice 12-03 asks firms selling complex products to periodically reassess whether each product's performance and risk profile remain consistent with how the firm is selling it.[10] Neither is a rule in its own right, but both describe what an examiner expects a reasonably designed supervisory system to include.

Channel Source of Product Monitoring Duty What Forces a Product Re-Review
Canadian dealer (CIRO / CSA) Explicit rule: IDPC 3301(1)(iii), NI 31-103 13.2.1(1)(c) A significant change as defined in the firm's written policy, which the notice expects every firm to have
US broker-dealer (Reg BI) Implied by the Care Obligation's product-understanding component; FINRA 3110 supervision Whatever the firm's written product-review procedures define; FINRA guidance points to post-approval and periodic review
US investment adviser Implied by the duty to conduct a reasonable investigation into the investment Not prescribed; the adviser's own procedures set the standard

The practical conclusion is the same on both sides of the border, even if the legal route isn't. Any firm that has approved a shelf needs a written answer to the question this paper opened with. In Canada, the rules require it outright. In the US, the absence of a prescribed trigger means the firm's own written procedures become the standard it's examined against.

Definition

The Triggers

The staff notice lists the kinds of significant change firms themselves identified: changes in a security's risk rating, costs and fees, liquidity, distribution and redemption privileges, issuer operations, management or significant ownership, credit rating, financial ratios, the geopolitical situation, and macroeconomic factors.[3] Those ten items don't behave the same way. Some are numbers that can be tested against a threshold; others are discrete events; two are conditions outside the security altogether. A complete framework needs a different kind of trigger for each.

1
Four Trigger Families
Threshold, event, contextual and scheduled - each detected differently, each failing differently

Most monitoring programs are built around the first family and underbuilt on the other three. That's understandable - thresholds are the easiest to automate - but it leaves the gaps the regulators described, particularly the reliance on issuers to report events.

Threshold
A measurable metric crosses a pre-defined line: a dividend cut, a quartile drop, fees rising, volatility exceeding a multiple of its own history.
Event
A discrete fact occurs: a portfolio manager leaves, a mandate changes, redemptions are suspended, a rating is downgraded, a fund merges.
Contextual
Conditions outside the security shift in a way that changes its risk: sanctions, a regional crisis, a rate shock hitting a specific exposure.
Scheduled
A time-based floor: a full re-review at a set interval regardless of whether anything fired, calibrated to the product's risk.
Required re-reviewAny one family firing is enough; the four are complementary, not alternatives
Threshold Triggers

These are the backbone of automated monitoring and are covered in detail in the Playbook's material change registry: a metric, a breach condition, an evaluation frequency and a severity for each security type. Of the staff notice's list, risk rating, costs and fees, credit rating and financial ratios all translate naturally into thresholds. Their failure mode is calibration - set too tight they flood reviewers with noise; set too loose they miss real deterioration (see Calibration).

Event Triggers

Events don't cross a line gradually; they happen. A change in management or significant ownership, a suspension of redemptions, a change in issuer operations - these are binary, and many can't be derived from price or fundamental data at all. They're detected from regulatory filings, issuer notices, fund documents and news. This is where passive reliance on the issuer shows up: the notice flagged firms that waited to be told, or asked issuers to confirm annually that nothing had changed.[3] An event trigger only works if the firm has its own way of finding out the event happened.

Contextual Triggers

Geopolitical and macroeconomic factors are on the regulator's list, but they're not properties of any one security. The practical way to make them triggerable is through exposure: define the conditions that matter (sanctions on a jurisdiction, a currency peg breaking, a sector-specific regulatory action) and map them to the securities with meaningful exposure. Without that mapping, a contextual trigger either fires on everything or nothing. These triggers are usually human-initiated - a product committee convenes because something happened - so the documentation has to show who decided which securities were affected, and why.

Scheduled Triggers

A scheduled review is the safety net for everything the other three families missed. It isn't a substitute for them - the notice is clear that annual monitoring alone wasn't sufficient[3] - but it guarantees every security gets a full look at a known interval. The interval should scale with risk and complexity: shorter for exempt-market, illiquid and complex products; longer for plain, liquid, widely held ones.

2
Triggers by Product Type
The same four families, populated differently for each part of the shelf

In the KYP HubTriggers in depth for each security type: equities, mutual funds and ETFs, structured products, segregated funds and annuities, model portfolios and alternatives and private markets.

The notice says the definition of significant change and the monitoring frequency should reflect the nature of the securities, the firm's business model and its investment strategy.[3] In practice, that means a trigger set per product type rather than one list for the shelf. The table below shows the event and contextual triggers most often missing from threshold-only programs. It's representative, not exhaustive, and every firm's list should reflect what it actually offers.

Product Type Event Triggers Contextual Triggers Typical Detection Source
Equities Change in control or significant ownership; CEO or CFO departure; auditor resignation or qualified opinion; restatement; delisting notice; regulatory or enforcement action Sanctions or trade restrictions affecting core markets; sector-specific regulatory change Continuous disclosure filings, exchange notices, regulator releases
Mutual funds and ETFs Portfolio manager or sub-advisor change; change in investment objective or strategy; fee or MER change; fund merger, closure or termination; risk rating change; ETF delisting Concentrated exposure to a jurisdiction or sector under stress Fund facts and ETF facts, prospectus amendments, material change reports, manager notices
Fixed income Credit rating downgrade or watch-negative; covenant breach; missed or deferred payment; call or redemption notice Rate or spread shock affecting a specific issuer class; sovereign stress Rating agency actions, trustee notices, issuer filings
Structured products Change in issuer or guarantor credit; underlying index methodology change or discontinuation; barrier or knock-in event; early call Market conditions that change the probability of hitting a barrier Issuer notices, index provider announcements, pricing supplements
Exempt market and alternatives Redemption suspension or gating; change in valuation policy or valuation agent; distribution cut; key-person event; change in sponsor or manager ownership Stress in the underlying asset class (for example, real estate or private credit) Offering memorandum amendments, investor letters, audited financial statements, direct manager diligence

Two patterns stand out. First, the higher-risk end of the shelf leans most heavily on event triggers, and those are exactly the products for which the notice found annual monitoring inadequate. Second, the detection source for many of these events is a document, not a data feed. A monitoring program that only ingests market data will be structurally blind to most of this table.

Model portfolios need their own treatment. The notice expects model portfolios made available to clients to be subject to KYP assessment at the model level,[3] which means a change to the model itself - a new holding, a changed allocation, a changed mandate - is a trigger in its own right, separate from changes in its underlying securities.

3
What Shouldn't Trigger a Re-Review
Keeping the trigger set honest, so that reviews stay meaningful

A trigger framework is defined as much by what it leaves out. Every false trigger costs review time, and a high enough false-trigger rate trains reviewers to close alerts without reading them - which is worse than not having the alert. Three categories deserve care.

A security falling in line with its market isn't, by itself, a change in the security. Its structure, features and costs are the same as they were; a broad drawdown doesn't mean every product on the shelf needs a KYP re-review. Threshold triggers should be relative where it makes sense - measured against sector, category or the security's own history - so that they pick out securities that behave differently from their peers, not the ones moving with everything else. A market event can still be a contextual trigger when it changes the risk of specific products, but that needs a defined exposure mapping, not a blanket review.

A security that breaches a threshold and is reviewed, with the outcome documented, shouldn't open a fresh review every day the condition persists. Firm policy should define in advance how long a reviewed condition stays settled, and what breaks that window early - most obviously, the condition getting materially worse. The Playbook's monitoring section covers this in more detail.

Issuers and manufacturers publish constantly: quarterly commentary, refreshed fact sheets, periodic filings. Most of it changes nothing about the product's structure, features, risks or costs. A trigger that fires on the publication of a document, rather than on a change in what the document says, will bury reviewers in paperwork. Event triggers should be defined by the change - a new portfolio manager, a changed fee, a new risk rating - with the document as the detection source, not the trigger itself.

Response

The Re-Review

A trigger firing is the start of the obligation, not the end of it. What the firm does next - and what it can show it did - is what an examiner will actually test.

1
One Trigger, Two Levels of KYP
The firm's assessment of the product, and its people's understanding of it, both have to catch up

In the KYP HubPutting triggers into practice: Material Change covers the rules, engine and alerts, and From Alert to Decision covers the review that follows.

A significant change raises two KYP questions. At the firm level: does the firm's assessment and approval of this security still stand? At the individual level: do the registered individuals who deal in it still understand it as it now is? The staff notice expects firms to document their assessment of a significant change and consider appropriate responses, which it says may include notifying registered individuals of the change, revisiting the firm's approval of the security, and implementing additional controls around its sale, such as restricting new sales to certain types of investors.[3]

Defined trigger met on a security
Firm-Level KYP
Reassess the productDoes the original assessment of structure, features, risks and costs still hold? Documented by the product committee or designated reviewer.
Decide the shelf statusMaintain, restrict new sales, suspend, or remove - with the reason recorded.
Update the KYP fileA new, dated version of the assessment, with the prior version retained.
Individual-Level KYP
Identify who deals in itEvery registered individual who recommends or holds the security for clients, including securities no longer on the shelf.
Notify and informTell them what changed, and give them access to the updated assessment.
Confirm understandingWhere the firm's policy requires it, record acknowledgement or re-certification before further recommendations.

The individual branch is where many frameworks stop short. The notice's examples of firm practices include technology that requires registered individuals to acknowledge reviewing key information about a security before recommending it, and, at some exempt market dealers, an examination on each approved security, "including re-examination when a significant change impacts the security."[3] The firm is also expected to give registered individuals access to the information gathered through its own KYP process.[3] A trigger that updates the product file but never reaches the people using it leaves Rule 3302 unmet.

Not every trigger needs both branches at the same depth. That's what severity is for: a critical change may require a full product reassessment and mandatory re-certification within a short, defined window, while a lower-severity change may require only a documented acknowledgement and a note to the people who deal in the security. What matters is that the routing is decided in advance and written down, not improvised per alert.

Some products limit what the firm can do about a change. For illiquid securities or those with redemption restrictions, the notice says appropriate responses may involve halting new sales.[3] The inability to exit doesn't remove the obligation to reassess the product and update everyone who deals in it.

2
Calibration
A trigger set is a control, and controls drift if nobody tests them

Writing triggers down is the first step. Keeping them right is the ongoing one. Four signals suggest a trigger set needs attention:

  • A trigger that never fires. Over a long enough period, a threshold that no security has ever crossed is either well-calibrated for a stable product or set so loosely it isn't monitoring anything. Only a review of the underlying data can tell which.
  • A trigger that always fires. If most securities of a type breach a threshold most periods, reviewers will stop reading. The line is probably in the wrong place or measured against the wrong benchmark.
  • A problem found without a trigger. Any time a significant change is discovered by some other route - a client complaint, a news story, an advisor's own reading - the framework missed it. That's the most valuable calibration input there is.
  • A new product type on the shelf. A new kind of product needs its own trigger set before it's approved, not after the first problem.

Frequency is part of calibration. The notice ties it directly to risk: the more likely a significant change, the more frequently and closely a security should be monitored,[3] and it gives examples of firms tracking and flagging changes on a daily, weekly or monthly basis.[3] A single frequency for the whole shelf is hard to defend when the shelf runs from government bonds to private placements.

Changes to the trigger set should be treated like any other policy change: owned by a named committee, logged with the date and rationale, and versioned, so that any past review can be tied to the definitions in force when it happened.

3
Documentation
What a re-review record has to show to count as a re-review

Having current information isn't the same as having reviewed it. The notice found firms that kept up-to-date issuer financials but had no evidence the information was reviewed or considered as part of monitoring,[3] and it sets the expectation plainly:

"Firms should have written policies and procedures outlining their monitoring process and maintain evidence that the process was followed (e.g., records of information obtained and reviewed)." Joint CSA/CIRO Staff Notice 31-368, p.18 [3]

For each triggered re-review, the record should be able to answer:

Question What the Record Shows
What fired? The specific trigger, its family, the version of the definition in force, and the data or document that met it
When did the firm become aware? The date and time of detection - the point from which the firm's response timeframe is measured
Who reviewed it? The named reviewer or committee responsible for the product assessment
What was considered? The information reviewed and the reasoning, specific to the change - not a template sentence
What was decided? The shelf outcome, any new sales restrictions, and the updated version of the KYP assessment
Who was told? Which registered individuals were notified, when, and whether acknowledgement or re-certification was required and completed
Was it on time? The close date against the timeframe the firm's policy sets for that severity

The same discipline applies when nothing fires. A security that was evaluated and cleared should leave a dated record saying so; otherwise an empty log can't be told apart from a security nobody checked. The Playbook's documentation section sets out the full set of records that makes this provable.

Five Questions to Test a Trigger Framework
  1. Is there a written definition of significant change for every product type the firm offers or holds, including transfers-in and securities no longer on the shelf?
  2. Does the definition cover all four trigger families, or only thresholds?
  3. For event triggers, does the firm have its own way of detecting the event, or is it relying on the issuer to say so?
  4. For every trigger, is it written down what KYP response it requires - product reassessment, staff notification, re-certification - and by when?
  5. Could the firm produce, for any security on any date, which triggers applied, whether any fired, what was done about it, and who was told?
A note on scope: This paper covers Know-Your-Product monitoring obligations in Canada and the United States as of its publication date. It does not address decisions about individual client accounts. It is general information, not legal or compliance advice. The product-type triggers above are representative examples, not a complete or prescribed list; each firm's trigger set should reflect its own shelf and business model. Where rules are quoted, the quotation is from the source cited; firms should confirm current requirements against the source documents.
References
  1. CIRO. Investment Dealer and Partially Consolidated Rules, Rule 3300 series (Product Due Diligence and Know-Your-Product), including Rules 3301(1)(iii) and 3302(1). Parallel requirements for other registrants: NI 31-103, section 13.2.1. Source document (PDF)
  2. CIRO Notice 20-0238, Appendix 03, Guidance: Product Due Diligence and Know-Your-Product. Source document
  3. Joint CSA/CIRO Staff Notice 31-368, Client Focused Reforms: Review of Registrants' Know Your Client, Know Your Product and Suitability Determination Practices and Additional Guidance, December 10, 2025. KYP for registered individuals, pp.13-14; monitoring for significant changes, pp.16-18. Source document (PDF)
  4. CIRO Notice 09-0086, Best Practices for Product Due Diligence. Source document
  5. U.S. Securities and Exchange Commission. Regulation Best Interest: A Small Entity Compliance Guide. Source document
  6. U.S. Securities and Exchange Commission. Regulation Best Interest: The Broker-Dealer Standard of Conduct, 17 C.F.R. § 240.15l-1, effective June 30, 2020. Source document (PDF)
  7. U.S. Securities and Exchange Commission. Commission Interpretation Regarding Standard of Conduct for Investment Advisers, Release No. IA-5248, June 5, 2019. Source document (PDF)
  8. FINRA. FINRA Rules, Rule 3110 (Supervision). Source document
  9. FINRA (then NASD). Notice to Members 05-26, NASD Recommends Best Practices for Reviewing New Products, April 2005. Source document
  10. FINRA. Regulatory Notice 12-03, Heightened Supervision of Complex Products, January 2012. Source document