Approving a security for the shelf is a decision made once. Keeping it there is a decision made continuously, and it's the half of Know-Your-Product that regulators keep finding firms can't evidence. The question at the center of it sounds simple: what, specifically, has to change about a security before someone is required to look at it again?
When the CSA and CIRO reviewed 105 registered firms, the most basic version of that question tripped up a lot of them. Many firms had monitoring in place but had never defined what counted as a significant change, or what that change should set in motion - so when monitoring surfaced something, there was no process for deciding what to do about it.[3] Others monitored on a schedule too slow for the products they sold, or waited for issuers to tell them something had changed.
This paper is about the trigger: the rule that converts a detected change into a required KYP review. It covers what the rules in Canada and the US actually require (they don't require the same thing), the four families of trigger a complete framework needs, how triggers differ by product type, what shouldn't trigger a re-review, and what a re-review has to produce once one fires. It's a companion to The Continuous KYP Playbook: Who Does What, which sets out how material change definitions are structured, monitored and documented once they exist. This paper sits one step earlier: deciding which changes belong in the definition set in the first place.
Two terms are used throughout. A trigger is a written, pre-defined condition that, when met, obliges the firm to act. A re-review is the documented KYP action that follows: a reassessment of the firm's assessment and approval of the security, and an update to what the registered individuals who deal in it understand about it. Canadian guidance uses "significant change"; older CIRO guidance[4] and most practitioners say "material change." This paper treats them as the same obligation. Its scope is the product: what the firm and its people need to know about a security. Decisions about individual client accounts are outside it.
Before defining triggers, it's worth being precise about what the rules require. Canada writes a product monitoring duty into its rules. The US gets to a similar place less directly, through the obligation to understand a product before recommending it.
Canada's framework is explicit, and it comes in two parts. The first sits with the firm. Under CIRO's Rule 3301 (mirrored for other registrants in NI 31-103, paragraph 13.2.1(1)(c)), a dealer can't make a security available to clients unless it has taken reasonable steps to assess it, approve it, and:[1]
The second sits with each registered individual. Rule 3302 bars an Approved Person from buying, selling or recommending a security unless they take steps to understand it:[1][2]
Read together, the two rules form a chain. The firm's monitoring (3301) is how it learns a security has changed; that knowledge is what keeps each individual's understanding (3302) accurate. An individual can't understand a security's current features and risks if the firm hasn't noticed they changed. A firm with no defined trigger breaks the chain in the middle: it may be collecting information, but it has no reliable point at which a change becomes something anyone must act on. The joint staff notice makes the same point directly - some firms kept up-to-date issuer financials on file but had no evidence anyone had reviewed them as part of monitoring.[3]
Joint CSA/CIRO Staff Notice 31-368 grouped the monitoring deficiencies into four issues:[3]
The monitored population is wider than the current shelf. The notice says monitoring applies to securities available for purchase through the firm and, for firms with ongoing client relationships, to securities held in client accounts "even if those securities are no longer available for purchase through the firm."[3] Securities transferred in, or bought through client-directed trades, must be assessed within a reasonable time and brought into the monitoring process too, even though the firm isn't required to approve them for the shelf.[3] A trigger framework that only covers the approved list misses both groups.
There is no US equivalent of Rule 3301(1)(iii) - no single rule that tells every firm to monitor every product for significant changes. The obligation is assembled from product-level diligence duties and supervisory expectations. Being precise here matters, because overstating the US requirement is a common mistake in cross-border material.
The first component of Reg BI's Care Obligation is product-level: a broker-dealer must understand the potential risks, rewards and costs associated with a recommendation, and have a reasonable basis to believe it could be in the best interest of at least some retail customers.[5][6] That understanding is tested at the time of each recommendation. A firm whose understanding of a product is a year out of date can't meet it, which makes ongoing product review a practical necessity even though the rule doesn't prescribe it.
The SEC's 2019 interpretation of the adviser standard of conduct sets a comparable bar at the product level:
Information about a product that has since changed is exactly the kind of inaccurate or incomplete information the interpretation warns against.
At the firm level, FINRA Rule 3110 requires a supervisory system and written procedures reasonably designed to achieve compliance.[8] FINRA's guidance on new products goes further on the shelf itself. Notice to Members 05-26 describes post-approval review as a best practice: formally reviewing complex or conditionally approved products for a set period after approval.[9] Regulatory Notice 12-03 asks firms selling complex products to periodically reassess whether each product's performance and risk profile remain consistent with how the firm is selling it.[10] Neither is a rule in its own right, but both describe what an examiner expects a reasonably designed supervisory system to include.
| Channel | Source of Product Monitoring Duty | What Forces a Product Re-Review |
|---|---|---|
| Canadian dealer (CIRO / CSA) | Explicit rule: IDPC 3301(1)(iii), NI 31-103 13.2.1(1)(c) | A significant change as defined in the firm's written policy, which the notice expects every firm to have |
| US broker-dealer (Reg BI) | Implied by the Care Obligation's product-understanding component; FINRA 3110 supervision | Whatever the firm's written product-review procedures define; FINRA guidance points to post-approval and periodic review |
| US investment adviser | Implied by the duty to conduct a reasonable investigation into the investment | Not prescribed; the adviser's own procedures set the standard |
The practical conclusion is the same on both sides of the border, even if the legal route isn't. Any firm that has approved a shelf needs a written answer to the question this paper opened with. In Canada, the rules require it outright. In the US, the absence of a prescribed trigger means the firm's own written procedures become the standard it's examined against.
The staff notice lists the kinds of significant change firms themselves identified: changes in a security's risk rating, costs and fees, liquidity, distribution and redemption privileges, issuer operations, management or significant ownership, credit rating, financial ratios, the geopolitical situation, and macroeconomic factors.[3] Those ten items don't behave the same way. Some are numbers that can be tested against a threshold; others are discrete events; two are conditions outside the security altogether. A complete framework needs a different kind of trigger for each.
Most monitoring programs are built around the first family and underbuilt on the other three. That's understandable - thresholds are the easiest to automate - but it leaves the gaps the regulators described, particularly the reliance on issuers to report events.
These are the backbone of automated monitoring and are covered in detail in the Playbook's material change registry: a metric, a breach condition, an evaluation frequency and a severity for each security type. Of the staff notice's list, risk rating, costs and fees, credit rating and financial ratios all translate naturally into thresholds. Their failure mode is calibration - set too tight they flood reviewers with noise; set too loose they miss real deterioration (see Calibration).
Events don't cross a line gradually; they happen. A change in management or significant ownership, a suspension of redemptions, a change in issuer operations - these are binary, and many can't be derived from price or fundamental data at all. They're detected from regulatory filings, issuer notices, fund documents and news. This is where passive reliance on the issuer shows up: the notice flagged firms that waited to be told, or asked issuers to confirm annually that nothing had changed.[3] An event trigger only works if the firm has its own way of finding out the event happened.
Geopolitical and macroeconomic factors are on the regulator's list, but they're not properties of any one security. The practical way to make them triggerable is through exposure: define the conditions that matter (sanctions on a jurisdiction, a currency peg breaking, a sector-specific regulatory action) and map them to the securities with meaningful exposure. Without that mapping, a contextual trigger either fires on everything or nothing. These triggers are usually human-initiated - a product committee convenes because something happened - so the documentation has to show who decided which securities were affected, and why.
A scheduled review is the safety net for everything the other three families missed. It isn't a substitute for them - the notice is clear that annual monitoring alone wasn't sufficient[3] - but it guarantees every security gets a full look at a known interval. The interval should scale with risk and complexity: shorter for exempt-market, illiquid and complex products; longer for plain, liquid, widely held ones.
In the KYP HubTriggers in depth for each security type: equities, mutual funds and ETFs, structured products, segregated funds and annuities, model portfolios and alternatives and private markets.
The notice says the definition of significant change and the monitoring frequency should reflect the nature of the securities, the firm's business model and its investment strategy.[3] In practice, that means a trigger set per product type rather than one list for the shelf. The table below shows the event and contextual triggers most often missing from threshold-only programs. It's representative, not exhaustive, and every firm's list should reflect what it actually offers.
| Product Type | Event Triggers | Contextual Triggers | Typical Detection Source |
|---|---|---|---|
| Equities | Change in control or significant ownership; CEO or CFO departure; auditor resignation or qualified opinion; restatement; delisting notice; regulatory or enforcement action | Sanctions or trade restrictions affecting core markets; sector-specific regulatory change | Continuous disclosure filings, exchange notices, regulator releases |
| Mutual funds and ETFs | Portfolio manager or sub-advisor change; change in investment objective or strategy; fee or MER change; fund merger, closure or termination; risk rating change; ETF delisting | Concentrated exposure to a jurisdiction or sector under stress | Fund facts and ETF facts, prospectus amendments, material change reports, manager notices |
| Fixed income | Credit rating downgrade or watch-negative; covenant breach; missed or deferred payment; call or redemption notice | Rate or spread shock affecting a specific issuer class; sovereign stress | Rating agency actions, trustee notices, issuer filings |
| Structured products | Change in issuer or guarantor credit; underlying index methodology change or discontinuation; barrier or knock-in event; early call | Market conditions that change the probability of hitting a barrier | Issuer notices, index provider announcements, pricing supplements |
| Exempt market and alternatives | Redemption suspension or gating; change in valuation policy or valuation agent; distribution cut; key-person event; change in sponsor or manager ownership | Stress in the underlying asset class (for example, real estate or private credit) | Offering memorandum amendments, investor letters, audited financial statements, direct manager diligence |
Two patterns stand out. First, the higher-risk end of the shelf leans most heavily on event triggers, and those are exactly the products for which the notice found annual monitoring inadequate. Second, the detection source for many of these events is a document, not a data feed. A monitoring program that only ingests market data will be structurally blind to most of this table.
Model portfolios need their own treatment. The notice expects model portfolios made available to clients to be subject to KYP assessment at the model level,[3] which means a change to the model itself - a new holding, a changed allocation, a changed mandate - is a trigger in its own right, separate from changes in its underlying securities.
A trigger framework is defined as much by what it leaves out. Every false trigger costs review time, and a high enough false-trigger rate trains reviewers to close alerts without reading them - which is worse than not having the alert. Three categories deserve care.
A security falling in line with its market isn't, by itself, a change in the security. Its structure, features and costs are the same as they were; a broad drawdown doesn't mean every product on the shelf needs a KYP re-review. Threshold triggers should be relative where it makes sense - measured against sector, category or the security's own history - so that they pick out securities that behave differently from their peers, not the ones moving with everything else. A market event can still be a contextual trigger when it changes the risk of specific products, but that needs a defined exposure mapping, not a blanket review.
A security that breaches a threshold and is reviewed, with the outcome documented, shouldn't open a fresh review every day the condition persists. Firm policy should define in advance how long a reviewed condition stays settled, and what breaks that window early - most obviously, the condition getting materially worse. The Playbook's monitoring section covers this in more detail.
Issuers and manufacturers publish constantly: quarterly commentary, refreshed fact sheets, periodic filings. Most of it changes nothing about the product's structure, features, risks or costs. A trigger that fires on the publication of a document, rather than on a change in what the document says, will bury reviewers in paperwork. Event triggers should be defined by the change - a new portfolio manager, a changed fee, a new risk rating - with the document as the detection source, not the trigger itself.
A trigger firing is the start of the obligation, not the end of it. What the firm does next - and what it can show it did - is what an examiner will actually test.
In the KYP HubPutting triggers into practice: Material Change covers the rules, engine and alerts, and From Alert to Decision covers the review that follows.
A significant change raises two KYP questions. At the firm level: does the firm's assessment and approval of this security still stand? At the individual level: do the registered individuals who deal in it still understand it as it now is? The staff notice expects firms to document their assessment of a significant change and consider appropriate responses, which it says may include notifying registered individuals of the change, revisiting the firm's approval of the security, and implementing additional controls around its sale, such as restricting new sales to certain types of investors.[3]
The firm-level reassessment feeds what individuals are told; notification doesn't wait for the full reassessment if the change is urgent.
The individual branch is where many frameworks stop short. The notice's examples of firm practices include technology that requires registered individuals to acknowledge reviewing key information about a security before recommending it, and, at some exempt market dealers, an examination on each approved security, "including re-examination when a significant change impacts the security."[3] The firm is also expected to give registered individuals access to the information gathered through its own KYP process.[3] A trigger that updates the product file but never reaches the people using it leaves Rule 3302 unmet.
Not every trigger needs both branches at the same depth. That's what severity is for: a critical change may require a full product reassessment and mandatory re-certification within a short, defined window, while a lower-severity change may require only a documented acknowledgement and a note to the people who deal in the security. What matters is that the routing is decided in advance and written down, not improvised per alert.
Some products limit what the firm can do about a change. For illiquid securities or those with redemption restrictions, the notice says appropriate responses may involve halting new sales.[3] The inability to exit doesn't remove the obligation to reassess the product and update everyone who deals in it.
Writing triggers down is the first step. Keeping them right is the ongoing one. Four signals suggest a trigger set needs attention:
Frequency is part of calibration. The notice ties it directly to risk: the more likely a significant change, the more frequently and closely a security should be monitored,[3] and it gives examples of firms tracking and flagging changes on a daily, weekly or monthly basis.[3] A single frequency for the whole shelf is hard to defend when the shelf runs from government bonds to private placements.
Changes to the trigger set should be treated like any other policy change: owned by a named committee, logged with the date and rationale, and versioned, so that any past review can be tied to the definitions in force when it happened.
Having current information isn't the same as having reviewed it. The notice found firms that kept up-to-date issuer financials but had no evidence the information was reviewed or considered as part of monitoring,[3] and it sets the expectation plainly:
For each triggered re-review, the record should be able to answer:
| Question | What the Record Shows |
|---|---|
| What fired? | The specific trigger, its family, the version of the definition in force, and the data or document that met it |
| When did the firm become aware? | The date and time of detection - the point from which the firm's response timeframe is measured |
| Who reviewed it? | The named reviewer or committee responsible for the product assessment |
| What was considered? | The information reviewed and the reasoning, specific to the change - not a template sentence |
| What was decided? | The shelf outcome, any new sales restrictions, and the updated version of the KYP assessment |
| Who was told? | Which registered individuals were notified, when, and whether acknowledgement or re-certification was required and completed |
| Was it on time? | The close date against the timeframe the firm's policy sets for that severity |
The same discipline applies when nothing fires. A security that was evaluated and cleared should leave a dated record saying so; otherwise an empty log can't be told apart from a security nobody checked. The Playbook's documentation section sets out the full set of records that makes this provable.