What happened

The Securities and Exchange Commission censured New York based broker dealer OTC Link LLC on September 22 and ordered it to pay a $575,000 civil penalty for longstanding violations of Regulation Systems Compliance and Integrity. The conduct in the settled order runs from August 2016 to March 2025, close to nine years.

OTC Link operates OTC Link ATS, an alternative trading system for over the counter securities. Under Regulation SCI the firm had to establish, maintain and enforce written policies and procedures for the system, including those covering system security, access control, and application vulnerability management, testing and remediation. The SEC found that it did not.

The detail that matters most is what the examiners did. Staff in the SEC's Division of Examinations looked at OTC Link ATS several times during the period and each time flagged required policies and procedures that the firm had not established, or had left in draft and never finalised or enforced. The order finds that OTC Link repeatedly failed to fix those deficiencies promptly, and the SEC connects the size of the penalty to that pattern.

"OTC Link's continual failure to remediate deficiencies even after they were repeatedly flagged by Division of Examinations staff reflects a disregard for their findings and the overall examinations process and justifies a meaningful penalty," said Laura D'Allaird, Chief of the Division of Enforcement's Cyber and Emerging Technologies Unit.

The order finds breaches of Rule 1001(a)(1), on maintaining adequate capacity, integrity, resiliency, availability and security for SCI systems, along with Rule 1001(a)(2) on having required minimum policies and periodically reviewing their effectiveness, and Rule 1001(a)(3) on taking prompt action to remedy deficiencies. OTC Link settled without admitting the findings and agreed to a cease and desist order, the censure and the penalty.

Why this is a GRC story

This is a documentation case, not an outage case. Regulation SCI is one of the few regimes that treats exchange grade technology controls as an enforceable obligation in their own right, and the SEC's theory here rests entirely on artefacts that either did not exist or were never approved and rolled out.

The aggravating factor is repetition. A finding that stays open across multiple examination cycles stops being a gap and becomes evidence of disregard, which is what moves a penalty upward. Many compliance functions track findings somewhere. Far fewer can produce a dated remediation trail that shows an owner, a decision and a closure date for each one.

Draft policy deserves its own line. A document that sits in draft for years is worse than nothing for a regulator, because it shows the organisation identified what was needed and never adopted it. Approval workflow and version control are control evidence, not housekeeping.

The rule also expects periodic review of how effective those policies are. Having the documents is the floor, and being able to show you tested them is the part most programmes skip.

What to watch

Watch whether the SEC applies the same reasoning to other SCI entities, and whether "flagged repeatedly and not remediated" settles in as a standard aggravating factor in technology enforcement.

A simple test for anyone running a regulated system: take the last two examination or audit reports, list every finding, and check each one has a dated closure with evidence attached. If any item appears twice, the SEC has just told you how it reads that.

Attribution: Analysis based on SEC Press Releases and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News