FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls
In plain language
FINRA requires a broker-dealer to supervise its business, and supervising a business that runs on technology means supervising the technology. That produces three concrete demands: written procedures describing who reviews what, a system that can actually surface the communications and activity being reviewed, and an annual test that checks whether the supervision happened.
Where the technology obligation comes from
FINRA does not have a rule that says “configure your systems this way.” It has Rule 3110, which requires each member to establish and maintain a supervisory system reasonably designed to achieve compliance with applicable securities laws and FINRA rules, including written supervisory procedures. Everything technological follows from the fact that the supervised activity now happens in systems.
Four rules do most of the work in practice:
| Rule | What it requires | Technology consequence |
|---|---|---|
| 3110 | Supervisory system, written procedures, correspondence review, office inspections | Systems must surface the activity being supervised, and the review must be evidenced |
| 3120 | Testing and verification of supervisory procedures, annual report to senior management | Someone has to check that the reviews happened, using system output |
| 4370 | Business continuity plan and emergency contact information | Recovery objectives, tested restores, a reachable alternate path |
| 4511 | Books and records, six-year default for unspecified periods | Retention configured per category — see books and records |
Supervision of electronic communications
Rule 3110(b)(4) requires procedures for the review of incoming and outgoing written and electronic correspondence and internal communications relating to the member’s investment banking or securities business.
The rule leaves the method to the firm, which is why the procedures matter more than the tool. A defensible arrangement states:
- Which systems hold reviewable communications, by name.
- Who reviews, by role, and who reviews the reviewer’s own communications.
- What the sampling basis is — lexicon hits, risk-based selection, percentage sample — and why that basis is reasonable for this firm.
- How review is evidenced, including for periods where nothing was escalated. A review with no findings still has to be visible as a review.
- What escalation looks like and where the escalated item’s disposition is recorded.
The most common deficiency is not a missing tool. It is a firm that reviews diligently and cannot produce evidence for the periods where nothing was found, because the reviewer only records exceptions.
Remote work and branch supervision
Rule 3110(c) requires inspections of offices on stated cycles. The distributed-work shift changed what an inspection has to look at rather than whether one happens.
The technology conditions worth inspecting at any location, office or otherwise:
- Devices are managed, encrypted, patched, and locked — and no unmanaged device has a standing route into firm systems.
- Access to firm systems runs through the same controlled path everywhere, with no site-specific exception that was granted once and never removed.
- Only approved communication channels are in use, and unapproved ones are blocked on managed devices rather than discouraged.
- Printed client material is handled and disposed of somewhere the firm can describe.
Business continuity as a tested capability
Rule 4370 requires a business continuity plan addressing, at a minimum, matters including data back-up and recovery, mission critical systems, alternate communications, and regulatory reporting.
The distinction that matters at examination is between a reviewed plan and a tested one. A reviewed plan has been read. A tested plan has produced a restore, from the backup the firm actually holds, into an environment someone logged into, with a recorded elapsed time. Firms that only review discover their gaps during the incident.
Test the parts that fail quietly:
- Restore a representative system, not a single file.
- Confirm the backup covers the cloud platforms, which are frequently assumed to be self-protecting.
- Check that the alternate communication path does not depend on the system that is down.
- Confirm the emergency contact information on file with FINRA is current.
Where broker-dealer and adviser programs diverge
Dually registered firms run one technology estate under two regimes. The places they genuinely differ:
- Retention defaults. FINRA’s six-year default for unspecified categories is longer than the adviser five-year general period. Configure the longer one.
- Supervision evidence. The adviser side is reviewed annually under Rule 206(4)-7; the broker-dealer side requires ongoing, evidenced review plus the Rule 3120 test.
- Office inspections. A FINRA obligation with a stated cycle; advisers have no direct equivalent.
Related sections
Books and records for the capture the review depends on, Regulation S-P for the safeguards obligations that apply to broker-dealers as covered institutions, and access control and MFA for the controls that make remote supervision viable.
Pylon’s service view is on SEC & FINRA compliance.
Primary sources
Frequently Asked Questions
Does FINRA have a cybersecurity rule?
There is no single rule titled cybersecurity. The obligations come through other rules: Rule 3110 supervision, Rule 3120 supervisory control testing, Rule 4370 business continuity, Rule 4511 books and records, and the Exchange Act privacy and safeguards obligations. FINRA also publishes cybersecurity guidance and examination findings that describe what it expects to see.
Do written supervisory procedures need to cover technology?
Yes, to the extent technology is how the supervised activity happens. If correspondence is reviewed, the procedures should say which systems hold it, who reviews, on what sampling basis, and how the review is evidenced. Procedures that describe a review with no named system tend not to survive a request to see the last one.
How does remote work change supervision obligations?
It does not reduce them. The supervisory system still has to reach the activity, which now happens on home networks and personal devices. The practical consequences are device management, captured communications on approved channels only, and access controls that do not assume the office network is a boundary.
What is the relationship between Rule 3110 and Rule 3120?
Rule 3110 requires the supervisory system and the written procedures. Rule 3120 requires a system of supervisory control policies and procedures that test and verify that the supervisory procedures are reasonably designed, and requires an annual report to senior management. One builds the program; the other checks it.
Scheduled actions
The recurring work this section implies. Each action carries a stable
action-id so it can be tracked in a compliance calendar and rolled up on
all scheduled actions.
Review the written supervisory procedures for technology accuracy: named systems, named reviewers, sampling basis, and evidencing method.
- Cadence:
- Annually
- Owner archetype:
- CCO, IT
- Source:
- FINRA Rule 3110
- action-id:
act.finra-supervision.wsp-technology-review
Perform the electronic correspondence review on the stated sampling basis and evidence it, including what the reviewer looked at and what was escalated.
- Cadence:
- Monthly
- Owner archetype:
- CCO
- Source:
- FINRA Rule 3110(b)(4)
- action-id:
act.finra-supervision.correspondence-review
Test and verify that the supervisory procedures are reasonably designed, and produce the annual report to senior management.
- Cadence:
- Annually
- Owner archetype:
- CCO
- Source:
- FINRA Rule 3120
- action-id:
act.finra-supervision.supervisory-control-test
Review and test the business continuity plan, including the technology recovery path and the emergency contact information, and update the disclosure if it changed.
- Cadence:
- Annually
- Owner archetype:
- CCO, IT, MSP
- Source:
- FINRA Rule 4370
- action-id:
act.finra-supervision.bcp-review-and-test
Inspect offices on the firm's stated cycle, covering the technology conditions at each location: device compliance, network, physical document handling, and use of approved channels.
- Cadence:
- Annually
- Owner archetype:
- CCO, IT
- Source:
- FINRA Rule 3110(c)
- action-id:
act.finra-supervision.branch-and-remote-inspection
Review current FINRA cybersecurity guidance and examination findings, and note which items the firm does not yet address.
- Cadence:
- Annually
- Owner archetype:
- CCO, MSP
- action-id:
act.finra-supervision.cyber-guidance-review
Configuration touchpoints
Where this section lands in a real environment. Each touchpoint is stated as a plain
configuration rule — not a vendor setting — and carries a stable config-id.
| Configuration rule | Applies to | config-id |
|---|---|---|
| Communications subject to supervisory review arrive in a review queue with lexicon or risk-based flagging, and reviewer actions are recorded in the system rather than in a spreadsheet alongside it. | Surveillance / archive review module | cfg.finra-supervision.review-queue |
| Supervisory reviewers can see what they are required to review and cannot alter or delete the underlying records. | Archive and surveillance access roles | cfg.finra-supervision.reviewer-permissions |
| Devices used for firm business meet a defined posture — managed, encrypted, patched, screen-locked — regardless of whether they are in an office. | Endpoint management | cfg.finra-supervision.remote-device-posture |
| Every office and remote location reaches firm systems through the same controlled path, with no location-specific exception that bypasses it. | Network and remote access configuration | cfg.finra-supervision.branch-network-standard |
| Recovery time and recovery point objectives are configured in the backup and failover systems, not only asserted in the plan document. | Backup and disaster recovery configuration | cfg.finra-supervision.bcp-recovery-targets |
More in the Compliance Library
- Regulation S-P: Safeguards, Incident Response, and the Notification Clocks
- Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program
- Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2
- Regulation S-ID: Identity Theft Red Flags, at a High Level
- Vendor and Service-Provider Oversight for Regulated Financial Firms
- Access Control and MFA for RIAs, Broker-Dealers, and Funds
- Incident Response and Exam Evidence for Financial Firms
- Private Fund and PE Adviser Technology Notes
Rollups: all scheduled actions and monitor and review.
- Author
- Rachel Lannon and Byron Foley
- Reviewed by
- Tim Quinn
- Last updated
This is operational technology guidance for regulated firms, not legal advice. Confirm how each requirement applies to your firm with your compliance counsel.