Against the backdrop of rapid technological advances and increasingly complex regulatory requirements, The Financial Industry Regulatory Authority (FINRA) gathered industry leaders, regulators, and compliance professionals in Washington D.C. for their 2024 annual conference. Titled ‘Navigating Change’ the conference reflected the urgency of addressing new challenges—from the rise of digital assets to the intensifying threats of financial crime.
This year’s conference wasn’t just a routine check-in but a critical moment for firms to recalibrate their strategies. With the SEC’s heightened scrutiny and evolving rules under FINRA’s watchful eye, firms are under pressure to rethink their approaches to compliance, risk management, and cybersecurity. The discussions were forward-looking, emphasizing the need for agility and proactive measures. Read on to learn about the key takeaways and what firms need to focus on to stay compliant, competitive, and secure in 2024 and beyond.
Opening Remarks: A Look into Regulatory Priorities
The kickoff session for the conference featured Robert W. Cook, President and CEO of FINRA, and Eric Noll, Chairman of the FINRA Board, in a dialogue moderated by Kayte Toczylowski, FINRA’s Vice President of Member Relations and Education, providing a well-rounded view of the challenges and opportunities facing the financial industry as well as FINRA’s priorities. The key points emerging from the discussion include:
- Addressing Technological Advancements: The speakers highlighted how advancements like artificial intelligence (AI), machine learning, and blockchain technology are reshaping the industry. While these innovations offer significant opportunities for growth and efficiency, they also pose new challenges for regulatory oversight and compliance. The speakers called for a balanced approach that supports innovation while ensuring responsible use of new technologies in compliance with existing laws.
- Focus on Market Integrity: Maintaining market integrity amid rapid technological and market changes was another major theme. Key areas of concern included cryptocurrency and digital assets, with the speakers emphasizing the need for a comprehensive regulatory framework to ensure that firms involved in crypto activities adhere to securities laws and implement appropriate safeguards.
- Cybersecurity Threats: With increasing frequency and sophistication of cyberattacks, robust cybersecurity measures are crucial. The speakers highlighted the need for firms to strengthen their defenses to protect market integrity from evolving cyber threats.
- Collaboration and Proactive Compliance: The speakers advocated for enhanced industry-regulator partnerships to navigate the complexities of the financial landscape. Firms were urged to adopt a proactive stance, anticipating challenges and taking preemptive measures to ensure compliance and protect investors.
- Commitment to Continuous Learning: Finally, the need for ongoing education and adaptability was underscored. Cook stressed the importance of continuous learning for both regulators and industry professionals to manage new risks and comply with evolving regulations.
The opening remarks set a tone of vigilance and forward-thinking, highlighting the need for continuous adaptation and collaboration in addressing technological and market dynamics.
Emerging Regulatory Themes: Adapting to New Challenges
The conference highlighted a range of emerging regulatory themes, reflecting the challenges that financial firms must address to remain compliant and competitive.
Crypto Asset Regulation
The conference underscored the urgent need for a regulatory framework specifically tailored to cryptocurrency assets, reflecting their increasing prominence and complexity. Key points included:
- Challenges and Safeguards: The rapid growth of cryptocurrency markets has led to heightened concerns about market manipulation, fraud, and investor protection. The need for firms involved in crypto assets to implement robust compliance measures, including enhanced anti-money laundering (AML) protocols and fraud detection systems was emphasized.
- Regulatory Evolution: Existing securities laws may need to be adapted or supplemented to address the unique aspects of cryptocurrency transactions. FINRA indicated that forthcoming regulations might introduce new requirements for transparency, disclosure, and safeguarding investor interests.
Generative AI and Technology Risks
Generative AI and machine learning were focal points of discussion, reflecting their growing role in financial services:
- Advanced Detection Capabilities: The use of AI and machine learning for detecting financial crimes such as money laundering and insider trading was emphasized. These technologies offer significant advantages in analyzing large datasets and identifying suspicious activities that traditional methods might miss. FINRA discussed the potential of AI to enhance real-time monitoring and predictive analytics to stay ahead of threats.
- Governance and Accountability: The conference highlighted the need for firms to develop comprehensive governance frameworks for AI, including clear guidelines for its ethical use, regular audits to ensure accuracy and fairness, and mechanisms for human oversight to mitigate risks associated with automated decision-making.
Cybersecurity
Cybersecurity remained a critical focus area, given the increasing sophistication of cyber threats:
- Enhanced Safeguards: The importance of implementing both technical and procedural measures to protect against cyberattacks was highlighted. This includes deploying advanced encryption technologies, conducting thorough security audits, and ensuring continuous monitoring of IT systems.
- Incident Reporting and Third-Party Management: The conference discussed the need for stricter requirements regarding incident reporting and management of third-party vendors. Firms were advised to establish clear protocols for reporting and responding to cyber incidents and to ensure that third-party vendors meet high cybersecurity standards to prevent vulnerabilities.
Off-Channel Communications
The rise of off-channel communications, such as messaging apps and social media, was a significant topic:
- Regulatory Requirements: The need for comprehensive monitoring and archiving of all forms of communication, including off-channel platforms, was stressed. Recent enforcement actions underscored the importance of maintaining accurate records of all communications to ensure compliance with regulatory standards.
- Technological Solutions: To address these challenges, firms are increasingly adopting advanced technological solutions for capturing and archiving off-channel communications. The conference showcased tools that automate the capture of communications across various platforms, reducing the risk of regulatory non-compliance and streamlining the retrieval of communication data for audits and investigations.
Regulation Best Interest (Reg BI) Compliance
The evolution of Reg BI in response to new technologies was a key discussion point:
- Integration with Technology: The conference emphasized the complexities introduced by technologies like chatbots, robo-advisors and predictive analytics. Firms must ensure that their use of these technologies aligns with Reg BI’s requirements to act in the best interests of clients. This involves not only meeting regulatory standards but also ensuring that algorithms and technological tools do not introduce conflicts of interest.
- SEC Scrutiny: The SEC’s increased scrutiny of Reg BI compliance was highlighted. The SEC is focusing on ensuring that firms genuinely adhere to the spirit of Reg BI, particularly in light of potential conflicts of interest arising from new technologies. Firms were advised to review and adjust their practices and technologies to maintain alignment with Reg BI principles.
Ensuring Best Execution
Best execution remained a vital focus, with discussions on the following aspects:
- Market Complexity: The conference addressed the challenges posed by a complex trading environment, including fragmented markets, high-frequency trading, and dark pools. Firms were encouraged to go beyond basic compliance and demonstrate a commitment to achieving the best possible execution outcomes for their clients.
- Regulatory Developments: Ongoing efforts by the SEC to refine and consolidate best execution rules were discussed. These developments aim to enhance fairness and transparency in the market, and firms must stay informed about these changes and adapt their practices accordingly.
The Future of Regulation: What’s In The Pipeline?
Given these takeaways, what should financial firms be expecting in regulatory changes moving forward?
- Regulation of Cryptocurrency and Digital Assets: As the popularity of cryptocurrencies continues to rise, FINRA is actively working on developing a comprehensive regulatory framework for digital assets. New rules are expected to focus on issues such as transparency, fraud prevention, and investor protection in the crypto space. These changes will likely require firms to adopt stricter compliance measures when dealing with digital assets.
- Enhanced Focus on Cybersecurity: FINRA is expected to introduce more stringent cybersecurity requirements, particularly around third-party vendor management, data protection, and incident reporting. Firms will need to demonstrate robust cybersecurity frameworks to meet these new standards.
- Generative AI and Predictive Analytics Regulation: With the growing use of AI and machine learning in the financial sector, FINRA is closely monitoring how these technologies are being integrated into business practices. FINRA is likely to introduce guidelines or rules that address the ethical and operational risks associated with generative AI, such as bias in decision-making processes and transparency in algorithmic models.
- Regulation Best Interest (Reg BI) Enhancements: New guidance is expected to further clarify how Reg BI applies to emerging financial technologies and complex products. Firms will need to demonstrate compliance with these enhanced standards, particularly in their interactions with retail investors.
- Off-Channel Communication Monitoring: FINRA is likely to implement stricter rules around the use of off-channel communications, requiring firms to adopt new technologies and protocols to capture and store these interactions in a compliant manner.
Ensuring Communications Compliance with LeapXpert
One of the central themes at the 2024 FINRA Annual Conference was the critical importance of communications compliance in an increasingly digital world, particularly in relation to off-channel communications. With the rise of encrypted messaging apps and the growing expectation for transparency, firms are under immense pressure to ensure that all business-related communications are properly recorded, stored, and accessible for regulatory review.
LeapXpert is a leader in the field of communications compliance, offering comprehensive solutions that ensure businesses meet stringent regulatory requirements while maintaining efficient communication practices.
The LeapXpert Communications Platform is designed to address the complex needs of enterprises, particularly in regulated industries like finance, where communication compliance is critical. The platform provides unmatched governance by capturing and securing client communications across various channels, including popular messaging apps like WhatsApp, iMessage, WeChat, and more. This ensures that all business-related conversations are recorded and stored in compliance with regulatory standards, reducing the risk of fines and legal issues. These records can be exported to third-party archiving systems through built-in integrations or APIs, making it easier for companies to manage their compliance obligations.
The platform employs end-to-end encryption to safeguard data during transmission, ensuring that sensitive information remains protected from unauthorized access. Secure data storage and stringent access controls further bolster security by protecting stored data and restricting access to authorized users only. Additionally, LeapXpert utilizes antivirus, antimalware, and Content Disarm and Reconstruction (CDR) technologies to prevent and remove file viruses and malware, alongside data leakage prevention (DLP) policies to mitigate risks of data loss.
Book now for a demo.
Book a personalized
product demo