Platform Why Features Security Score AI Engine AI Coding KYP Hub Pricing Company About Buckler News Contact Français Book Demo →
1 · CSA

The National Baseline

National Instrument 31-103, s.13.2.1, is the KYP obligation's national baseline - the CSA-level rule that CIRO's own dealer-member and mutual-fund-dealer rules, and the rules governing every other registration category, all build on top of. It binds every registrant directly, not only CIRO dealer members.

s.13.2.1 - Know Your Product

1. Who Is Responsible

Every registered firm and individual under NI 31-103, across every registrant category - portfolio managers, exempt market dealers, scholarship plan dealers, and investment fund managers, not only CIRO-regulated investment dealers and mutual fund dealers. CIRO's Rule 3300 series is the CIRO-specific implementation of this same national obligation for the firms it regulates; a firm outside CIRO's jurisdiction doesn't get an exemption from KYP, it just answers to 31-103 directly instead.

2. The Regulation

National Instrument 31-103, Registration Requirements, Exemptions and Ongoing Registrant Obligations, s.13.2.1, read together with Companion Policy 31-103CP, Part 13. This is the CSA-level rule; CIRO's IDPC Rules 3301/3302 (2, below) and MFD Rule 2.2.5 (3, below) are how CIRO operationalizes it for the firms CIRO regulates.[3]

3. What It Means in Practice

Example: a boutique portfolio management firm isn't a CIRO member, so the IDPC Rule 3300 series doesn't technically apply to it. That doesn't mean it's exempt from KYP - it owes the identical obligation directly under NI 31-103 s.13.2.1. If that firm recommends a private real-estate fund to a client, its portfolio manager has to independently understand the fund's structure, risks, and costs before recommending it, exactly as a CIRO-registered advisor would have to under Rule 3302.

4. What the Wording Actually Says

CSA guidance interpreting this section describes the obligation as requiring registrants to possess comprehensive product knowledge, and to understand "the structure, features, and risks of each security the individual recommends" before recommending it.[5] In plain English: the KYP obligation isn't a CIRO invention that happens to apply to investment dealers - it's a national baseline that every category of registrant owes to their clients, whichever regulator actually supervises them day to day.

5. Real-World Requirements
  • Independent product understanding by the individual registrant, regardless of registration category or which regulator has direct oversight.
  • Applies whether or not the firm is a CIRO member - a firm outside CIRO's jurisdiction still has to satisfy s.13.2.1 on its own terms.
  • Read together with Companion Policy 31-103CP for the CSA's interpretive guidance on what "understanding" a product requires in practice.
2 · CIRO: Investment Dealers

Investment Dealers

CIRO Rule 3300 is the Investment Dealer and Partially Consolidated (IDPC) Rules' implementation of that NI 31-103 baseline for investment dealers. The 3300 series splits product due diligence and KYP into two separate, non-substitutable obligations - one on the dealer, one on the individual - plus a narrow set of exemptions. Rule by rule: who it binds, what it says, what it means in practice, and what has to exist to prove it.

Rule 3301 - Product Due Diligence (The Dealer's Obligation)

1. Who Is Responsible

The Dealer Member - the firm - not the individual registrant. Product due diligence is a firm-level, non-delegable obligation. It sits with whichever function the firm assigns it to (compliance, product governance, a PDD committee), but the accountability is the dealer's, not any one person's.

2. The Regulation

CIRO Investment Dealer and Partially Consolidated (IDPC) Rule 3301. Rule 3301 is the dealer-level companion to Rule 3302 (Know-Your-Product, the individual obligation) and sits inside the broader 3300 series, alongside Rule 3303 (exemptions). It is implemented through CIRO Guidance Note GN-3300-21-001, Product Due Diligence and Know-Your-Product.[1]

3. What It Means in Practice

Before a security can be recommended, sold, or held by a client at the firm, the firm itself has to have assessed it - not relied on the issuer's marketing material, not relied on another dealer's shelf decision, not assumed a related-party fund is fine because it is "in-house." Example: a firm wants to add a new liquid alternative mutual fund to its shelf. Under Rule 3301, before any advisor can recommend it, the firm has to independently assess the fund's structure, strategy, use of leverage, liquidity terms, fee load, and target client profile, and formally approve it - producing a dated record of who did that assessment and what they found. If the firm instead treats the fund manufacturer's marketing deck as the assessment, that does not satisfy Rule 3301.

4. What the Wording Actually Says

In the regulator's own language, dealers must "assess all the relevant aspects of the securities made available to clients including their: structure, features, risks, initial and ongoing costs, and impact of those costs," and must "approve all securities made available to clients, and monitor all approved securities for significant changes."[1] In plain English: if it's on your shelf, you assessed it, you approved it, and you're still watching it - not just on day one.

5. Real-World Requirements
  • A written PDD policy describing assessment levels, approval processes, and the roles responsible for each step.
  • A documented assessment for every security covering structure, features, risks, initial and ongoing costs, and the impact of those costs.
  • A formal, recorded approval decision - not just inclusion on a list.
  • Ongoing monitoring of every approved security for "significant changes," not a one-time approval.
  • A review structure scaled to complexity - preliminary assessment by qualified staff, multi-departmental committee review for complex or structured products, formal senior-level sign-off.

Rule 3302 - Know-Your-Product (The Approved Person's Obligation)

1. Who Is Responsible

The Approved Person - the individual advisor or registrant recommending the security. This obligation runs in parallel with the firm's Rule 3301 obligation and does not substitute for it, or get discharged by it.

2. The Regulation

CIRO IDPC Rule 3302, the companion obligation to Rule 3301, also governed by GN-3300-21-001. Joint CSA/CIRO Staff Notice 31-368 describes it in Section B.2 as a "separate and distinct obligation" from the dealer's product due diligence.[1],[2]

3. What It Means in Practice

The firm approving a security does not mean the advisor automatically understands it. Example: the firm has approved that same liquid alternative fund under Rule 3301. Before recommending it to a client, the advisor still has to independently understand the fund's structure, its leverage, its liquidity terms, and its fee drag - well enough to explain it to the client and to an examiner, in their own words, without simply repeating the fund fact sheet. If the advisor's only basis for the recommendation is "compliance approved it," Rule 3302 has not been satisfied.

4. What the Wording Actually Says

Approved Persons must "take steps to understand the securities (KYP)" including "structure, features and risks, initial and ongoing costs and the impact of those costs, sufficient to enable the Approved Persons to meet their suitability determination."[1] In plain English: you personally have to understand what you're selling well enough to judge whether it fits the client - the firm's approval doesn't do that thinking for you.

5. Real-World Requirements
  • Cannot purchase or recommend a security that has not been approved by the firm.
  • Must be able to explain the security's structure, features, risks, and costs to the client directly.
  • Cannot rely solely on issuer-provided materials or a third party's recommendation as the basis for understanding the product.
  • A documented KYP Assessment Note per product, created at first recommendation and refreshed on material change - the artifact an inspection actually looks for.

Rule 3303 - Exemptions

1. Who Is Responsible

Applies narrowly to dealers and individuals operating order-execution-only (OEO) or direct-electronic-access channels, and to carrying-broker arrangements where PDD responsibility is contractually held by another registrant.

2. The Regulation

CIRO IDPC Rule 3303, the exemptions provision that closes out the 3300 series.[1]

3. What It Means in Practice

Example: a self-directed client buys a stock through an order-execution-only platform with no advisor involvement. Because no recommendation is being made and no suitability determination is owed, the full PDD/KYP obligation that exists to support that determination doesn't attach the same way it would in an advisory relationship.

4. What the Wording Actually Says

The exemption applies to "Order Execution Only accounts, Direct Electronic Access accounts, and carrying broker arrangements where another registrant holds PDD responsibility."[1] In plain English: if nobody at the firm is recommending the security, or another registrant already owns the PDD obligation for it, the exemption applies - but this is narrow, not a general opt-out for advisory business.

5. Real-World Requirements
  • A firm relying on this exemption has to be able to demonstrate the account genuinely qualifies - no advice given, no recommendation made, or the PDD obligation documented as sitting with a named other registrant.
  • Cannot be used to carve advisory relationships out of PDD/KYP by relabeling them.
The Through-Line Across 3301, 3302, and 3303

Notice 31-368's Phase 2 sweep of 105 firms found the dominant deficiency was not judgment - it was documentation and process discipline. The work, in many cases, was being done. The regulator's finding was that the work could not be shown to have been done, and an obligation that cannot be evidenced cannot be supervised, audited, or defended.[2]

3 · CIRO: Mutual Fund Dealers

Mutual Fund Dealers

CIRO MFD Rule 2.2.5 is the same NI 31-103 baseline, applied through CIRO's separate Mutual Fund Dealer (MFD) rulebook rather than the IDPC Rules covered in 2, above. CIRO regulates investment dealers and mutual fund dealers under two separate rulebooks; this is the mutual-fund-dealer channel's parallel obligation.

MFD Rule 2.2.5

1. Who Is Responsible

Mutual Fund Dealer (MFD)-registered firms and their registered mutual fund representatives - the same two-layer structure as Rule 3300 (firm-level and individual-level), administered under CIRO's separate MFD rulebook rather than the IDPC Rules.

2. The Regulation

CIRO Mutual Fund Dealer (MFD) Rule 2.2.5, the MFD-channel's Know-Your-Product obligation, structurally parallel to IDPC Rules 3301 and 3302.[4]

3. What It Means in Practice

Example: an MFD-registered representative recommends a fund-of-funds product. The same two-layer test applies as in the IDPC world: the mutual fund dealer has to have assessed and approved the fund for its shelf, and the individual representative has to independently understand it before recommending it - being registered under the MFD Rules rather than the IDPC Rules doesn't lower the bar.

4. Real-World Requirements
  • The same substantive requirements as Rule 3301/3302 - a written PDD policy at the MFD-firm level, and a documented individual-level KYP note per product - administered under the MFD Rules rather than the IDPC Rules.
4 · CSA: Portfolio Managers

KYP for Portfolio Managers & Exempt Market Dealers

The CSA's own dedicated KYP guidance for the non-SRO registrant world - portfolio managers, exempt market dealers, and other firms outside CIRO's rulebook - published well before the Client Focused Reforms and still the foundational interpretation of what independent product due diligence looks like for these firms.

CSA Staff Notice 31-336

1. Who Is Responsible

Portfolio managers, exempt market dealers, scholarship plan dealers, and other registrants outside CIRO's dealer-member and mutual-fund-dealer rulebooks - the same registrant population that NI 31-103 s.13.2.1 (1, above) reaches directly.

2. The Regulation

CSA Staff Notice 31-336, Guidance for Portfolio Managers, Exempt Market Dealers and Other Registrants on the Know-Your-Client, Know-Your-Product and Suitability Obligations, January 9, 2014.[5]

3. What It Means in Practice

Example: an exempt market dealer is selling units in a prospectus-exempt mortgage investment corporation. Because that product is sold on an offering memorandum with far less mandated disclosure than a prospectus-qualified fund, Notice 31-336 requires the EMD to go further than it would for a comparable public product - independently reviewing the offering documents, questioning the issuer where the disclosure is thin, and not treating "it looks similar to a product we already sell" as a substitute for that review.

4. What the Wording Actually Says

The notice states registrants "should carefully review offering documents or other documentation prepared by the issuer or other third parties and ask questions where appropriate," and that "products that are sold under a prospectus exemption may require a more extensive review because of the limited disclosure available about them."[5] In plain English: the murkier or more exempt the product, the deeper the independent digging has to go - a thin offering memorandum is a reason to look harder, not an excuse to look less.

5. Real-World Requirements
  • Documented independent review of offering documents and other issuer- or third-party-prepared materials, not just receipt and filing of them.
  • An explicit questioning or escalation step directed at the issuer or manufacturer where disclosure is limited.
  • A heightened diligence standard specifically for exempt-market and other limited-disclosure products, distinct from the baseline review given to prospectus-qualified products.
  • Cannot substitute "similarities with other products already reviewed" for an actual independent assessment - the notice names this as an unacceptable practice.
5 · 2025 Regulatory Sweep

The KYP Findings From the Phase 2 Sweep

Joint CSA/CIRO Staff Notice 31-368, Section B, is where the 105-firm Phase 2 sweep's KYP-specific findings live, separate from the notice's KYC and suitability findings. Five findings, B.1 through B.5, each a distinct way firms fell short - across CIRO and non-CIRO registrants alike.

B.1 & B.2 - Relying on Someone Else's KYP

1. Who Is Responsible

The firm - this is a Rule 3301 (product due diligence) failure mode specifically, found repeatedly across the 105 firms reviewed.

2. The Regulation

Joint CSA/CIRO Staff Notice 31-368, Sections B.1 and B.2, December 10, 2025.[2]

3. What It Means in Practice

Example: a firm adds a related-party fund to its shelf and treats the fund manager's own KYP work, or the offering memorandum the manager prepared, as if that discharged the firm's own Rule 3301 obligation. The regulator found this repeatedly and rejected it in every instance reviewed - a related issuer's analysis, an OM, or a third-party change notification is input to the firm's own assessment, not a substitute for it.

4. What the Wording Actually Says

Firms relied on a related issuer's KYP, an offering memorandum, or third-party change notifications as if those discharged the firm's own KYP obligation; the regulator rejected each as a substitute for the firm's own analysis.[2] In plain English: someone else having done work on the product isn't the same as the firm having done its own work on the product - and Phase 2 found firms treating those as interchangeable.

5. Real-World Requirements
  • A firm's own Product Assessment Report for every security, even a related-party or affiliate product, distinct from any analysis the manufacturer supplied.
  • Third-party materials (an OM, a change notification) treated as input to the firm's review, never as the review itself.

B.3 - Approval Without an Evidenced Process

1. Who Is Responsible

The firm - specifically whoever owns the shelf-approval decision.

2. The Regulation

Joint CSA/CIRO Staff Notice 31-368, Section B.3, p.15.[2]

3. What It Means in Practice

Example: a security appears on a firm's approved-product list, but the file behind that entry has no documented review, no named analyst, and no stated rationale - just the fact of inclusion on the list. Phase 2 found this pattern across the 105 firms and treated the list itself as insufficient evidence that a meaningful review occurred.

4. What the Wording Actually Says

"Firms must establish approval processes for securities made available to clients."[2] In plain English: the approval has to come from a defined process with named criteria and named roles - not just a name appearing on a list with no file behind it.

5. Real-World Requirements
  • A written approval process defining the criteria, the roles responsible, and the required documentation for each shelf decision.
  • A dated, attributable record behind every approved-list entry - not the list alone.

B.4 - Monitoring Without a Defined Trigger

1. Who Is Responsible

The firm - the monitoring function specifically, as distinct from the initial approval covered in B.3.

2. The Regulation

Joint CSA/CIRO Staff Notice 31-368, Section B.4, p.17.[2]

3. What It Means in Practice

Example: a firm reviews its shelf once a year and treats that annual cycle as its entire monitoring obligation. Phase 2 found this insufficient on its own - without a written definition of what counts as a "significant change," an issuer downgrade or a fee increase in month three of the cycle goes unaddressed until the next annual review, by which point clients have been holding an unmonitored position for months.

4. What the Wording Actually Says

"Annual monitoring alone was not found to be sufficient."[2] In plain English: a once-a-year check-in doesn't satisfy the monitoring obligation on its own - the firm needs a written definition of what triggers a re-review and a process that fires on that trigger whenever it happens, not just on the calendar.

5. Real-World Requirements
  • A written, specific definition of "significant change" for monitoring purposes - not left implicit.
  • Continuous, risk-based monitoring capable of catching an event mid-cycle, not only at the annual review point.

B.5 - The Transfer-In and Top-Holdings Carve-Out

1. Who Is Responsible

Both the firm (for defining the perimeter) and the individual advisor (for the KYP assessment on each position once it's inside that perimeter).

2. The Regulation

Joint CSA/CIRO Staff Notice 31-368, Section B.5.[2]

3. What It Means in Practice

Example: a client transfers a small, rarely-traded position into their account from another firm. The advisor's KYP process only covers actively recommended securities and top holdings, so this transferred-in position never gets a KYP assessment. Phase 2 found this exact carve-out across multiple firms and rejected it explicitly - small size and low trading frequency are not exemptions from the obligation.

4. What the Wording Actually Says

Transfer-in securities and client-directed trades were excluded from KYP processes on the basis of small size or low frequency; the regulator rejected the carve-out.[2] In plain English: the KYP perimeter is every security in the account, not just the ones the advisor actively picked or the ones with the largest dollar value - "it's small" and "the client chose it, not me" are not exemptions.

5. Real-World Requirements
  • A KYP assessment triggered for every transfer-in and client-directed trade within a reasonable time of it landing in the account, regardless of size.
  • No "top holdings only" or "actively recommended only" scoping of the KYP perimeter.
6 · Summary

Putting It Together: Process, Triggers, and Supervision

The five sources above sit in different rulebooks, but underneath them all is one operating model. This section pulls that model together by who owns each piece of it: the firm defines it, the advisor executes it, and supervision has to be able to prove both happened.

For the Firm

Defining a Process and Approval

Product due diligence starts with a formally defined approval process: who assesses a product before it goes on the shelf, what criteria they apply, and who signs off. Section B.3 of Notice 31-368 is explicit that this cannot be informal or left to individual judgment - the firm has to be able to produce the approval record, the criteria applied, and the name of the approver, for every product on the shelf.[2]

Defining Material Change

A material change is any change to a security's structure, risk profile, costs, liquidity, or issuer circumstances significant enough that it could affect whether the product remains suitable for the clients it was approved for. In practice this covers things like a shift in a fund's investment strategy or asset mix, a fee increase, a credit-rating downgrade, a liquidity restriction such as a redemption gate or suspension, a deterioration in the issuer's financial condition, or a regulatory or legal action against the issuer or manager. The firm has to define this threshold in writing, in advance - not case by case, after something has already gone wrong.

Defining Triggers Based on Material Change

Triggers are the specific, predefined events that force a re-assessment: a rating downgrade, a redemption gate, an issuer restatement, a change in fund manager, a breach of a stated investment mandate. Rule 3302 and Section B.4 both require these triggers to be defined in advance and applied systematically - not identified reactively after a client complaint or a news story.[1][2]

Monitoring the Shelf Against Those Triggers

Once a product is approved, the firm's obligation doesn't stop there - it has to monitor the shelf against the triggers it defined, on an ongoing, risk-based basis. Section B.4 found annual-only monitoring insufficient on its own; the monitoring cadence has to match the product's risk profile, with higher-risk or more complex products reviewed more frequently than a simple, low-risk security.[2]

For the Advisor

The Process When a Material Change Occurs

When the firm's monitoring identifies that a trigger has fired, the advisor's obligation is to refresh their own KYP assessment for every client holding that position - not to treat the firm's notification as a substitute for their own analysis. The advisor reviews the updated source documents, re-assesses whether the position still suits each client who holds it, and records that refreshed understanding in a Triggered KYP Review Record. Where the change means the product no longer suits a client, the advisor has to act on it - a reposition recommendation, a conversation with the client, or an escalation - not simply note the change and move on.

For Supervision

Supervising and Documenting the Whole Process

None of the above is worth much to a regulator without a supervisory layer that checks it is actually happening. Supervision has to confirm that shelf approvals were documented with the required criteria and sign-off, that triggers were monitored on the defined cadence, that a Triggered KYP Review Record was produced whenever a trigger fired, and that there is no gap between when a trigger fired and when the advisor's review was completed and recorded. Notice 31-368 treats supervisory and training failures as their own standalone deficiency category - a firm with a correct policy on paper but no evidence of active supervision is still exposed.[2]

What This Means in Practice

Every regulation covered above - the CSA's national baseline, CIRO's two dealer channels, and the Phase 2 sweep's findings - collapses into the same six-part operating model: a defined approval process, a defined threshold for material change, defined triggers that follow from it, ongoing risk-based monitoring, a standard advisor workflow when a trigger fires, and active, evidenced supervision over all of it.

The firms that come through an inspection cleanly are rarely the ones with the best-written policy. They are the ones that can produce the approval record, the trigger log, the advisor's review, and the supervisor's sign-off, for any product, on request.

Recommendations

Six changes, organized by who owns each one and grounded in the sources covered above.

For the Firm

1. Formalize the Approval Process

Commit the approval workflow to writing so it holds up under review rather than existing only as informal practice - a named approver, a fixed set of criteria, and a record of both for every product on the shelf.[1][2]

2. Define Material Change and Its Triggers, in Writing

Set the material-change threshold and the specific trigger list ahead of time, not after something happens. A trigger that was never written down cannot be systematically monitored for.[1][2]

3. Move Monitoring From Calendar-Only to Risk-Based

Replace calendar-only shelf reviews with continuous, risk-weighted monitoring and a clear escalation path the moment a trigger fires.[2]

For the Advisor

4. Standardize the Advisor's Workflow and Artifact

Give every advisor the same workflow and the same documentation artifact for an initial assessment, a transfer-in, or a material-change refresh, so the firm can supervise consistently across its whole book.[2][3]

For Supervision

5. Build Supervision as an Active, Evidenced Control

Make supervision produce its own paper trail - approvals checked, triggers reviewed, advisor refreshes confirmed - rather than a policy that exists only on paper.[2]

6. Retain Records in a Contemporaneous, Retrievable Form

Capture each record at the point the obligation arises, not reconstructed later, and keep it retrievable for seven years on request.[3][4]

Recommendation Owner Source
1. Formalize the approval processFirm[1] [2]
2. Define material change and its triggers, in writingFirm[1] [2]
3. Move monitoring from calendar-only to risk-basedFirm[2]
4. Standardize the advisor's workflow and artifactAdvisor[2] [3]
5. Build supervision as an active, evidenced controlSupervision[2]
6. Retain records in a contemporaneous, retrievable formFirm / Supervision[3] [4]
References
  1. CIRO Guidance Note GN-3300-21-001, Product Due Diligence and Know-Your-Product, implementing CIRO Investment Dealer and Partially Consolidated (IDPC) Rules 3301 (Product Due Diligence), 3302 (Know-Your-Product), and 3303 (Exemptions). Source document
  2. Joint CSA/CIRO Staff Notice 31-368, Client Focused Reforms: Review of Registrants' Know Your Client, Know Your Product and Suitability Determination Practices and Additional Guidance, December 10, 2025, Section B.2. Source document
  3. National Instrument 31-103, Registration Requirements, Exemptions and Ongoing Registrant Obligations, ss.11.5-11.6, 13.2, 13.2.1. Source document
  4. CIRO Investment Dealer and Partially Consolidated (IDPC) Rules and Mutual Fund Dealer (MFD) Rules; legacy guidance MSN-0048 (KYP). Source document
  5. CSA Staff Notice 31-336, Guidance for Portfolio Managers, Exempt Market Dealers and Other Registrants on the Know-Your-Client, Know-Your-Product and Suitability Obligations, January 9, 2014. Source document