Four years after the Client Focused Reforms (CFRs) came into force, CIRO and the CSA jointly reviewed 277 firms across every major registration category - 172 in the Phase 1 sweep on conflicts of interest, and a further 105 in the Phase 2 sweep covering Know Your Client, Know Your Product, and suitability. Phase 2 was published as Joint CSA/CIRO Staff Notice 31-368 on December 10, 2025; the OSC walked the industry through the consolidated findings at its Registrant Outreach session on April 15, 2026. Where the gaps were significant, regulatory action followed.
This page focuses on a single slice of those findings: product due diligence at the firm level - what goes on the shelf, how it gets there, how it stays there - and Know Your Product at the advisor level - what each registered individual has to understand about each security they recommend or hold. The recurring finding, narrowed to that slice, is the thesis of this page: the dominant deficiency was documentation and process discipline. Firms had policies. Advisors had judgment. What was missing, repeatedly, was a defined, supervised, evidenceable process and a documentation trail that demonstrated the analysis behind each shelf decision and each advisor-level KYP.
CIRO operationalizes the underlying NI 31-103 baseline for investment dealers under IDPC Rule 3300 and for mutual fund dealers under MFD Rule 2.2.5; the CSA provides the equivalent guidance directly to portfolio managers and exempt market dealers. Across every channel, the recurring failure was the same: undefined approval criteria, undefined triggers for material change, monitoring that stopped at an annual calendar check, and no supervisory record connecting any of it together.
Firm-level product due diligence and advisor-level KYP are two separate, parallel obligations under NI 31-103 s.13.2.1(1) and (2) - neither substitutes for the other. The KYP perimeter covers every security a client holds, including transfer-ins and small positions, and every record has to survive seven years and be retrievable in readable form.
This page walks through the KYP-specific requirements in order: 1, the national baseline under NI 31-103, s.13.2.1; 2, how CIRO implements it for investment dealers under Rule 3300; 3, mutual fund dealers under MFD Rule 2.2.5; 4, how the CSA guides portfolio managers and exempt market dealers under Staff Notice 31-336; 5, the KYP-specific findings from Notice 31-368, Section B; and 6, how it all comes together - process, triggers, and supervision, for the firm, the advisor, and the supervisory function.
National Instrument 31-103, s.13.2.1, is the KYP obligation's national baseline - the CSA-level rule that CIRO's own dealer-member and mutual-fund-dealer rules, and the rules governing every other registration category, all build on top of. It binds every registrant directly, not only CIRO dealer members.
Every registered firm and individual under NI 31-103, across every registrant category - portfolio managers, exempt market dealers, scholarship plan dealers, and investment fund managers, not only CIRO-regulated investment dealers and mutual fund dealers. CIRO's Rule 3300 series is the CIRO-specific implementation of this same national obligation for the firms it regulates; a firm outside CIRO's jurisdiction doesn't get an exemption from KYP, it just answers to 31-103 directly instead.
National Instrument 31-103, Registration Requirements, Exemptions and Ongoing Registrant Obligations, s.13.2.1, read together with Companion Policy 31-103CP, Part 13. This is the CSA-level rule; CIRO's IDPC Rules 3301/3302 (2, below) and MFD Rule 2.2.5 (3, below) are how CIRO operationalizes it for the firms CIRO regulates.[3]
Example: a boutique portfolio management firm isn't a CIRO member, so the IDPC Rule 3300 series doesn't technically apply to it. That doesn't mean it's exempt from KYP - it owes the identical obligation directly under NI 31-103 s.13.2.1. If that firm recommends a private real-estate fund to a client, its portfolio manager has to independently understand the fund's structure, risks, and costs before recommending it, exactly as a CIRO-registered advisor would have to under Rule 3302.
CSA guidance interpreting this section describes the obligation as requiring registrants to possess comprehensive product knowledge, and to understand "the structure, features, and risks of each security the individual recommends" before recommending it.[5] In plain English: the KYP obligation isn't a CIRO invention that happens to apply to investment dealers - it's a national baseline that every category of registrant owes to their clients, whichever regulator actually supervises them day to day.
CIRO Rule 3300 is the Investment Dealer and Partially Consolidated (IDPC) Rules' implementation of that NI 31-103 baseline for investment dealers. The 3300 series splits product due diligence and KYP into two separate, non-substitutable obligations - one on the dealer, one on the individual - plus a narrow set of exemptions. Rule by rule: who it binds, what it says, what it means in practice, and what has to exist to prove it.
The Dealer Member - the firm - not the individual registrant. Product due diligence is a firm-level, non-delegable obligation. It sits with whichever function the firm assigns it to (compliance, product governance, a PDD committee), but the accountability is the dealer's, not any one person's.
CIRO Investment Dealer and Partially Consolidated (IDPC) Rule 3301. Rule 3301 is the dealer-level companion to Rule 3302 (Know-Your-Product, the individual obligation) and sits inside the broader 3300 series, alongside Rule 3303 (exemptions). It is implemented through CIRO Guidance Note GN-3300-21-001, Product Due Diligence and Know-Your-Product.[1]
Before a security can be recommended, sold, or held by a client at the firm, the firm itself has to have assessed it - not relied on the issuer's marketing material, not relied on another dealer's shelf decision, not assumed a related-party fund is fine because it is "in-house." Example: a firm wants to add a new liquid alternative mutual fund to its shelf. Under Rule 3301, before any advisor can recommend it, the firm has to independently assess the fund's structure, strategy, use of leverage, liquidity terms, fee load, and target client profile, and formally approve it - producing a dated record of who did that assessment and what they found. If the firm instead treats the fund manufacturer's marketing deck as the assessment, that does not satisfy Rule 3301.
In the regulator's own language, dealers must "assess all the relevant aspects of the securities made available to clients including their: structure, features, risks, initial and ongoing costs, and impact of those costs," and must "approve all securities made available to clients, and monitor all approved securities for significant changes."[1] In plain English: if it's on your shelf, you assessed it, you approved it, and you're still watching it - not just on day one.
The Approved Person - the individual advisor or registrant recommending the security. This obligation runs in parallel with the firm's Rule 3301 obligation and does not substitute for it, or get discharged by it.
CIRO IDPC Rule 3302, the companion obligation to Rule 3301, also governed by GN-3300-21-001. Joint CSA/CIRO Staff Notice 31-368 describes it in Section B.2 as a "separate and distinct obligation" from the dealer's product due diligence.[1],[2]
The firm approving a security does not mean the advisor automatically understands it. Example: the firm has approved that same liquid alternative fund under Rule 3301. Before recommending it to a client, the advisor still has to independently understand the fund's structure, its leverage, its liquidity terms, and its fee drag - well enough to explain it to the client and to an examiner, in their own words, without simply repeating the fund fact sheet. If the advisor's only basis for the recommendation is "compliance approved it," Rule 3302 has not been satisfied.
Approved Persons must "take steps to understand the securities (KYP)" including "structure, features and risks, initial and ongoing costs and the impact of those costs, sufficient to enable the Approved Persons to meet their suitability determination."[1] In plain English: you personally have to understand what you're selling well enough to judge whether it fits the client - the firm's approval doesn't do that thinking for you.
Applies narrowly to dealers and individuals operating order-execution-only (OEO) or direct-electronic-access channels, and to carrying-broker arrangements where PDD responsibility is contractually held by another registrant.
CIRO IDPC Rule 3303, the exemptions provision that closes out the 3300 series.[1]
Example: a self-directed client buys a stock through an order-execution-only platform with no advisor involvement. Because no recommendation is being made and no suitability determination is owed, the full PDD/KYP obligation that exists to support that determination doesn't attach the same way it would in an advisory relationship.
The exemption applies to "Order Execution Only accounts, Direct Electronic Access accounts, and carrying broker arrangements where another registrant holds PDD responsibility."[1] In plain English: if nobody at the firm is recommending the security, or another registrant already owns the PDD obligation for it, the exemption applies - but this is narrow, not a general opt-out for advisory business.
Notice 31-368's Phase 2 sweep of 105 firms found the dominant deficiency was not judgment - it was documentation and process discipline. The work, in many cases, was being done. The regulator's finding was that the work could not be shown to have been done, and an obligation that cannot be evidenced cannot be supervised, audited, or defended.[2]
CIRO MFD Rule 2.2.5 is the same NI 31-103 baseline, applied through CIRO's separate Mutual Fund Dealer (MFD) rulebook rather than the IDPC Rules covered in 2, above. CIRO regulates investment dealers and mutual fund dealers under two separate rulebooks; this is the mutual-fund-dealer channel's parallel obligation.
Mutual Fund Dealer (MFD)-registered firms and their registered mutual fund representatives - the same two-layer structure as Rule 3300 (firm-level and individual-level), administered under CIRO's separate MFD rulebook rather than the IDPC Rules.
CIRO Mutual Fund Dealer (MFD) Rule 2.2.5, the MFD-channel's Know-Your-Product obligation, structurally parallel to IDPC Rules 3301 and 3302.[4]
Example: an MFD-registered representative recommends a fund-of-funds product. The same two-layer test applies as in the IDPC world: the mutual fund dealer has to have assessed and approved the fund for its shelf, and the individual representative has to independently understand it before recommending it - being registered under the MFD Rules rather than the IDPC Rules doesn't lower the bar.
The CSA's own dedicated KYP guidance for the non-SRO registrant world - portfolio managers, exempt market dealers, and other firms outside CIRO's rulebook - published well before the Client Focused Reforms and still the foundational interpretation of what independent product due diligence looks like for these firms.
Portfolio managers, exempt market dealers, scholarship plan dealers, and other registrants outside CIRO's dealer-member and mutual-fund-dealer rulebooks - the same registrant population that NI 31-103 s.13.2.1 (1, above) reaches directly.
CSA Staff Notice 31-336, Guidance for Portfolio Managers, Exempt Market Dealers and Other Registrants on the Know-Your-Client, Know-Your-Product and Suitability Obligations, January 9, 2014.[5]
Example: an exempt market dealer is selling units in a prospectus-exempt mortgage investment corporation. Because that product is sold on an offering memorandum with far less mandated disclosure than a prospectus-qualified fund, Notice 31-336 requires the EMD to go further than it would for a comparable public product - independently reviewing the offering documents, questioning the issuer where the disclosure is thin, and not treating "it looks similar to a product we already sell" as a substitute for that review.
The notice states registrants "should carefully review offering documents or other documentation prepared by the issuer or other third parties and ask questions where appropriate," and that "products that are sold under a prospectus exemption may require a more extensive review because of the limited disclosure available about them."[5] In plain English: the murkier or more exempt the product, the deeper the independent digging has to go - a thin offering memorandum is a reason to look harder, not an excuse to look less.
Joint CSA/CIRO Staff Notice 31-368, Section B, is where the 105-firm Phase 2 sweep's KYP-specific findings live, separate from the notice's KYC and suitability findings. Five findings, B.1 through B.5, each a distinct way firms fell short - across CIRO and non-CIRO registrants alike.
The firm - this is a Rule 3301 (product due diligence) failure mode specifically, found repeatedly across the 105 firms reviewed.
Joint CSA/CIRO Staff Notice 31-368, Sections B.1 and B.2, December 10, 2025.[2]
Example: a firm adds a related-party fund to its shelf and treats the fund manager's own KYP work, or the offering memorandum the manager prepared, as if that discharged the firm's own Rule 3301 obligation. The regulator found this repeatedly and rejected it in every instance reviewed - a related issuer's analysis, an OM, or a third-party change notification is input to the firm's own assessment, not a substitute for it.
Firms relied on a related issuer's KYP, an offering memorandum, or third-party change notifications as if those discharged the firm's own KYP obligation; the regulator rejected each as a substitute for the firm's own analysis.[2] In plain English: someone else having done work on the product isn't the same as the firm having done its own work on the product - and Phase 2 found firms treating those as interchangeable.
The firm - specifically whoever owns the shelf-approval decision.
Joint CSA/CIRO Staff Notice 31-368, Section B.3, p.15.[2]
Example: a security appears on a firm's approved-product list, but the file behind that entry has no documented review, no named analyst, and no stated rationale - just the fact of inclusion on the list. Phase 2 found this pattern across the 105 firms and treated the list itself as insufficient evidence that a meaningful review occurred.
"Firms must establish approval processes for securities made available to clients."[2] In plain English: the approval has to come from a defined process with named criteria and named roles - not just a name appearing on a list with no file behind it.
The firm - the monitoring function specifically, as distinct from the initial approval covered in B.3.
Joint CSA/CIRO Staff Notice 31-368, Section B.4, p.17.[2]
Example: a firm reviews its shelf once a year and treats that annual cycle as its entire monitoring obligation. Phase 2 found this insufficient on its own - without a written definition of what counts as a "significant change," an issuer downgrade or a fee increase in month three of the cycle goes unaddressed until the next annual review, by which point clients have been holding an unmonitored position for months.
"Annual monitoring alone was not found to be sufficient."[2] In plain English: a once-a-year check-in doesn't satisfy the monitoring obligation on its own - the firm needs a written definition of what triggers a re-review and a process that fires on that trigger whenever it happens, not just on the calendar.
Both the firm (for defining the perimeter) and the individual advisor (for the KYP assessment on each position once it's inside that perimeter).
Joint CSA/CIRO Staff Notice 31-368, Section B.5.[2]
Example: a client transfers a small, rarely-traded position into their account from another firm. The advisor's KYP process only covers actively recommended securities and top holdings, so this transferred-in position never gets a KYP assessment. Phase 2 found this exact carve-out across multiple firms and rejected it explicitly - small size and low trading frequency are not exemptions from the obligation.
Transfer-in securities and client-directed trades were excluded from KYP processes on the basis of small size or low frequency; the regulator rejected the carve-out.[2] In plain English: the KYP perimeter is every security in the account, not just the ones the advisor actively picked or the ones with the largest dollar value - "it's small" and "the client chose it, not me" are not exemptions.
The five sources above sit in different rulebooks, but underneath them all is one operating model. This section pulls that model together by who owns each piece of it: the firm defines it, the advisor executes it, and supervision has to be able to prove both happened.
Product due diligence starts with a formally defined approval process: who assesses a product before it goes on the shelf, what criteria they apply, and who signs off. Section B.3 of Notice 31-368 is explicit that this cannot be informal or left to individual judgment - the firm has to be able to produce the approval record, the criteria applied, and the name of the approver, for every product on the shelf.[2]
A material change is any change to a security's structure, risk profile, costs, liquidity, or issuer circumstances significant enough that it could affect whether the product remains suitable for the clients it was approved for. In practice this covers things like a shift in a fund's investment strategy or asset mix, a fee increase, a credit-rating downgrade, a liquidity restriction such as a redemption gate or suspension, a deterioration in the issuer's financial condition, or a regulatory or legal action against the issuer or manager. The firm has to define this threshold in writing, in advance - not case by case, after something has already gone wrong.
Triggers are the specific, predefined events that force a re-assessment: a rating downgrade, a redemption gate, an issuer restatement, a change in fund manager, a breach of a stated investment mandate. Rule 3302 and Section B.4 both require these triggers to be defined in advance and applied systematically - not identified reactively after a client complaint or a news story.[1][2]
Once a product is approved, the firm's obligation doesn't stop there - it has to monitor the shelf against the triggers it defined, on an ongoing, risk-based basis. Section B.4 found annual-only monitoring insufficient on its own; the monitoring cadence has to match the product's risk profile, with higher-risk or more complex products reviewed more frequently than a simple, low-risk security.[2]
When the firm's monitoring identifies that a trigger has fired, the advisor's obligation is to refresh their own KYP assessment for every client holding that position - not to treat the firm's notification as a substitute for their own analysis. The advisor reviews the updated source documents, re-assesses whether the position still suits each client who holds it, and records that refreshed understanding in a Triggered KYP Review Record. Where the change means the product no longer suits a client, the advisor has to act on it - a reposition recommendation, a conversation with the client, or an escalation - not simply note the change and move on.
None of the above is worth much to a regulator without a supervisory layer that checks it is actually happening. Supervision has to confirm that shelf approvals were documented with the required criteria and sign-off, that triggers were monitored on the defined cadence, that a Triggered KYP Review Record was produced whenever a trigger fired, and that there is no gap between when a trigger fired and when the advisor's review was completed and recorded. Notice 31-368 treats supervisory and training failures as their own standalone deficiency category - a firm with a correct policy on paper but no evidence of active supervision is still exposed.[2]
Every regulation covered above - the CSA's national baseline, CIRO's two dealer channels, and the Phase 2 sweep's findings - collapses into the same six-part operating model: a defined approval process, a defined threshold for material change, defined triggers that follow from it, ongoing risk-based monitoring, a standard advisor workflow when a trigger fires, and active, evidenced supervision over all of it.
The firms that come through an inspection cleanly are rarely the ones with the best-written policy. They are the ones that can produce the approval record, the trigger log, the advisor's review, and the supervisor's sign-off, for any product, on request.
Six changes, organized by who owns each one and grounded in the sources covered above.
Commit the approval workflow to writing so it holds up under review rather than existing only as informal practice - a named approver, a fixed set of criteria, and a record of both for every product on the shelf.[1][2]
Set the material-change threshold and the specific trigger list ahead of time, not after something happens. A trigger that was never written down cannot be systematically monitored for.[1][2]
Replace calendar-only shelf reviews with continuous, risk-weighted monitoring and a clear escalation path the moment a trigger fires.[2]
Give every advisor the same workflow and the same documentation artifact for an initial assessment, a transfer-in, or a material-change refresh, so the firm can supervise consistently across its whole book.[2][3]
Make supervision produce its own paper trail - approvals checked, triggers reviewed, advisor refreshes confirmed - rather than a policy that exists only on paper.[2]
Capture each record at the point the obligation arises, not reconstructed later, and keep it retrievable for seven years on request.[3][4]
| Recommendation | Owner | Source |
|---|---|---|
| 1. Formalize the approval process | Firm | [1] [2] |
| 2. Define material change and its triggers, in writing | Firm | [1] [2] |
| 3. Move monitoring from calendar-only to risk-based | Firm | [2] |
| 4. Standardize the advisor's workflow and artifact | Advisor | [2] [3] |
| 5. Build supervision as an active, evidenced control | Supervision | [2] |
| 6. Retain records in a contemporaneous, retrievable form | Firm / Supervision | [3] [4] |