Platform Why Features Security Score AI Engine AI Coding KYP Hub Pricing Company About Buckler News Contact Français Book Demo →
Team Requirements

Product Management

At a wealth management firm, investment dealer, or broker-dealer, a head office committee of product specialists, market specialists, and compliance officers decides what goes on the product shelf. Under Know-Your-Product obligations that apply across Canada and the US,[1] its job doesn't end at approval - it carries five ongoing responsibilities.

1
Product Approval
Setting baseline eligibility parameters before a security is ever available for recommendation

In the KYP HubStep by step: Product Approval.

The product team sets baseline eligibility parameters across every category on a full-service shelf: equities, mutual funds, exchange-traded funds (ETFs), bonds, principal-protected notes, municipal bonds, and private equity. Equities are screened on minimum share price or market capitalization, ruling out illiquid or highly speculative names. Mutual funds and ETFs require a minimum fund size or track record for a new fund family, and a minimum AUM threshold within an approved family. Bonds and municipal bonds are screened on issuer credit quality and minimum rating; principal-protected notes on the structuring counterparty's creditworthiness and guarantee terms; private equity and other exempt-market products get the most intensive review, given their illiquidity and thinner disclosure. Most firms run an open-architecture model - once a fund family or equity class clears the baseline, new products inside it are added routinely. Scrutiny concentrates on the higher-risk edge of each category: leveraged and inverse ETFs, crypto and Bitcoin funds, hedge funds, thinly traded or micro-cap equities, complex structured notes, and private placements. The standard doesn't change with what a firm trades - a full-shelf dealer and a fund-only shop face the same bar for whatever they carry.

Approval isn't a formality anywhere in North America: regulators on both sides of the border require an approval decision to be documented, analytically grounded, and defensible on demand - not just recorded.

CIRO, the CSA, and the OSC treat approval the same way. Their joint review of 105 registered firms found many with approvals that lacked supporting KYP assessment rationale, or that leaned on an affiliate's work instead of the firm's own analysis.[5] CIRO's bar is documented, meaningful consideration with supporting analysis behind every approval - whether it comes from a committee or a single reviewer - scaled to the shelf's complexity.[3]

The bar doesn't drop under US rules. The SEC's Regulation Best Interest requires reasonable diligence, care, and skill to understand a security's risks, rewards, and costs before recommending it.[6] Registered investment advisers carry the same fiduciary duty directly under the Investment Advisers Act. FINRA Rule 3110 goes further on the shelf itself: a broker-dealer's written supervisory procedures have to cover every product line it offers, which in practice means a documented new-product review process before anything is added to the shelf, and ongoing supervision of what's already on it - not just a one-time sign-off.[7] Whichever regulator - CIRO, the SEC, or FINRA - the question is the same: can the firm produce the analysis behind the decision, not just the decision itself.

Ongoing Reviews

Approval isn't a one-time event. Once a security is on the shelf, the same committee keeps reviewing it against three inputs: whether the original investment thesis still holds, the firm's current exposure, and how it has performed against its defined material change thresholds over time (Section 2). None of that holds up in isolation - it's measured against comparable securities in the same segment and market.

That process is defined once, not reassembled by hand for each review. Four categories of information feed every decision:

Fundamental Data
The security's investment case, refreshed against current figures - the same basis used at initial approval.
Comparables
How the security stacks up against others in the same segment and market.
Monitoring History
Performance against documented material change thresholds over time - a track record, not a single snapshot.
Exposure
The firm's current stake in the outcome - number of advisors holding the security, total AUM, and number of client positions.
Ongoing shelf-approval decisionRecorded in the same auditable review record as the initial approval (Section 2)

Reviews run on a defined schedule: opened immediately by a qualifying alert (Section 3), or on a regular 12-to-18-month cadence otherwise. Either path closes only with a formal, attributed sign-off.

2
Material Change
Defining, in writing and in advance, what counts as a material change to a security's underlying fundamentals

In the KYP HubStep by step: Material Change. The rule behind it: Material Change: When to Reopen a KYP Assessment. Triggers by security type: equities, mutual funds and ETFs, structured products, segregated funds and annuities, model portfolios and alternatives and private markets.

Monitoring can't start until the firm has written down, in advance, what counts as a material change to a security's fundamentals - specific to the product type, not one generic rule across the shelf. Skip this step and "monitoring" is just a word: there's nothing concrete to check against.

The terminology has shifted over time, but the obligation hasn't. CIRO's foundational guidance calls this a "material change":[3]

"A change to the characteristics or terms of a product that may change the conclusions of the product assessment or the suitability of the product for certain types of clients." CIRO Notice 09-0086 [3]

The December 10, 2025 findings[5] use "significant change" for the same obligation, and flagged this gap as widespread: most of the 105 firms reviewed had no written definition of what a significant change meant for a given security type. A firm without a documented threshold can't demonstrate it was looking for the right thing. This document treats "material change" and "significant change" as the same requirement.

Neither the SEC nor FINRA defines a single term the way CIRO does, but the expectation lands in the same place. FINRA's suitability rule[8] requires a reasonable basis to believe a recommendation is suitable, built on genuine understanding of the product - understanding that can't stay frozen at the moment of the original recommendation. The SEC's Regulation Best Interest goes further: a recommendation compliant at one point in time doesn't stay compliant if the facts underneath it change,[6] and examiners have flagged firms with no written process for catching that. In practice, every firm - Canadian dealer or US broker-dealer - needs the same thing: a documented, product-specific definition of what change forces a fresh look.

That definition can't live only in a policy document or training deck - it has to sit in a system the firm can produce on demand, the same standard as the approval documentation in Section 1. A material change definition that exists only as a compliance officer's verbal understanding, or an analyst's personal spreadsheet, doesn't meet that bar, even if it's being followed faithfully.

For each material change definition, the system of record needs to capture, at minimum:

  • Security Type - the sector, category, or asset class the material change definition applies to. Thresholds are sector-relative (benchmarked against GICS sector), category-relative (benchmarked against peer category), or a flat rule across an entire asset class.
  • Metric - the specific underlying data field being tracked.
  • Breach Condition - the precise movement in that metric which counts as crossing the threshold - what actually constitutes a breach.
  • Evaluation Frequency - how often the metric is checked: daily, monthly, quarterly, or event-driven.
  • Severity Level - how significant the change is judged to be (Critical, Important, or Watch), which is what determines how the firm has to respond (Section 4).

The registry itself has to stay current, not just get defined once and filed away. The December 10, 2025 findings criticized firms with no defined threshold at all; a stale one has the same effect if never revisited as products, markets, and risk tolerance change. The registry should have a defined owner - the same committee responsible for shelf approval in Section 1 - and a defined cadence for reassessing whether each material change definition's metric, condition, frequency, and severity still reflect current conditions, with changes logged and dated rather than edited in place.

The tables below show a representative material change definition, organized by severity rather than product type - six Critical, six Important, five Watch - mixing equities, mutual funds, and ETFs, the way a firm prioritizes response: by significance, not security type.

AlertAsset ClassSecurity TypeMetricBreach Condition
Dividend CutEquityAll equities (flat rule)Declared dividend per shareCurrent period's DPS is below the prior period's.
Earnings MissEquityAll equities (flat rule)Reported EPS vs. consensus estimateActual EPS comes in below consensus estimate.
Quartile Ranking DropMutual FundCategory-relative (peer category)Peer-category quartile ranking, trailing 3-yearAny quartile-boundary drop (1st to 2nd, 2nd to 3rd, or 3rd to 4th).
Alpha Turns NegativeMutual FundSelf-relative (fund's own trailing history)Trailing alpha vs. benchmarkTrailing alpha crosses from positive to negative.
Net Outflow AlertMutual FundAll fund categories (flat rule)Monthly net flow, % of total net assets6 consecutive months of negative net flow, each month's outflow at least 1% of total net assets.
Fund Status ChangeETFAll ETFs (flat rule)Fund status fieldAny status change event (closed to new investors, or terminated).
AlertAsset ClassSecurity TypeMetricBreach Condition
Volatility SpikeEquitySelf-relative (security's own trailing history)30-day realized volatilityExceeds a defined multiple of its own 1-year average.
Margin CompressionEquityAll equities (flat rule)Operating / profit marginDeclines by 2 or more points quarter-over-quarter or year-over-year.
Free Cash Flow DeclineEquityAll equities (flat rule)Free cash flowDeclines by a defined percentage year-over-year.
Management Fee / MER IncreaseMutual FundAll fund categories (flat rule)Management fee / MERAny increase versus the prior period.
Underperformance vs. CategoryMutual FundCategory-relative (peer category)Trailing return vs. peer categoryUnderperforms peer category average by a defined margin over a trailing period.
AUM DeclineETFAll ETFs (flat rule)Total assets under managementDeclines by a defined percentage over a trailing period.
AlertAsset ClassSecurity TypeMetricBreach Condition
Drawdown from PeakEquityAll equities (flat rule)Price vs. rolling peakPercentage decline from the security's rolling price peak, past a defined threshold.
P/E, EV/EBITDA, P/B DeviationEquitySector-relative (GICS sector)Valuation multiples vs. sectorDeviates from the security's own sector average by a defined margin.
Turnover SpikeMutual FundSelf-relative (fund's own trailing history)Portfolio turnover ratioExceeds a defined multiple of its own historical average.
Valuation Drift vs. CategoryMutual FundCategory-relative (peer category)Portfolio valuation multiples vs. peer categoryDrifts from peer category average by a defined margin.
Tracking Error IncreaseETFCategory-relative (fund's own benchmark)Fund return vs. benchmark returnStandard deviation between the two widens beyond a defined tolerance over a trailing period.

Each threshold should tie back explicitly to the regulatory obligation it satisfies, rather than leaving the connection implicit.

A note on the figures above: several exact multiples and thresholds shown here are illustrative, not backtested or calibrated against real data. They represent the metrics and mechanics accurately; the specific numbers are placeholders, not finalized firm policy.
3
Monitoring
Evaluating every security on the shelf against its defined threshold continuously, not through periodic sampling

In the KYP HubWhen an alert fires: From Alert to Decision. Testing the data behind monitoring: Auditing KYP Monitoring Data.

Once thresholds are documented, every security on the shelf has to be evaluated against them continuously, not through periodic sampling. The December 10, 2025 findings[5] are direct on this: annual review alone was judged insufficient for complex or risky products, and passively waiting for an issuer to announce a change was flagged as a deficiency in its own right. A quarterly check of the shelf's higher-profile names will always miss a change between checks. Monitoring frequency should be calibrated to each security's risk and complexity, not applied on one blanket schedule.

Ongoing monitoring should also account for a condition that stays flagged over time. If the same issue keeps re-opening a fresh review, reviewers tune out - which defeats the purpose. Firm policy should define, in advance, how long a reviewed condition stays "settled" before it warrants re-review, and what breaks that window immediately, such as the condition getting materially worse. That's decided once, up front, not left to individual judgment.

Mechanically, that evaluation runs as a continuous loop across the whole shelf, with one decision at its center: does the cycle end quietly, or open an alert?

1
Market Data
The full dataset captured for every security: fundamentals, market pricing, performance, risk, cost, and other financial metrics - all of it, not a curated subset.
2
Every Security Checked Against Its Material Changes
Security 1
Material Change 1
Material Change 2
Material Change 3
Material Change 4
Material Change 5
Security 2
Material Change 1
Material Change 2
Material Change 3
Material Change 4
Material Change 5
Security 3
Material Change 1
Material Change 2
Material Change 3
Material Change 4
Material Change 5
Security 4
Material Change 1
Material Change 2
Material Change 3
Material Change 4
Material Change 5
Security 5
Material Change 1
Material Change 2
Material Change 3
Material Change 4
Material Change 5
Defined per product type in Section 2. Every material change is checked independently, on every security; any single red is enough to constitute a breach and generate an alert on that security.
3. Has There Been a Breach of Material Change?
No
(a) Log to the Audit TrailRecorded as checked, not breached - provable on demand even when nothing crosses (Section 5).
↻ The security returns for its next scheduled evaluation - the loop closes back to Step 1.
Yes
(b) Generate AlertThe breaching material change sets the alert's severity level, and it routes to two destinations at once.
Product Shelf Team
Evaluates whether the security's platform status needs to change from Maintain to Suspend or Wind-Down (Section 4).
Advisor Who Owns It
Opens the advisor-level review described below, on a timeframe set by the breach's severity (Advisors section).
4
Workflows
What has to happen, who owns it, and how the firm closes out a review once a threshold is crossed

When a security crosses its defined threshold, the response that follows - who has to act, what they have to produce, and by when - is the workflow defined once, at the regulatory level, in Supervision, Section 1, scaled to the severity already assigned to that material change in the registry (Section 2). What belongs to Product Management is the shelf-level piece of that workflow: the review below, which closes with the firm recording one of three outcomes:

Maintain
The security stays active on the shelf and available for continued use.
Suspend
New sales are paused until a specific issue is resolved or a defined condition is met; existing positions are unaffected.
Wind-Down
The security is fully removed from the shelf. Because this requires unwinding existing client positions rather than a single trade, it plays out over a defined period - which is why it should have an owner and a timeframe, not just a decision.

A Critical breach opens a defined product management workflow: the committee reviews the security, records a status decision, and notifies every advisor holding it - whose own review is covered in the Advisors section.

Critical Material Change Breach on an Approved Security
  • (a) Product Management ReviewThe committee reviews the security under the same standards as Sections 1-3, assessing whether the original investment thesis still holds.
  • (b) Status DecisionRecorded as Maintain, Suspend, or Wind-Down, in the same auditable record as the initial approval.
  • (c) Advisor NotificationEvery advisor holding the security is notified of the new platform-level status, opening the advisor-level review described in Advisors, Section 2.

This is the mechanism behind the timeframe and ownership questions above: a Critical material change breach opening a defined, three-step product management workflow that closes with every affected advisor notified.

5
Documentation
The record a firm needs to be able to produce, not just assert, when asked to show its monitoring obligation was met

Every step above has to leave a record - whether the standard is CIRO's in Canada or the SEC and FINRA's in the US[6][7], the test is the same: can the firm produce evidence, not just assert the work happened. Each review opened by a material change breach must capture: the date the threshold was crossed, who reviewed it and when, what was reviewed, the rationale for the outcome, and, where an advisor-level review was opened, what the advisor concluded.

That documentation needs to be stored somewhere retrievable on demand, not scattered across email or individual notes. For a Wind-Down decision, documentation tracks progress through to completion - the unwind, not the decision, is the end of the record. This is what a firm hands a regulator or auditor to show the monitoring obligation was met, not just asserted.

Concretely, once material change is defined (Section 2), the firm has to be able to produce five categories of record on demand:

  • Material Change Breach History - when a specific material change was breached for a specific security, timestamped to the evaluation that caught it.
  • Breach Frequency - how many times a given material change has been breached across every security it applies to, not just the single instance under review.
  • Proof of Ongoing Evaluation - evidence a security was checked and cleared, not only that it eventually breached. A material change that's never breached must be provable as "evaluated, nothing crossed," dated and timestamped at its own cadence - an absence in the log should never mean either "clean" or "never checked."
  • Alert Delivery Confirmation - confirmation that every advisor holding the security actually received the resulting alert, not just that the alert was generated.
  • Critical Workflow Timeliness - confirmation that the product-level workflow a Critical alert opens (Section 4) was completed within its required timeframe, not only that it was opened.

Two further record types make this trustworthy, not just complete. Entries should be appended, never edited: a correction is a new, dated entry referencing the one it corrects, preserving the history of what was known and when - the same discipline this document applies to the material change registry (Section 2). And every breach and evaluation record needs to reference the specific material-change-definition version in effect when it was created; a record has no evidentiary value if it can't show which threshold and severity level applied on the date it was breached.

RecordWhat It ProvesCapturedGranularity
Material Change Breach LogA specific material change was breached for a specific security.At the moment of evaluationPer security, per material change, per event
Breach Frequency RollupHow often a given material change has been breached across the whole shelf.Derived from the Material Change Breach LogPer material change, aggregated across securities
Evaluation (No-Breach) LogThe security was checked and cleared, not simply left unchecked.Every scheduled evaluation, whether or not it firesPer security, per evaluation cycle
Alert Delivery RecordEvery advisor holding the security received the resulting alert.At time of alert dispatchPer alert, per recipient advisor
Critical Workflow Timeliness RecordThe product-level Critical workflow was completed within its required timeframe.At each workflow milestone (opened, decision, closed)Per Critical material change event
Shelf Coverage CompletenessEvery security on the shelf was evaluated on its defined cadence - a full sweep, not a sample.Rolled up over a reporting periodFirm-wide, across the full shelf
Material Change Version LinkageWhich threshold and severity level was in effect when a given record was created.At the moment each record is writtenPer record, referencing the registry version (Section 2)

That monitoring obligation doesn't depend on ownership. A security with no advisor currently holding it still has to be evaluated on the same schedule as everything else on the shelf (Section 3) - the shelf, not any advisor's book, defines the monitored population. The only difference is on alert delivery: with no advisor of record, there's no one to route an alert to. The evaluation itself, and the proof of it, still has to exist.

All of this needs to be retrievable as more than disconnected logs - an audit trail a product management team can generate on demand, for any material change or any security, rather than reconstructing it by hand each time an auditor asks:

  • Breach count by material change - for a given material change, how many securities on the shelf have breached it, and how many times, over any period (Breach Frequency Rollup, above).
  • Which securities were evaluated - the full evaluation record for a security or across the shelf, whether or not anything breached (Evaluation (No-Breach) Log, above).
  • What the material change definition is - the metric, condition, frequency, and severity in effect for any material change, and the version that applied on a given date (Section 2, and Material Change Version Linkage, above).
  • Which securities are due for review - what's coming up against the shelf's defined evaluation cadence (Section 3), before anything breaches.
  • Which securities haven't been reviewed - any gap against that cadence, surfaced directly rather than discovered later (Shelf Coverage Completeness, above).

Because that data is captured as it happens rather than assembled after the fact, none of this is new reporting work - it's the same records above, filtered and rolled up on demand.

Team Requirements

Advisors

Product Management covers how the shelf is defined and monitored - what belongs on it, what counts as a material change, and how the firm responds when one crosses a threshold. This section covers what an individual advisor is responsible for, on a purely know-your-product basis, once a security from that shelf is in a client's account.

An advisor shouldn't be re-litigating the shelf-level approval - that's the product team's job. An advisor answers a narrower question about their own book: has anything changed about a security they hold that changes whether the advisor still genuinely understands it the way KYP requires, and if fundamentals have shifted, is there now a better alternative on the shelf. That question runs through the same material change and alert infrastructure the product team uses, not a separate one.

This section covers what an advisor configures on their own book, and what the platform requires the moment an alert reaches them: a documented, product-level review of the security itself - not a review of any client's account, and not a determination that turns on client-specific facts like risk tolerance or investment horizon.

An advisor's know-your-product obligation[1] sits one level below the shelf: everything below applies the material change definitions and severities the product team has already defined (Product Management, Section 2) to the securities an advisor actually holds. Under CIRO's rules, this is a distinct, standalone obligation[1] - it sits with the individual advisor, not just the committee, and it applies regardless of who any given client is:

"An Approved Person of a Dealer may not purchase, sell or recommend securities for a client unless the Approved Person takes steps to understand the securities." CIRO Notice 20-0238, Appendix 03, interpreting Rule 3300 series (Know-Your-Product) [4]

South of the border, the same review sits inside the broker-dealer's Care Obligation under Regulation Best Interest[6]: before a registered representative can recommend a security at all, the firm has to have a reasonable basis to believe it understands that security's features, costs, and risks - a product-level, standalone requirement that exists independently of any individual client's circumstances. Whether the standard is CIRO's or the SEC's, the review below asks the same question: does the firm still genuinely understand this security, not whether it's still right for a particular client.

1
Monitoring and Alerts
What an advisor can configure and monitor on their own book - the full set of metrics tracked for every security they hold, and which of those carry an alert

Monitoring and alerts are two distinct things, and the platform keeps them distinct. Monitoring is the ongoing tracking of a security's metrics for material change - all of them, whether or not any currently carries an alert threshold. An alert is a threshold set on one of those monitored metrics that generates a notification when it's crossed. A security can be monitored on twenty metrics with only one or two of them alert-worthy; the advisor should still have visibility into all twenty, not just the ones configured to fire.

What gets monitored is itself layered:

Firm Level
Material change metrics defined firm-wide, tracked across every security on the shelf.
+
Advisor Level
Additional metrics an advisor adds across their entire book, reflecting what they consider material for the securities they manage and their own investment style.
+
Security Level
Additional metrics added for one specific security in the book.
Effective Monitoring Set for This SecurityEvery metric tracked for the security, labeled by source layer - firm, advisor, or security - and flagged where an alert threshold is attached

Alerts are a threshold layered on top of a subset of those metrics, not a separate tracking system. The same three layers apply to thresholds: firm-level alert thresholds are mandatory across the shelf; an advisor can add or tighten thresholds across their book, or for one security specifically, on top of whatever the firm already monitors. An advisor can toggle any alert on or off, including mandatory firm-level ones - the underlying metric stays monitored either way; only the notification stops.

Beyond configuration, advisors should have visibility into a security's full monitoring history, not just what it's alerted on:

  • By security: how it has tracked historically against a specific alert metric, alongside every other metric being monitored for that security - the complete picture, not only what's alerted.
  • By metric: every security across the book tracked historically against that one metric, whether or not it's currently running close to a threshold.
  • How many alert breaches a specific security has generated in the past period or period-to-date.
  • How close a security is running to any of its monitored metrics, alerted or not - not only the ones already at threshold.

In short, the view should work in both directions:

By Security
Every metric monitored for one security, across all layers, with its full history - and which of those carry an alert.
⇄
By Monitored Metric
Every security across the book tracked against that one metric historically, whether or not an alert is currently attached to it for that security.
2
Workflow and Investment Review
How responsibility shifts from firm-level monitoring to the advisor once an alert fires, and what a Critical investment review covers

Monitoring itself sits at the firm level (Section 1) - it runs continuously against every security an advisor holds, whether or not anything ever breaches. The moment a material change is breached and an alert generates, that changes: responsibility shifts to the advisor holding the security, who now owns conducting the resulting due diligence review. What that review actually requires - and how quickly - depends on the alert's severity, and that scaling shouldn't be the advisor's call to make case by case. Supervision should define the workflow once, for every severity level, and both the shelf-level and advisor-level response follow it (Supervision, Section 1).

For a Critical alert specifically, that firm-defined workflow is what triggers the investment review automatically - it shouldn't be a judgment call the advisor makes on receiving the alert. If Supervision has defined, ahead of time, that a Critical alert on a held security requires a review within a set window - ten business days, for example - the advisor is notified the moment the alert generates and guided directly into that review, rather than deciding independently whether the alert warrants one. When that notification reaches the advisor, it should carry full context, not just the fact that something happened: what alert and material change condition fired, the specific metric and the data behind the breach, when it happened, and whether the same alert has occurred on that security before.

The response required scales with severity, and the table below shows what each level looks like in practice, from the alert opening through to how it closes:

SeverityExampleLifecycle
CriticalA dividend cut on a held equity, or a mutual fund's fund status changing to closed or terminated.Opens automatically on the security and routes to every advisor holding it. Triggers the investment review below, due within the timeframe Supervision has defined for Critical alerts. Closes once the review is completed and filed.
ImportantMargin compression on a held equity, or a management fee increase on a held mutual fund.Opens on the security. The advisor acknowledges it and documents notes directly on the alert. Closes on acknowledgment - unless two or three Important alerts recur on the same security within a defined window, in which case the pattern escalates into a full investment review.
WatchA drawdown from peak price, or a valuation drift against peer category.Opens on the security. Eligible for bulk close alongside other open Watch alerts, within its own designated timeframe, without an individual write-up unless the advisor chooses to document one.

CIRO and the CSA are direct about why the Critical-level review can't be optional once a security is flagged:

"Registrants must reassess a client's account and holdings to ensure they remain suitable and continue to put the client's interest first." Joint CSA/CIRO Staff Notice 31-368, December 10, 2025 [5]

That review runs in parallel with the shelf-level review the product team conducts on the same material change (Product Management, Section 4) - the shelf-level status decision feeds directly into what the advisor sees, but neither side waits on the other to start. The review itself breaks into four steps, each of which becomes part of the permanent record rather than a private working note:

StepWhat It Covers
1. Investment ReviewA review of the security's fundamentals, paying specific attention to the material change that generated the alert, and drawing on any due diligence notes already captured at the firm level for that security.
2. Comparable Securities ReviewA review of comparable securities in the same segment, so the decision isn't reached in isolation from what else is available on the shelf.
3. Written DecisionThe advisor's decision on the security, confirmed in writing: hold and maintain, or initiate a transition out and identify replacement positions, drawing on a documented, reasonable range of alternatives rather than a single default choice - the December 2025 findings flagged firms with no documented process for assessing alternatives at all.[5]
4. Documentation and Audit TrailEverything above, documented in an auditable format accessible to the supervision team, so completion of every step can be confirmed without asking the advisor directly (Section 4).

The review shouldn't be a rigid checklist. It's non-delegable - it has to be completed directly by the advisor, which is exactly why it should stay efficient rather than layered with unnecessary steps - but within that, it draws on the advisor's own judgment and analysis of the security, not a mechanically filled-in form. What matters for the record is that the fundamentals were genuinely reconsidered, that a snapshot of the data as of the review is captured rather than a live reference that can drift afterward, and that the reasoning behind the decision is written down, not just the conclusion. When more than one review is open at once, Critical takes priority, followed by Important, then Watch.

Once the review is completed and the review record is filed, the alert is closed. If the outcome also calls for a suitability review of specific clients holding the security, that has to be completed too - but it's a separate process from the one above, run against a different set of inputs entirely: client-specific facts like KYC profile, risk tolerance, and investment horizon, rather than the security itself. Suitability is evaluated per client;[2] KYP is evaluated per product[1] - the joint CSA/CIRO reform work draws that line explicitly[5] - and closing the KYP-level review above doesn't wait on it.

A Suspend or Wind-Down decision reached on the shelf side (Product Management, Section 4) becomes information the advisor's review has to account for, though here too, neither workflow waits on the other to start.

3
Due Diligence
What opens a due diligence review, on what cadence, and how the review clock resets

In the KYP HubStep by step: Advisor Due Diligence.

An advisor's due diligence obligation starts before any ongoing monitoring does. Adding a security to a client's account - by transfer-in or a new transaction - requires its own due diligence review at that point, independent of anything the monitoring record captures afterward.

From there, ongoing due diligence for an advisor runs on one of two tracks: it's opened by an alert, or it runs on a periodic cadence when nothing has fired. Both tracks, and the specific conditions that open a review, are defined once at the firm level as a minimum standard - not something each advisor sets for themselves.

Absent a triggering alert, the advisor still conducts a periodic review on a defined cadence - typically every 12 to 18 months per firm policy - as a separate, calendar-driven workflow that runs alongside the alert-driven one. That obligation to keep checking, not just to have checked once, isn't unique to either side of the border: it mirrors the ongoing suitability obligation under CIRO's suitability determination rule[2] in Canada, and it sits inside FINRA's supervision rule[7] and the SEC's Care Obligation under Regulation Best Interest[6] in the US - a recommendation that was compliant when it was made doesn't stay compliant on its own; someone has to keep checking.

Ongoing due diligence isn't just a scheduled check-in - it requires the advisor to build and maintain notes and documentation supporting the position over time: manager commentaries, analyst reviews, annual reports, or other supporting content. The bar is substantive, not perfunctory, on either side of the border. Canada's December 2025 findings singled out firms where "a note stating only 'no update' or 'no changes' in the client file...was insufficient without other evidence that a meaningful interaction took place,"[5] and firms that broadly "failed to properly document periodic suitability reassessments or demonstrate that a full suitability review of the account and holdings had been conducted."[5] FINRA's own supervision rule sets the same bar in the US: written procedures and the records to show they were actually followed, not just that they exist.[7]

Concretely, three conditions open a review, and each resets the periodic clock the same way a completed review does - the table below shows what triggers each one and the process that follows:

TriggerExampleResulting Process
Critical AlertA dividend cut on a held equity, or a mutual fund's status changing to closed or terminated.Opens a due diligence review - the investment review of that security defined in Section 2 - at the advisor level, completed within the timeframe Supervision has set for Critical alerts.
Repeated Important AlertsThree Important alerts on the same security within a 90-day period, for example - the specific count and window are set by firm policy, not fixed by regulation.The pattern itself opens a full investment review, even though no single Important alert in the group would have on its own.
Periodic Review (No Alerts)No Critical or Important alert on the security within the past 18 months.Opens a periodic review on schedule: the advisor determines whether better alternatives are now available, or whether the security still meets their requirements, even though nothing has fired.

Whichever of the three opens it, completing the review resets the clock: the 12-to-18-month cycle restarts from the date of that review, not from the date of the last one, regardless of which condition actually opened it.

All three conditions, and the cadence itself, are a firm-defined floor, not a ceiling. Supervision sets them as the minimum that applies to every advisor and every security; individual advisors can layer on additional review triggers or a tighter cadence of their own, based on how they manage their own book, the same way they can add monitoring metrics and alert thresholds on top of the firm's own (Section 1). What an advisor adds is theirs to define, but it doesn't lower the floor, and none of it sits outside view: supervision needs visibility into whether the firm-level minimum itself is being met for every advisor and every security, independent of whatever an individual advisor has added on top (Section 4).

Each security's monitoring history - every alert: material change, direction, severity, date breached, status, and who acted and when (Product Management, Section 5) - should surface automatically alongside the due diligence review. That pairs the advisor's point-in-time judgment with the full paper trail, so a review reflects how the security behaved over the period, not just how it looks on the day it's reviewed.

The same principle applies at the book level. An advisor - and, firm-wide, compliance - should have a rolled-up view across the whole book: every material change in effect and every alert against it, filterable by type, security, and date, prioritized by dollar AUM exposure rather than raw count. That view lets an advisor tell, before opening a single account, whether an issue is isolated or systemic across their book - a handful of unacknowledged Critical alerts with real AUM behind them is a different problem than the same count spread across Watch alerts on small positions.

4
Documentation
Why a documented process, applied the same way by every advisor, is what determines whether this framework holds up under regulatory scrutiny

When a regulator evaluates whether an advisor's know-your-product obligation is actually being met, the question comes down to two components, and both have to be answered yes. First: does a documented process exist at all - not tribal knowledge, not a training deck, but a written, followable process. Second: is that process actually being followed, provably, not just described on paper. Sections 1 through 3 above establish the process itself - what gets monitored, how an alert routes into a review, and when a periodic review opens absent one. None of that survives contact with a regulator, though, unless it's documented as it happens.

Documentation here doesn't mean producing a PDF after the fact. It means an audit trail that shows the process was actually followed over time, not reconstructed after the fact to look like it was. Concretely, that audit trail has to include:

  • Alert history and monitoring history for every security an advisor holds.
  • Proof that a security is monitored on an ongoing basis, even when nothing generates or triggers an alert - an evaluation that clears is still a record, not a non-event.
  • Reviews completed on time, not just eventually completed.
  • Point-in-time market data supporting the advisor's due diligence review, captured as of the review itself rather than reconstructed later from whatever the data happens to show today.

Together, that's what documentation means for an advisor, and it's fundamental: a firm with a well-designed process but no way to prove it was followed fails the same way a firm with no process at all does - the whole framework falls apart without it. It's critical that an advisor can consistently generate and store due diligence review documentation, proof of ongoing monitoring, and proof that alerts were processed and closed - not occasionally, and not only for the securities that happen to draw attention, but as a matter of course for everything they hold.

That consistency requirement isn't a design preference - it's written into CIRO's own rules. A Dealer Member must establish, maintain, and apply written policies and procedures that provide reasonable assurance the firm, its employees, and its Approved Persons all comply with CIRO's requirements[9] - one process, applied the same way across every advisor, not left to individual discretion. The same section of the rulebook requires the firm to maintain evidence that those procedures are actually being followed[9] - the audit-trail obligation above, in other words. An advisor can't meet a documentation standard that varies from one advisor to the next; the process and the proof of it have to be the same, whoever is holding the security.

The December 2025 findings were pointed about firms that fell short of that bar:

"Some firms had little or no documentation or recorded only that an investment was 'suitable' without showing the basis for that determination." Joint CSA/CIRO Staff Notice 31-368, December 10, 2025 [5]

The per-security audit log exists specifically to close that gap. Every acknowledgment, comment, closure reason, and know-your-product confirmation an advisor records feeds the same enterprise registry Product Management establishes for the shelf, rendered for each held security as a log specific to that security - reviews and their documentation, the complete monitoring record, alert history, and scheduled reviews still to come, all in one place, so a reviewer can see why a decision was reached, not just that one was made.

An advisor's actions complete two of the record types that registry requires (Product Management, Section 5): the Alert Delivery Confirmation - proof the advisor received and acted on the alert, not just that it was sent - and the Critical Workflow Timeliness Record, on the advisor-level side. That's what makes the record complete: a regulator or auditor reviewing one security sees both halves of the response, the shelf-level decision and the advisor-level review, without reconstructing either from separate systems.

Supervision covers how compliance consumes that combined record to demonstrate the monitoring obligation was met - at the shelf level, and at the level of every individual advisor action.

Team Requirements

Supervision

Compliance's job is different from the other two. Product Management covers what belongs on the shelf and how it's monitored; Advisors covers what an individual advisor does once a security is in a client's account. Compliance shouldn't need to run a third, separate monitoring process - its job should be proving, after the fact, that both of the others happened, for every security, every time.

Compliance shouldn't need to maintain its own independent log. It should consume the enterprise registry the product team establishes at the shelf level (Product Management, Section 5) and the per-security audit trail advisors feed at the position level (Advisors, Section 4), and should be able to produce both, for any security, on demand - to an internal auditor or to CIRO directly.

This section covers what that combined record needs to show, and how it gets produced when someone actually asks for it.

1
Defining the Workflow
What a firm needs to define once a material change is breached, and an example of what that workflow could look like, scaled by severity

In the KYP HubStep by step: Supervising a KYP Program. What the file must show: KYP Documentation: What Your File Must Show.

Product Management, Section 2 defines what counts as a material change and the condition that breaches it - that definition is a product decision. What happens once a material change is breached - who acts, what they produce, and by when - is a firm-defined workflow: each firm sets it based on how it wants its advisors and product team to respond. That a documented workflow needs to exist at all, and needs to be followed the same way every time, is the regulatory requirement - it's what CIRO and the CSA actually examine when they assess whether a firm's monitoring obligation was met,[5] and the same expectation holds under FINRA's supervision rule[7] and the SEC's Regulation Best Interest[6] in the US. Supervision needs to define that workflow once, for the firm, and both Product Management, Section 4 and Advisors, Section 2 follow whatever Supervision has set.

A material change is a documented condition that, once breached, generates an alert carrying its assigned severity (Product Management, Section 2). What follows below is one example of how a firm might scale that response by severity - the specific timeframes, review scope, and closure mechanics are illustrative, not prescribed by regulation; each firm defines its own. The two tables below show the same three severities from each side of the workflow: what the product team's review covers at the shelf level, and what an advisor's review covers once it reaches their book.

SeverityTriggerReview & OutcomeTimeframeDownstream Impact
Critical Critical alert on a shelf security. Formal investment review - fundamentals, financial ratios, costs, risks, and other changes, benchmarked against comparables. All supporting data is captured and saved. Resolves to Maintain, Hold (no new buys, sells only), or Exit/Wind-Down (reduce client positions). 10 business days from alert generation (example). A Hold or Exit/Wind-Down status pushes to every advisor holding the security, triggering the advisor-level workflow below.
Important Important alert on a shelf security. Acknowledged with notes. Escalates to the same formal investment review as Critical if more than two Important alerts recur on the same security within 90 days. Firm-defined for acknowledgment; an escalation review follows the Critical timeframe. Escalation triggers the same status push and advisor-level workflow as Critical.
Watch Watch alert on a shelf security. No individual review - eligible for bulk closure. Firm-defined; every alert still closes within its own window - it shouldn't be left open indefinitely. None.
SeverityTriggerReview & OutcomeTimeframeSuitability / Client Impact
Critical Critical alert on a held security, or a Hold / Exit-Wind-Down status pushed down from Product Management. Investment review of the security as held in the advisor's book - the same fundamentals, comparables, and cost/risk analysis as the shelf-level review, focused on whether it still belongs in the accounts holding it. Resolves to Maintain, Hold (no further buys), or Exit/Wind-Down (reduce or close client positions). 10 business days from alert generation (example, matching the firm's Critical window). A Hold or Exit/Wind-Down outcome flags every client account holding the security for a suitability follow-up - confirming the position, or its wind-down, still fits each client's KYC profile and risk tolerance. A separate, client-specific process, run against different inputs than the KYP review itself.
Important Important alert on a held security. Acknowledged with notes. Escalates to the same investment review as Critical if more than two Important alerts recur on the same security within 90 days. Firm-defined for acknowledgment; an escalation review follows the Critical timeframe. No suitability trigger on a routine acknowledgment. An escalation that produces a Hold or Exit/Wind-Down outcome carries the same client-level follow-up as Critical.
Watch Watch alert on a held security. No individual review - eligible for bulk closure. Firm-defined; every alert still closes within its own window - it shouldn't be left open indefinitely. None.

The two tables above are illustrative, not prescriptive: what a regulator examines isn't whether the response matches these specific numbers, but whether Product Management and Advisors both consistently follow whatever workflow Supervision has actually defined for the firm.

2
Enterprise Overview
The single record built by aggregating shelf- and advisor-level data across the firm, what it has to show for any security, and what it lets supervision see about whether the firm's own processes are actually being followed

Consolidated reporting is the aggregation of everything the firm has generated at the shelf level and the advisor level, across every security and every advisor, into one continuous record rather than two disconnected ones. Compliance shouldn't need to build that aggregation as a separate system - it should be assembled from the records Product Management and Advisors are already required to produce. For any security, at any time, that record needs to cover the following - and be able to confirm, not just capture, each one:

LevelRecord ComponentWhat It Captures & ConfirmsEstablished In
ShelfShelf ApprovalThe documented, analytically grounded decision behind adding the security to the shelf - the approval rationale and ongoing review documentation on file.Product Management, Section 1
ShelfMaterial Change DefinitionThe metric, condition, and severity that define a material change for that security, and the version in effect on any given date.Product Management, Section 2
ShelfMonitoring & Breach HistoryA continuous log of monitoring activity against the security relative to that definition - evaluations that clear as well as ones that breach - with breach frequency and proof of ongoing evaluation current at all times.Product Management, Section 3 & 5
ShelfAlert TriggerIdentification of exactly when an alert was triggered, which material change condition fired, and at what severity.Product Management, Section 2 & 5
ShelfEvaluation CadenceEvery security on the shelf evaluated on its defined cadence - a full sweep, including securities no advisor currently holds.Product Management, Section 5
ShelfShelf-Level WorkflowThe workflow triggered once a material change was breached - how it was initiated, the sequence followed, the output reached, and the documentation behind it - and whether any Critical workflow closed within its required timeframe.Product Management, Section 4 & 5; Supervision, Section 1
BothAlert DeliveryWhere the alert was sent and when it was received, at both the shelf level and the advisor level - and confirmation that every advisor holding the security received it and acted on it.Product Management, Section 5; Advisors, Section 4
AdvisorAdvisor-Level WorkflowThe investment review triggered on the advisor's book - how it was initiated, the sequence followed, the output reached, and the documentation behind it - a documented review for the outcome reached, not just the conclusion.Advisors, Section 2
AdvisorSuitability Follow-UpA client suitability follow-up completed wherever the outcome required one.Advisors, Section 2
AdvisorPeriodic Review CadenceThe periodic due diligence review run on cadence, or correctly reset by a qualifying material change breach.Advisors, Section 3
AdvisorKnow-Your-Product ConfirmationA know-your-product confirmation recorded for the security.Advisors, Section 1 & 2
BothDownstream WorkflowsAny workflow triggered off the back of the initial one - a firm-level decision to place a security on Hold, for example, and the advisor-level workflow that decision in turn triggers.Product Management, Section 4; Advisors, Section 2

None of this is a separate checklist maintained on the side - every row above reads against a record Product Management or Advisors is already required to produce. Compliance should confirm the record exists and is complete; it shouldn't need to generate new data.

Aggregated this way, the record does more than answer questions about a single security. It gives supervision one continuous view of the entire firm - not just what happened, but whether the firm's own defined process was actually followed, security by security and advisor by advisor. Held up against that same defined process, the aggregated record surfaces exactly where it wasn't, including patterns like:

  • Advisor Timeliness - specific advisors not completing investment reviews within the required timeframe.
  • Hold-Status Breaches - a security marked Hold continuing to be newly acquired in client accounts.
  • Shelf-Level Review Gaps - shelf-level reviews not being completed against the defined cadence.
  • Periodic Review Gaps - scheduled periodic reviews not being carried out.

Supervision needs the ability to see the firm's activity in aggregate against that predefined, documented process - not security by security, but across the whole business at once. That aggregate view is what a regulator is actually looking for[5][9]: a defined process, documentation that the process is being followed, and evidence of the follow-up taken when it isn't - a practice-management response, not necessarily a disciplinary one, showing the firm actively manages adherence rather than assuming it. Structured this way, consolidated reporting gives supervision as clear a picture as possible of those processes and how they're being managed across the business.

3
Documentation
How supervision produces the record for regulatory review, and what it needs to see to manage risk proactively

The mechanism for producing all of this is an audit log a compliance officer or examiner can generate on demand, for a single security or for a reporting period across the shelf - drawing on the records Product Management defines (Product Management, Section 5) and the per-security audit log Advisors maintains (Advisors, Section 4), joined so the shelf-level decision and the advisor-level response can be reviewed side by side rather than pulled from separate systems.

Why that matters on demand, not reconstructed after the fact, is spelled out in the same December 2025 findings[5]: as noted in Product Management, Section 1, many firms CIRO reviewed couldn't produce documentation showing the analysis behind a decision - not because the work hadn't happened, but because there was no single, retrievable record to confirm it had. A firm that has to manually reconstruct a security's history each time doesn't have a supervision record; it has raw material for one. The same expectation holds under the SEC and FINRA's supervision and suitability rules[6][7][8] in the US: a firm has to be able to show its process was followed, not just assert that it was.

At bottom, an audit log generated on demand has to answer three things: what the rules are, what happened, and whether the rules were followed. Concretely, that means it has to be able to produce, for any security, advisor, or reporting period, without further digging:

  • The rules - the severity-scaled response workflow that applies once a material change is identified, defined once, firm-wide (Supervision, Section 1).
  • The definition of material change - the specific thresholds, by security type and severity, that the firm has adopted and keeps current (Product Management, Section 2).
  • The process once a material change is identified - who has to act, what they have to produce, and by when, at both the shelf level and the advisor level (Product Management, Section 4, Advisors, Section 2).
  • How many alerts were generated - the breach frequency for a given material change, or across the shelf, over the reporting period (Product Management, Section 5).
  • Which securities generated them - the specific securities and advisors' books an alert touched, not just an aggregate count.
  • What the closure rate was - how many of those alerts closed within their required timeframe, and how many are still open.
  • Whether advisors followed the process - a documented review for every alert that reached an advisor's book, not just the alert itself (Advisors, Section 4).

Put together, that's a summary of the rules and the process, backed by documented proof that both have been followed consistently - not a single conclusion, but the evidence a regulator can trace decision by decision.

Beyond producing a record on request, supervision needs the same visibility applied proactively - surfacing risk before someone has to go looking for it, not only confirming it after the fact.

At the advisor population level, that means confirming, across every advisor, who is and isn't following the documented process - and flagging those who aren't. It also means seeing the risk behind outstanding alerts specifically: how much monetary exposure sits behind them, and how many positions are involved. That view should be available at both the branch and national level.

At the shelf level, the same visibility applies to positions actually generating breach alerts. Supervision has to satisfy a regulator on three points: an end-to-end process exists for monitoring the shelf's material change definitions, the shelf is actively managed rather than left to run on its own, and advisors follow a defined, consistent review process rather than each handling alerts their own way. On that basis, supervision confirms that everything in an advisor's book is monitored and reviewed - on a periodic cadence or a predefined material change breach - with nothing falling outside either path.

The final step sits at the client level: confirming that suitability requirements tied to that client's KYC profile are met and optimized against the KYP conclusions reached upstream. That closes the loop the Introduction opened with - the shelf-level decision, advisor-level review, and client-level suitability outcome all trace back to the same documented process, so supervision can demonstrate the system as a whole is working, not just that one security looks fine in isolation.

Advisor Population
Which advisors are following the documented process and which aren't, flagged directly - plus the monetary exposure and position count behind every outstanding alert.
Shelf
The exposure and risk behind positions generating breach alerts, and proof the shelf is actively managed against a defined, end-to-end monitoring process.
Client
Suitability requirements tied to each client's KYC profile, met and optimized against the KYP conclusions reached upstream.

All three levels above draw from the same audit log, available to Supervision at the branch and national level alike - not three separate views, but the same underlying record filtered to whoever is looking for risk in the system.

That's the same standard this document opened with: not whether the work happened, but whether anyone can show it.

References
  1. CIRO. Investment Dealer and Partially Consolidated Rules, Rule 3300 series (Product Due Diligence and Know-Your-Product). Source document (PDF)
  2. CIRO. Investment Dealer and Partially Consolidated Rules, Rule 3400 series (Suitability Determination). Source document (PDF)
  3. CIRO Notice 09-0086, Best Practices for Product Due Diligence. Source document
  4. CIRO Notice 20-0238, Appendix 03, Guidance: Product Due Diligence and Know-Your-Product. Source document
  5. Joint CSA/CIRO Staff Notice 31-368, Client Focused Reforms: Review of Registrants' Know Your Client, Know Your Product and Suitability Determination Practices and Additional Guidance, December 10, 2025. Source document (PDF)
  6. U.S. Securities and Exchange Commission. Regulation Best Interest: The Broker-Dealer Standard of Conduct, 17 C.F.R. § 240.15l-1, effective June 30, 2020. Source document (PDF)
  7. FINRA. FINRA Rules, Rule 3110 (Supervision). Source document
  8. FINRA. FINRA Rules, Rule 2111 (Suitability). Source document
  9. CIRO. Investment Dealer and Partially Consolidated Rules, Rule 1404 (Policies and Procedures) and Rule 1405 (Evidence of Compliance). Source document (PDF)