Platform Why Features Security Score AI Engine AI Coding KYP Hub Pricing Company About Buckler News Contact Français Book Demo →
Part One

What End-to-End Means

An end-to-end KYP system covers the life of every product, from the documents that describe it to the evidence that the firm understood it.

1
The Eight Capabilities
What the whole job looks like
1
Source
Collect the documents and data that describe each product.
2
Assess
Analyze structure, features, risks and costs, to a depth that fits the product.
3
Approve
Record a decision, conditions and rationale.
4
Shelve
Keep one register of products and their status.
5
Monitor
Watch every product continuously for significant change.
6
Review
Turn alerts into documented decisions.
7
Inform
Get decisions and product knowledge to advisors, and record that they understood.
8
Evidence
Supervise the program and produce the record a regulator will ask for.

Each step depends on the one before it. A system that monitors well but can't show how the product was approved leaves the firm unable to say what it is monitoring against. A system that approves well but can't reach advisors leaves the firm's knowledge stuck at head office.

2
What the Market Offers
Four common types of platform, and where each usually stops

Platforms sold into the Canadian market for KYP tend to start from one part of the job and extend outward. Understanding where a platform started helps predict where its gaps will be.

Platform TypeWhere It StartsTypical StrengthsWhere Gaps Often Appear
Change detection toolsFund data feedsFrequent monitoring of fund attributes; configurable materiality thresholds; alertsAssessment and approval workflow; primary documents; securities beyond funds and ETFs
Advisor sales and proposal platformsProposals and product comparisonsAdvisor experience; off-shelf warnings; acknowledgementsHead-office due diligence; how changes are detected; depth of product analysis
Compliance and supervision suitesCompliance, disclosure and supervisionSupervisory dashboards; audit trails; disclosure delivery; product risk ratingsDepth of product assessment; complex products; primary document analysis
Research and data providersRatings, research and dataBroad data coverage; analyst research; comparison tools for advisorsFirm-specific approval and shelf governance; linking alerts to the firm's own holdings and advisors

None of these is a criticism. Each type does its own job well. The point for a buyer is that most firms will either choose one platform and fill its gaps, or combine several. Either way, the RFP needs to test every capability, not just the ones a given vendor leads with. A firm that assembles several tools also needs to ask how they connect: a change detected in one system is of little use if the approval record lives in another and the advisor acknowledgement in a third.

Part Two

The Requirements

Each area below sets out what to look for, then the questions to put in the RFP. Ask vendors to show, not describe: every Must requirement should be demonstrated on the firm's own products.

1
Data
Where the system's understanding of each product comes from

Data is the requirement most often under-specified, and the one that decides everything else. A system can only detect changes in what it reads. If it reads a data feed of fund attributes, it will catch a fee change in the feed. It won't catch a new risk factor added to a prospectus, a change in redemption terms in an offering memorandum, or an amendment that the feed doesn't carry.

Canadian regulators have said third-party reports can support a firm's KYP work, but firms should document their own analysis.[3] A system built only on third-party summaries makes that harder.

RefRequirementAsk the VendorPriority
D1Reads primary documents: Fund Facts, ETF Facts, simplified prospectuses and amendments, annual information forms, MRFPs, financial statements, offering memoranda, term sheets and pricing supplements, and regulatory filingsWhich document types do you read directly? From which sources? Show a change detected from a document rather than a data feed.Must
D2Uses structured market and reference data for prices, holdings, ratings and identifiersWhich data providers do you use? Can the firm bring its own licences?Must
D3Every data point traceable to its source document or feed, with dateShow the source for any value on screen, in one click.Must
D4Stores a fixed copy of each document version usedIf an issuer replaces a document online, can you show the version you used?Must
D5Maps every identifier (FundSERV code, CUSIP, ISIN, ticker) down to series or share classHow do you handle series, share classes, mergers and name changes?Must
D6Stated freshness for each data typeHow quickly after filing is a document read? How often is each data type refreshed?Must
D7Reports missing or stale data as a gap, never as "no change"What happens when a source is unavailable? Show the result.Must
D8Handles scanned and poorly formatted documentsWhat is your accuracy on scanned term sheets and offering memoranda?Should
D9French-language documentsDo you read French documents, and at what accuracy?Should
2
AI
What AI should do, and the controls that make it safe to rely on

AI is what makes reading primary documents at scale practical. It is also where a buyer needs to be most careful. Canadian securities regulators expect AI systems to be fit for purpose, tested before and after adoption, and explainable enough for the firm to meet its record keeping requirements.[4] Firms inside bank or insurance groups will also need AI tools to fit their group's model risk framework.[5]

The single most useful test of an AI-driven KYP system is whether every output is tied to its source. An AI that summarizes a prospectus is only useful if the reviewer can check each statement against the page it came from.

RefRequirementAsk the VendorPriority
A1Every AI output cites its source document, page or data pointShow an AI-generated product summary with sources for each statement.Must
A2Outputs without a source are flagged, not presented as factWhat happens when the AI can't find support for a statement?Must
A3Validation results available, broken down by document and product typeProvide your accuracy results for extraction and change detection, by document type.Must
A4The firm can run its own test setCan we test the system against documents where we already know the answers?Must
A5Model, prompt and configuration versions recorded on every outputWould we know which model version produced a given output a year from now?Must
A6Advance notice of model changes, with a test periodHow and when do you notify clients of model changes?Must
A7AI does not approve products or change product statusWhich actions can the AI take without a person?Must
A8Reviewer corrections captured and fed into monitoringHow are corrections recorded, and do they change the model's behaviour for our firm?Should
A9Firm data not used to train shared models without consentIs our data used to train models used by other clients?Must
3
Securities Coverage
Which products are covered, and what is watched for each

Coverage is often described as a list of asset classes. That isn't enough. A system that "covers structured products" may hold the issue terms but not watch barrier levels or issuer credit. The RFP should ask what is monitored for each type, not just whether the type is in the system.

Product TypeWhat an End-to-End System Should MonitorPriority
Mutual fundsFees and series, manager and sub-advisor changes, mandate and strategy changes, risk rating, mergers and terminations, fund size and flows, performance against categoryMust
ETFsAll of the above plus tracking difference, premium or discount to NAV, liquidity, index changes, leverage or inverse featuresMust
Segregated funds and annuitiesGuarantee levels and resets, fees including guarantee fees, underlying fund changes, insurer financial strength, contract changesMust, if offered
EquitiesCorporate actions, credit and ratings changes, regulatory filings, price and volatility events, trading haltsMust
Fixed incomeCredit ratings, issuer events, call and redemption features, liquidityMust
Structured productsBarrier and call levels against the underlying, observation dates, issuer credit, estimated value, secondary market availabilityMust, if offered
Alternative mutual fundsLeverage, short exposure, strategy drift, liquidity, fees including performance feesMust, if offered
Private and exempt-market fundsRedemption gates and queues, valuation frequency and lag, leverage, key person events, service provider changes, audited statementsMust, if offered
Managed and model portfoliosChanges to underlying holdings, model changes, drift from stated strategy, overlay manager changesShould

Ask for a coverage map. Request the vendor's list of every product on the firm's current shelf, with what the system can monitor for each. Gaps found now are cheaper than gaps found after launch.

4
Workflow
Assessment, approval, the shelf, monitoring and review

Canadian regulators expect approval records to show "meaningful consideration" of the elements assessed, and where firms rely on algorithmic models, evidence of ongoing oversight.[3] The workflow is where that evidence is created.

RefRequirementAsk the VendorPriority
W1Product assessment templates by complexity tier, covering structure, features, risks, costs and partiesShow the assessment for a complex product. Can we set our own templates and tiers?Must
W2Cost comparison against approved alternativesHow is cost compared, and against what?Must
W3Approval workflow with named reviewers, committee sign-off, conditions and rationaleWalk through an approval from request to decision.Must
W4A single product register at series level, with defined statuses (approved, watch, restricted, suspended, wind-down, removed)Can status changes flow to order entry to block or flag purchases?Must
W5Configurable monitoring rules with thresholds, severity and ownersCan compliance change a rule without a vendor release? Is every rule change logged?Must
W6Alert routing by severity to product, supervision and the advisors who hold the productShow an alert reaching the advisors whose clients hold the product.Must
W7Noise control: grouping, deduplication and settle periodsWhat is the typical number of alerts per product per month? How do you prevent duplicates?Must
W8Product review workflow from alert to decision, with defined outcomes and timeframesShow an alert being triaged, reviewed, decided and closed.Must
W9Holdings mapping to the register, with exceptions for unmatched and off-shelf positionsHow do you match client holdings to the shelf? How are transferred-in products handled?Must
W10Removal and wind-down plans tracked to the last positionHow is a product removal managed and tracked?Should
5
Advisors and Supervision
Getting knowledge to advisors, and showing it arrived

The firm's approval of a product doesn't replace each advisor's own obligation to understand it.[2] A KYP system should support that obligation directly, and give supervisors a view of who has kept up.

RefRequirementAsk the VendorPriority
S1An advisor view of alerts, product statuses and the products held in their bookShow what an advisor sees when they log in.Must
S2Plain-language product summaries, updated after every review decision, with sourcesWho writes summaries, and how quickly are they updated?Must
S3Acknowledgement of product decisions, tracked by advisorShow acknowledgement tracking and escalation for an overdue advisor.Must
S4Advisor product notes, in the advisor's own words, kept with the productCan advisors record product notes? Are they kept separately from client files?Should
S5Annual product-by-product attestation against a book list the system producesCan the system generate each advisor's book list and record attestations product by product?Should
S6Training conditions linked to productsCan a product be restricted to advisors who have completed training?Should
S7Supervisory dashboards and exception reports: overdue reviews, overdue acknowledgements, purchases in suspended productsShow the supervisor's daily view.Must
S8Escalation rules applied automaticallyCan escalations be configured and recorded?Should
6
Reporting and Documentation
The record a regulator will ask for

When a regulator asks how the firm meets its KYP obligations, the answer should be a report the system produces, not a file assembled by hand. Canadian regulators also expect policies to describe automated systems in detail,[3] so the vendor's documentation matters as much as its reports.

RefRequirementAsk the VendorPriority
R1Complete audit trail: every assessment, approval, alert, review, decision, notice, acknowledgement and status change, with user and timeCan records be altered after the fact? Show the audit trail for one product.Must
R2State of the program as at any past dateShow the shelf, product statuses and open alerts as at a date six months ago.Must
R3Product file export: full history of one product in one documentProduce the full file for a product we name.Must
R4Program metrics: monitoring coverage, holdings match rate, review timeliness, acknowledgement rates, exceptionsWhich program metrics are available out of the box?Must
R5Regulatory exam pack generated from the systemWhat would you produce for a regulatory exam of our KYP program?Should
R6Vendor documentation detailed enough for the firm's policiesProvide the documentation you would give us to describe your system in our policies.Must
R7Retention for the firm's required period, with export on exitHow long are records kept? In what format can we take them if we leave?Must
R8Scheduled and ad hoc reports for committees and senior managementShow a committee report and a senior management summary.Should
7
Infrastructure and Security
Where it runs, how it connects, and how it is protected
RefRequirementAsk the VendorPriority
I1Canadian data residency for firm and client dataWhere is our data stored and processed, including by AI services and subprocessors?Must
I2Independent security assurance, such as a SOC 2 Type II reportProvide your latest report and any exceptions noted.Must
I3Single sign-on and role-based accessWhich identity providers do you support? How are roles defined?Must
I4Integration with back office, order entry and holdings sourcesWhich back-office systems have you integrated with? How is status sent to order entry?Must
I5APIs and data exportWhich data and events are available by API?Must
I6Integration with CRM and advisor desktopsCan alerts and summaries appear in the advisor's existing tools?Should
I7Availability, support and incident commitmentsWhat are your uptime commitment, support hours and incident notification terms?Must
I8Business continuity and exit planWhat happens to our records and monitoring if you are acquired or stop operating?Must
I9Subprocessors, including AI model providers, disclosedList your subprocessors and where they operate.Must
8
User Interface and Experience
Whether people will actually use it

A KYP system has at least four kinds of user: product analysts, committee members, advisors and supervisors. Each needs something different, and a system designed for one often frustrates the others. The best test is time: how long does it take each user to do their most common task?

RefRequirementAsk the VendorPriority
U1Role-based views for analysts, committees, advisors and supervisorsShow each role's home screen.Must
U2An advisor can clear their daily alerts in minutesTime an advisor clearing a typical day's alerts.Must
U3Any answer about a product traceable to source in one or two clicksStarting from an alert, how many clicks to the source document?Must
U4English and French interfacesIs the full interface available in French?Must, where required
U5Accessibility to a recognized standard, such as WCAG 2.1 AAWhich accessibility standard do you meet?Should
U6Usable on tablet and mobile for alerts and summariesShow alerts and summaries on a phone.Should
Part Three

Running the RFP

Requirements tell vendors what to answer. The process around them decides whether the answers can be trusted.

1
Buy, Configure or Build
What a vendor should supply, and what stays with the firm

No platform removes the firm's own work. The RFP should make clear what the firm expects the vendor to supply, and what the firm will configure or build itself.

ComponentVendor Should SupplyFirm Configures or Builds
Data and documentsCollection, reading and storage of documents and data; source linksAny proprietary or private product documents not publicly available
Monitoring rulesA starting rule library by product typeThresholds, severity and owners that match the firm's risk appetite
Assessment and approvalTemplates and workflowComplexity tiers, committee structure, approval authorities
Product registerThe register and status modelThe firm's shelf, conditions and status-to-order-entry connection
Advisor contentSummaries with sourcesFirm-specific guidance and training requirements
Policies and proceduresDetailed system documentationThe firm's written KYP policies, referencing the system
IntegrationsAPIs and standard connectorsConnections to the firm's back office, order entry and CRM
OversightValidation results and change noticesThe firm's own testing, supervision and vendor oversight
2
Scoring
An illustrative weighting

Any Must requirement a vendor can't meet should be scored as a gap the firm will have to fill, with its cost added to the vendor's price. The weights below are illustrative; firms should set their own before responses arrive, not after.

AreaIllustrative WeightWhy
Data and securities coverage25%Decides what the system can see at all
Workflow20%Where the firm's evidence is created
AI and explainability15%Decides whether outputs can be relied on and defended
Reporting and documentation15%Decides whether the firm can prove what it did
Advisors and supervision10%Carries knowledge to where recommendations are made
Infrastructure and security10%Must requirements here are usually pass or fail
User experience5%Tested directly in the proof of concept

Score cost separately, over at least three years, including the firm's own configuration, integration and ongoing oversight work, and the cost of filling any gaps.

3
Proof-of-Concept Scenarios
Six tests to run on the shortlist, using the firm's own products

Demonstrations on a vendor's chosen examples show what a system can do at its best. Scenarios on the firm's own products show what it will do in practice. Give each shortlisted vendor the same material and the same time.

Proof-of-Concept Scenarios
Illustrative
Coverage
Provide the firm's full shelf. The vendor returns a coverage map showing, for each product, what the system can monitor and from which sources.
Extraction
Provide ten documents with known answers, including a fund amendment, a structured note term sheet, a scanned document and a private fund offering memorandum. Score extraction accuracy and source accuracy.
Change
Provide pairs of old and new documents with changes the firm has already identified, including one buried in the risk factors. Score what the system catches, and whether it reports anything that didn't change.
Workflow
Take one product from request through assessment, approval and shelf listing; then raise an alert on it and take it through review, decision and advisor acknowledgement.
Evidence
Ask for the full product file and the program's state as at a past date, produced from the system without manual assembly.
Users
Have two advisors and one supervisor use the system unaided for their common tasks. Time them and record where they got stuck.
4
Red Flags
Answers that should prompt a closer look
If the Vendor SaysAsk
"We cover all asset classes"What do you monitor for each one, on our shelf specifically?
"Our AI reads every document"Show your accuracy by document type, and let us test it.
"You'll never miss a change"What happens when a source is unavailable? What is your missed-change rate on known changes?
"The approval workflow is configurable"Show us an approval with committee sign-off configured for our structure, today.
"Everything is audited"Show the program as at a date six months ago.
"It's on the roadmap"Score it as not available. Ask for the date in the contract if it matters.
"Our data provider handles that"Which provider, what is refreshed and how often, and who is accountable when it is wrong?
Part Four

Responsibilities

A firm can buy a system. It can't buy its way out of its KYP obligations. The selection itself should be run so that the firm can later show why the system it chose is fit for the job.

1
Firm and Advisor Roles
Who does what in the selection
What the Firm Needs to Do
  • Define the whole job first. Write requirements for all eight capabilities before talking to vendors.
  • Map its own shelf. Know every product type it offers, so coverage can be tested against reality.
  • Test on its own products. Run proof-of-concept scenarios with known answers.
  • Score gaps honestly. Count the cost of filling every Must requirement a vendor can't meet.
  • Involve every user group. Product, compliance, supervision, technology and advisors.
  • Contract for oversight. Validation results, change notices, testing access, data residency, retention and exit.
  • Keep the analysis its own. Use the system to support, not replace, the firm's documented assessment.
  • Record the decision. Keep the selection file: requirements, responses, scores, tests and rationale.
What the Individual Advisor Needs to Do
  • Take part in testing. Advisor time in the proof of concept is the best predictor of adoption.
  • Say what they need. Which product information they need, when and where.
  • Test the sources. Check that product summaries lead back to the documents behind them.
  • Remember the duty is theirs. A better system helps an advisor understand products; it doesn't do it for them.
2
Example Evaluation Process
How the firm runs the selection, as numbered clauses
Example: KYP System Selection Process
Illustrative
1
Steering group. A steering group of product, compliance, supervision, technology, procurement and advisor representatives owns the selection, chaired by the Chief Compliance Officer or delegate.
2
Requirements. Requirements covering data, AI, securities coverage, workflow, advisors and supervision, reporting, infrastructure and user experience are approved, with priorities, before the RFP is issued.
3
Weights. Scoring weights and the method for costing gaps are approved before responses are received.
4
Coverage. Each shortlisted vendor provides a coverage map against the firm's full product shelf.
5
Proof of concept. Each shortlisted vendor completes the same scenarios on the firm's own products, including documents with known answers, scored by the steering group.
6
Due diligence. Security, data residency, subprocessor, AI validation, financial and continuity due diligence is completed on the preferred vendor before contract.
7
Contract. The contract includes validation reporting, advance notice of model and data changes, testing access, record retention, data residency, service levels and exit provisions.
8
Record. The selection file, including requirements, responses, scores, proof-of-concept results, gaps and the rationale for the decision, is retained.
Five Questions Before Signing
  1. Does the chosen system, alone or with other tools, cover all eight capabilities, and who fills each gap?
  2. Did the proof of concept use the firm's own products and documents with known answers?
  3. Can every output the system produces be traced to its source?
  4. Can the firm show the state of its KYP program as at any past date?
  5. If the vendor disappeared, would the firm still have its records and know what it was monitoring?
A note on scope: This blueprint describes practical requirements for selecting a Know-Your-Product system, focused on the Canadian regulatory framework. It covers product-level due diligence, approval, monitoring and advisor product knowledge; client-level requirements are outside its scope. The platform types described are general categories, not descriptions of any particular vendor. It is general information, not legal, compliance or procurement advice. The requirements, priorities, weights, scenarios and process are illustrations, not prescribed requirements; firms should adapt them to their own business and obligations.
References
  1. National Instrument 31-103 Registration Requirements, Exemptions and Ongoing Registrant Obligations, s.13.2.1 (know your product); CIRO Investment Dealer and Partially Consolidated Rules, Rule 3301. Source document (PDF)
  2. CIRO. Investment Dealer and Partially Consolidated Rules, Rule 3302 (Know-Your-Product, registered individuals). Source document (PDF)
  3. Joint CSA/CIRO Staff Notice 31-368, Client Focused Reforms: Review of Registrants' Know Your Client, Know Your Product and Suitability Determination Practices and Additional Guidance, December 10, 2025. Third-party reports and the firm's own analysis, p.11; approval and algorithmic models, pp.15-16; monitoring, p.18; policies describing automated systems, p.34. Source document (PDF)
  4. Canadian Securities Administrators. CSA Staff Notice and Consultation 11-348, Applicability of Canadian Securities Laws and the use of Artificial Intelligence Systems in Capital Markets, December 5, 2024. Source document (PDF)
  5. Office of the Superintendent of Financial Institutions. Guideline E-23 - Model Risk Management (2027), published September 11, 2025, effective May 1, 2027. Source document