The first four guides describe a KYP program: the shelf, rules and alerts, product reviews, and the advisor's due diligence. Each one produces records. Supervision is what turns those records into assurance that the program is actually working, and into evidence the firm can show a regulator.
Both Canadian and US rules expect firms to supervise, not just to have policies. Canadian registrants must maintain a compliance system that provides reasonable assurance the firm and its individuals comply with securities law.[2] FINRA members must maintain a supervisory system reasonably designed to achieve compliance,[3] and SEC-registered advisers must review their compliance policies at least annually for adequacy and effectiveness.[4] For KYP specifically, Canadian regulators have said that annual monitoring alone "was not found to be sufficient",[1] which makes the ongoing evidence matter as much as the yearly review.
This guide sets out how to supervise a KYP program, how to measure it, and how to keep the file that proves it. It covers what supervision watches and how often, reviewing advisor attestations and product notes, escalation, a set of program metrics with an example report, the contents of a KYP exam file, and a trace test that shows whether the pieces connect.
It is the last of five guides in the Product series, following Product Approval, Material Change, From Alert to Decision and Advisor Due Diligence. Client-level supervision is outside its scope.
Supervising a KYP program means checking that each step happened, on time, and to the standard the firm set. It is not a second product review.
Supervise the process, not the product. The product committee decides whether a product stays on the shelf. Supervision checks that the committee's process was followed and recorded. Keeping the two separate is what makes supervision independent.
Include the automation. Where monitoring rules or scoring models run automatically, Canadian regulators expect the firm's policies to describe those systems in detail and have noted the need for evidence of ongoing oversight.[1] Supervision should check that rules ran, that changes to rules were approved, and that "could not evaluate" results were followed up. Auditing KYP Monitoring Data covers the data side in depth.
| Cadence | Who | What Is Checked |
|---|---|---|
| Daily | Supervision desk | Critical alerts opened on time; purchases in suspended or wind-down products; failed monitoring runs |
| Weekly | Supervision desk | Overdue reviews and decisions; decisions not yet communicated; overdue advisor acknowledgements |
| Monthly | Compliance | Program metrics against thresholds; exception aging; unresolved "could not evaluate" results; rule changes made in the month |
| Quarterly | Compliance, reporting to senior management | Program report; trends; a sample of review records tested for meaningful consideration |
| Annually | Branch managers and compliance | Review of every advisor attestation with a sample of product notes; trace tests; annual review of the program's adequacy and effectiveness |
The daily and weekly checks catch individual failures while they can still be fixed. The monthly and quarterly checks show whether the failures are isolated or a pattern. The annual review asks whether the design itself still works.
An advisor's annual attestation says they understand every product in their book. The supervisor's job is to test whether the evidence supports it. A signature on its own shows only that the form was completed.
Select a sample of the advisor's product notes, weighted towards risk. An illustrative approach:
| Sample From | Illustrative Size |
|---|---|
| Complex products in the book | At least one, or all if there are two or fewer |
| Products with a Critical or Important alert in the year | At least one |
| Products with the most accounts | At least one |
| Advisors with prior findings, or unusually few "not able to attest" responses for a complex book | Double the standard sample |
| Outcome | When | Next Step |
|---|---|---|
| Accepted | Complete, and sampled notes meet the test | None |
| Accepted with follow-up | Minor gaps, such as a missing source date | Advisor corrects within 30 days |
| Returned | Incomplete, or one or more sampled notes fail the test | Advisor refreshes the failed notes and re-attests; supervisor re-samples |
A worked attestation example is in the fourth guide. The supervisor's record should name the notes sampled, the result for each, and the outcome.
| Item | First Escalation | Second Escalation |
|---|---|---|
| Critical review not decided on time | Product committee chair, next business day | Chief compliance officer, after 5 further business days |
| Purchase in a suspended or wind-down product | Advisor's supervisor, same day | Compliance, if repeated within 12 months |
| Advisor acknowledgement overdue | Advisor's supervisor, day 14 | Compliance, day 30 |
| Attestation returned twice, or not submitted | Branch manager | Compliance; restriction from complex products until resolved |
| Product with no successful monitoring check for 5 business days | Product owner and data owner | Product committee; consider suspension if not resolved |
The thresholds are illustrative. What matters is that they are written down, applied automatically where possible, and that each escalation is recorded along with what happened next.
A small set of metrics, tracked over time, tells senior management whether the program is working and tells supervision where to look.
| Group | Metric | What It Shows | Illustrative Threshold |
|---|---|---|---|
| Coverage | Holdings match rate (share of client assets mapped to the register) | Whether the program covers what clients actually hold | 99% or more |
| Coverage | Monitoring coverage (approved products with a successful check in the last 5 business days) | Whether approved products are actually being watched | 100% |
| Coverage | Unresolved "could not evaluate" results over 5 days | Data gaps hiding changes | 0 |
| Timeliness | Critical reviews decided within target | Whether the review process keeps pace | 95% or more |
| Timeliness | Decisions communicated within 1 business day | Whether decisions reach advisors | 95% or more |
| Advisors | Acknowledgements completed within 10 business days | Whether advisors keep up with decisions | 90% or more |
| Advisors | Products in books with a product note under 12 months old | Whether advisor understanding is recorded and current | 90% or more |
| Advisors | Attestations accepted first time | Quality of advisor attestations | 85% or more |
| Control | Purchases in suspended or wind-down products | Whether status controls hold | 0 |
| Control | Holdings exceptions over 90 days | Whether exceptions are being resolved | Falling month on month |
| Noise | Alerts per advisor per week | Whether the alert load is realistic | Tracked; firm sets its own range |
Watch for metrics that are too good. Zero "not able to attest" responses across hundreds of advisors, or every review decided in exactly the target time, usually means the process has become a checkbox. A healthy program shows some friction.
Pair speed with quality. Time-to-decision is easy to improve by writing thinner rationales. Sampling review records for meaningful consideration each quarter keeps the timeliness metrics honest.
An illustrative quarterly report for a hypothetical firm:
| Metric | This Quarter | Last Quarter | Threshold | Status |
|---|---|---|---|---|
| Holdings match rate | 99.4% | 98.7% | 99% | Met |
| Monitoring coverage | 99.2% | 99.6% | 100% | Below |
| Critical reviews decided within target | 92% | 97% | 95% | Below |
| Decisions communicated within 1 day | 98% | 96% | 95% | Met |
| Acknowledgements within 10 days | 88% | 84% | 90% | Below |
| Purchases in suspended products | 2 | 0 | 0 | Breach |
| Holdings exceptions over 90 days | 14 | 21 | Falling | Met |
Every metric below threshold needs a short explanation and an action. In this example: monitoring coverage fell because a data feed for four private funds failed for six days (fixed, with a backup source added); Critical review timeliness fell during a week with eleven Critical alerts from one market event (committee now meets on demand for clusters); the two purchases were entered by one advisor before an order entry block was applied to a newly suspended product (block now applied at the moment of suspension). The report is only useful if the actions are followed up in the next one.
When a regulator asks how the firm meets its KYP obligations, the answer should be a file the firm already keeps, not one it builds in the weeks before an exam.
In the KYP HubWhat the KYP file must show: KYP Documentation: What Your File Must Show. Testing the data behind it: Auditing KYP Monitoring Data.
| Section | Contents | Kept Current By |
|---|---|---|
| 1. Policies | KYP policies and procedures, including a detailed description of automated monitoring and scoring, the rule catalogue, severity matrix and escalation ladder | Compliance, on each change and at annual review |
| 2. Governance | Product committee terms of reference, membership, minutes; approved rule changes | Committee secretary |
| 3. The shelf | Register extract at any date requested: every product, status, tier, conditions, owner | Generated from the register |
| 4. Product files | For each product: approval record, current assessment, reviews, decisions and notices | Product team, linked in the register |
| 5. Monitoring evidence | Run logs, alerts raised, triage results, "could not evaluate" results and how they were resolved | Generated from the monitoring system |
| 6. Advisor evidence | Acknowledgements, product notes, training completion, annual attestations | Generated from advisor records |
| 7. Supervision | Daily and weekly exception reports and follow-up, escalations, attestation reviews with notes sampled | Supervision |
| 8. Program reporting | Quarterly program reports, actions and follow-up; the annual review of adequacy and effectiveness | Compliance |
Generate, don't assemble. Sections 3, 5 and 6 should come straight out of the systems that run the program. If building them requires someone to collect spreadsheets and emails, that is a finding waiting to happen: the records exist only because someone went looking for them.
Answer for any date. Regulators often ask what the firm knew and did at a particular point. The register, product files and advisor records should all be able to show their state as at a given date, not just today. KYP Documentation: What Your File Must Show covers record-keeping in more detail.
A file can be complete section by section and still not connect. The trace test picks a product and follows it through every stage, checking that each record leads to the next. It is how an examiner is likely to test the program, so it is worth doing first.
An illustrative trace result, using the hypothetical fund from the From Alert to Decision guide:
A good trace test usually finds something. The point is to find it first, fix it, and show the fix in the file.
Supervision is mostly the firm's job. The advisor's part is to leave a record that can be supervised, and to respond when it is questioned.