Since CIRO formed in 2023 from the merger of IIROC and MFDA, the regulatory environment for Canadian wealth firms has changed in a specific, measurable way: more audits, more complaints, and bigger sanctions, year over year. Complaints to CIRO reached 4,127 in FY2025 - up 21% year-over-year - and total sanctions climbed to $16.3 million in FY2026, a 58% increase in a single year. Suitability and Know Your Product (KYP) failures have been the top enforcement category for five years running, and the December 2025 Joint CSA/CIRO Staff Notice 31-368 - a review of 105 firms - made the pattern explicit: the same handful of KYP gaps, repeated across the industry.
What regulators are actually looking for comes down to two things: a defined process, and proof it was followed - a consistent process for reviewing a security before it reaches the shelf, documentation of that process itself, and documentation of the outcome every time it runs. Three of the six enforcement categories CIRO, IIROC, and MFDA report on - unsuitable investments, supervisory deficiencies, and documentation gaps - now trace back to that same undocumented-process root cause, and the consequences extend well past the fine itself: suspensions, permanent bars, mandatory independent consultants, and a public record on CIRO's AdvisorReport that follows a firm or advisor indefinitely.
The cost of staying manual isn't only regulatory. An advisor working through a typical annual load of 400 securities, at roughly $176 an hour, loses approximately $70,000 a year in capacity to manual due diligence alone - and for a 500-advisor firm, that is $35 million a year, before accounting for the shelf-monitoring and supervision teams needed to run the process at all. A single system that runs that entire workflow - shelf approval, monitoring, documentation, alerts, and advisor-level suitability - can do it at a fraction of that cost.
This page reviews the enforcement environment wealth firms now operate in, organized the way the underlying data breaks down: the change in regulators and what's driving it, what regulators actually look for, where enforcement is concentrated, and what staying manual actually costs, in both regulatory exposure and lost advisor capacity.
What CIRO is actually doing, why it has changed since 2021, and what that means in practice for advisor productivity, technology spend, compliance spend, and complaint exposure at the firm level.
The regulator itself is not the one wealth firms grew up with. Since CIRO formed in 2023, firms have faced more audits, at an increasing cadence; more complaints reaching the regulator; and bigger sanctions on the cases that get pursued. None of this is a perception problem or a headline effect - it shows up directly in CIRO's own published numbers, year over year.
| Fiscal Year | Complaints Received | Proceedings Concluded | Avg. Sanction / Case |
|---|---|---|---|
| FY2021 | 1,049 | ~25 | ~$168,000 |
| FY2022 | 1,540 | 37 | ~$408,000 |
| FY2023 | 4,104 | 108 | ~$233,000 |
| FY2024 | 3,408 | 75 | ~$188,000 |
| FY2025 | 4,127 | 57 | ~$180,000 |
| FY2026 | 6,692 | 48* | ~$340,000 |
Source: CIRO enforcement reports, FY2021-FY2026 (fiscal years run April-March; FY2026 covers April 2025-March 2026, CIRO's most recently published data as of this writing). *FY2026 figure is decisions rendered against individuals and firms combined (39 + 9); CIRO's FY2026 report presents this metric separately from the "proceedings concluded" figure used in earlier years. All figures CAD.
Complaint volume is roughly 6x higher than FY2021. Total sanctions climbed to $16.3 million in FY2026, up from $10.3 million in FY2025 - a 58% increase in a single year. The sharpest move is at the firm level: sanctions against firms (as opposed to individual advisors) nearly tripled, from $3.1 million to $8.7 million, while the number of firm-level decisions rose from 7 to 9. CIRO is running a risk-based model - fewer, larger cases, concentrated increasingly on firms rather than individuals, with greater deterrent value. Every firm that ends up in one pays more, defends harder, and carries the disclosure permanently.
Three structural changes to the Canadian regulatory environment explain the shift - not a single new rule, but a new regulator, a higher bar, and better detection.
CIRO was formed January 1, 2023, consolidating IIROC and MFDA into a single national self-regulatory organization with one harmonized rulebook. Investment dealers and mutual fund dealers - previously examined under two separate regimes with different standards - are now overseen by one body applying one bar. The CSA reinforced this consolidation by delegating the registration function itself to CIRO - investment dealers, mutual fund dealers, and (by jurisdiction) futures commission merchants and derivatives dealers are now all registered through the same body that examines and enforces against them. A unified examiner population with a single rulebook means fewer gaps between regimes for a firm's practices to fall through, and a broader, more consistent base of firms coming under review each cycle.
The Client Focused Reforms took effect December 31, 2021, raising the substantive bar on KYC, KYP, and suitability - creating far more documentation surface for a complaint or an examiner to test against. Separately, CIRO's February 2025 migration to its unified ComSet reporting platform began capturing service-related events and complaint categories the old, separate IIROC and MFDA systems did not track. CIRO itself attributed most of the jump to 6,692 complaints in FY2026 to this system change, clarifying that the additional volume "did not raise regulatory concerns or increase the number of enforcement cases opened." The bar didn't just rise - the ability to see over it improved.
CIRO has been explicit that its enforcement strategy targets cases with "significant deterrent impact." Its 2025-2026 enforcement report also cites a new E-Discovery and Evidence team and a migrated case management system as capacity built specifically to support stronger, better-documented cases. The result shows up directly in the sanction data: total sanctions rose 58% in a single year, and firm-level sanctions - the category that hits supervisory and compliance failures hardest - nearly tripled.
The same change shows up one level up, across the Canadian Securities Administrators (CSA) - the council of provincial and territorial commissions that oversees CIRO and the broader capital markets. In fiscal 2025-2026, CSA members commenced 129 enforcement proceedings and concluded 108, ordered $20.7 million in fines and administrative penalties plus a further $59.4 million in restitution, compensation, and disgorgement, and issued 763 investor alerts and warnings - more than 85% of them related to crypto assets. CSA members also disrupted more than 11,700 fraudulent investment platforms and scam websites targeting Canadians. This isn't one regulator having a busy year. It's the whole system - the SRO that examines dealers and the commissions that oversee it - raising the bar at the same time.
None of this stays theoretical for long. A harmonized, better-instrumented regulator translates into four concrete costs for wealth firms still running investment due diligence, KYP, and suitability by hand.
Industry benchmarking of advice firms puts compliance-related work at roughly 13 hours a week per advisor on average - close to two months of the working year - with firms reporting they spend over 60% of their time on business and compliance activities rather than client-facing work. Every hour spent assembling a manual KYP file or reconstructing a suitability rationale after the fact is an hour not spent managing client relationships or growing the book.
Compliance technology has moved from optional to load-bearing. Firms report direct and indirect compliance costs now running around 20% of annual revenue, an increase on the prior year, driven in large part by the tooling and headcount needed to keep pace with documentation standards. Firms that have automated the audit-heavy parts of the workflow report meaningfully lower compliance overhead than those still running it manually.
Beyond technology, firms are carrying higher direct regulatory costs: legal defense for a contested CIRO hearing, outside consultants engaged to remediate a supervisory finding, and the ongoing overhead of a close-supervision condition once one is imposed - all set out in full in Part Four. None of this was a meaningful line item for most firms five years ago. With CIRO pursuing fewer but larger cases, the firms that do get examined are absorbing materially higher costs when a gap is found.
A single, harmonized examiner population and a reporting system that captures more means a larger share of firms will touch at least one complaint or examination each cycle than under the old, split IIROC/MFDA regime. Every proceeding that concludes is published permanently on CIRO's AdvisorReport, tied to both the firm and the registered individual - a disclosure that follows the firm regardless of the outcome, and one prospective clients and recruits can see.
A new, harmonized regulator, a higher documentation bar, and better detection infrastructure are combining to produce more audits, more complaints, and bigger sanctions - and CIRO is not acting alone, with the CSA raising its own bar in parallel. For the individual advisor, that shift shows up as time: roughly two months of the working year now going to compliance rather than clients, spent reconstructing by hand what a documented process should already prove. For the firm, it shows up as money and exposure: compliance technology and headcount now running near a fifth of revenue, real legal and remediation costs on the table the moment an examiner finds a gap, and a growing likelihood that any given cycle will touch at least one complaint or review - each one a permanent, public record once it concludes. The firms absorbing this best are the ones that have already turned the process itself into the record, rather than trying to reconstruct one after the fact.
Strip away the rule numbers and Know Your Product comes down to two things: a defined process, and proof you followed it. What CIRO's own rules require at each stage of the KYP lifecycle, and what the December 2025 CSA/CIRO review found firms still getting wrong.
KYP obligations sit in CIRO's Investment Dealer and Partially Consolidated (IDPC) Rules 3300 through 3303 - Rule 2.2.5 for mutual fund dealers - and feed directly into the suitability determination requirement in Rule 3400: a recommendation cannot be suitable if the firm and advisor behind it never took reasonable steps to understand what they were recommending in the first place.[6] On December 10, 2025, the CSA and CIRO published Joint Staff Notice 31-368 - the first formal accounting of how firms have actually implemented these requirements since the Client Focused Reforms took effect.[5] Staff reviewed KYC, KYP, and suitability practices across 105 registered firms spanning nearly every registration category, and the KYP findings were the most consistent of the three - the same gaps, in roughly the same shape, regardless of firm size or business model.[8]
An examiner is not scoring investment judgment. They are scoring whether the firm can demonstrate a repeatable process, carried out the same way for every security, with a record a third party can reconstruct. Anything that is not written down, time-stamped, and retained is - for the examiner - not part of the record.
Rule 3301 requires a documented product due diligence (PDD) process before a security ever reaches a shelf, applied consistently across everything the firm offers rather than assessed ad hoc as products come up. Staff's guidance sets out what that assessment has to cover for every security: its structure, features, risks, and initial and ongoing costs - with the depth of review scaling to complexity. A streamlined review may suit a plain-vanilla mutual fund; a leveraged, illiquid, or novel structure warrants a full committee-level review before it is approved.[7] Firms may reasonably group similar, non-complex securities into a single assessment, and may use centralized product committees or automated systems to help carry it out - but Staff was explicit that doing so does not relax the obligation: "the process followed should be set out in detail," and the individuals responsible for carrying out and supervising each step must be clearly identified.[5]
Getting onto the shelf is the beginning of the obligation, not the end of it. Rule 3301(1)(iii) and (2) require ongoing monitoring of every approved security for significant changes - to structure, risk profile, fees, liquidity, or issuer condition - for as long as it stays available to clients. This is where Staff found the widest gap between what firms believed they were doing and what they could actually demonstrate: "many firms did not have an adequate monitoring process in place as they did not define what constitutes a significant change in a security," and where a cadence existed at all, "annual monitoring alone was not found to be sufficient" for riskier, illiquid, or more complex products.[5]
The process does not end at the shelf either. Rule 3302 imposes a separate, individual obligation on every advisor: before purchasing, selling, or recommending a security, the advisor must independently take reasonable steps to understand it - its structure, features, risks, and the impact of its costs - sufficient to support a suitability determination under Rule 3400. A firm-level assessment does not discharge this on the advisor's behalf, and it extends past the firm's own shelf: securities transferred in from another dealer, or acquired through a client-directed trade, fall under the same KYP obligation and must be assessed within a reasonable time of the transfer or trade, not waved through because the position is small or infrequent.[6]
Every stage above has to exist on paper before it exists in practice. Staff's guidance is specific about what a firm's written policies and procedures need to state, not just imply: which parts of the KYP process the firm carries out and which fall to registered individuals; how each asset class will be assessed given its structure, complexity, and risk; how the firm treats model portfolios; and - critically, given how often this was missing - a firm-specific description of what counts as a significant KYP change for the securities it offers, and the frequency at which monitoring for that change actually happens.[5] A policy that says the firm "monitors for material changes" without defining the trigger or the cadence is not, in Staff's own findings, a process a firm can demonstrate it followed.
The same standard applies to the advisor side of the process. Policies need to set out how the firm ensures every registered individual actually understands the securities made available to them before they recommend one - through direct access to the firm's underlying KYP work, training, or both - and, separately, how the firm notifies advisors when a significant change occurs to something they've already recommended. Firms that rely on transferred-in positions or client-directed trades still need a written process for those too: Staff found firms that had simply excluded them from KYP altogether, citing small size or infrequency as if that were itself a documented threshold rather than an undocumented exception.[5]
None of this requires a heavier process than a firm's shelf can support. Staff acknowledged that grouping similar securities and using centralized committees or automated tools is a reasonable way to run PDD and KYP at scale - the requirement is that the process itself, however it is built, is written down clearly enough that someone outside the room who ran it could reconstruct what happened and why.[7]
A written process only closes the gap if it produces a record every time it runs. For shelf approval, that means a retained assessment showing the key elements that were actually considered and why the security was approved - not a label. Staff's own language on this point is unambiguous:
Acceptable evidence, in Staff's own examples, is concrete: sign-off recorded directly on the due diligence memo or KYP assessment that evidences the review; detailed committee minutes documenting what was discussed; or an email record that sets out the required information alongside the approval confirmation itself.[5] The same standard carries through monitoring: a firm needs retained evidence that the review actually happened on schedule - not just that the information was available to review - and, when a significant change is identified, a documented reassessment of that change, an updated conclusion, and a record that the firm notified every advisor who had already recommended the security. Firms that periodically update their due diligence memos and retain every prior version, rather than overwriting them, were among the practices Staff pointed to as sufficient.[5]
The same principle closes the loop back to the advisor. Documentation that the individual understood what they recommended - not just that the firm's centralized assessment existed somewhere - is what Staff found most often missing, and it's the same gap that shows up in transferred-in and client-directed positions: an assessment performed but never written down is, for an examiner, indistinguishable from an assessment never performed at all.[9]
Firms and advisors without a process - or without the documentation to prove the process was actually carried out - are the ones who will be liable for regulatory sanction going forward. The exposure is not making a bad call on a security. It is having no record that KYP, ongoing monitoring, and diligence ever took place at all.
Six enforcement categories, five years of reports, and one thread running through half of them: a process that existed on paper but couldn't be proven to have run.
The table below tracks every major enforcement category IIROC, MFDA, and CIRO have reported on since FY2021, what a firm or advisor typically pays when a case lands in that category, what the actual exposure looks like beyond the fine itself, and how each category has moved since the Client Focused Reforms took effect. Categories tagged KYP / Suitability are the ones where unsuitable-investment and Know Your Product findings are the primary or growing driver of the sanction - tracking them separately is what makes the shift visible.[3]
| Enforcement Category | Typical Sanction | Actual Risk to the Firm | Trend, 2021 → 2026 |
|---|---|---|---|
| Unsuitable investments / KYP failuresKYP / Suitability | $50K - $500K+ (individuals); firm-level exposure rising | The single most-cited violation at the individual level in every year of data. Since Notice 31-368, it's also the category regulators now expect a firm to disprove proactively, not just defend if asked. | Rising every cycle. A generic KYC/suitability line item pre-2021 became a named CFR obligation in 2021, a rulebook-wide theme under CIRO from 2023, and the most consistently deficient finding across the 105-firm Notice 31-368 review in December 2025.[5] |
| Supervisory deficienciesKYP / Suitability | $125K - $2M+ (firms); firm-level sanctions nearly tripled FY25→FY26[10] | The firm had a policy but no evidence anyone checked it was followed. Increasingly, this is where an undocumented KYP monitoring gap actually gets sanctioned - at the firm, not the advisor. | Steady presence as a top-3 category since FY2021; CIRO's own FY2026 report names supervision "the most common firm-level regulatory violation," appearing in six of the year's concluded proceedings.[10] |
| Documentation / record-keepingKYP / Suitability | $20K - $150K+, but rarely stands alone - usually attached to a suitability or supervisory finding | Due diligence records incomplete, undated, or missing when examiners arrive. Notice 31-368's single most repeated deficiency: an assessment that may well have happened, but can't be proven. | Present in every enforcement cycle since 2021, but the bar keeps rising - a broader documentation standard under the CFRs, followed by a Notice that turned "keep better records" into a formally published, citable finding.[5] |
| Gatekeeper / red-flag response | Not yet broken out separately - currently folded into supervisory sanctions | Firm or advisor saw a warning sign (unusual trading, a vulnerable client, a conflict) and didn't act on it before harm occurred, rather than after. | New as a named priority. CIRO's FY2026 report is the first to call out gatekeeper failures as a distinct enforcement focus - the category to watch through the next reporting cycle.[10] |
| Individual misconduct | Highly variable; the largest individual fines and nearly all disgorgement sit here - $950K in one FY2022 misappropriation case | Outside business activities, undisclosed conflicts, misappropriation of client funds. Lower frequency than KYP-linked categories, but the highest per-case dollar exposure. | Stable in frequency, but disgorgement penalties specifically jumped nearly sevenfold in FY2026 (to $4.3M, from $624K in FY2025) under CIRO's new Disgorgement Distribution Program - a structural change, not just a bigger number.[10] |
| Market integrity / trading violations | Often resolved by referral rather than a direct CIRO sanction | Lower direct sanction exposure for the dealer, but real reputational and regulatory-referral risk once a pattern is flagged. | Relatively stable share of total enforcement activity across the period - 59 market-related cases referred to the CSA in FY2024 alone, including 23 manipulation and 17 insider-trading matters - but flat rather than rising, unlike the KYP-linked cluster above.[3] |
Three of the six categories above are tagged KYP / Suitability for a reason: unsuitable investments, supervisory deficiencies, and documentation gaps all trace back to the same root cause Notice 31-368 named explicitly - a process that existed on paper but couldn't be proven to have run. The other three - gatekeeper response, individual misconduct, and market integrity - are enforcement themes in their own right, not symptoms of an undocumented KYP process, and their trend lines are comparatively flat. KYP has gone from one line item among several in FY2021 to the connective tissue running through roughly half of what CIRO panels are actually sanctioning by FY2026.
The largest fines grab headlines but are rare. The common exposure sits in the $50,000 - $300,000 mid-range, for suitability, KYP, and supervisory gaps - the three categories above that keep pointing back to the same undocumented process. Those are exactly the categories a documented, monitored process is designed to prevent.
KYC has been the enforcement baseline for two decades - did the firm know its client, did the recommendation fit their profile. What Notice 31-368 makes explicit is a second, parallel front: whether the firm understood, approved, and kept monitoring the product it was recommending in the first place. Staff's own findings trace nearly every KYP deficiency back to a handful of repeated gaps - no independent firm-level review of related-issuer or model-portfolio securities, an "approved" label with no rationale behind it, monitoring that never defined what a significant change actually was, and advisors recommending products with no evidence they understood what they were recommending.[5] That is where the pressure is being dialled up, and it lands on both the firm and the individual advisor - in ways that go well past the dollar figure on the sanction itself.
The fine is rarely the largest number on the bill. A CIRO hearing panel can order a fine of up to the greater of $5 million per contravention or three times the profit made or loss avoided, and separately order disgorgement of the amount obtained or the loss avoided as a result of the contravention - a return of gains, on top of the fine, not instead of it.[11] For the firm, that stacks with the costs of the investigation and hearing itself, legal defense, any independent consultant a panel requires the firm to retain, and the ongoing cost of whatever heightened supervision gets imposed as a condition of staying registered - all before accounting for the AUM and client attrition that typically follows a public finding.[1] For the advisor, the exposure is personal and immediate: an individual fine, disgorgement of their own compensation tied to the finding, and in many cases responsibility for a share of the hearing costs - paid from personal assets, not the firm's.
The sanctions that don't show up as a dollar figure are often the ones that do the most damage to how a firm operates. CIRO's Sanction Guidelines give hearing panels a wide toolkit beyond a fine: suspension of a Dealer Member or an individual "for any period of time and on any terms and conditions," permanent termination or bar from the securities industry in the more severe cases, and - specific to supervisory failures - suspension of an individual from acting in any supervisory capacity, or from all registered activities entirely where the failing is serious enough.[11] Short of a suspension, panels routinely impose remedial terms that follow a firm for years: submission of new procedures for improved compliance, mandatory retention of a qualified independent consultant, heightened supervision of specific individuals, branches, or departments, restrictions on the activities or products a firm or advisor can offer, and - for the individual - mandatory professional re-qualification by re-sitting a proficiency exam before they can resume registered activity.[11] For a firm already running a manual KYP process, a term of conditions requiring demonstrable, ongoing monitoring is exactly the obligation it couldn't prove it was meeting in the first place.
Every concluded proceeding becomes a permanent public record. For the firm, that means a disclosed enforcement history that surfaces in institutional due diligence, RFPs, and prospective-advisor recruiting conversations indefinitely - there is no expiry on a CIRO decision. For the advisor, it's more direct still: outcomes are published on CIRO's AdvisorReport, tied to their name and licence, visible to any client, any recruiter, and any dealer considering their next registration - a disclosure that follows the individual firm to firm, not just for the duration of any suspension but for as long as the record exists.[9] A firm that has been through a KYP-related finding also tends to inherit a longer shadow with its own regulator: routine exams get closer scrutiny, timelines to close findings shrink, and the benefit of the doubt on the next borderline call is largely gone.
The cost of staying manual isn't only regulatory. Manual monitoring, a disjointed alert process, and time-consuming advisor workflows quietly consume some of the firm's most valuable time - long before a regulator ever gets involved.
Part One put a number on the compliance burden generally: roughly 13 hours a week, or close to two months a year, per advisor. A large share of that time is this specific workflow - pulling data, assembling comparables, and documenting the review every time a security triggers an alert or comes up for periodic reassessment. At the head-office level, the same workflow scales into a standing resource requirement: a firm monitoring thousands of securities across its shelf needs staff dedicated to running that process continuously, on top of whatever it also costs every advisor individually, every year.
Put real numbers against that burden and the practice-management cost becomes concrete - what a manual, alert-driven due diligence process actually takes out of an advisor's working year, and what that time is worth.
| Cost Component | Per Advisor (Annual) | Firm-Wide (500 Advisors) |
|---|---|---|
| Lost advisor capacity - 50 days / 400 hours of manual review, at $176/hour | $70,588 | $35,294,000 |
An advisor working through a typical annual load of 400 securities, at roughly $176 an hour, loses approximately $70,000 a year in revenue-generating capacity to this process alone.[2] Across a 500-advisor firm, that is $35 million a year in lost revenue opportunity - and it's a floor, not a ceiling. It does not include the cost of the team that has to monitor the product shelf, or the supervision team that has to confirm 500 different advisors are actually following the process. Add those in, and the real number is materially higher.
The fix isn't more headcount split across a shelf-monitoring desk and a supervision team chasing down whether 500 advisors actually followed the process. It's a single system that runs the entire workflow, end to end:
That is the actual impact of the requirement to do this properly: a bare-minimum cost of over $70,000 a year per advisor to run the process manually, before the shelf-monitoring and supervision teams are counted.