OTC Link LLC recently agreed to pay $575,000 to settle SEC allegations that it failed to establish and enforce adequate compliance policies for its OTC stock trading platform. This settlement not only represents a financial hit but also highlights a pattern of control failures that any trading platform, broker-dealer, or financial services firm should examine closely.
Here's what happened, which controls collapsed, and what you need to fix before your regulator comes knocking.
What Happened
The SEC alleged that OTC Link LLC repeatedly failed to create and enforce compliance policies and procedures for one of its trading platforms handling over-the-counter stocks. The company agreed to pay $575,000 to settle the matter without admitting or denying the findings.
The core issue: inadequate compliance infrastructure. This wasn't a one-time lapse or a technical glitch. It was a systemic failure to build and maintain the policies and procedures required by federal securities law.
Timeline
The SEC order doesn't provide a detailed timeline, but the term "repeatedly" indicates this wasn't an isolated incident. The failures occurred over a period long enough for the SEC to see them as a pattern, not an exception.
For compliance officers, that's crucial. A single missed control might draw a warning letter. Repeated failures to establish foundational policies? That's when settlement discussions start with a dollar sign and six figures.
Which Controls Failed or Were Missing
The SEC's language points to failures at the governance and oversight level, the controls above day-to-day transaction monitoring. Here's where OTC Link's program broke down:
Policy development and documentation. The firm didn't create adequate compliance policies. This isn't about needing updates; it's about lacking documented, board-approved policies entirely. Without written policies, you can't train staff, audit adherence, or show regulators what compliance looks like.
Policy enforcement mechanisms. Even if policies existed, the firm failed to enforce them. Enforcement requires monitoring controls, escalation procedures, and consequences for non-compliance. If your policy states trades must meet certain criteria but lacks automated checks or manual reviews, you don't have enforcement, you have a Word document.
Supervisory oversight. Broker-dealers must operate under a supervisory framework requiring designated supervisors to review and approve certain activities. The allegations suggest OTC Link's supervisory controls either didn't exist or weren't functioning. This means trades, customer interactions, or platform activities may have proceeded without the required oversight.
Compliance program governance. Someone must own the compliance program, typically a Chief Compliance Officer or designated compliance officer. The SEC's action implies that governance role either wasn't clearly assigned, wasn't adequately resourced, or wasn't empowered to enforce the necessary policies.
What the Relevant Standard Requires
Broker-dealers operate under SEC Rule 15c3-1 (net capital requirements), Rule 15c3-3 (customer protection), and Exchange Act Rule 15b4-1, which requires firms to establish, maintain, and enforce written policies and procedures reasonably designed to prevent violations of federal securities laws.
The rule requires:
- Written policies addressing the firm's specific business model and risks
- Procedures translating those policies into repeatable, auditable actions
- Enforcement mechanisms ensuring staff follow the procedures
- Periodic review to confirm policies remain effective as the business evolves
FINRA Rule 3110 adds supervisory requirements: firms must establish a supervisory system, including written procedures, to supervise associated persons' activities. This means you need named supervisors, defined review frequencies, and documentation of supervisory actions.
If you're running a trading platform, Alternative Trading System regulations under Regulation ATS (SEC Rule 300) impose additional obligations around fair access, system capacity, and operational integrity. While the SEC order doesn't specify ATS violations, any platform handling OTC securities needs policies that address these requirements.
The NIST Cybersecurity Framework (CSF) 2.0 Govern function also applies here, even though it's not a regulatory mandate for broker-dealers. GV.PO-01 calls for organizational cybersecurity and privacy policies that are established, communicated, and enforced. GV.OV-01 requires cybersecurity supply chain risk management policies, relevant if your trading platform relies on third-party technology providers.
Lessons and Action Items for Your Team
If you're a compliance officer at a broker-dealer, trading platform, or any regulated financial services firm, here's what to do this quarter:
Audit your policy inventory. Pull every compliance policy you're supposed to have under your regulatory framework. Match each one to the specific rule or regulation it addresses. If you can't find a policy for a required area, that's a control gap you need to close before your next exam.
Test enforcement, not just existence. Pick three policies at random. Pull transaction records, emails, or system logs from the last 90 days. Can you prove the policy was followed? If your policy says supervisors must review certain trades within 24 hours, can you show timestamped evidence of those reviews? If not, you have an enforcement problem.
Define supervisory roles in writing. Create a supervisory chart that maps every business activity to a named supervisor. Include review frequencies, escalation paths, and documentation requirements. Make sure those supervisors have been trained and have access to the systems they need to perform their reviews.
Resource your compliance function properly. If your compliance officer is also handling operations, customer service, or technology projects, you're setting up the same failure pattern the SEC just penalized. Compliance needs dedicated time, budget, and authority to say no.
Schedule quarterly policy reviews. Business models change. New products launch. Staff turnover happens. Set a recurring calendar event to review whether your policies still match your actual operations. If you've added a new trading feature but haven't updated your supervisory procedures, you've created a gap.
Document everything. When regulators investigate, they don't want to hear about your good intentions, they want to see evidence. Every policy review, every supervisory action, every compliance meeting should generate a record with a date, attendees, and outcomes.
The $575,000 settlement OTC Link just paid buys you a case study in what not to do. Use it.





