How to Master Your FINRA Fall Inspection

How to Master Your FINRA Fall Inspection

MCG Consulting • Compliance Insights

How to Master Your FINRA Fall Inspection: Communications, Records & Reg BI

Three areas carry outsized weight in almost every branch exam. This post explains what a thorough year-end review of each should look like.

Our previous post walked through the foundation of a year-end branch inspection under FINRA Rule 3110: documentation, complaints, and outside activities. This installment goes deeper on three areas that consistently show up in exam findings, because they carry the bulk of the risk: communications and advertising, books and records, and suitability under Regulation Best Interest.

1. Communications and Advertising Review

Between social media, texting, and firm-approved email platforms, the volume of reviewable communications has grown faster than most supervisory procedures were originally built to handle. As a result, a year-end inspection should confirm that the review program is keeping pace with FINRA Rule 2210, not just technically compliant on paper.

What examiners look for

  • Evidence that the branch reviewed correspondence and retail communications at the frequency your WSPs require
  • Approval documentation for advertising and marketing materials, including social media posts
  • Confirmation that reps are using only approved channels, not personal email or unmonitored apps, for business communications
  • Sampling that catches outliers, not just a rotating set of the same low-risk accounts
  • A record of any corrective action taken on flagged communications
Common gap

Firms often have a solid email review process but no consistent method for capturing or reviewing texting and approved social platforms at the branch level. Confirm the inspection actually tests for this rather than assuming the firm-wide system caught everything.

2. Books and Records

Books and records reviews are where many otherwise well-run branches lose points, not because anything is wrong substantively, but because the records are not where they should be, the branch does not retain them long enough, or the branch cannot easily produce them on request. The 2022 amendments to SEC Rule 17a-4 gave firms more flexibility here, but the underlying retention and accessibility standards still apply.

  • Confirm required books and records are maintained at the branch or accessible on demand
  • Verify retention periods align with SEC Rule 17a-4 and firm policy
  • Check that account opening documentation, new account forms, and updates are complete and signed
  • Test whether a sample record request could be fulfilled quickly, because this is often exactly what examiners will do
  • Review electronic recordkeeping systems for proper indexing and non-rewriteable storage where required

3. Suitability and Reg BI Controls

Since Regulation Best Interest took effect, branch inspections have had to expand well beyond suitability in the traditional sense. Inspectors need to see that the branch can demonstrate a best-interest process, not just a suitable outcome.

Reg BI review points

  • Care obligation documentation supporting recommendations, especially for complex or higher-cost products
  • Evidence that the branch considered and documented costs, risks, and reasonably available alternatives
  • Disclosure documents (Form CRS, conflict disclosures) provided and updated as required
  • Consistent application of the firm's Reg BI supervisory procedures across reps at the branch
  • Sampling of recommendations involving rollovers, account type changes, and complex products for enhanced review
Why it matters

Reg BI findings are increasingly about process, not just outcome. A branch can have a defensible recommendation and still draw a finding if the file does not show the reasoning behind it.

Pulling It Together

Communications, records, and Reg BI controls tend to generate the bulk of substantive findings in a branch exam because they touch nearly every account and every representative. Building dedicated review steps for each, rather than folding them into a generic checklist, makes the difference between an inspection that satisfies the letter of Rule 3110 and one that actually reduces risk.

The final post in this series covers cybersecurity, remote and hybrid supervision, and how firms can track remediation once they identify findings.

Tighten Up Your Inspection Program

MCG Consulting builds communications review, recordkeeping, and Reg BI supervisory frameworks that stand up to exam scrutiny.

Talk to Our Team
© 2026 MCG Consulting • mcgcomply.com • This content is for informational purposes and does not constitute legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *

Post comment