Feature Regulatory Compliance
FINRA's 2026 Annual Regulatory Oversight Report: What Broker-Dealers and Investment Advisers Need to Fix Before Examiners Arrive
FINRA's nearly 90-page 2026 Annual Regulatory Oversight Report dropped in December 2025. Here's a practitioner's walkthrough of the top deficiencies — Reg BI, GenAI governance, new AML fraud typologies, cybersecurity, and third-party vendor management — and what your compliance program needs to address now.
Table of Contents
TL;DR
- FINRA published its nearly 90-page 2026 Annual Regulatory Oversight Report on December 9, 2025 — it’s the clearest signal you’ll get about what examiners are focused on before they walk through your door
- Reg BI deficiencies continue to center on Written Supervisory Procedures that don’t specify how account recommendations should be evaluated, and complex product documentation gaps
- GenAI gets its own new section this year: FINRA expects governance frameworks, pre-deployment compliance assessments, and testing for hallucinations and bias — especially in customer communications, surveillance, and regulatory analysis
- New AML fraud typologies — disaster scams, gold bar courier fraud, crypto confidence fraud, mail theft check fraud — need to be incorporated into your SAR narratives and monitoring scenarios now
FINRA published its 2026 Annual Regulatory Oversight Report in December 2025 and gave member firms something rare: a nearly 90-page document showing precisely what was wrong at other firms so you can fix it before examiners show up at yours. Most firms read it once and move on. The ones that use it well read it with a highlighter and a gap list.
Here’s the practitioner’s version — what the report actually says about each major topic, what deficiencies it documented, and what a compliance officer should do differently as a result.
What the Report Is and How to Read It
The Annual Regulatory Oversight Report is FINRA’s distilled view of examination findings from the prior cycle. It’s not a rulemaking and it’s not an enforcement action — but it functions as a public announcement of where FINRA found problems and what it expects firms to have in place.
This year’s report covers ten areas: Regulation Best Interest, GenAI (a new standalone section), cybersecurity, AML, digital assets, options supervision, Reg S-P, third-party vendor management, best execution, and the Consolidated Audit Trail. That breadth is intentional: FINRA wants firms to self-assess across the full program, not just patch the most obvious gap.
The SEC’s Division of Examinations released its 2026 examination priorities separately in November 2025, covering investment adviser fiduciary standards, broker-dealer financial responsibility rules, and AI governance across the advisory and trading functions. For dual registrants, both documents apply.
Read the FINRA report as a gap analysis template: go section by section, apply each finding to your firm, and document where your program matches the expected standard and where it doesn’t. That documentation itself is useful when an examiner asks how you reviewed the report.
Regulation Best Interest — Same Focus, New Deficiency Patterns
Reg BI remains the dominant examination theme for broker-dealers, and FINRA’s 2026 findings surface two consistent deficiencies.
WSPs that don’t tell staff how to make the recommendation. FINRA found firms whose Written Supervisory Procedures identified the standard — best interest — without explaining how to apply it. Specifically, WSPs that omitted clear guidance on what factors staff should evaluate when recommending account types: account costs, services provided, whether services would be duplicative. A WSP that says “recommend in the customer’s best interest” without specifying the analytic is not a compliant WSP under Reg BI’s Compliance Obligation.
Complex product documentation gaps. Variable annuities, structured products, and tax-advantaged account recommendations showed recurring gaps in Care Obligation documentation. The obligation requires firms to have a reasonable basis for the recommendation based on the customer’s investment profile — but examiners found that the customer-specific analysis often wasn’t contemporaneous or specific enough to demonstrate that the Care Obligation was actually applied.
Mobile app disclosure failures. FINRA called out mobile applications providing false, misleading, inaccurate, or unbalanced information, specifically including failures to disclose — or inaccurate disclosures of — the risks of options transactions. This is a Reg BI Communication Obligation issue that’s increasingly being tested through digital channels, not just traditional product presentations.
What to check: Pull your most recent WSPs for account type recommendations and complex products. Map each WSP to the four Reg BI obligations (Care, Conflict of Interest, Disclosure, Compliance). For mobile and digital content, review the most recent customer-facing disclosures on options and leveraged products for balance and accuracy.
GenAI Governance — FINRA’s New Explicit Section
The 2026 report adds a standalone GenAI section — the first time FINRA has treated AI governance as a discrete exam topic rather than a subset of technology or cybersecurity risk.
FINRA’s stated expectations:
Pre-deployment compliance assessment. Firms must assess regulatory compliance obligations before deploying GenAI tools, not after. If your firm has let an engineering team deploy a GenAI-powered feature and compliance assessed the risks retroactively, that sequence is exactly what the report flags. The expectation is that compliance is part of the decision to deploy, not a review of what already happened.
Governance frameworks for supervision. Firms must establish governance frameworks to supervise GenAI usage. FINRA doesn’t prescribe the framework structure, but the expectation is that someone owns GenAI oversight, that policies define permitted and prohibited uses, and that usage is monitored.
Testing for hallucinations and bias. FINRA explicitly identifies hallucination (confident but incorrect outputs) and bias (skewed outputs from limited or outdated training data) as known risks that firms must test for and manage. This is especially acute where GenAI touches regulatory analysis, surveillance, customer communications, or product design — areas where an inaccurate output creates a direct compliance or customer harm risk.
For teams building an AI audit trail, the documentation requirements under OCC 2026-13 and the FS AI RMF translate directly to the FINRA governance expectation: pre-deployment testing records, ongoing monitoring evidence, and governance documentation showing who owns the AI risk decision.
AML — New Fraud Typologies, Same Underlying Failures
The core AML deficiency pattern in the 2026 report is familiar: failures to detect, investigate, escalate, and report suspicious activity. But FINRA identifies five specific new fraud typologies that member firms must incorporate into their monitoring programs.
Disaster-related scams. Fraudsters exploit natural disasters and emergency assistance programs to generate suspicious transaction activity. Firms serving retail customers in disaster-affected areas need monitoring scenarios that flag rapid movement of emergency-source funds.
Investment club scams tied to pump-and-dump schemes. The structure involves coordinated investment groups that artificially inflate small-cap securities prices. FINRA’s 2026 report specifically calls out small-cap fraud in exchange-listed equities as a new concern — distinguishing it from OTC pump-and-dump patterns that appeared in earlier reports.
Gold bar courier scams. A variant of the government impersonation fraud typology, where victims are instructed to convert funds to gold bars and hand them off to “agents.” The red flags include rapid ATM withdrawals or liquidations followed by cash transactions, combined with elderly customer profiles.
Crypto confidence fraud. Increasingly sophisticated schemes where victims are cultivated over weeks or months before being induced to transfer funds to fraudulent crypto investment platforms. The transaction pattern looks like legitimate crypto investment before it ends in a complete loss event.
Mail theft-related check fraud. Stolen checks altered and deposited, often with rapid withdrawal before holds clear. FINRA flags this as a growing pattern as physical mail interception has increased.
The practical requirement: update your SAR narrative templates and transaction monitoring scenarios to cover these five typologies. If you run a BSA/AML independent testing program, the next test cycle should include validation of scenario coverage against these typologies.
FINRA also reemphasizes Rule 2165 — the temporary hold authority for situations where the firm has a reasonable belief that a customer is being financially exploited — and trusted contact person requirements. Both are relevant in the context of elder financial exploitation, which several of the new typologies target.
Cybersecurity — AI-Enhanced Threats Are Changing the Controls Calculus
FINRA’s cybersecurity section emphasizes a theme that appears throughout the 2026 report: AI is making traditional controls less effective if those controls aren’t continuously updated.
Specific threats called out: account takeovers, impersonation scams, social engineering attacks, and insider misuse of access. All four are described as “increasingly enhanced through AI-generated content” — synthetic voice, deepfake video, AI-drafted phishing messages — that make it harder for employees and systems to distinguish legitimate from fraudulent.
The implication for compliance programs: controls that relied on pattern recognition (suspicious email formatting, accented voice, unusual request language) need to be re-evaluated. This isn’t a FINRA rule citation; it’s an operational observation that your IT and security teams need to incorporate into their control design.
What FINRA expects: robust cybersecurity programs aligned with SEC and FINRA rules, including safeguards for customer information and identity theft prevention. The Reg S-P amendments — requiring written incident response programs and 30-day breach notification — are a specific examination focus in 2026.
Third-Party Vendor Management — Perennial, Still Deficient
Third-party vendor management appears in every FINRA report, and 2026 is no exception. The persistent deficiencies: insufficient initial due diligence, missing contract provisions, and inadequate ongoing monitoring once vendors are onboarded.
FINRA’s expectations in this area track closely with the interagency guidance that governs bank TPRM programs. For broker-dealers that have inherited vendor relationships through growth or acquisition, the risk is that a vendor is providing a critical service but was never formally assessed. A material change in a vendor’s ownership, financial condition, or service delivery capacity is the kind of event your vendor management program needs a process to catch.
The SEC’s 2026 exam priorities separately call out broker-dealer liquidity risk and reliance on third-party service providers as a specific focus — suggesting that examiners will be asking how firms have assessed the operational impact of losing a critical vendor, not just whether initial due diligence was completed.
So What? The Pre-Exam Gap Analysis
The 2026 report functions as an examiner’s checklist in advance. Work through it as follows:
| Area | Key Exam Question | Quick Self-Check |
|---|---|---|
| Reg BI | Do WSPs specify the factors for account recommendations? | Pull the account-type recommendation WSP and verify it lists evaluation criteria |
| Reg BI — Complex Products | Is Care Obligation documentation contemporaneous and customer-specific? | Sample 5 recent VA or structured product recommendations and review files |
| GenAI | Is there a governance framework and pre-deployment compliance process? | Map existing AI tools to a governance owner and document the pre-deployment review that occurred |
| AML | Do monitoring scenarios cover the 5 new 2026 typologies? | Review scenario library against the typologies in the report |
| Cybersecurity | Is there a written Reg S-P incident response program? | Confirm IRP exists, was tested in the last 12 months, and covers the 30-day notification obligation |
| Vendor Management | Are there contract provisions for incident notification and audit rights? | Sample 3 critical vendor contracts for notification SLAs and audit rights |
| Digital Assets | Is there a risk-based framework for digital asset business activities? | Document the current state of digital asset activity and the controls in place |
Run this gap analysis now and document the results. The firms that get the best examination outcomes are the ones that identified the gap before the examiner did — and can show a remediation plan already in motion.
The KRI Library includes 10 BSA/AML-specific Key Risk Indicators, compliance program health metrics, and third-party risk indicators — the same categories FINRA is examining. Pre-built green/amber/red thresholds. Operationalize your monitoring before the next exam cycle.
Sources:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is FINRA's 2026 Annual Regulatory Oversight Report and why does it matter?
What are the most common Reg BI deficiencies FINRA found?
What does FINRA expect from firms using GenAI in compliance or client-facing applications?
How should a BSA officer update their AML program for the new fraud typologies in the 2026 report?
What does the FINRA 2026 report say about third-party vendor management?
How does the FINRA 2026 report relate to the SEC's 2026 examination priorities?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Regulatory Compliance
Effective Challenge in Model Risk Management: Document the Disagreement
Model risk management effective challenge needs a decision trail. Build a challenge memo that preserves evidence, responses, conditions, and escalation.
Jul 24, 2026
Regulatory Compliance
FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now
FinCEN's student aid fraud alert gives banks nine red flags, a SAR keyword, and a clear transaction-monitoring task for ACH refunds.
Jul 23, 2026
Regulatory Compliance
Magnolia Diagnostics False Claims Act Settlement: Why Investors Paid Part of the $24 Million
The Magnolia Diagnostics False Claims Act settlement reached investors, requisition controls, and $24M in payments. Here is what to fix.
Jul 23, 2026