Skip to content
RiskTemplates · The Daily Brief Thursday, October 1, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Breaking Regulatory Compliance

OTC Link Got Censured for Systems It Kept in Draft for Eight Years. Regulation SCI Doesn't Forgive 'Work in Progress'.

The SEC's September 22, 2026 censure of OTC Link LLC shows what happens when Regulation SCI examinations flag the same gaps repeatedly and a firm keeps policies in draft form for nearly a decade.

By Rebecca Leung · September 29, 2026 ·
Table of Contents

TL;DR

  • On September 22, 2026, the SEC censured OTC Link LLC and ordered a $575,000 civil penalty for repeated failures to establish, maintain, and enforce written policies and procedures required by Regulation Systems Compliance and Integrity (Regulation SCI).
  • The violations spanned August 2016 to March 2025 — nearly nine years — covering system security, access controls, and application vulnerability management.
  • The defining fact: OTC Link kept certain required policies in draft form for years. Multiple examination cycles flagged the gaps. The firm repeatedly failed to finalize or enforce them.
  • If your Regulation SCI compliance program has policies in draft, in review, or marked “pending approval” — the OTC Link action just described your exam finding.

The most predictable enforcement action is the one you were warned about. Repeatedly.

On September 22, 2026, the SEC censured OTC Link LLC — the alternative trading system (ATS) operated by OTC Markets Group — and ordered it to pay a $575,000 civil penalty. The release covers nearly nine years of Regulation SCI non-compliance. But the operational lesson fits in one sentence: the SEC examined this firm multiple times, flagged the same gaps each time, and OTC Link still didn’t finish writing the policies it was missing.

Draft is not done.

What Regulation SCI Requires

Regulation Systems Compliance and Integrity — Regulation SCI — was adopted in 2014 following a wave of market disruptions that exposed how fragile the technology underpinning the equity markets had become. It applies to a specific set of market participants whose systems are load-bearing infrastructure for national market integrity:

  • National securities exchanges (registered)
  • Registered clearing agencies (not exempt)
  • FINRA
  • Alternative trading systems (ATSs) that exceed specified volume thresholds in NMS securities
  • Plan processors (e.g., the SIPs)
  • Exempt clearing agencies with ARP relief

For each of these entities, Regulation SCI mandates written policies and procedures reasonably designed to ensure that SCI systems — the ones that directly support the core market functions of order routing, order execution, trade reporting, clearance and settlement, market surveillance, and market regulation — maintain adequate:

  • Capacity: the ability to handle peak load without degradation
  • Integrity: accuracy and completeness of data
  • Resiliency: ability to recover from disruption
  • Availability: service continuity within defined parameters
  • Security: protection from unauthorized access, misuse, and attack

Critically, Regulation SCI requires that these policies and procedures be established, maintained, and enforced. All three. It is not satisfied by a policy that exists on paper but is never reviewed. It is not satisfied by a policy that is written but not operationalized. And — as OTC Link just demonstrated — it is not satisfied by a policy that is drafted but never finalized.

The SEC’s September 22 Order (Release No. 34-106458) is specific about what was missing. Between August 2016 and March 2025, OTC Link failed to establish, maintain, and enforce written policies and procedures for OTC Link ATS covering:

Gap categoryWhat was requiredWhat OTC Link had
System securityWritten policies and procedures reasonably designed to ensure adequate security for OTC Link ATSDeficient or in draft
Access controlsPolicies and procedures for account management and access controlDeficient or in draft
Vulnerability managementPolicies for application vulnerability identification, testing, and remediationDeficient or in draft
Network device configurationWritten configuration management proceduresDeficient, remediated in March 2025

The SEC found that OTC Link’s ATS lacked written policies and procedures that were reasonably designed to ensure its SCI systems had levels of capacity, integrity, resiliency, availability, and security adequate to maintain operational capability.

The Draft Problem

This is the detail that should land hardest for every compliance officer running Regulation SCI or related programs.

According to the SEC, its staff examined OTC Link ATS multiple times during the relevant period. Each examination flagged certain required policies and procedures that OTC Link had not established, or that it had kept in draft form and failed to finalize or enforce. After each examination, OTC Link repeatedly failed to promptly remediate the deficiencies.

Think about what that means operationally. OTC Link’s compliance team presumably knew the gaps existed — they showed up in examinations. They apparently started writing something, because there were drafts. But the drafts were never completed, never signed, never trained on, and never enforced. For nearly a decade.

A draft policy is not a policy. Regulation SCI requires that covered entities establish written policies (which means finalizing them), maintain them (which means keeping them current), and enforce them (which means actually following them). A document sitting in a folder marked “v0.3 – DRAFT – pending legal review” fails all three requirements simultaneously.

When the Remediation Finally Happened

Since March 2025, OTC Link established the additional written policies and procedures required by Regulation SCI, including policies covering application vulnerability management, account management and access control, and network device configuration management.

The remediation worked. The problem is that it happened nine years after the gaps first appeared.

The SEC’s enforcement timeline is instructive. The violations ran from August 2016 through March 2025. OTC Link remediated in March 2025. The SEC announced enforcement on September 22, 2026. The agency took enforcement action after the remediation was confirmed — not before — which is the standard pattern. But the firm still got the censure, the penalty, and the cease-and-desist, because the nine-year gap was the violation. Fixing it afterward reduces the scope of remediation required; it doesn’t undo the years of non-compliance.

What Is Regulation SCI Examining?

If you run an ATS, operate a broker-dealer with SCI-covered systems, or work in compliance at any market structure participant, the OTC Link action maps out exactly where SEC examiners focus.

The SEC’s examination program for Regulation SCI entities includes review of:

System documentation:

  • Are SCI systems, indirect SCI systems, and critical SCI systems formally designated?
  • Are the written policies and procedures current, finalized, and distributed?

Access controls:

  • Who has access to SCI systems and how is that access provisioned, reviewed, and revoked?
  • Is there documented evidence of access reviews?

Vulnerability management:

  • Is there a written process for identifying, testing, and remediating vulnerabilities?
  • Are remediation timelines tracked and met?
  • What happens to patches that are deprioritized or delayed?

Incident notification:

  • Does the firm have written procedures for the 24-hour notice to the SEC when an SCI event occurs?
  • Are the materiality thresholds for determining what counts as an SCI event defined in writing?

Annual review:

  • Is there a documented annual systems review that assesses the adequacy and effectiveness of SCI policies and procedures?
  • Has the review been conducted in the last 12 months?

OTC Link’s deficiencies were in the foundational layer — written policies for security, access, and vulnerability management. Those are the same categories that appear in the SEC’s 2026 examination priorities for broker-dealers and market participants and align with the access control and technology risk requirements in the Reg S-P incident response program for investment advisers and broker-dealers.

So What? The Compliance Program Implications

The OTC Link censure is not an abstract systems-integrity story. It’s a compliance program story. Here’s what it tells practitioners:

1. Draft is a liability, not a defense

If your Regulation SCI program has a policy in draft, you do not have a policy. You have documented evidence that you know a gap exists and have not closed it. If an examiner finds it in that state, you have not demonstrated a reasonable good-faith effort — you’ve demonstrated you identified the gap and didn’t fix it.

Close your drafts, or formally document why you’re delaying and when you’ll complete them. “Pending review” that has been pending for six months is its own red flag.

2. Repeated examination findings compound, they don’t reset

Each time the SEC examined OTC Link and found the same gaps, OTC Link’s risk profile went up, not down. The OTC Link action covers the entire period from first identification to remediation — not just the year before enforcement.

If your annual review or exam response has carried the same open finding for two consecutive cycles, the finding has become a pattern. Patterns are what enforcement actions are made of.

3. Remediation before enforcement matters but doesn’t eliminate liability

OTC Link remediated in March 2025. The SEC still enforced in September 2026. The message is not “fix it before they file, and you’re fine.” The message is “fix it as fast as possible because the clock started at first identification, not at first enforcement.”

For compliance teams using an RCSA to track control gaps, the OTC Link action confirms that technology controls — access management, vulnerability management, configuration management — need to be assessed with the same rigor as process controls. A rated control gap with a past-due remediation date isn’t just a management risk. It’s an examiner exhibit.

4. The Regulation SCI scope question is worth answering now

If you’re not sure whether your ATS meets the volume thresholds that make you an SCI entity, answer that question. The SEC does not give credit for not knowing. An ATS above the threshold is a covered entity whether or not its compliance program reflects that status.

The threshold for Regulation SCI coverage applies to ATSs that execute 5% or more of the aggregate average daily share volume in any NMS stock during at least four of the preceding six calendar months. If you’re approaching that threshold, begin building your Regulation SCI program now. If you’re well below it, document that determination.

What This Looks Like on an Exam

The OTC Link order gives any SCI-covered entity a clear pre-exam checklist. Walk through your systems inventory and ask the following for each SCI system:

QuestionStatusEvidence
Is this system formally designated as an SCI system (or indirect SCI system, or critical SCI system)?
Are written policies and procedures for this system’s security finalized, approved, and in effect?
Are access control procedures documented, including provisioning, review, and revocation?
Is there a written vulnerability management procedure? Is the last scan, finding log, and remediation tracker current?
Does the firm have written network device configuration management procedures?
Has the annual systems review been completed within the last 12 months?
Are SCI event notification procedures documented and tested?

If any cell in that table is blank, you’re looking at a potential OTC Link-style finding. If any item is “in draft,” close the draft before the exam, not during it.

The Bigger Regulatory Context

Regulation SCI is one of several technology-control frameworks the SEC is actively examining in 2026. The September 14, 2026 risk alert on Rule 206(4)-7 annual compliance reviews makes the same point in a different domain: compliance programs with persistent uncorrected deficiencies draw enforcement, not just observations. The SEC’s off-channel communications sweep similarly confirmed that written policies without enforcement are indistinguishable from no policies at all.

The OTC Link censure fits the same pattern. The SEC is not impressed by compliance binders. It examines whether the policies are real — finalized, enforced, tested, and effective.

For SCI-covered entities, the takeaway from September 22, 2026 is that Regulation SCI examinations are cumulative. If the same gap appeared in your last exam, it will appear in your next one too. The difference between an observation and a $575,000 civil penalty with a censure is whether you actually fixed it.


The OTC Link enforcement order is available at the SEC’s enforcement page. For SCI-covered entities using a Risk & Control Self-Assessment to track technology control gaps, the RCSA template includes pre-built control categories for access management and technology risk that map to the Regulation SCI requirements examined here.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is Regulation SCI and who does it apply to?
Regulation Systems Compliance and Integrity (Regulation SCI) applies to certain market participants whose systems are critical to the national securities markets, including national securities exchanges, registered clearing agencies, FINRA, alternative trading systems (ATSs) that exceed specified volume thresholds in NMS securities, plan processors, and exempt clearing agencies subject to ARP relief. It requires them to establish written policies and procedures reasonably designed to ensure their systems have adequate capacity, integrity, resiliency, availability, and security.
What did OTC Link LLC fail to do under Regulation SCI?
Between August 2016 and March 2025, OTC Link LLC failed to establish, maintain, and enforce written policies and procedures required by Regulation SCI covering system security, access control, and application vulnerability management, testing, and remediation. The SEC found that OTC Link kept certain required policies in draft form without finalizing or enforcing them, even after multiple examination cycles flagged the same deficiencies.
Why is the 'kept in draft' finding significant?
A draft policy is not a policy. Regulation SCI requires that covered entities establish, maintain, AND enforce written policies and procedures. A document in draft form that is never finalized fails all three requirements simultaneously. The OTC Link censure confirms that the SEC treats draft-stage documentation as non-compliance, not partial credit.
What is the penalty for Regulation SCI violations?
The SEC ordered OTC Link to pay a $575,000 civil penalty, issued a censure, and required a cease-and-desist. The censure is notable because it signals a pattern of repeated non-compliance, not a one-time oversight. The SEC flagged the same deficiencies across multiple examination cycles before taking enforcement action.
What Regulation SCI policies and procedures do ATSs and broker-dealers need?
Regulation SCI requires covered entities to have written policies and procedures covering: system capacity, integrity, resiliency, availability, and security; access controls and account management; network device configuration management; application vulnerability management, testing, and remediation; incident notification and response; systems review; and designation of SCI systems, indirect SCI systems, and critical SCI systems.
Does Regulation SCI apply to non-exchange broker-dealers?
Regulation SCI directly applies only to SCI entities — national securities exchanges, clearing agencies, FINRA, certain ATSs above volume thresholds, and plan processors. However, broker-dealers that operate ATSs above those thresholds are covered, and the substantive control requirements (access controls, vulnerability management, BCP, incident notification) reflect baseline expectations the SEC and FINRA also apply to the broader broker-dealer population under Exchange Act Rules 17a-3/17a-4 and FINRA Rule 4370.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

● Don't wait for your own enforcement action

Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.

RCSA (Risk & Control Self-Assessment)

141 fintech risks with mapped controls, a 97-question self-assessment, control testing plan, challenge log and a one-page Board Summary.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.