Breaking Regulatory Compliance
OTC Link Got Censured for Systems It Kept in Draft for Eight Years. Regulation SCI Doesn't Forgive 'Work in Progress'.
The SEC's September 22, 2026 censure of OTC Link LLC shows what happens when Regulation SCI examinations flag the same gaps repeatedly and a firm keeps policies in draft form for nearly a decade.
Table of Contents
TL;DR
- On September 22, 2026, the SEC censured OTC Link LLC and ordered a $575,000 civil penalty for repeated failures to establish, maintain, and enforce written policies and procedures required by Regulation Systems Compliance and Integrity (Regulation SCI).
- The violations spanned August 2016 to March 2025 — nearly nine years — covering system security, access controls, and application vulnerability management.
- The defining fact: OTC Link kept certain required policies in draft form for years. Multiple examination cycles flagged the gaps. The firm repeatedly failed to finalize or enforce them.
- If your Regulation SCI compliance program has policies in draft, in review, or marked “pending approval” — the OTC Link action just described your exam finding.
The most predictable enforcement action is the one you were warned about. Repeatedly.
On September 22, 2026, the SEC censured OTC Link LLC — the alternative trading system (ATS) operated by OTC Markets Group — and ordered it to pay a $575,000 civil penalty. The release covers nearly nine years of Regulation SCI non-compliance. But the operational lesson fits in one sentence: the SEC examined this firm multiple times, flagged the same gaps each time, and OTC Link still didn’t finish writing the policies it was missing.
Draft is not done.
What Regulation SCI Requires
Regulation Systems Compliance and Integrity — Regulation SCI — was adopted in 2014 following a wave of market disruptions that exposed how fragile the technology underpinning the equity markets had become. It applies to a specific set of market participants whose systems are load-bearing infrastructure for national market integrity:
- National securities exchanges (registered)
- Registered clearing agencies (not exempt)
- FINRA
- Alternative trading systems (ATSs) that exceed specified volume thresholds in NMS securities
- Plan processors (e.g., the SIPs)
- Exempt clearing agencies with ARP relief
For each of these entities, Regulation SCI mandates written policies and procedures reasonably designed to ensure that SCI systems — the ones that directly support the core market functions of order routing, order execution, trade reporting, clearance and settlement, market surveillance, and market regulation — maintain adequate:
- Capacity: the ability to handle peak load without degradation
- Integrity: accuracy and completeness of data
- Resiliency: ability to recover from disruption
- Availability: service continuity within defined parameters
- Security: protection from unauthorized access, misuse, and attack
Critically, Regulation SCI requires that these policies and procedures be established, maintained, and enforced. All three. It is not satisfied by a policy that exists on paper but is never reviewed. It is not satisfied by a policy that is written but not operationalized. And — as OTC Link just demonstrated — it is not satisfied by a policy that is drafted but never finalized.
What OTC Link Failed to Do
The SEC’s September 22 Order (Release No. 34-106458) is specific about what was missing. Between August 2016 and March 2025, OTC Link failed to establish, maintain, and enforce written policies and procedures for OTC Link ATS covering:
| Gap category | What was required | What OTC Link had |
|---|---|---|
| System security | Written policies and procedures reasonably designed to ensure adequate security for OTC Link ATS | Deficient or in draft |
| Access controls | Policies and procedures for account management and access control | Deficient or in draft |
| Vulnerability management | Policies for application vulnerability identification, testing, and remediation | Deficient or in draft |
| Network device configuration | Written configuration management procedures | Deficient, remediated in March 2025 |
The SEC found that OTC Link’s ATS lacked written policies and procedures that were reasonably designed to ensure its SCI systems had levels of capacity, integrity, resiliency, availability, and security adequate to maintain operational capability.
The Draft Problem
This is the detail that should land hardest for every compliance officer running Regulation SCI or related programs.
According to the SEC, its staff examined OTC Link ATS multiple times during the relevant period. Each examination flagged certain required policies and procedures that OTC Link had not established, or that it had kept in draft form and failed to finalize or enforce. After each examination, OTC Link repeatedly failed to promptly remediate the deficiencies.
Think about what that means operationally. OTC Link’s compliance team presumably knew the gaps existed — they showed up in examinations. They apparently started writing something, because there were drafts. But the drafts were never completed, never signed, never trained on, and never enforced. For nearly a decade.
A draft policy is not a policy. Regulation SCI requires that covered entities establish written policies (which means finalizing them), maintain them (which means keeping them current), and enforce them (which means actually following them). A document sitting in a folder marked “v0.3 – DRAFT – pending legal review” fails all three requirements simultaneously.
When the Remediation Finally Happened
Since March 2025, OTC Link established the additional written policies and procedures required by Regulation SCI, including policies covering application vulnerability management, account management and access control, and network device configuration management.
The remediation worked. The problem is that it happened nine years after the gaps first appeared.
The SEC’s enforcement timeline is instructive. The violations ran from August 2016 through March 2025. OTC Link remediated in March 2025. The SEC announced enforcement on September 22, 2026. The agency took enforcement action after the remediation was confirmed — not before — which is the standard pattern. But the firm still got the censure, the penalty, and the cease-and-desist, because the nine-year gap was the violation. Fixing it afterward reduces the scope of remediation required; it doesn’t undo the years of non-compliance.
What Is Regulation SCI Examining?
If you run an ATS, operate a broker-dealer with SCI-covered systems, or work in compliance at any market structure participant, the OTC Link action maps out exactly where SEC examiners focus.
The SEC’s examination program for Regulation SCI entities includes review of:
System documentation:
- Are SCI systems, indirect SCI systems, and critical SCI systems formally designated?
- Are the written policies and procedures current, finalized, and distributed?
Access controls:
- Who has access to SCI systems and how is that access provisioned, reviewed, and revoked?
- Is there documented evidence of access reviews?
Vulnerability management:
- Is there a written process for identifying, testing, and remediating vulnerabilities?
- Are remediation timelines tracked and met?
- What happens to patches that are deprioritized or delayed?
Incident notification:
- Does the firm have written procedures for the 24-hour notice to the SEC when an SCI event occurs?
- Are the materiality thresholds for determining what counts as an SCI event defined in writing?
Annual review:
- Is there a documented annual systems review that assesses the adequacy and effectiveness of SCI policies and procedures?
- Has the review been conducted in the last 12 months?
OTC Link’s deficiencies were in the foundational layer — written policies for security, access, and vulnerability management. Those are the same categories that appear in the SEC’s 2026 examination priorities for broker-dealers and market participants and align with the access control and technology risk requirements in the Reg S-P incident response program for investment advisers and broker-dealers.
So What? The Compliance Program Implications
The OTC Link censure is not an abstract systems-integrity story. It’s a compliance program story. Here’s what it tells practitioners:
1. Draft is a liability, not a defense
If your Regulation SCI program has a policy in draft, you do not have a policy. You have documented evidence that you know a gap exists and have not closed it. If an examiner finds it in that state, you have not demonstrated a reasonable good-faith effort — you’ve demonstrated you identified the gap and didn’t fix it.
Close your drafts, or formally document why you’re delaying and when you’ll complete them. “Pending review” that has been pending for six months is its own red flag.
2. Repeated examination findings compound, they don’t reset
Each time the SEC examined OTC Link and found the same gaps, OTC Link’s risk profile went up, not down. The OTC Link action covers the entire period from first identification to remediation — not just the year before enforcement.
If your annual review or exam response has carried the same open finding for two consecutive cycles, the finding has become a pattern. Patterns are what enforcement actions are made of.
3. Remediation before enforcement matters but doesn’t eliminate liability
OTC Link remediated in March 2025. The SEC still enforced in September 2026. The message is not “fix it before they file, and you’re fine.” The message is “fix it as fast as possible because the clock started at first identification, not at first enforcement.”
For compliance teams using an RCSA to track control gaps, the OTC Link action confirms that technology controls — access management, vulnerability management, configuration management — need to be assessed with the same rigor as process controls. A rated control gap with a past-due remediation date isn’t just a management risk. It’s an examiner exhibit.
4. The Regulation SCI scope question is worth answering now
If you’re not sure whether your ATS meets the volume thresholds that make you an SCI entity, answer that question. The SEC does not give credit for not knowing. An ATS above the threshold is a covered entity whether or not its compliance program reflects that status.
The threshold for Regulation SCI coverage applies to ATSs that execute 5% or more of the aggregate average daily share volume in any NMS stock during at least four of the preceding six calendar months. If you’re approaching that threshold, begin building your Regulation SCI program now. If you’re well below it, document that determination.
What This Looks Like on an Exam
The OTC Link order gives any SCI-covered entity a clear pre-exam checklist. Walk through your systems inventory and ask the following for each SCI system:
| Question | Status | Evidence |
|---|---|---|
| Is this system formally designated as an SCI system (or indirect SCI system, or critical SCI system)? | ||
| Are written policies and procedures for this system’s security finalized, approved, and in effect? | ||
| Are access control procedures documented, including provisioning, review, and revocation? | ||
| Is there a written vulnerability management procedure? Is the last scan, finding log, and remediation tracker current? | ||
| Does the firm have written network device configuration management procedures? | ||
| Has the annual systems review been completed within the last 12 months? | ||
| Are SCI event notification procedures documented and tested? |
If any cell in that table is blank, you’re looking at a potential OTC Link-style finding. If any item is “in draft,” close the draft before the exam, not during it.
The Bigger Regulatory Context
Regulation SCI is one of several technology-control frameworks the SEC is actively examining in 2026. The September 14, 2026 risk alert on Rule 206(4)-7 annual compliance reviews makes the same point in a different domain: compliance programs with persistent uncorrected deficiencies draw enforcement, not just observations. The SEC’s off-channel communications sweep similarly confirmed that written policies without enforcement are indistinguishable from no policies at all.
The OTC Link censure fits the same pattern. The SEC is not impressed by compliance binders. It examines whether the policies are real — finalized, enforced, tested, and effective.
For SCI-covered entities, the takeaway from September 22, 2026 is that Regulation SCI examinations are cumulative. If the same gap appeared in your last exam, it will appear in your next one too. The difference between an observation and a $575,000 civil penalty with a censure is whether you actually fixed it.
The OTC Link enforcement order is available at the SEC’s enforcement page. For SCI-covered entities using a Risk & Control Self-Assessment to track technology control gaps, the RCSA template includes pre-built control categories for access management and technology risk that map to the Regulation SCI requirements examined here.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is Regulation SCI and who does it apply to?
What did OTC Link LLC fail to do under Regulation SCI?
Why is the 'kept in draft' finding significant?
What is the penalty for Regulation SCI violations?
What Regulation SCI policies and procedures do ATSs and broker-dealers need?
Does Regulation SCI apply to non-exchange broker-dealers?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
RCSA (Risk & Control Self-Assessment)
141 fintech risks with mapped controls, a 97-question self-assessment, control testing plan, challenge log and a one-page Board Summary.
◆ Keep reading
Related posts.
Regulatory Compliance
FinCEN's A7 Network Rule: A Rejection Control, Not Another Watchlist Refresh
FinCEN's A7 Network rule and Alert007 require payment rejection, sub-agent screening, notice evidence, and new sanctions-evasion monitoring.
Oct 1, 2026
Regulatory Compliance
SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake
SEC v. Meyer Global turns a missed SpaceX capital call into a control lesson for private fund advisers. Here is what compliance teams should test.
Oct 1, 2026
Regulatory Compliance
SEC Private Markets Proposal: What Fund Sponsors Must Build Before Retailization Becomes a Product
The SEC private markets proposal could expand performance fees, interval funds and accredited-investor pathways. Here is the control build list.
Oct 1, 2026