Module 4 — Trading, Accounts and Prohibited Activities · Lesson 4.3
Anti-Money Laundering, Books and Records, and Privacy
Knowing the customer, keeping the record, and protecting the information
~10 min
What you'll learn
- State the elements of an AML programme and the customer identification requirements
- State the thresholds and deadlines for suspicious activity reports and currency transaction reports
- Identify the principal record retention periods
- Describe the confirmation and account statement requirements
- State Regulation S-P's notice and opt-out requirements
These three regimes have nothing to do with each other in origin — one comes from the fight against money laundering, one from securities law, one from financial privacy legislation — but they all attach at the same moment, when an account is opened, and the exam groups them accordingly.
Anti-money laundering
Money laundering is the process of making the proceeds of crime appear legitimate, conventionally described in three stages: placement, getting the money into the financial system; layering, moving it through transactions to obscure its origin; and integration, bringing it back as apparently legitimate wealth.
The Bank Secrecy Act, as amended by the USA PATRIOT Act, requires every broker-dealer to maintain a written anti-money-laundering programme. Its minimum elements are written policies and procedures reasonably designed to achieve compliance, a designated AML compliance officer, ongoing training for appropriate personnel, and independent testing of the programme — the four pillars. Risk-based customer due diligence, including identification of the beneficial owners of legal entity customers, has since been added as a fifth.
Within the programme sits the customer identification programme. Before opening an account the firm must obtain the customer's name, date of birth for a natural person, a physical address, and an identification number — a taxpayer identification number for a US person, or for a non-US person a passport number and country of issuance or similar. Identity must be verified within a reasonable time, and customers must be checked against government lists including the Office of Foreign Assets Control's list of specially designated nationals. A match on the OFAC list is a prohibition on doing business, not a flag to consider.
A suspicious activity report is filed with FinCEN when a transaction of at least $5,000 is suspected of involving funds from illegal activity, being designed to evade reporting requirements, having no apparent business purpose, or facilitating criminal activity. It must be filed within 30 calendar days of detection, and it is confidential — a firm may never tell the customer a SAR has been filed, and doing so is itself a violation.
A currency transaction report is filed for cash transactions exceeding $10,000 in a day. Structuring — breaking a transaction into smaller pieces to stay under that threshold — is a federal offence in itself, and a customer who asks how to avoid the report has given you something to escalate.
Red flags the exam expects: reluctance to provide identifying information, a customer whose activity is inconsistent with their stated profile, wire transfers to or from high-risk jurisdictions, unexplained third-party funding, and a pattern of activity with no apparent economic purpose.
Books, records, confirmations and statements
SEC Rule 17a-3 specifies the records a broker-dealer must make; Rule 17a-4 specifies how long they are kept.
Six years: blotters, general ledgers, stock records, and customer account records.
Three years: order tickets, confirmations, trial balances, communications relating to the business, advertising and sales literature, records of written customer complaints, and trading authorizations.
Lifetime of the firm plus three years: articles of incorporation, partnership agreements, minute books and stock certificate books.
Records must generally be readily accessible for the first two years of any period.
The compact way to hold it: six years for the records that describe the firm and its customer relationships, three for the records of individual transactions and communications.
An order ticket must record the account identifier, the security, buy or sell, quantity, price and order type, the time of entry and execution, whether the order was solicited or unsolicited, whether discretion was exercised, the capacity, and the representative who took it. It does not record the customer's name — the account number identifies the account.
SEC Rule 10b-10 requires a written confirmation at or before completion of the transaction, disclosing the security, the price and quantity, the capacity in which the firm acted, its compensation, the settlement date, and for a debt security the yield and any call features.
FINRA Rule 2231 requires account statements at least quarterly for any account with a position, a money balance or activity in the period.
Privacy
Regulation S-P implements the privacy provisions of the Gramm-Leach-Bliley Act for broker-dealers.
It requires an initial privacy notice no later than when the customer relationship is established, and an annual notice thereafter, describing the categories of non-public personal information collected and disclosed and the categories of third parties who receive it.
It requires an opt-out notice and a reasonable opportunity to opt out before disclosing non-public personal information to a non-affiliated third party — with exceptions, including disclosures necessary to process a transaction the customer requested, disclosures to service providers under a confidentiality agreement, and disclosures required by law or made to regulators.
And its safeguards rule requires written policies covering administrative, technical and physical safeguards for customer records and information, together with a response programme for unauthorized access.
Related: Regulation S-ID requires an identity theft prevention programme with red flags for detecting identity theft, and Regulation S-AM restricts using information received from an affiliate to make marketing solicitations.
One practical rule for a representative: customer information is the firm's confidential record, not yours. Taking a client list to a new firm is a privacy violation as well as, usually, a breach of contract.
Key takeaways
- ·The AML programme's four pillars: written procedures, a designated compliance officer, training, and independent testing.
- ·CIP requires name, date of birth, physical address and an identification number, plus verification and OFAC screening.
- ·SARs: $5,000 threshold, filed within 30 calendar days, and never disclosed to the customer. CTRs: cash over $10,000.
- ·Six years for blotters, ledgers and customer account records; three for tickets, confirms, communications and complaints.
- ·Regulation S-P requires initial and annual privacy notices, an opt-out before disclosure to non-affiliates, and written safeguards.
Communications and the standard of care come next.
Sources
- 1.Securities Industry Essentials (SIE) Examination Content Outline
Financial Industry Regulatory Authority (FINRA) · 2025
Sections 3.2.3 and 3.2.4 cover anti-money laundering and the books, records and privacy requirements tested.
- 2.17 CFR 240.17a-4 — Records to be preserved by certain exchange members, brokers and dealers
Securities and Exchange Commission · Electronic Code of Federal Regulations
The six-year, three-year and lifetime-of-the-firm preservation periods and the readily-accessible requirement for the first two years.
- 3.17 CFR 240.10b-10 — Confirmation of transactions
Securities and Exchange Commission · Electronic Code of Federal Regulations
The requirement to give or send a written confirmation at or before completion of a transaction, and its required content.
- 4.17 CFR Part 248 — Regulations S-P, S-AM and S-ID
Securities and Exchange Commission · Electronic Code of Federal Regulations
The initial and annual privacy notices, the opt-out right and its exceptions, the safeguards rule, and the related identity theft and affiliate marketing regulations.