FINRA Rule 4370 has been on broker-dealer compliance radars since it was adopted, but the rule has not been static. A regulatory notice issued by FINRA in early 2026 clarified expectations in three specific areas that most existing business continuity plans do not address with sufficient granularity. The clarifications do not require filing an amended BCP with FINRA, but they do represent a shift in what examiners will expect to see documented when they evaluate your plan.
This post focuses on those three clarified elements and what they mean practically for a compliance team that is maintaining a BCP under the existing rule framework. We are not covering the full scope of Rule 4370 here; if you need a general orientation to the rule's structure, FINRA's published guidance is the right starting point.
Background: What Rule 4370 Requires
Rule 4370 requires each FINRA member to create and maintain a written business continuity plan identifying procedures relating to an emergency or significant business disruption. The rule specifies a set of elements the plan must address, including data backup and recovery, mission-critical systems identification, financial and operational assessments, alternate communications, customer access to funds and securities, regulatory reporting continuity, and supervisory procedures for the plan itself.
The rule also requires firms to designate two emergency contact persons and to review and update the BCP annually and whenever material changes occur in the firm's operations, structure, business, or location.
What the regulatory notice did: it sharpened the definition of "adequate documentation" in three of these required elements, drawing on patterns from recent examinations where firms had plans that met the surface requirement but lacked the specificity examiners were looking for.
Change 1: Mission-Critical Systems Must Include Third-Party Dependencies
Rule 4370 requires firms to identify mission-critical systems. Most BCPs do this by listing internal platforms: order management systems, execution infrastructure, clearing connectivity, surveillance tools. What the notice clarified is that mission-critical systems should explicitly include third-party vendor systems and services on which the firm's critical functions depend.
This is not a new legal requirement, but it represents a documented change in examination standard. Examiners are now expected to ask: for each third-party system you rely on to execute, clear, or communicate with customers, does your BCP document what happens if that vendor's service is disrupted?
The practical implication: if your BCP lists your order management system but does not identify that the OMS depends on a specific market data feed provider and a specific connectivity vendor, your mission-critical systems section is incomplete by the current examination standard. Firms that have a third-party vendor risk management program should be pulling that system dependency inventory into the BCP directly, not treating them as separate documents.
For firms using cloud-hosted execution infrastructure, this means documenting not just the platform but the specific cloud region dependencies and fallback region capabilities. A BCP that says "we use cloud infrastructure" without specifying what happens during a regional outage is not going to hold up to the updated examination standard.
Change 2: Annual Review Must Be Evidenced, Not Just Attested
The annual review requirement under Rule 4370 is not new. What changed in the notice is the expectation around evidence. Previously, many firms treated the annual BCP review as a signature process: compliance officer attests that the plan was reviewed, board or principal approves, attestation goes in the file. That process meets the literal requirement, but it does not document what was actually reviewed and what, if anything, was changed.
The clarification: the annual review should produce documented evidence of the review activities performed, the conclusions reached, and the basis for any decision that no changes were needed. A checklist showing each required BCP element was evaluated, with notes on whether it reflects current operations, is the type of documentation that will satisfy the updated expectation.
We are not saying that every annual review must result in BCP changes. A thoughtful review that concludes the plan remains current is perfectly appropriate. But the documented basis for that conclusion needs to exist. An attestation without supporting review evidence is now a documentation gap, not just a procedural preference.
This change is operationally meaningful for firms that have delegated the annual review to a junior compliance analyst who does a calendar-triggered checklist walkthrough. That walkthrough needs to be documented in a format that can be produced on examination request, not just described verbally during an examiner interview.
Change 3: Customer Notification Procedures Need Explicit Timing and Channel Documentation
Rule 4370 requires firms to address how customers will be notified and given access to their funds and securities during a significant business disruption. Most BCPs address this with language along the lines of "we will notify customers via available channels including email, website posting, and phone." The notice clarified that customer notification procedures should document the expected timeframe for notification and specify which channels are considered primary versus backup.
Why this matters: in an actual disruption scenario, the channels available will depend on the nature of the disruption. If your primary notification mechanism is email and the disruption involves an email system outage, a BCP that lists "email" as the notification method without identifying backup channels is not operational. Examiners are looking for a plan that actually reflects the firm's thinking about channel failure scenarios, not just a list of available technology.
Timing specificity is the other piece. How quickly would customers be notified in an overnight system failure discovered at 3 AM versus a trading-hours disruption discovered at 11 AM? Those scenarios have different operational constraints, and a plan that does not distinguish them does not demonstrate that the firm has actually thought through the notification workflow under real conditions.
What to Do With Your Current BCP
The honest answer here: if your BCP was last substantively updated more than two years ago and the annual reviews have been attestation-only, you have work to do. That is not a crisis; it is a gap, and it is a gap that is common across broker-dealers of all sizes based on what we have seen in examination findings.
A practical remediation sequence. Start with third-party system dependencies: pull your vendor list, identify which vendors support mission-critical functions as defined in your current BCP, and create an explicit dependency map. That map goes into the BCP, and it should be maintained as vendor relationships change. Second, build a documented review protocol for the annual review process: a structured checklist tied to each of the required BCP elements, with a field for reviewer notes and a status field (current / needs update / under review). Third, revise the customer notification section to specify primary and backup channels, expected notification timeframes by scenario type, and the individual or role responsible for executing each notification step.
None of this requires rebuilding the BCP from scratch. It requires adding specificity to areas that were previously handled at a surface level.
How We Track FINRA Guidance in Regloom
When we ingest regulatory notices from FINRA, we distinguish between notices that represent new rule text and notices that clarify examination expectations under existing rules. The Rule 4370 notice falls in the second category, and that distinction matters for control mapping. A new rule requires evaluating whether your controls address the new obligation. An examination expectation clarification requires evaluating whether your existing controls produce the documentation evidence that examiners now expect.
In Regloom, when we tagged this notice, we mapped it to the three control categories covering BCP documentation, annual review procedures, and customer communication protocols. The obligation change type was marked as "examination standard clarification" rather than "rule amendment," which helps compliance teams quickly understand whether they need to evaluate their control design or their control evidence quality. That distinction is easy to lose when guidance is tracked in a shared email inbox or a spreadsheet without structured metadata.
Staying current on FINRA's regulatory notice cadence is the kind of monitoring that gets deprioritized during busy periods and then causes examination surprises. Building a systematic process for capturing and acting on guidance notices, separate from the major rulemaking calendar, is a meaningful gap for teams that rely on manual monitoring of multiple regulatory channels.