Regulation Watch

Reg BI Surveillance Gaps: What the SEC Is Finding in Broker-Dealer Exams

Laura Bennett Back to blog
Reg BI Surveillance Gaps: What the SEC Is Finding in Broker-Dealer Exams article cover

Regulation Best Interest has been in effect since June 2020. By mid-2025, the SEC's OCIE examination staff has accumulated enough examination findings to identify recurring control gaps that show up across broker-dealer firms of different sizes and business models. The 2025 examination priorities document flags Reg BI as a continued focus, and the published risk alerts and staff observations make clear that the common problems are not about understanding the rule. They are about whether surveillance controls are actually detecting non-compliant recommendations before they become examination findings.

This post focuses on three control gaps that the SEC's published materials and examination findings have identified most consistently. We are drawing from the SEC's own risk alerts and published examination observations, not from internal data.

Gap One: Best Interest Analysis Documentation for Complex Products

The Care Obligation under Reg BI (Rule 15l-1(a)(2)(ii)) requires that a recommendation be in the retail customer's best interest based on a reasonable understanding of the customer's investment profile and the potential risks, rewards, and costs of the recommended security. The SEC's examination findings consistently show that for complex products, including leveraged and inverse ETFs, structured products, and high-cost variable annuities, many broker-dealers lack evidence that the best interest analysis was actually performed.

The documentation gap takes a specific form: the firm has a written policy requiring that registered representatives document best interest analysis for complex product recommendations. The system captures the transaction. But the suitability review process does not create a timestamped record that ties the specific recommendation to the customer's investment profile at the time of the recommendation. When examiners pull a sample of complex product transactions and ask to see the best interest analysis supporting each recommendation, the response is often a general suitability memo rather than transaction-specific documentation.

A control that addresses this gap is not complicated. It requires that for any product categorized as complex, the order management or suitability review system generates a checklist prompt at the time of recommendation entry, the representative completes it, and the completed record is stored with the transaction record. Surveillance can then report exceptions where complex product transactions lack a linked best interest analysis record.

Gap Two: Conflicts of Interest Identification and Mitigation Disclosure

The Conflict of Interest Obligation under Reg BI requires that broker-dealers establish, maintain, and enforce written policies and procedures to identify and at a minimum disclose, or eliminate, all material conflicts of interest. The SEC has found that firms often have conflict identification processes that are thorough at the program level but miss specific recommendation-level conflicts that arise from compensation structures.

The specific pattern: a firm offers multiple share classes for the same mutual fund, with different fee structures that affect registered representative compensation. The firm's conflict disclosure policy accurately describes that compensation differentials exist in general. But the trade surveillance system does not flag instances where a representative consistently recommends the higher-cost share class to customers who would be eligible for the lower-cost class. The individual transaction is compliant on suitability grounds. The pattern, examined over time, suggests a compensation-driven recommendation pattern that the firm's conflict mitigation framework was supposed to prevent.

We are not saying that recommending a higher-cost share class is automatically a Reg BI violation. A representative may have legitimate reasons for a particular recommendation. What the SEC is looking for is whether the firm's surveillance can detect the pattern and generate a review when the pattern is present. A surveillance rule that flags a statistical anomaly in share class selection by representative, relative to peer benchmarks, lets compliance ask the question before an examiner does.

Gap Three: Reasonably Available Alternatives Analysis

The SEC's examination staff has noted that firms often cannot demonstrate that registered representatives considered reasonably available alternatives before making specific recommendations, particularly for securities with substantially similar risk-return profiles but meaningfully different cost structures. The Care Obligation requires considering the costs of a recommendation, and costs include ongoing fees that affect net returns.

The control gap here is less about what the policy says and more about what data the representative had access to at the time of the recommendation. If the firm's product shelf includes a low-cost index fund and a higher-cost actively managed fund with a similar mandate and no demonstrated outperformance record, best interest analysis requires some documentation of why the higher-cost option was recommended. Firms that flag this at the product approval level (deciding what goes on the shelf) without also capturing it at the recommendation level create a gap between shelf construction controls and point-of-sale documentation.

What Makes These Gaps Persist

The commonality across these three gaps is that they involve surveillance of representative behavior patterns, not just individual transaction review. Most suitability and Reg BI compliance frameworks were built around transaction-level review, where a compliance officer reviews a specific recommendation for a specific customer. Reg BI's requirements around conflicts and reasonably available alternatives create obligations that are only fully visible at the pattern level, across multiple recommendations and customers over time.

Surveillance systems designed for transaction-level suitability review do not automatically produce the aggregate analytics needed for pattern detection. Adding Reg BI pattern surveillance often requires either building new surveillance rules in the existing trade surveillance platform or adding a reporting layer that aggregates transaction data in ways the core system was not designed to do.

Connecting Reg BI Updates to Your Control Library

One of the practical challenges with Reg BI compliance is that the SEC continues to issue guidance, no-action letters, and examination risk alerts that refine the practical interpretation of the rule without changing the rule text itself. A broker-dealer compliance team that is tracking SEC guidance only when the rule formally changes will miss the signal these publications provide.

Within Regloom, we ingest the SEC's risk alerts and examination observation publications alongside formal rule amendments. When an SEC publication refines the expected practice for a Reg BI obligation, that change surfaces to the relevant controls in a firm's library. The formal rule text may not have changed, but the expected implementation practice has, and the control documentation should reflect it.

For broker-dealers doing their own monitoring, the SEC's OCIE published risk alerts on Reg BI are the most operationally useful documents to track. They describe actual examination findings, which means they describe controls that actually failed or were absent. Reading them as a control gap checklist, rather than as general compliance guidance, produces more actionable results.

Preparing for the Next Examination

If a broker-dealer's Reg BI compliance review has not been refreshed since initial implementation in 2020 or 2021, the gap between the firm's original control design and current examination expectations has likely grown. The SEC staff's understanding of what best interest analysis documentation looks like has been informed by three-plus years of examination findings. That understanding is more specific today than when the rule first took effect.

A self-assessment that focuses on the three gaps above, specifically asking whether surveillance controls exist that would detect these patterns, is a reasonable starting point. Surveillance gaps are fixable before an examination. They are considerably more difficult to address after findings are already in the exam report.