AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Examination Readiness

skill-joellewis-finance-skills-examination-readiness · by JoelLewis

Prepare for and respond to SEC and FINRA regulatory examinations across the full exam lifecycle. Use when the user asks about exam notification letters, document request lists, deficiency letter responses, mock examination programs, annual compliance reviews under Rule 206(4)-7, or SEC/FINRA examination priorities. Also trigger when users mention 'we just got an exam letter', 'preparing for our f…

No reviews yet
0 installs
3 views
0.0% view→install

Install

$ agentstack add skill-joellewis-finance-skills-examination-readiness

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-joellewis-finance-skills-examination-readiness)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Examination Readiness? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Examination Readiness — SEC & FINRA Regulatory Examinations

Regulatory status current as of June 2026 — verify effective dates, dollar thresholds, and pending rulemakings against current SEC/FINRA/FinCEN sources before advising.

Core Concepts

SEC Examination Process (Division of Examinations)

The SEC's Division of Examinations (formerly the Office of Compliance Inspections and Examinations, or OCIE) conducts examinations of registered entities including investment advisers, broker-dealers, transfer agents, clearing agencies, and self-regulatory organizations. The Division uses a risk-based approach to select firms for examination and to determine the scope and intensity of each exam.

Risk-based selection. The Division selects firms for examination based on a range of risk indicators rather than examining every registrant on a fixed schedule. Selection criteria include:

  • New registrant status — Newly registered investment advisers and broker-dealers are frequently examined within the first one to three years of registration. These initial examinations assess whether the firm has implemented the compliance infrastructure described in its registration filings.
  • Risk indicators and quantitative screens — The Division uses data analytics to identify firms with characteristics associated with higher risk: rapid asset growth, concentrated portfolios, high employee turnover, customer complaint patterns, significant regulatory history, unusual fee structures, or material conflicts of interest.
  • Tips, complaints, and referrals — Complaints from investors, tips from whistleblowers (including those submitted under the SEC Whistleblower Program established by Section 21F of the Securities Exchange Act of 1934), and referrals from other SEC divisions or regulatory bodies can trigger cause examinations.
  • Sweep examinations — The Division periodically conducts industry-wide sweep examinations focused on a single issue or practice across many firms simultaneously. Recent sweep topics have included off-channel communications, Reg BI implementation, private fund fee practices, and ESG-related disclosures.

Types of examinations:

  1. Routine/periodic examinations — Scheduled examinations conducted as part of the Division's ongoing oversight program. These typically cover a broad range of compliance topics and may review multiple years of activity.
  2. Cause examinations — Triggered by a specific complaint, tip, referral, or red flag. Cause examinations are typically narrower in scope, focused on the specific issue that prompted the examination, but can expand if additional problems are discovered.
  3. Sweep examinations — Industry-wide examinations focused on a single topic. Sweep exams allow the Division to assess industry-wide compliance with a particular rule or to evaluate emerging risks across many firms. Results often inform future rulemaking or guidance.

Examination lifecycle:

  1. Notification letter — The examination begins with a notification letter (sometimes called an "announcement letter") sent to the firm. The letter identifies the examination team, provides an initial document request list (IDR), and specifies a deadline for document production (typically two to four weeks). For cause examinations, the notification may be abbreviated or, in rare circumstances, the examination may begin without advance notice.
  2. Document production — The firm produces the requested documents, typically through a secure file-sharing platform. The initial IDR is often extensive (see the Document Production section below). The examination staff may issue supplemental document requests as they review the initial production.
  3. On-site or remote examination — Examination staff conduct their review either on-site at the firm's offices or remotely (remote examinations became common during and after the COVID-19 pandemic and remain a standard option). The review includes analysis of documents, records, and data.
  4. Staff interviews — Examiners conduct interviews with key personnel, typically including the Chief Compliance Officer (CCO), portfolio managers, traders, operations staff, and senior management. Interviews may be informal discussions or more structured questioning sessions. Firms should prepare interviewees by reviewing relevant policies and recent compliance activity, but should not coach witnesses to give scripted answers.
  5. Follow-up requests — As the examination progresses, staff frequently issue additional document requests or ask clarifying questions based on their findings. Responsiveness and transparency during this phase are important.
  6. Exit conference — Near the end of the examination, staff typically hold an exit conference with the firm to discuss preliminary observations and potential areas of concern. The exit conference is not a formal proceeding, and the observations discussed may change before a final determination is made.
  7. Outcome — The examination concludes with one of several outcomes: (a) a no-action letter or no further action (the examination revealed no material issues); (b) a deficiency letter identifying compliance deficiencies and requesting a written response describing corrective actions; (c) a referral to the SEC's Division of Enforcement for potential enforcement action (reserved for more serious violations or patterns of non-compliance).

Typical duration. SEC examinations typically last from several weeks to several months, depending on the firm's size, the scope of the examination, the complexity of issues discovered, and the responsiveness of the firm's document production.

Firms' rights during examination. Firms have the right to: receive identification of the examination staff and their supervisors; understand the general scope of the examination; request reasonable extensions for document production deadlines (extensions are granted at the staff's discretion); have counsel present during interviews (though the SEC may interview individuals separately); and receive a closing communication describing the examination outcome. Firms may also submit a response to preliminary findings discussed at the exit conference before a deficiency letter is finalized.

FINRA Examination Process

FINRA (the Financial Industry Regulatory Authority) examines its member broker-dealer firms through its Risk Monitoring and Examination programs. As a self-regulatory organization (SRO), FINRA has direct authority to examine, sanction, and discipline its members — a key distinction from the SEC, which must refer potential enforcement actions to its Division of Enforcement.

Types of FINRA examinations:

  1. Cycle examinations — Regular examinations conducted on a schedule determined by the firm's risk profile. Higher-risk firms are examined more frequently (annually or even continuously for the largest firms), while lower-risk firms may be examined on a two- to four-year cycle. The cycle exam typically covers a broad range of compliance areas.
  2. Cause examinations — Triggered by specific concerns such as customer complaints, tips, unusual trading patterns, financial difficulties, or referrals from other regulators. Cause exams are focused on the specific issue that prompted the examination.
  3. Sweep examinations — Similar to SEC sweeps, FINRA conducts targeted reviews across multiple firms to assess industry-wide compliance with specific rules or to evaluate emerging risks.

Risk-based approach. FINRA assigns each member firm a risk rating based on a comprehensive assessment of factors including the firm's business model, product mix, customer demographics, complaint history, financial condition, regulatory history, and supervisory structure. This risk rating determines examination frequency and intensity.

  • Annual risk assessment — FINRA provides firms with an annual risk assessment summary identifying the key risk areas FINRA associates with the firm's business. This summary can be a valuable tool for compliance planning.
  • Examination priorities letter — FINRA publishes an annual examination and risk monitoring priorities letter identifying the topics and issues that will be focal points for the coming year. This letter is a critical compliance planning resource (see the Annual Examination Priorities section below).

Key differences from SEC examinations:

  • Direct sanction authority — FINRA can impose sanctions directly through its Department of Enforcement, including fines, suspensions, bars, expulsions, and censures. The SEC, by contrast, must bring enforcement actions through its own Division of Enforcement or through administrative proceedings.
  • Financial surveillance — FINRA conducts ongoing financial surveillance of member firms, including monitoring net capital compliance (SEC Rule 15c3-1), reviewing FOCUS reports (Financial and Operational Combined Uniform Single reports filed monthly or quarterly), and assessing the financial health of firms. FINRA may take emergency action if a firm's financial condition deteriorates below minimum thresholds.
  • Trade surveillance — FINRA operates sophisticated market surveillance programs (including the Cross-Market Surveillance system) to detect potential market manipulation, insider trading, and other trading violations.

Annual Examination Priorities

Both the SEC Division of Examinations and FINRA publish annual examination priorities or focus areas that signal where regulatory attention will be concentrated in the coming year. These publications are among the most important compliance planning tools available.

SEC Division of Examinations annual priorities. The Division publishes its examination priorities early each calendar year — always read the current year's letter. Recurring themes from the 2023-2026 letters have included:

  • Regulation Best Interest (Reg BI) compliance — Assessment of broker-dealer compliance with Reg BI's Disclosure, Care, Conflict of Interest, and Compliance Obligations (17 CFR 240.15l-1). The SEC has examined both the written policies and the actual practices of firms, with particular attention to whether recommendations are in the customer's best interest and whether conflicts are adequately disclosed and mitigated.
  • Investment adviser fiduciary duty — Examination of advisers' compliance with their fiduciary obligations, including duty of care and duty of loyalty, as interpreted by the SEC in its June 2019 Fiduciary Interpretation.
  • Private fund advisers — Scrutiny of fee calculations, expense allocations, performance reporting, preferential treatment of certain investors (side letters), and compliance with new rules under the Investment Advisers Act.
  • ESG and sustainability claims — Review of whether advisers and funds that market themselves as ESG-focused actually implement the ESG investment processes they describe. The SEC has brought enforcement actions for "greenwashing" — claiming ESG integration that does not occur in practice.
  • Cybersecurity and information security — Assessment of firms' cybersecurity programs, including governance, access controls, data loss prevention, incident response plans, vendor management, and compliance with Regulation S-P (privacy of consumer financial information) and Regulation S-ID (identity theft red flags).
  • Crypto and digital assets — Examination of firms offering digital asset products or services, including custody arrangements, valuation practices, and compliance with securities laws.
  • Off-channel communications — Review of whether firms are capturing and retaining business-related communications conducted through personal devices, text messages, messaging apps (WhatsApp, Signal, iMessage), or other channels outside the firm's approved communication platforms. This has been a major enforcement focus, with the SEC and FINRA imposing billions of dollars in combined penalties across dozens of firms.
  • Anti-money laundering — Review of AML programs, particularly SAR filing practices, customer risk rating, and beneficial ownership due diligence.
  • Marketing Rule compliance — Assessment of compliance with the SEC's Marketing Rule (Rule 206(4)-1), including performance advertising, hypothetical performance, testimonials, and endorsements.

FINRA annual examination priorities. FINRA's annual report on examination and risk monitoring activities similarly identifies key focus areas. Recurring FINRA priorities include:

  • Reg BI and Form CRS — Compliance with Regulation Best Interest and the requirement to deliver and file Form CRS.
  • Communications with the public — Compliance with FINRA Rule 2210, including social media supervision and digital communications.
  • Market integrity — Surveillance for manipulative trading, best execution compliance, and order handling obligations.
  • Financial crimes — AML program effectiveness, fraud detection, and sanctions compliance.
  • Firm operations — Net capital compliance, customer protection (Rule 15c3-3), books and records, and business continuity planning.

Using exam priority letters for proactive compliance planning. Firms should treat published examination priorities as a roadmap for their own internal compliance reviews. Best practices include:

  • Reading the SEC and FINRA priority letters immediately upon publication and assessing the firm's readiness in each identified area.
  • Conducting targeted internal reviews or mock examinations of the highest-priority topics.
  • Updating compliance policies and procedures to address new or evolving priority areas.
  • Allocating compliance resources — staff time, technology, and budget — to priority areas.
  • Briefing senior management and the board on examination priorities and the firm's preparedness.

Document Production and Requests

Document production is often the most operationally demanding phase of a regulatory examination. The initial document request list (IDR) sets the tone for the examination, and the quality and timeliness of the firm's response significantly influences the examination experience.

Typical items on an initial document request list. While every IDR is tailored to the specific examination, common elements include:

  • Compliance program documents — Written compliance policies and procedures (the compliance manual), code of ethics, annual compliance review reports, CCO designation documentation, compliance committee meeting minutes.
  • Organizational and governance documents — Organizational charts, ownership structure, affiliated entity relationships, board or governance committee minutes, management committee meeting minutes.
  • Registration and regulatory documents — Current and historical Form ADV (Parts 1, 2A, 2B), Form BD, Form CRS, state registration filings, regulatory examination history, correspondence with regulators.
  • Advertising and marketing materials — All advertisements, pitchbooks, fact sheets, website content, social media archives, client newsletters, performance presentations, and the advertising review log.
  • Client documents — Client agreements (advisory agreements, brokerage agreements), fee schedules, client onboarding documents, suitability or Reg BI documentation, account opening documents.
  • Fee and billing records — Fee calculation methodology, billing records, fee schedules, any fee adjustments or waivers, accounts with negotiated fees.
  • Trading and investment records — Trade blotters, order tickets, allocation records, best execution reviews, soft dollar arrangements, brokerage committee minutes, directed brokerage documentation.
  • Complaint and litigation records — Customer complaint log, complaint files, litigation and arbitration history, regulatory action history, whistleblower complaints.
  • Exception reports — Trade error logs, personal trading exception reports, gifts and entert

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.