OTC Link's $575,000 SEC Penalty: The Exam Finding Nobody Closed

OTC Link's $575,000 SEC Penalty: The Exam Finding Nobody Closed
October 5, 2026

OTC Link's $575,000 SEC Settlement Came From Exam Findings That Stayed Open

The SEC fined OTC Link LLC $575,000 on September 22, 2026, for policy gaps its own examiners flagged on several exams between 2016 and 2025. The Commission found that the firm failed to establish, maintain, and enforce the written policies and procedures that Regulation SCI requires for OTC Link ATS, its alternative trading system for over-the-counter securities. According to SEC press release 2026-91, the conduct ran from August 2016 to March 2025. OTC Link consented to a cease-and-desist order, a censure, and the penalty without admitting the findings, according to the settled order.

The headlines leave out the most useful part. The SEC's announcement describes no hack, no outage, and no trading halt. What it describes is a pattern. SEC examiners inspected OTC Link ATS several times, and each time they flagged required policies that were missing or still in draft. The firm did not promptly fix them. "OTC Link's continual failure to remediate deficiencies even after they were repeatedly flagged by Division of Examinations staff reflects a disregard for their findings and the overall examinations process and justifies a meaningful penalty," said Laura D'Allaird, Chief of the Division of Enforcement's Cyber and Emerging Technologies Unit (SEC press release 2026-91). The SEC official quoted on the case leads the Enforcement Division's Cyber and Emerging Technologies Unit, yet the announcement describes no intrusion. The charged violations are policy failures under Rule 1001(a), including the duty in Rule 1001(a)(3) to take prompt action to remedy deficiencies. The repeated, unclosed exam findings are what turned those gaps into a censure and a penalty.

The exam findings were the warning, and the enforcement order followed when the warning went unaddressed.

Regulation SCI Rules 1001(a)(1)–(3): What the Order Actually Charged

Compliance Week summarized the case as a failure to create and enforce compliance policies. The order itself is more specific about what went wrong. The settled order is Exchange Act Release No. 106458, Administrative Proceeding File No. 3-22748. It was instituted under Exchange Act Sections 15(b)(4) and 21C and finds violations of three specific provisions of Regulation SCI Rule 1001:

  • Rule 1001(a)(1) requires written policies reasonably designed to keep covered systems at adequate levels of capacity, integrity, resiliency, availability, and security.
  • Rule 1001(a)(2) sets the minimum contents of those policies, including testing, vulnerability reviews, and monitoring.
  • Rule 1001(a)(3) requires periodic review of how effective the policies are, and prompt action to fix deficiencies.

The gaps the press release identifies include system security, access control, and application vulnerability management, testing and remediation. These are not compliance-department documents in the traditional sense. Engineering teams own them in practice. They govern who can touch production systems, how code is tested, and how known weaknesses get patched.

Regulation SCI applies to a defined set of SCI entities, including exchanges, clearing agencies, and alternative trading systems above specified volume thresholds. Most advisers and fund managers are not covered. The failure mode it punishes, an exam finding left open, is not unique to SCI entities.

The Distinction That Matters: A Drafted Policy Versus an Established One

Rule 1001(a) uses three verbs: establish, maintain, and enforce. Each one is a separate obligation, and a draft document sitting in a shared drive satisfies none of them.

Established means adopted. A policy is established when it has been approved, dated, and put into effect. Until then, it is a proposal. According to the SEC, examiners flagged required policies that the firm had not established or had kept "in draft form" on repeated visits.

Maintained means current. A security policy written for one system architecture does not cover the next one. Rule 1001(a)(3) builds the review cycle into the rule itself.

Enforced means evidenced. If a firm cannot show testing records, access reviews, or remediation logs, it cannot show the policy operates.

The practical gap is ownership. When the controls belong to engineering and the policy belongs to compliance, the document can fall between the two teams for years. According to the SEC, some required policies were kept in "draft" form and not finalized or enforced. The order also states that OTC Link retained third-party compliance consultants in 2024, roughly eight years after the conduct period began. That is a structural problem that a reminder email will not solve.

What Your Leadership Team Should Decide Now

Regulation SCI does not reach most advisers, but RIAs and fund managers have a parallel obligation under Advisers Act Rule 206(4)-7, which requires written compliance policies and an annual review of their adequacy. An unremediated deficiency letter a year later is the kind of record that invites an examiner to question whether the annual review is working.

  • Assign a named owner to every open exam finding. A finding without an owner stays open, and an open finding becomes the record in the next exam.
  • Treat a deficiency letter as a deadline, not a suggestion. Each item needs a remediation date, and the date belongs on the leadership agenda until it closes.
  • Require evidence that each policy operates, not just that it exists. Testing records, access reviews, and remediation logs are what an examiner will ask to see.
  • Close the gap between engineering and compliance. When engineering owns the controls, engineering signs off on the policy that describes them.

FinTech Law's SEC exam counsel team reviews open exam findings and builds remediation plans with owners and deadlines before the next examination. Contact FinTech Law.

This article is for informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship.

FinTech Law fixed engagements: Startup Legal Path Review ($1,500) · Emerging Manager Launch Kit ($7,500) · Regulatory Path Outline ($7,500) · RIA/ERA Registration ($8,500) · Private Fund Formation (~$18,000) · Fractional General Counsel · $7,500/qtr (from Jan 2027). See the catalog.