SEC Regulation SCI Automation Review Policy Compliance December 2014 Proprietary.

Slides:



Advertisements
Similar presentations
Module N° 4 – ICAO SSP framework
Advertisements

Building on Our Core Values Building on Our Core Values © 2003 by the AICPA The Sarbanes-Oxley Act.
John Bredemeyer, SRA President Realcorp Inc Hot Topics in Appraisal.
CIP Cyber Security – Security Management Controls
More CMM Part Two : Details.
©2010 Prentice Hall Business Publishing, Auditing 13/e, Arens/Elder/Beasley The CPA Profession Chapter 2.
The Advisers Act Custody Rule
SEC Regulation SCI Automation Review Compliance
Conversation on the Chemical Facility Anti-Terrorism Standards (CFATS) and Critical Infrastructure Protection Chemical-Terrorism Vulnerability Information.
Regulatory Reform and Implications for the Municipal Bond Market RBDA Financial Regulatory Reform Webinar Lynnette Kelly Hotchkiss, Executive Director.
Congress and Contractor Personal Conflicts of Interest May 21, 2008 Jon Etherton Etherton and Associates, Inc.
The Islamic University of Gaza
Chapter © 2009 Pearson Education, Inc. Publishing as Prentice Hall.
SOX and IT Audit Programs John R. Robles Thursday, May 31, Tel:
Environmental Management Systems An Overview With Practical Applications.
1. 2 CVM’s OBJECTIVES u to stimulate the creation of savings and their investment in securities; u to promote the expansion and regular and efficient.
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
The CPA Profession Chapter 2.
Topics OATS Overview, Rules and Reporting Obligations Order Reports
TELLEFSEN AND COMPANY, L.L.C. SEC Regulation SCI and Automation Review Policy Compliance March 2013 Proprietary and Confidential.
Risk Management Controls for Brokers or Dealers with Market Access
Per Anders Eriksson
Proposed Rules to Help Ensure the Safety of Imported Food 1.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Independent IB Financial Requirements. Today’s Presenters Gregory Prusik Vice-President, Registration Jamila Piracci Vice-President, OTC Derivatives Copyright.
Self Regulation: The US Experience Ethiopis Tafara US Securities & Exchange Commission.
Outsourcing Louis P. Piergeti VP, IIROC March 29, 2011.
The CPA Profession Chapter 2 By Arens et. al. Learning Objective 1 Describe the nature of CPA firms, what they do, and their structure.
Erica Cummings Grant Coordinator 1.  The New Mexico Department of Homeland Security and Emergency Management (DHSEM) is responsible for:  Monitoring.
Technical Regulations – U.S. Procedures and Practices U.S.-Brazil Commercial Dialogue Digital Video Conference Series August 22, 2006 Mary Saunders Chief,
NIST Special Publication Revision 1
SEC Regulation SCI Automation Review Compliance January 2015 Proprietary.
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Patient Protection and Affordable Care Act March 23, 2010.
Model For Effective Self-Regulation November 2002 Daniel M. Sibears Senior Vice President & Deputy Member Regulation, NASD.
State Program Review Process Presented by GSFC Compliance Team.
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
Compliance with IOSCO requirements AMEDA Leadership Forum Alexandria Egypt Monday 27 th April 2009 by Dr. Ashraf EL Sharkawy Senior Advisor to the CMA.
Presented by: Yolanda Chavez, RN, BSN Policy Rules and Curriculum Development Unit DADS Regulatory Services 1 DADS REGULATORY UPDATE March 2013.
1 NASD Rule 3040 & Proposed FINRA Rule 3110: Oversight of Dual-Hatted Employees Joan R. Dindoffer, VP and Chief Compliance Officer, Private Fiduciary Services,
U N I T E D S T A T E S D E P A R T M E N T O F C O M M E R C E N A T I O N A L O C E A N I C A N D A T M O S P H E R I C A D M I N I S T R A T I O N State.
Practice Management Quality Control
Copyright © 2007 Pearson Education Canada 1 Chapter 1: The Demand for Auditing and Assurance Services.
The right item, right place, right time. DLA Privacy Act Code of Fair Information Principles.
Programme Performance Criteria. Regulatory Authority Objectives To identify criteria against which the status of each element of the regulatory programme.
IAEA International Atomic Energy Agency School of Drafting Regulations – November 2014 Government and Regulatory Body Functions and Responsibilities IAEA.
The Impact of Evolving IT Security Concerns On Cornell Information Technology Policy.
Revisions to Primacy State Underground Injection Control Programs Primacy State Implementation of the New Class V Rule.
Electronic Trading Rules Presentation to CLS Education Committee May 15, 2013.
The U.S. Securities and Exchange Commission (SEC).
Overview of the SEC Summer What is the SEC? Securities and Exchange Commission The mission of the U.S. Securities and Exchange Commission is to.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Software Quality Assurance SOFTWARE DEFECT. Defect Repair Defect Repair is a process of repairing the defective part or replacing it, as needed. For example,
State of Georgia Release Management Training
Arkansas Department of Emergency Management Arkansas’ Homeland Security & Preparedness Agency Sandy Recovery Improvement Act of 2013 Public Assistance.
Sicherheitsaspekte beim Betrieb von IT-Systemen Christian Leichtfried, BDE Smart Energy IBM Austria December 2011.
0 Copyright © 2008 Deloitte Development LLC. All rights reserved. Dong Hee Kim, Audit Manager IFRS Conversion For seminar.
Building on Our Core Values Building on Our Core Values © 2003 by the AICPA The Sarbanes-Oxley Act.
May 5, 2016 May 5, Reporting obligations for  Investment banks,  Stockbrokers and dealers  FM and Investment advisers 2. Publication financial.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Organization and Implementation of a National Regulatory Program for the Control of Radiation Sources Program Performance Criteria.
 The U.S. Securities and Exchange Commission (SEC) oversees the key participants in the securities world.  Concerned with promoting disclosure of important.
Overview of Tampa Electric’s Compliance Program APPA Reliability Standards and Compliance Program January 10, 2007.
The CPA Profession Chapter 2.
Legislative Compliance Management Insurance Industry Workshop 1 – 2 November 2005 Bangkok, Thailand Kim Norris Managing Director International Advisory.
Real World Control Failures : Merrill Lynch
TRTR Briefing September 2013
Presentation transcript:

SEC Regulation SCI Automation Review Policy Compliance December 2014 Proprietary

SEC Regulation SCI - Systems Compliance and Integrity On November 19, 2014 the SEC adopted new rules to require certain key market participants to have comprehensive policies and procedures in place surrounding their technology. Regulation SCI under the Securities Act of 1934 (“Systems Compliance and Integrity”) replaces the current voluntary ARP compliance program with rules whose violation of which may be the subject to enforcement actions. SROs, selected alternative trading systems (ATS), plan processors, and exempt clearing agencies are required to design, develop, test, maintain, and oversee their mission-critical systems. The rules require them to ensure that their core technology meets certain standards, conduct regular business continuity testing, and provide certain notifications in the event of systems disruptions, intrusions and other events. Tellefsen and Company, L.L.C

SEC Regulation SCI - Systems Compliance and Integrity The rulemaking was largely adopted as proposed, with the following revisions and exceptions: The proposed 30 day advance reporting requirement was changed to quarterly. The Direct Access requirement which would have required SCI Entities to provide SEC staff with remote or on-site access to SCI Systems was not adopted. Safe Harbor protection from liability is limited to those individuals who reasonably discharge their responsibilities under Reg SCI. Senior management involved in the annual Reg SCI review will be required to certify that they have implemented policies and procedures reasonably designed to ensure compliance with the rulemaking. Tellefsen and Company, L.L.C

SEC Regulation SCI -Systems Compliance and Integrity The new regulations will present challenges to the Chief Compliance Officer, who is responsible for the creation and enforcement of reasonable supervisory procedures related to the implementation and maintenance of applicable hardware and software technologies and infrastructure. While these responsibilities are far from a routine compliance skill set, Reg. SCI is a continuation of a trend by the SEC of placing increased responsibility on compliance with respect to policies and procedures for implementing and maintaining various types of technology. For the past two decades, SROs have followed a voluntary set of principles articulated in the SEC’s Automation Review Policy and participated in what is known as the ARP Inspection Program. Reg SCI now supersedes this. Link to the final rulemaking in the Federal Register: Tellefsen and Company, L.L.C

SEC Regulation SCI -Systems Compliance and Integrity Recent technical glitches in the securities markets including those that arose during the 2010 Flash Crash, the initial public offerings of Facebook and BATS Global Markets as well as the Knight Capital trading incident have illustrated that investors can be at risk when technology fails, and confidence in the markets can falter. The market closures following Hurricane Sandy in 2012 also highlighted the importance of having a robust market technology infrastructure. These events, subsequent discussions and commentary from a cross section of market participants have helped shape the development of the new rulemaking. Tellefsen and Company, L.L.C

Reg SCI Applicability Reg SCI applies to “SCI Entities”, including:   All national securities exchanges and self regulatory organizations   Registered and ARP-exempt clearing agencies   ATSs that meet certain trading volume thresholds (“SCI ATSs”)   Reg NMS plan processors (SIPs)   FINRA   The MSRB The SEC anticipates that 14 ATSs will fall within the definition of SCI ATS Tellefsen and Company, L.L.C

Regulation SCI - Designed to Ensure: Core technology of national securities exchanges, self-regulatory organizations, significant alternative trading systems, clearing agencies, and plan processors meets certain standards. These entities conduct regular business continuity testing with their members or participants. They provide certain notifications regarding systems disruptions, intrusions and other types of systems issues. The probability of technology problems is reduced, and key entities are well-positioned to take appropriate, corrective action if problems do occur. Tellefsen and Company, L.L.C

Regulation SCI – Applicability The proposed rule would apply to “SCI Entities” such as: – –Self-regulatory organizations (the registered national securities exchanges, registered clearing agencies, FINRA, and MSRB). – –Alternative Trading Systems that exceed specified volume thresholds (SCI ATS). – –Disseminators of market data under certain National Market Systems plans (“plan processors”). – –Certain clearing agencies exempt from SEC registration. It would apply primarily to the systems of SCI Entities that are core to the functioning of the securities markets, such as those that directly support trading, clearance and settlement, order routing, market data, regulation, or surveillance. It is questionable whether other “mission critical” business systems such as a shared drive or phone system are within scope. Tellefsen and Company, L.L.C

SCI Entities Will Be Required To:   Establish policies and supervisory procedures relating to the capacity, integrity, resiliency and security of its technology systems.   Ensure its systems operate in the manner intended, including in compliance with relevant federal securities laws and rules   Take timely corrective action in response to systems disruptions, systems compliance issues and systems intrusions.   Notify and provide the SEC with detailed information when such systems issues occur, systems intrusions, and when there are material changes in its systems. Written notices of “SCI Events” will be reported to members and market participants and filed electronically to the SEC on Form SCI.   Inform its members or participants about certain systems problems and provide information about the systems and market participants affected by the problem and the progress of corrective action. Tellefsen and Company, L.L.C

SCI Entities Will be Required To (Cont’d)…   Provide quarterly notice to the SEC of any material system changes, including completed, ongoing and planned material changes to SCI systems and the security of indirect SCI systems, during the prior, current and subsequent calendar quarters.   Conduct an annual review of its compliance with Regulation SCI, and submit a report of the annual review to its senior management and the SEC.   Plan and engage in annual business continuity and disaster recovery testing   Designate certain individuals or firms to participate in the testing of its business continuity and disaster recovery plans, and coordinate such testing with other entities on an industry- or sector-wide basis.  Demonstrate systems testing, test results and related capabilities to SEC staff on-site during inspections. Tellefsen and Company, L.L.C

Reg SCI Effective Dates  The SEC has granted Safe Harbor protection from liability to individuals within SCI Entities who reasonably discharge their Reg SCI compliance responsibilities under their policies, procedures and controls.  Reg SCI is effective 60 days after publication in the Federal Register, and SCI Entities must comply with the requirements within 9 months of the effective date.  ATSs that satisfy volume threshold levels for the first time will be granted an additional 6 months from that time to comply.  SCI Entities will have 21 months from the effective date to comply with the industry or sector wide BC/DR testing requirement. Tellefsen and Company, L.L.C

Tellefsen and Company – Automation Review Expertise Tellefsen and Company has a core competency and depth of experience in assisting exchanges, clearing houses and ATS in complying with regulatory guidelines and developing regulatory requirement filings for exchange designation status. We have conducted numerous ARP reviews for clients in the last several years, including ATS, clearing houses and exchanges. We have counseled and guided our clients through the preparation for designation reviews and inspections by the CFTC, FINRA and the SEC. Our mission-critical systems expertise includes trading systems, market data dissemination, clearing, risk management and market surveillance components. Tellefsen and Company, L.L.C

Our Market Structure, Compliance and Automation Review Expertise Experience on prior client assignments has included the development of relevant compliance documentation and procedures for trading and operations management, including:   Business Impact Analysis   Business Continuity Management   Capacity Planning   Systems Development Methodology   QA and Acceptance Testing   Configuration and Release Management   Network Management   Problem Management/Problem Tracking   Information and Physical Security   Failover, Stress and Capacity Testing Tellefsen and Company, L.L.C

Our Market Structure, Compliance and Automation Review Expertise The development of systems failover and fall back testing strategies and plans are a core competency of our firm, as is systems quality assurance and acceptance testing. We have provided independent test oversight and test results attestation for various exchanges, clearing houses and numerous market participants. Tellefsen and Company, L.L.C

For More Information, Contact Tellefsen and Company, L.LC. John Rapa