You open an email from your firm's compliance department. The subject line references FINRA Rule 3110, and the request asks for supervisory procedures, inspection records, exception reports, and an explanation of what you knew about a representative's conduct. You're no longer dealing with a theoretical compliance issue. You're dealing with a record that may affect your license, your Form U5, your compensation, and your next job.
Failure to supervise cases are usually built from workflow failures. A rule changed, but the written supervisory procedure didn't. An alert appeared, but nobody escalated it. An inspection identified a problem, but the firm never documented corrective action. The defense starts by finding the exact point where that workflow broke.
The Letter That Changes the Week
A branch manager receives a letter asking for an on-the-record interview under FINRA Rule 8210. The letter may describe the issue narrowly, perhaps a recommendation, a trade, an outside business activity, or an account-document discrepancy. It may also ask for broad categories of documents covering emails, supervisory reviews, exception reports, branch inspections, and communications with the registered representative.
The manager's first instinct is often to answer immediately and explain the situation. That instinct can create problems. A rushed explanation may fill gaps in the regulator's theory, adopt language the firm later uses in a termination decision, or overlook a conflict between the written supervisory procedure and what happened.

What regulators will ask first
Expect questions that test the entire supervision chain:
- Assigned responsibility: Who was responsible for reviewing the activity?
- Written procedures: Which WSP governed the product, account, representative, or office?
- Actual execution: What review did you perform, when did you perform it, and what did you do with the result?
- Red flags: What exception, complaint, email, inspection finding, or customer communication should have triggered escalation?
- Evidence: Where are the review notes, approvals, follow-up emails, and remediation records?
The sequence often moves from an information request to interviews, document analysis, deficiency communications, and a potential enforcement recommendation. The regulator may also compare your testimony with the firm's WSPs, system records, branch inspection reports, and the representative's Form U5.
Practical rule: Treat the first request as the beginning of the defense, not as an administrative task.
During the first week, preserve documents without altering them, identify every person involved in the workflow, and build a chronology from the underlying activity through the firm's response. Don't delete informal notes, move files into a new folder without preserving metadata, or ask employees to “clean up” records. Involve counsel before an interview, particularly where the firm and the individual may have different interests.
The most effective response combines defense and repair. Counsel should analyze the allegation while the firm conducts a focused supervisory-compliance audit. That means mapping the allegation to the governing procedure, the assigned reviewer, the alert or inspection that should have caught the issue, and the corrective action that followed. Kons Law approaches these matters through early counsel, disciplined responses, and parallel attention to the advisor's regulatory and employment record.
What Failure to Supervise Actually Means
The modern U.S. legal basis for failure to supervise dates to 1964, when Congress enacted what are now Section 15(b)(4)(E) and Section 15(b)(6) of the Securities Exchange Act. Those provisions allow the SEC to sanction broker-dealers and associated persons when someone subject to supervision commits a securities-law violation and the supervisor did not reasonably oversee that activity, as described in FINRA's archived supervision materials.
The concept later became operational through FINRA standards. FINRA Rule 3110 requires each member firm to establish, maintain, and enforce written supervisory procedures reasonably designed to achieve compliance with federal securities laws, SEC regulations, and FINRA rules. The rule also requires firms to designate and identify principals responsible for supervisory controls, so supervision must function as an operating system, not sit in a binder.
Think of an air-traffic controller. The controller needs a defined procedure, authority to act, and enough training to use the procedure properly. A firm faces the same three questions when a violation occurs.
The three building blocks
Assigned responsibility. Someone must have responsibility for the activity. If the firm assigned supervisory duties to a compliance officer, branch manager, or another principal, that assignment matters. If nobody clearly owned the review, the firm has a governance problem.
Reasonable procedures. The firm needs a written process suited to its business. A generic policy that mentions supervision but says nothing about a new product, remote office, or automated alert may not withstand scrutiny.
Reasonable execution. A sound procedure must be followed, documented, and enforced. A completed checklist with no supporting analysis may be weak evidence if the underlying activity presented obvious exceptions.
These building blocks create two related but distinct theories. The firm may have failed to maintain a reasonable supervisory system. An individual may also face exposure if the firm assigned that person supervisory responsibility and the person failed to discharge it reasonably.
That distinction matters to compliance professionals. FINRA stated in Regulatory Notice 22-10 that it won't bring an action against a CCO under Rule 3110 for failure to supervise unless the firm assigned supervisory responsibilities to the CCO and the CCO then failed to discharge them reasonably. FINRA also stated that charges against CCOs for supervisory failures make up only a small fraction of the supervision-related enforcement actions it brings each year.
For firms reviewing their governance model, FINRA member-firm guidance is useful context. The practical question isn't whether a compliance officer holds a senior title. It's whether the firm assigned a specific supervisory function, supplied workable authority and resources, and can prove how that function was performed.
How Regulators Prove a Supervisory Failure
Regulators don't need to show that every supervisor personally participated in the underlying misconduct. They typically build the case by connecting the violation to a responsibility, a procedure, and a missed or inadequate response.
The underlying violation comes first. It may involve an unsuitable recommendation, an unauthorized trade, an undisclosed outside business activity, inaccurate account information, or manipulative trading that a surveillance system should have detected. The supervisory allegation asks why the firm or responsible individual didn't reasonably prevent, detect, escalate, or correct that conduct.
The evidence trail
A regulator will usually compare the written rule with the operational record. Important documents include:
- Written supervisory procedures: What did the WSP require, and did it address the particular product, office, activity, or alert?
- Inspection reports: Did the firm inspect the branch or non-branch location as required, and did the report identify exceptions?
- Exception logs: Was the issue visible in a report, and did anyone investigate it?
- Email and messaging records: Did employees discuss a concern without escalating it through the formal process?
- Approval records: Who approved the account, recommendation, trade, disclosure, or outside activity?
- Remediation files: Did the firm correct the problem and document follow-through?
“We had a manual” usually doesn't answer the allegation. The regulator wants to know whether the manual covered the conduct and whether the responsible person used it.
A stronger defense has a different shape. It shows a reasonable procedure, a defined assignment, evidence of performance, and a response proportionate to the information available at the time. It may also show that the supervisor delegated a task to qualified personnel, reviewed the resulting work, and lacked a red flag that a reasonable supervisor should have recognized.
Human failures and system failures
The defense analysis changes when surveillance is automated. A firm may have a functioning written policy and still face questions about alert design, data feeds, calibration, exception thresholds, and vendor oversight. The issue becomes whether the system was reasonably designed for the firm's business and whether employees handled alerts properly.
The strongest response identifies the failed control precisely:
| Alleged gap | Evidence regulators seek | Practical defense or fix |
|---|---|---|
| Missing WSP coverage | Rule-change records and procedure history | Show timely updates and approval |
| Ignored exception | Alert, log, and escalation history | Show review, rationale, and follow-up |
| Weak inspection | Inspection schedule and report | Show risk-based scope and remediation |
| Poor vendor surveillance | Contract, testing, thresholds, and validation | Show oversight and documented testing |
Prompt corrective action helps, but it doesn't erase an earlier failure. It does, however, give counsel a concrete record showing that the firm identified the problem, assigned ownership, protected customers, and closed the control gap.
Human Oversight Versus Algorithmic Surveillance
The classic failure-to-supervise case involved a person. A branch manager failed to review an outside business activity, overlooked signature deficiencies, or approved account information that didn't match the customer's actual circumstances. The evidence was largely human, including emails, forms, inspection notes, approval records, and testimony.
The newer version may involve a surveillance system. FINRA's 2026 Annual Regulatory Oversight Report emphasizes inadequate systems for detecting manipulative patterns such as layering, spoofing, wash trades, marking the close, and odd-lot manipulation. It also identifies thresholds that are too high, too low, or not tied to the firm's business mix as supervisory concerns.

The legal theory is familiar
The technology doesn't remove the supervisory duty. It changes the questions:
- Who approved the surveillance logic?
- Which business lines and products did the system cover?
- How did the firm set and test thresholds?
- Who reviewed alerts and unresolved exceptions?
- What did the firm do when the vendor's system failed?
- Did employees understand the system's limitations?
A vendor-managed tool doesn't outsource accountability. The firm still needs to understand what the tool monitors, what it excludes, and how alerts reach a qualified reviewer.
The risk became concrete in a 2025 matter involving automated system monitoring failures that resulted in a $1 million FINRA fine, as identified in FINRA's 2026 oversight materials. The lesson isn't just to buy better software. It's to document ownership of the surveillance workflow, including vendor diligence, testing, threshold changes, alert disposition, and escalation.
Compare the control environments
| Traditional branch issue | Automated-surveillance issue |
|---|---|
| Missing review of outside activity | Missing detection of manipulative patterns |
| Inaccurate account documents | Incomplete or inaccurate data feed |
| Failed branch inspection | Inadequate system validation |
| Ignored email red flag | Unresolved alert or excessive threshold |
| Weak manager follow-up | Weak exception-management governance |
Review your surveillance stack this week. Pull representative alerts, inspect the reasons for closure, identify open exceptions, and compare thresholds with the products and trading activity the firm conducts. If the business has changed but the system configuration hasn't, the written procedure and the technology may now be out of alignment.
The Allegations Regulators Actually Bring
FINRA's exam findings show that supervisory problems are often operational. FINRA's supervision findings identify recurring weaknesses involving written supervisory procedures, branch supervision, internal inspections, account documents, non-branch inspections, written inspection reports, and corrective action.
The first warning sign is a rule or business change that never reaches the WSP. A new product launches, a branch begins handling a different activity, or employees adopt a new communication channel. The firm continues using an old procedure, leaving reviewers without instructions suited to the actual risk.
Where workflows break
New or amended rules. The firm may know about a regulatory change but fail to update procedures, train staff, or assign implementation ownership. Preserve the change assessment, approval record, training materials, and effective date.
Branch and non-branch supervision. Firms have been cited when they didn't understand the activities conducted through branch offices, failed to account for location-specific risks, or omitted required periodic inspections of non-branch locations. The fix is a location inventory tied to defined inspection responsibilities and documented completion.
Inaccurate account documents. Incorrect account information can impair supervision of recommendations and activity. Don't treat data accuracy as a customer-service issue only. Require a review path for discrepancies and preserve evidence that someone resolved them.
Inspection reports without follow-through. An inspection that identifies an exception but contains no owner, deadline, or closing evidence creates a second problem. The original weakness remains, and the firm can't prove remediation.
Product and recommendation oversight. Unsuitable recommendations, undisclosed outside business activities, signature deficiencies, and unauthorized trading each point to a different control gap. The analysis must identify the precise approval, review, or escalation step that should have operated.
Turn findings into controls
Use a simple operational test. For each business line and office, identify the activity, the responsible principal, the review frequency, the triggering exception, the escalation route, and the evidence retained. A one-size-fits-all schedule won't account for different products, remote locations, or higher-risk activity.
The fix is not a longer WSP. It's a WSP that tells a specific person what to review, what counts as an exception, and what happens next.
Consequences From Fines to Form U5
A supervisory matter can move through several layers. The underlying conduct creates the customer or market issue. The supervisory allegation asks whether the firm or an individual should have prevented, detected, escalated, or corrected it. The final consequence may reach beyond the enforcement order.
FINRA's sanctions guidance for supervisory violations under Rules 2010 and 3110 identifies a fine range of $5,000 to $73,000 and says FINRA should consider suspending a responsible individual in all supervisory capacities for up to 30 business days. In more serious cases, the guidance allows a longer suspension or a bar, and it contemplates limiting a branch office or department for up to 30 business days. These figures appear in FINRA's supervision sanctions guidance.
The practical stakes can be greater than the sanction itself. A finding may affect a principal's role, the firm's ability to operate a location, and the individual's future employment. It can also influence settlement negotiations because the parties are not negotiating only about a fine. They're negotiating about the record.
Why Form U5 language matters
A Form U5 amendment can disclose the reason for termination or clarify circumstances surrounding a departure. That disclosure can appear in the advisor's regulatory record and be reviewed through BrokerCheck. Recruiters, compliance departments, arbitration counsel, and professional disciplinary bodies may all evaluate the wording.
The language matters because a supervisory dispute can become an employment dispute. An advisor may be weighing deferred compensation, incentive payments, production credits, a promissory note, or a transition agreement while the firm is deciding how to describe the separation. A poorly framed disclosure can complicate hiring and provide a former employer with an advantage in later proceedings.
A Form U5 and FINRA guide can help frame the record issues, but the immediate need is a coordinated strategy. Don't negotiate the regulatory response, employment separation, and Form U5 language as unrelated matters. They describe the same events to different audiences.
Responding to a FINRA Investigation
The first defensive decision is posture. Cooperate with lawful requests, but don't confuse cooperation with unstructured disclosure. A Rule 8210 response should be complete, accurate, organized, and reviewed before submission.
Start by preserving documents. Issue a litigation hold where appropriate, suspend routine deletion practices, preserve email and messaging records, and collect the versions of WSPs that were in effect during the relevant period. Don't rewrite a chronology to make the record look cleaner. Build a factual timeline that identifies what happened, who knew it, what the procedure required, and what action followed.
Prepare for the interview
An on-the-record interview isn't a casual compliance meeting. Counsel should help you understand the scope, review the relevant documents, and practice answering directly. If you don't know, say so. Don't guess, speculate, or adopt the question's characterization of an event without examining the record.
Your preparation should address:
- The assignment: What supervisory duties did your role include?
- The procedure: Which WSP applied at the time?
- The review: What did you personally do, and what did you delegate?
- The warning signs: What information reached you, and when?
- The response: What did you escalate, correct, document, or miss?
Counsel also needs to identify privilege issues. Don't forward legal advice to business colleagues, mix attorney communications with ordinary operational emails, or assume that a document is protected because a lawyer was copied. Preserve the original records and separate factual collection from legal analysis.
Protect the career record
The firm's interests may diverge from yours. A firm may want to characterize the matter as an individual supervisory failure, while you may have evidence that the WSP was unclear, the system failed, or another department owned the review. That conflict becomes sharper if the firm threatens termination, withholds deferred compensation, seeks repayment under a promissory note, or challenges a transition.
A failure-to-supervise investigation can also create facts relevant to wrongful-termination or employment-discrimination claims. Those claims require their own analysis, but you shouldn't surrender useful evidence while focusing only on the FINRA response.
For broader context on the investigative process, see Kons Law's discussion of SEC investigations and defense strategy. The core position is straightforward: defend the supervisory record and protect the career record at the same time. The Form U5 language written during the investigation may matter long after the enforcement matter ends.
Building a Supervisory Program That Survives an Exam
Start with structure, not paperwork. FINRA generally expects supervisory personnel not to oversee their own activities, with narrow exceptions when the firm's size or structure makes independent supervision impossible, such as a sole proprietor or senior executive who can't realistically be supervised by another person within the firm. Document why any exception is unavoidable.
Then use written supervisory procedures as an operational control, not a reference file:
- Update WSPs when rules, products, offices, or systems change.
- Map risk across each office and product line, then set an appropriate inspection cadence.
- Preserve evidence of reviews, alerts, approvals, inspections, and escalations.
- Close remediation with an owner, deadline, written follow-up, and proof of completion.
- Test surveillance thresholds, vendor controls, data feeds, and alert disposition.

If you're facing a supervisory inquiry, Form U5 dispute, FINRA investigation, employment claim, or compliance-program review, contact Kons Law at (860) 920-5181.
Kons Law represents financial advisors, brokerage professionals, and firms in FINRA investigations, Rule 8210 responses, supervisory disputes, Form U5 matters, compensation claims, and related employment or transition disputes. If you want to discuss your business law matter, contact Kons Law at (860) 920-5181 or visit Kons Law.
