If your firm's AML binder still says NASD Rule 3310, you're already in the danger zone. The name survives in old WSPs, vendor templates, and legacy supervisory manuals, but the examiner sitting across the table is not interested in nostalgia. They want to see whether your firm has a current, written, working anti-money-laundering program that matches what FINRA Rule 3310 demands.
That confusion matters because the phrase NASD Rule 3310 points to two different historical rules. One is the retired publications-and-quotations rule. The other is the modern AML rule that compliance teams mean. If you do not separate those two in your own documentation, you invite sloppy policies, bad exam responses, and avoidable findings.

Why NASD Rule 3310 Still Surfaces in Compliance Conversations
A compliance officer usually finds this problem the hard way, while pulling together annual AML materials and discovering that an old WSP still cites NASD Rule 3310 as if the label never changed. That is exactly how stale language survives, in vendor templates, legacy manuals, and inherited supervisory documents. It looks harmless until an examiner asks why the firm is citing a retired rule without understanding what it became.
The practical answer starts with the lineage. The old NASD Rule 3310 was adopted on June 6, 1939, and the Federal Register later noted there had been no subsequent amendments to that original rule before it was superseded in FINRA's rulebook. FINRA now identifies that old version as retired and replaced by FINRA Rule 5210, which means the “3310” number historically referred to a publications-and-quotations rule, not the modern AML rule. The modern AML rule lives elsewhere in the rulebook as FINRA Rule 3310, adopted on April 24, 2002, and later amended effective May 11, 2018. That is the number your compliance program needs to respect.
Practical rule: if your document says NASD Rule 3310, check whether it means the retired market-publications rule or the AML program rule. If the document is unclear, rewrite it before an examiner does it for you.
The confusion persists because older materials never got cleaned up. That is why firms with decent supervision still end up with sloppy citations in manuals, exam binders, and training decks. If your IT and document-management environment lets those legacy references linger, coordinated cleanup matters. A resource on managed IT for financial institutions can help firms control versioning, permissions, and document retention, which is where stale rule references often hide.
The right mindset is simple. Treat every appearance of NASD Rule 3310 as a prompt to verify whether the text is talking about the retired rule or the current AML obligation. If it is the AML obligation, the document should say so plainly and consistently. If it is the retired rule, the citation should not be repurposed as if it still governs AML.
The Rule's Lineage and Which 3310 You Actually Mean
Many individuals who mention NASD Rule 3310 are not referring to the former publications-and-quotations rule. Instead, they mean the modern AML program rule, as that is where the significant compliance burden lies. The error is in assuming the number itself indicates which obligation is relevant. It does not.
The old version is now retired. FINRA's retired-rules page makes that clear and ties the old 3310 number to a superseded rule, while the current rulebook shows the AML version separately. The Federal Register history noted that the original NASD rule had no later amendments before supersession, while FINRA's current rulebook records the AML lineage as its own thing, with April 24, 2002 adoption and a later amendment effective May 11, 2018. That distinction is not trivia. It is the difference between a market-integrity citation and a real AML control obligation.
How to read the rule in a document
If a document discusses publishing quotations or market publications, it is almost certainly referencing the old lineage that FINRA now treats as retired and repurposed into FINRA Rule 5210. If it discusses AML controls, suspicious activity, customer due diligence, testing, or training, it is the modern FINRA Rule 3310. When litigators or compliance officers face a regulatory inquiry, that is the version they are usually dealing with.
The current FINRA rulebook also makes the AML framework explicit. The rule is not a slogan. It is a program requirement. It is also not optional because a firm says it has “general compliance procedures” somewhere else. If the AML obligation is not broken out as a written, maintained, and tested program, the firm is exposed.
You can confirm the split in FINRA's own materials, including the retired rule history for NASD Rule 3310 and the current internal-law guidance on member firms at this FINRA member-firm resource. Read them together and the confusion disappears.
FINRA's rulebook is not ambiguous once you know what to look for. The danger is internal paperwork that keeps using an obsolete label as if the rule never changed.
The Six Minimum Elements of an AML Program
FINRA Rule 3310 is a control framework, not a slogan, and it only works if all six minimum elements exist in practice. The easiest way to think about it is this. If one element is weak, the whole program leaks. A polished policy binder cannot fix missing monitoring, and good monitoring cannot rescue a firm that never tests its own controls.
| Element | What It Requires | What Breaks Without It |
|---|---|---|
| Written policies and internal controls | A documented AML framework tailored to the firm's business | Staff improvise instead of following a real process |
| Transaction monitoring and reporting | Systems and procedures to review activity and escalate suspicious behavior | Alerts sit unreviewed or suspicious conduct goes unnoticed |
| Independent testing | An outside-the-function review of the AML program | Gaps stay hidden until an exam exposes them |
| Designated AML contact | A named person responsible for the program | Nobody owns remediation, escalation, or reporting |
| Ongoing training | Regular education for relevant personnel | Employees miss red flags or follow outdated procedures |
| Risk-based customer due diligence | Customer risk profiling and ongoing review | The firm can't explain why activity is unusual |
The written program is the foundation. It should not read like a generic template copied from another firm's business model. Internal controls need to reflect the firm's actual client base, product mix, supervision model, and escalation path. If a WSP describes an alert review process that no one follows, the document is not a control, it is wallpaper.
Transaction monitoring is where many firms get sloppy. A firm can have software, but if nobody owns triage, review, or escalation, the system is decorative. That is why the rule's monitoring requirement matters more than the tool itself. The tool has to support an actual decision-making process.
Independent testing is a separate failure point. The test has to be independent of the day-to-day AML function, and it has to produce findings the firm can act on. If testing ends with a polite memo and no remediation, the program is still broken. The same is true when the AML officer has authority on paper but no ability to force change.
The due diligence piece is the one many firms underbuild. If your customer profiles stop at onboarding and never get refreshed against new alerts or unusual conduct, your risk profile becomes fiction. That is where bad decisions start, because the firm no longer has a credible baseline for what “suspicious” should look like.
For a practical view of written controls and how they should be documented, see this AML compliance program resource.
SARs, CTRs and the Reporting Trigger Line
The reporting obligation is where AML compliance becomes real. A firm either knows when to escalate, or it doesn't. Under the modern rule, broker-dealers generally must file suspicious activity reports for transactions involving or totaling at least $5,000 when they know, suspect, or have reason to suspect money laundering or other suspicious conduct. That threshold matters because it tells you the rule is not limited to high-value criminal schemes. It reaches activity that should have triggered a human review.
SARs are judgment calls, CTRs are threshold-based
A SAR is a judgment-based filing. Someone at the firm has to decide that the facts create suspicion. A CTR is different. It is a threshold-based cash-reporting requirement tied to the transaction type and amount. A compliant firm knows how to distinguish the two, document the difference, and preserve the rationale for each decision.
Failure usually starts upstream. If customer due diligence is thin, the firm cannot tell whether a transaction is inconsistent with the customer's profile. That makes the SAR decision harder and slower. Weak onboarding leads to weak monitoring, and weak monitoring leads to bad filing decisions.
Operational point: if your analysts cannot explain why a transaction was escalated, closed, or filed, your documentation is not strong enough for an exam file.
The best firms treat alert review as a documented workflow, not a gut feeling. That means the reviewer should be able to point to the customer profile, the account activity, the alert history, and the basis for the final decision. If the narrative is absent, the filing decision will look arbitrary later.
The source material from the AML framework history notes the modern rule's active lineage and the reporting trigger environment, including the current AML rule's April 24, 2002 adoption and the later May 11, 2018 amendment. That matters because FINRA is not treating this as dead law. It is an active standard, and reporting failures still create exposure.

Independent Testing, Annual Cadence and Exam-Ready Evidence
Independent testing is the part of the program most firms underestimate. FINRA requires annual testing for firms that execute customer transactions, hold customer accounts, or act as introducing brokers. A two-year cycle is generally available only to firms limited to proprietary trading or business solely with other broker-dealers. That cadence is not a formality. It is the baseline for whether the program is being pressure-tested before the exam staff shows up.
What independent really means
Independent testing should be done by someone outside the day-to-day AML function. If the person who builds the monitoring rules also grades the program's effectiveness, the test loses value fast. The test has to challenge the program, not validate assumptions the firm already likes.
The evidence matters as much as the conclusion. Examiner-ready files should include the scope memo, work papers, findings, management responses, and remediation tracking. If the test identified gaps, there should be a record of what changed, who owned the change, and whether the firm checked back on the fix. Without that paper trail, the test is just a report.
A clean testing memo with no remediation record tells an examiner one thing. The firm found issues and did not close the loop.
That annual cadence is also a practical benchmark for exam readiness. It forces firms to spot drift early. If the program has not been tested in a current cycle, the risk is not just that errors exist. The risk is that the same errors have repeated long enough to become normalized.
For firms building a defensible supervisory structure, written supervisory procedures guidance is useful because AML testing only works when the firm's broader supervisory framework is organized enough to support it. If the WSPs are vague, outdated, or contradictory, independent testing becomes harder to scope and easier to challenge.
A strong test does not chase perfection. It identifies control failures that matter, documents them clearly, and gives management a real chance to remediate before the next review cycle. That is what FINRA expects to see.
Where Rule 3310 Programs Break Down in Enforcement
FINRA enforcement does not usually punish a firm for lacking a fancy acronym. It punishes firms for failing to maintain the specific controls the rule requires. The recurring patterns are predictable. Outdated risk assessments, alerts that nobody reviewed on time, SARs that were delayed or never filed, customer due diligence that stopped at onboarding, training that existed only as a slide deck, and independent testing reports with no meaningful remediation. Those are the weaknesses that turn a rule on paper into a problem in an exam file.
The common failure patterns
A stale risk assessment is a red flag because the firm can't show that its AML controls still match the business. Ignored alerts are worse, because they suggest the monitoring function exists but doesn't function. Training failures matter when employees cannot explain what to escalate or why. A weak AML officer role matters when no one can say who had authority to demand fixes.
Enforcement posture closely tracks those failures. FINRA actions commonly result in censures, fines, and undertakings that require outside consultants. A clear signal is not the label on the sanction. It is the fact pattern inside the complaint, which usually maps to one or more failed elements of the AML framework.
If you are dealing with a regulator or internal escalation, bring the documentation with you before the issue metastasizes. That is where SEC investigation guidance becomes relevant in a broader sense, because AML problems often overlap with other inquiries, disclosures, and supervisory questions. The sooner counsel sees the control record, the less room there is for a bad narrative to take hold.
Recommended check before an exam: verify the current risk assessment, confirm that alerts were closed with a documented basis, and review whether the last testing cycle produced actual remediation.
Do not treat Rule 3310 as a checkbox. Treat it as a live operating standard. If your program only works when someone is looking at it, it does not work.
Practical Compliance Checklist and Recommended Next Steps
Use the six elements as a hard checklist, not a comfort exercise. Confirm that the written AML program matches the firm's actual business, not an inherited template. Verify that the designated AML officer has real authority, real access to records, and a clear route to management escalation. Then sample alert reviews, SAR decisions, and training records to see whether the file tells a coherent story.

The checklist that actually matters
- Written Program: confirm the AML program is current, customized, and approved.
- Testing: confirm the independent review happened on cadence and produced usable findings.
- Designated Officer: confirm the AML contact is qualified and can act.
- Training: confirm personnel training is ongoing and documented.
- Information Sharing: confirm the firm can move relevant data where it needs to go.
- Customer Identification Program (CIP): confirm identity verification is working at onboarding and beyond.
What to do next
If an exam is coming, close the obvious gaps first. Update the WSPs, assess the AML officer's role, and test whether recent alerts were reviewed against the customer profile. If there is a Form U5 issue, a transition, or a FINRA inquiry under Rule 8210, document every decision before the request lands on someone's desk. That record is what protects the firm later.
Kons Law handles securities regulation, securities arbitration, and regulatory defense matters for firms and financial professionals who need a legal response to FINRA issues, AML scrutiny, or disclosure problems. If you want to discuss your business law matter, contact Kons Law at (860) 920-5181.
If your firm is dealing with a NASD Rule 3310 question, an AML exam issue, or a stale supervisory file that needs to be cleaned up fast, talk to counsel before the next regulator does. Kons Law helps firms and financial professionals confront FINRA inquiries, sharpen compliance records, and respond to disclosure or enforcement problems with a plan that fits the facts. Visit Kons Law to discuss the issue and move before the file gets worse.
