The U.S. Securities and Exchange Commission has censured New York-based broker-dealer OTC Link LLC and ordered it to pay a $575,000 civil penalty for longstanding violations of Regulation Systems Compliance and Integrity (SCI). The enforcement action stems from the firm's failure to establish, maintain, and enforce required written policies and procedures for its alternative trading system, OTC Link ATS, between August 2016 and March 2025. These deficiencies specifically concerned system security, access control, and application vulnerability management, testing, and remediation.
According to the SEC’s settled order, staff in the Division of Examinations repeatedly identified these gaps during multiple examinations over the relevant period, noting that certain policies remained in draft form or were not finalized. Despite these repeated flags, OTC Link LLC failed to promptly remediate the issues. The Commission found that this lack of adequate policies violated Rules 1001(a)(1), 1001(a)(2), and 1001(a)(3) of Regulation SCI, which mandate that SCI systems possess sufficient capacity, integrity, resiliency, availability, and security to ensure fair and orderly markets. Without admitting the findings, OTC Link agreed to a cease-and-desist order alongside the censure and monetary penalty.
This enforcement action underscores the regulatory expectation that identifying compliance gaps is insufficient without prompt and effective remediation. By penalizing OTC Link for failures spanning nearly a decade, the SEC signals that prolonged neglect of Regulation SCI requirements, particularly regarding system security and vulnerability management, constitutes a serious breach of operational integrity. The case highlights the critical role of examination feedback loops, demonstrating that firms cannot treat regulator warnings as advisory suggestions but must view them as mandatory directives for immediate corrective action.
From an institutional adoption perspective, consistent adherence to Regulation SCI is foundational for maintaining market credibility and ensuring the resilience of alternative trading systems. The emphasis on cyber and emerging technologies within the Division of Enforcement suggests heightened scrutiny on how traditional financial infrastructure manages digital risks. Market participants should observe whether this precedent encourages more rigorous internal audits and faster response times for policy finalization across other SCI entities, thereby strengthening the overall stability of electronic trading venues.


