Singuard Home Blog Contact eTrader eTrader for Businesses eTrader for Traders Broker Broker CRM Live Demo Prop Firm Prop Firm CRM Live Demo
Licenses & Regulation

Broker Audits: What Regulators Actually Inspect.

Inspections rarely uncover something nobody knew. They uncover that the firm could not evidence what it already believed to be true.

Roman Onta, Executive Director, SINGUARD By July 27, 2026 7 min read

The first request list is almost always the same: the client money reconciliation for a chosen date, the trade blotter for a chosen week, the complaints register for the year, the AML risk assessment with its last review date, and the compliance monitoring plan with evidence that the tests in it were actually performed. Five documents. A supervisor learns more from whether those exist and match than from a month of interviews.

Broker audits come in several shapes. There is the annual external audit of the financial statements, the client asset audit that some regimes require separately, the routine supervisory visit, and the thematic review where a regulator examines one topic across many firms at once. They ask different questions but they test the same thing: does the operation described in the licence application still describe the operation that runs today.

Client money is the first and hardest test

Where a regime requires segregation, the reconciliation between what clients are owed and what sits in the segregated accounts is the central control. The test is not whether the number is right today. It is whether the reconciliation is performed at the required frequency, whether shortfalls were funded from own resources the same day, and whether breaks were investigated rather than carried forward. A firm that reconciles weekly under a daily obligation has a finding regardless of the balance.

Common failures are unglamorous. Unallocated deposits sitting in a suspense account for weeks, payment provider balances counted as client money before settlement, and negative client equity treated as an asset. The rules behind all of this are set out in client fund segregation, and the capital side that sits alongside it is covered in capital requirements for brokers.

Execution quality

Under conduct regimes with a best execution obligation, a supervisor will pull a sample of trades and ask you to show why the price the client received was consistent with your published policy. That means keeping timestamped records of the quote stream, the client order, the fill and any requote or rejection, and being able to explain slippage patterns that skew against clients.

Asymmetric slippage is the classic finding: positive slippage passed to the firm and negative slippage passed to the client. It shows up quickly in aggregate data and it is hard to defend. So are systematic rejections during news. What the obligation actually requires is explained in best execution rules, and the record keeping in transaction reporting feeds the same evidence base.

Most findings are evidence findings. The control existed, the staff performed it, and nobody wrote down that they had. If a test leaves no artefact with a date and a name on it, treat it as not performed.

Financial crime files

The AML review follows a predictable path: the business-wide risk assessment, the customer risk model, a sample of client files, the sanctions screening configuration and the record of suspicious activity considerations. Reviewers look for the gap between policy and practice. A policy that says enhanced due diligence applies to politically exposed persons is worth nothing if the sample shows three such clients onboarded on standard checks.

Source of funds is where retail brokers get caught. A client depositing amounts inconsistent with the profile they declared at onboarding should have triggered a review, and the file should show that someone looked and reached a documented conclusion. The framework sits in the AML directives, the practical checks in source of funds checks, and the named responsibility in the MLRO role.

Governance, complaints and outsourcing

Supervisors read complaints as a signal about the business model. A cluster of complaints about withdrawal delays points at payments or at deliberate friction. A cluster about platform freezes during volatility points at infrastructure. What matters in the file is the response time against your published timescale and whether root causes fed back into anything.

Outsourcing gets more attention than it used to. If your platform, your CRM, your KYC provider and your payment orchestration are all third parties, the regulator wants the contracts, the due diligence you performed, the exit plan and evidence that you can still access your own records if a vendor disappears. Firms discover the weakness of that position when a platform licence is withdrawn at short notice, a scenario that has already played out in this industry and is described in platform concentration risk.

Preparing without theatre

Preparation is mostly the compliance monitoring programme done honestly through the year. Pick the tests that match your actual risks, run them on a schedule, record the result including the failures, and record what changed afterwards. A monitoring file that reports everything satisfactory for twelve consecutive months is read as a file nobody completed.

The mechanical part is the audit trail. Every material action inside the client lifecycle, approval of an account, a manual balance adjustment, a rule override, a change to a client's leverage, should be attributable to a named user with a timestamp that cannot be edited. That is a software property rather than a policy, and it is why we build immutable logging into the systems described in compliance audit trails and in our Broker CRM. This article describes general supervisory practice and is not legal advice; obligations depend on your licence and jurisdiction.

"The firms that survive an inspection are boring. Daily reconciliation, dated approvals, a complaints log nobody argues with. The clever ones are the ones that get the follow-up letter."

— Roman Onta, Executive Director, SINGUARD

Key Takeaways

Frequently Asked Questions

How often is a broker audited?

Financial statement audits are annual in most regimes, and where client asset rules apply a separate client money audit usually runs alongside. Supervisory visits and thematic reviews are not on a fixed cycle and are driven by firm size, complaint volume and risk rating.

What is the most common finding in a broker inspection?

Evidence gaps. The firm performed the control but cannot show a dated record of it. Client money reconciliation frequency, unresolved breaks and incomplete customer due diligence files account for a large share of the rest.

Does using outsourced technology increase audit risk?

It shifts the questions rather than removing them. A regulator will ask for the vendor due diligence, the contract, the exit plan and proof that the firm can still reach its own client and trade records if the provider stops serving it.


About the Author

Roman Onta, Executive Director, SINGUARD
Roman Onta Executive Director, SINGUARD

Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.

Your Own Trading Firm, Live in 24 Hours.

SINGUARD builds the technology behind brokers and prop firms: trading platform, CRM, client portal and payment rails, one bundle, one predictable price. Book a call and see it working, or keep reading the guides.

More in Licenses & Regulation