A supervisor sends a request for information with a date on it. That date is the first test, and it is not really about the information. It measures whether the firm has a functioning compliance operation, because a firm that cannot produce its own records on time is telling the supervisor something about its controls before answering a single question.
Read what was actually asked
Information requests are drafted with care. They name a period, a product, a client population and a document type. The answer should track that scope precisely. Answering more broadly feels cooperative and is usually damaging: it puts material into the file that was never requested, invites follow-up questions on new subjects, and makes it harder to argue later that a matter was outside the scope of the review.
Answering more narrowly is worse. If a request is ambiguous, the correct move is to write and ask, in writing, what interpretation is intended, and to state the interpretation the firm intends to use if no clarification arrives. That exchange becomes part of the record and protects the firm if the reading turns out to be wrong.
Deadlines and the extension request
Extensions are routinely granted when they are asked for early, with a reason and a specific new date. They are rarely granted on the afternoon they fall due. A supervisor's tolerance is for firms that manage the process, not for firms that discover the problem at the end.
Some requests carry statutory force and cannot be extended at all. Reading which power a letter is issued under matters, because the consequences of missing a statutory information requirement differ sharply from missing an informal supervisory request. That distinction also determines what happens next, and the stages of enforcement action follow from it.
Self-reporting
Most regimes impose a duty to notify the supervisor of anything of which it would reasonably expect notice. Firms delay these notifications hoping to arrive with a complete picture and a fix already in place. That instinct is understandable and it is the single most common way a manageable issue becomes an enforcement matter.
The workable pattern is an early notification that says plainly what is known, what is not yet known, what has been done to contain it and when the next update will come, followed by that update arriving on the date promised. A supervisor who learns of a breach from a client complaint, a whistleblower or another authority after the firm knew about it will treat the delay as a separate failing from the breach itself.
Regulatory correspondence has legal consequences and privilege rules differ by jurisdiction. This describes practice, not advice. Any firm dealing with a supervisory request, an investigation or a notification duty should be taking its own legal advice on that specific matter.
The record is the firm's own file
Everything said to a supervisor sits alongside everything else the firm has ever filed: the application pack, the business plan submitted at authorisation, annual returns, complaints data, past correspondence. Contradictions between them are noticed. A firm that described one operating model at authorisation and now describes another has to explain the change, and "the business evolved" is only an acceptable answer if the change was notified when it happened.
Internally the same principle applies. If the compliance officer raised an issue in a monitoring report and management did nothing, that report will be requested and it will be read. The absence of a record is also read, and firms that keep no evidence of their monitoring are usually treated as not having done any. Practical audit trails across onboarding, approvals and client communications are what makes a response provable rather than asserted.
Tone, channel and who signs
Correspondence should be factual, short and free of argument about whether the question was fair. Save disagreement for the point where a finding is put to the firm and there is a formal opportunity to respond. Arguing with the request itself rarely changes the request and consistently changes how the firm is perceived.
Route everything through one owner, normally the compliance officer or MLRO, so the firm speaks with one voice and one version of the facts. Phone calls with supervisors should be followed by a written note of what was discussed, sent to the supervisor. Firms that skip this discover months later that their recollection of a call and the supervisor's differ, and only one of those recollections is in a file.
"Supervisors expect firms to have problems. What they do not forgive is finding out about one from somebody else after you knew."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- Answer the exact scope of the request, ask in writing when it is ambiguous, and never volunteer material that was not requested.
- Ask for extensions early with a specific new date, and check whether the request is statutory before assuming it can be moved.
- Notify early with what is known and what is not, then deliver the promised update on time, rather than waiting for a complete picture.
- Assume every answer is read against the authorisation file and past correspondence, and keep a written note of every call.
Frequently Asked Questions
Should I self-report a breach before I have fixed it?
In most regimes the duty is to notify the supervisor of matters of which it would reasonably expect notice, and waiting until a fix is complete usually breaches that timing. The common approach is an early notification stating what is known, what is being done and when the next update will follow. Firms should take their own legal advice on the specific duty that applies.
Can I ask a regulator for more time to respond?
Often yes, when the request is informal and the extension is sought early with a reason and a specific date. Requests made under statutory information powers may not be extendable at all, so the power the letter is issued under needs to be identified first.
Who should sign correspondence with a supervisor?
One accountable owner, normally the compliance officer or MLRO, with senior management aware of the content. A single channel keeps the firm's account of the facts consistent, which matters because every response is read against the authorisation file and earlier correspondence.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.