Enforcement notices are not press releases. They are long documents that set out what a firm did, which rule it broke, over what period, and what the firm should have had in place. Read a dozen of them across different regimes and the individual firms blur together while the failures resolve into a short list. Client money handling. Transaction monitoring that nobody read. Marketing that promised what the product could not deliver. Execution that was never measured. Records that could not be produced.
None of those are exotic. Every one is a control that a competent operations team could run, and in almost every case the notice makes clear that the firm knew it was missing. That is the part worth studying, because it means the failure is organisational rather than technical.
Failure one: client money treated as working capital
The most serious category, and the one that produces the largest penalties, involves money held for clients. Regulators describe the same sequence repeatedly: reconciliations performed late or not at all, shortfalls identified and not corrected within the required window, client money paid into house accounts and left there, and calculations built on a spreadsheet that only one person understood.
Enforcement in this area does not require an actual loss. The rules exist so that money is protected on the day a firm fails, so a firm that never lost a penny can still be penalised for a year of missing reconciliations. The lesson for operators is that client fund segregation is a daily process with evidence, not a bank account structure that gets set up once.
Failure two: monitoring that produced alerts nobody closed
AML cases follow a recognisable shape. The firm bought a transaction monitoring system, configured it with default thresholds, and generated more alerts than the team could handle. A backlog formed. Alerts were closed in bulk to clear it. Suspicious patterns that the system had correctly identified were dismissed without a documented rationale, and the regulator found them years later.
A second version involves customer due diligence that stopped at onboarding. Identity was verified, a risk rating was assigned, and nothing was ever revisited even as the client's activity diverged wildly from the profile. Effective AML programmes for trading firms depend on the file staying current, which means periodic review triggered by behaviour rather than by calendar alone, and on the money laundering reporting officer having genuine authority to stop business.
The practical signal to watch inside your own firm is alert closure time. If the median time to close an alert is under two minutes, nobody is investigating anything.
A compliance system that generates alerts nobody has capacity to review is worse than no system at all. It creates a documented record that the firm was told about the risk and did nothing, which is the exact evidence an enforcement case is built on.
Failure three: marketing that promised outcomes
Retail-facing enforcement concentrates heavily on communications. The recurring findings are performance figures presented without the losses that produced them, risk warnings buried or omitted on the channel where the client actually saw the ad, bonus structures with withdrawal conditions that were not clear at the point of sign-up, and affiliate content that would never have passed the firm's own approval process.
Affiliates are where firms most often lose control. A regulator's position is generally that a firm is responsible for communications made on its behalf, whether or not it wrote them. If your partners are producing content you have never seen, you are carrying that exposure. This is the reason CFD marketing restrictions and affiliate compliance rules deserve a real review workflow rather than a clause in a contract.
The same logic now reaches social content. Enforcement and supervisory attention on financial influencers has established that paid promotion of a leveraged product is a financial promotion regardless of the format it appears in.
Failure four: execution nobody measured
Best execution cases rarely allege deliberate manipulation. They allege absence of evidence. The firm had a policy document, the policy was never tested against actual fills, no monitoring compared the prices clients received against a reference, and nobody could demonstrate the outcome was consistent with the policy.
Related findings cover asymmetric slippage, where negative slippage was passed to clients while positive slippage was retained, and requote or rejection behaviour that varied by client profitability. Both are detectable in a firm's own data long before a regulator arrives, which is exactly why best execution rules emphasise monitoring rather than policy drafting. If you cannot produce a distribution of slippage by client segment on request, you do not know what your platform is doing.
Failure five: records that could not be produced
The quiet category. Firms unable to retrieve communications from the relevant period, order data that did not reconcile with the platform, missing recordings of calls that were supposed to be recorded, and reports submitted late or with fields that were wrong for years. Reporting failures under regimes such as MiFIR transaction reporting have produced substantial penalties on their own, without any underlying misconduct at all.
This failure is structural. It happens when the CRM, the platform, the ticketing system and the payment console each hold part of the truth and no process joins them. Building a firm where every material action leaves a timestamped, attributable record is unglamorous work that pays only when someone asks a question about a date two years ago. Compliance audit trails are the cheapest insurance in the business.
What the pattern says about how to build a firm
Read enough notices and a management lesson emerges alongside the technical one. Failures persist because the compliance function had no authority, or because a control was owned by one person with no cover, or because growth outran the operations team and nobody stopped to rebuild the process. Regulators say this explicitly in their findings about governance, and it is why the compliance officer role is treated as a control function rather than an administrative one.
For firms building from scratch, the practical version is to design the evidence trail before the volume arrives. Daily reconciliations that run automatically. Alerts with capacity to match. A marketing approval queue with a record of who approved what. Execution monitoring that runs whether or not anyone asks. SINGUARD's Executive Directors, Alex Onta & Roman Onta, spend a large share of their time on this side of the business with operating firms, and the Broker CRM is built around the assumption that every material action needs to be reconstructable later.
SINGUARD supplies software only and is not a broker, adviser or compliance consultancy. Nothing here is legal advice, and every firm should take its own advice on the rules that apply to its licence.
"I have never read an enforcement notice that surprised me. The firm always knew. What was missing was someone with the authority to stop the business until it was fixed."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- Client money penalties usually follow missing daily reconciliations rather than actual losses, so the evidence of the process matters as much as the bank structure.
- Transaction monitoring that produces more alerts than the team can investigate creates a documented record of ignored risk, which is what enforcement cases are built on.
- Firms are generally held responsible for promotions made on their behalf, so affiliate and influencer content needs a real approval workflow, not a contractual clause.
- Best execution and reporting cases most often allege absence of evidence, meaning the firm could not demonstrate outcomes rather than that it acted badly.
Frequently Asked Questions
Do regulators fine firms even when no client lost money?
Yes. Many rules, particularly around client money, monitoring and reporting, are preventive. A firm can be penalised for a sustained control failure that never produced a loss, because the control exists for the day something does go wrong.
Is a firm responsible for what its affiliates publish?
Regulators generally treat communications made on a firm's behalf as the firm's responsibility. That makes a documented approval process and ongoing monitoring of partner content part of the compliance programme rather than a marketing preference.
What is the single most common finding in broker enforcement?
Inadequate records and monitoring. Whether the subject is client money, AML alerts or execution quality, the recurring finding is that the firm could not evidence that a control was operating over the relevant period.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.