examination-readiness
Prepare for and respond to SEC and FINRA regulatory examinations across the full exam lifecycle. Use when the user asks about exam notification letters, document request lists, deficiency letter responses, mock examination programs, annual compliance reviews under Rule 206(4)-7, or SEC/FINRA examination priorities. Also trigger when users mention 'we just got an exam letter', 'preparing for our first SEC exam', 'how to respond to a deficiency finding', 'staff interview preparation', 'what does OCIE look for', 'examination readiness checklist', 'sweep exam on off-channel comms', or ask what to expect during a regulatory audit.
What this skill does
# Examination Readiness — SEC & FINRA Regulatory Examinations ## Purpose Prepare registered investment advisers, broker-dealers, and their compliance teams for SEC and FINRA examinations. This skill covers the full examination lifecycle — from risk-based selection and notification through document production, staff interviews, deficiency findings, remediation, and follow-up. It provides frameworks for mock examinations, annual compliance reviews, and proactive use of published examination priorities to reduce regulatory risk. ## Layer 9 — Compliance & Regulatory Guidance ## Direction prospective ## When to Use - Receiving an SEC or FINRA examination notification letter and preparing a response - Organizing and producing documents in response to an initial document request list (IDR) - Responding to a deficiency letter or examination findings - Designing or conducting an internal mock examination program - Reviewing SEC or FINRA annual examination priorities for proactive compliance planning - Conducting the annual compliance review required under SEC Rule 206(4)-7 - Assessing whether the firm's compliance program, policies, and procedures are examination-ready - Preparing key personnel for staff interviews during an examination - Evaluating remediation progress after prior examination findings - Building an examination readiness checklist organized by functional area - Advising a newly registered firm on what to expect from its first regulatory examination ## Core Concepts ### SEC Examination Process (Division of Examinations) The SEC's Division of Examinations (formerly the Office of Compliance Inspections and Examinations, or OCIE) conducts examinations of registered entities including investment advisers, broker-dealers, transfer agents, clearing agencies, and self-regulatory organizations. The Division uses a risk-based approach to select firms for examination and to determine the scope and intensity of each exam. **Risk-based selection.** The Division selects firms for examination based on a range of risk indicators rather than examining every registrant on a fixed schedule. Selection criteria include: - **New registrant status** — Newly registered investment advisers and broker-dealers are frequently examined within the first one to three years of registration. These initial examinations assess whether the firm has implemented the compliance infrastructure described in its registration filings. - **Risk indicators and quantitative screens** — The Division uses data analytics to identify firms with characteristics associated with higher risk: rapid asset growth, concentrated portfolios, high employee turnover, customer complaint patterns, significant regulatory history, unusual fee structures, or material conflicts of interest. - **Tips, complaints, and referrals** — Complaints from investors, tips from whistleblowers (including those submitted under the SEC Whistleblower Program established by Section 21F of the Securities Exchange Act of 1934), and referrals from other SEC divisions or regulatory bodies can trigger cause examinations. - **Sweep examinations** — The Division periodically conducts industry-wide sweep examinations focused on a single issue or practice across many firms simultaneously. Recent sweep topics have included off-channel communications, Reg BI implementation, private fund fee practices, and ESG-related disclosures. **Types of examinations:** 1. **Routine/periodic examinations** — Scheduled examinations conducted as part of the Division's ongoing oversight program. These typically cover a broad range of compliance topics and may review multiple years of activity. 2. **Cause examinations** — Triggered by a specific complaint, tip, referral, or red flag. Cause examinations are typically narrower in scope, focused on the specific issue that prompted the examination, but can expand if additional problems are discovered. 3. **Sweep examinations** — Industry-wide examinations focused on a single topic. Sweep exams allow the Division to assess industry-wide compliance with a particular rule or to evaluate emerging risks across many firms. Results often inform future rulemaking or guidance. **Examination lifecycle:** 1. **Notification letter** — The examination begins with a notification letter (sometimes called an "announcement letter") sent to the firm. The letter identifies the examination team, provides an initial document request list (IDR), and specifies a deadline for document production (typically two to four weeks). For cause examinations, the notification may be abbreviated or, in rare circumstances, the examination may begin without advance notice. 2. **Document production** — The firm produces the requested documents, typically through a secure file-sharing platform. The initial IDR is often extensive (see the Document Production section below). The examination staff may issue supplemental document requests as they review the initial production. 3. **On-site or remote examination** — Examination staff conduct their review either on-site at the firm's offices or remotely (remote examinations became common during and after the COVID-19 pandemic and remain a standard option). The review includes analysis of documents, records, and data. 4. **Staff interviews** — Examiners conduct interviews with key personnel, typically including the Chief Compliance Officer (CCO), portfolio managers, traders, operations staff, and senior management. Interviews may be informal discussions or more structured questioning sessions. Firms should prepare interviewees by reviewing relevant policies and recent compliance activity, but should not coach witnesses to give scripted answers. 5. **Follow-up requests** — As the examination progresses, staff frequently issue additional document requests or ask clarifying questions based on their findings. Responsiveness and transparency during this phase are important. 6. **Exit conference** — Near the end of the examination, staff typically hold an exit conference with the firm to discuss preliminary observations and potential areas of concern. The exit conference is not a formal proceeding, and the observations discussed may change before a final determination is made. 7. **Outcome** — The examination concludes with one of several outcomes: (a) a no-action letter or no further action (the examination revealed no material issues); (b) a deficiency letter identifying compliance deficiencies and requesting a written response describing corrective actions; (c) a referral to the SEC's Division of Enforcement for potential enforcement action (reserved for more serious violations or patterns of non-compliance). **Typical duration.** SEC examinations typically last from several weeks to several months, depending on the firm's size, the scope of the examination, the complexity of issues discovered, and the responsiveness of the firm's document production. **Firms' rights during examination.** Firms have the right to: receive identification of the examination staff and their supervisors; understand the general scope of the examination; request reasonable extensions for document production deadlines (extensions are granted at the staff's discretion); have counsel present during interviews (though the SEC may interview individuals separately); and receive a closing communication describing the examination outcome. Firms may also submit a response to preliminary findings discussed at the exit conference before a deficiency letter is finalized. ### FINRA Examination Process FINRA (the Financial Industry Regulatory Authority) examines its member broker-dealer firms through its Risk Monitoring and Examination programs. As a self-regulatory organization (SRO), FINRA has direct authority to examine, sanction, and discipline its members — a key distinction from the SEC, which must refer potential enforcement actions to its Division of Enforcement. **Types of FINRA examinations:** 1. **Cycle examinat
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.