WASHINGTON D.C. — In a regulatory enforcement action underscoring the strict operational and cybersecurity standards required of critical financial market infrastructure, the Securities and Exchange Commission (SEC) announced today that it has censured New York-based broker-dealer OTC Link LLC. The firm has been ordered to pay a $575,000 civil monetary penalty and has agreed to a cease-and-desist order to resolve charges stemming from nearly a decade of non-compliance with Regulation Systems Compliance and Integrity (SCI).

According to the SEC’s settled administrative order, OTC Link LLC repeatedly failed to establish, maintain, and enforce essential written policies and procedures required under federal securities laws for its alternative trading system (ATS), known as OTC Link ATS. The deficiencies—which spanned from August 2016 to March 2025—principally involved core operational safeguards, including system security, access controls, application vulnerability management, system testing, and timely remediation protocols.

The enforcement action highlights a persistent breakdown in corporate governance and regulatory responsiveness. Federal regulators revealed that despite repeated warnings, red flags, and examination findings issued by the SEC’s Division of Examinations over multiple years, OTC Link LLC failed to take prompt and effective corrective action.

Without admitting or denying the SEC’s findings, OTC Link LLC consented to the entry of the order, agreeing to the financial penalty, a formal censure, and undertakings to cease future violations of Regulation SCI.


Chronology of Non-Compliance: A Multi-Year Regulatory Timeline

The path to the September 2026 enforcement action reflects a prolonged cycle of regulatory oversight, repeated warnings, and unheeded examination findings. A detailed chronological review of the case highlights the protracted nature of the violations:

  • August 2016: The statutory timeline for the violations begins. According to the SEC order, this is when OTC Link LLC first fell out of full compliance with Regulation SCI mandates regarding the governance of its alternative trading system, failing to implement comprehensive, finalized written policies for system security and access control.
  • 2017–2020 (Periodic Examinations): During routine and cycle examinations conducted by the SEC’s Division of Examinations, agency staff reviewed the operations of OTC Link ATS. In multiple successive examination cycles during this period, SEC examiners identified and flagged specific required policies and procedures that the firm had either entirely omitted or left in a perpetual "draft" state. Rather than finalizing and enforcing these crucial guidelines, the firm allowed deficiencies to persist.
  • 2021–2023 (Continued Oversight and Stagnation): As examination staff returned for subsequent reviews, they discovered that prior warnings had gone largely unaddressed. Critical policies concerning application vulnerability management, testing, and remediation remained unfinalized. The firm’s internal compliance mechanisms failed to elevate these regulatory warnings to executive leadership for urgent resolution.
  • March 2025: The period of active, ongoing violations officially concludes following heightened scrutiny from regulatory authorities, prompting the formal referral of the matter to the SEC’s Division of Enforcement.
  • September 22, 2026: The SEC officially publicizes the settled administrative order, imposing the censure, the $575,000 civil penalty, and the cease-and-desist mandate against OTC Link LLC.

Supporting Data and Regulatory Mechanics: Decoding Regulation SCI

To understand the gravity of the SEC’s action against OTC Link LLC, it is necessary to examine the specific regulatory framework governing the infraction: Regulation Systems Compliance and Integrity (Regulation SCI). Adopted by the SEC in 2014, Regulation SCI was designed to strengthen the technological infrastructure of the U.S. securities markets. It applies to "SCI entities," which include self-regulatory organizations, alternative trading systems (ATSs) meeting certain volume thresholds, clearing agencies, and plan processors.

The Role of OTC Link ATS

OTC Link ATS plays a vital operational role in the United States financial ecosystem. As an alternative trading system specializing in over-the-counter (OTC) securities—including unlisted equities, pink sheet securities, and American Depositary Receipts (ADRs)—it provides the electronic infrastructure where broker-dealers can quote, negotiate, and execute trades outside of major national exchanges like the New York Stock Exchange or Nasdaq. Because thousands of micro-cap, foreign, and emerging companies rely on OTC markets for liquidity and price discovery, the technological integrity, security, and resiliency of OTC Link ATS are matters of systemic importance.

Specific Violations of Regulation SCI

The SEC’s order details specific breaches of three primary sub-rules under Rule 1001 of Regulation SCI:

  1. Rule 1001(a)(1) — Lack of Comprehensive Policies and Procedures:
    The rule mandates that each SCI entity establish, maintain, and enforce written policies and procedures reasonably designed to ensure that its SCI systems—and, where applicable, indirect SCI systems—have levels of capacity, integrity, resiliency, availability, and security adequate to maintain the entity’s operational capability and promote the maintenance of fair and orderly markets.

    • The Violation: OTC Link LLC lacked robust written policies and procedures covering foundational technological safeguards. Specifically, its frameworks governing system security, access controls, vulnerability management, testing, and remediation fell short of the regulatory threshold.
  2. Rule 1001(a)(2) — Periodic Review Requirements:
    Regulation SCI requires SCI entities to periodically review the effectiveness of the policies and procedures required under paragraph (a)(1) and to take prompt action to remedy any deficiencies.

    • The Violation: While OTC Link LLC may have intermittently reviewed its operational landscape, it failed to conduct meaningful, effective reviews of its compliance posture, allowing identified vulnerabilities to languish for years without structural correction.
  3. Rule 1001(a)(3) — Enforcement and Remediation:
    Entities are bound not merely to draft policies on paper, but to actively enforce them and promptly remediate identified gaps or vulnerabilities in their systems.

    • The Violation: The firm’s failure to act on the explicit warnings of SEC Division of Examinations staff directly violated the mandate for prompt remediation. Draft policies remained in limbo, and access control protocols were left unenforced.

Official Responses and Enforcement Philosophy

The enforcement action against OTC Link LLC serves as a public messaging vehicle for the SEC’s Division of Enforcement, particularly regarding the handling of examination findings. Regulatory authorities are increasingly signaling that ignoring feedback from examination staff carries severe institutional consequences.

Laura D’Allaird, Chief of the Division of Enforcement’s Cyber and Emerging Technologies Unit, issued a stern statement highlighting the rationale behind the penalty and the philosophical stance of the Commission:

"OTC Link’s continual failure to remediate deficiencies even after they were repeatedly flagged by Division of Examinations staff reflects a disregard for their findings and the overall examinations process and justifies a meaningful penalty," D’Allaird emphasized.

She added a direct warning to the broader financial technology sector: "All SCI entities are expected to take their regulatory responsibilities seriously and promptly fix issues when they’re identified."

The Cyber and Emerging Technologies Unit, which spearheaded the investigation, focuses heavily on holding market participants accountable for technological lapses, data security failures, and non-compliance with digital infrastructure rules. By targeting a prominent OTC market operator, the SEC is signaling that operational resilience is just as critical as financial solvency in maintaining market integrity.

Legal representatives for OTC Link LLC chose a settled resolution, opting to avoid protracted litigation by accepting the cease-and-desist order, the formal censure, and the financial penalty without admitting or denying the underlying findings. Industry analysts note that such settlements allow firms to draw a line under historical regulatory compliance failures while committing internal resources toward upgrading their technological and compliance infrastructure.


Broader Implications for Market Infrastructure and Fintech

The $575,000 penalty levied against OTC Link LLC, while modest relative to multi-million-dollar fines seen in banking and high-frequency trading enforcement, carries profound symbolic and practical implications for the alternative trading system (ATS) and over-the-counter (OTC) marketplace.

1. The Real Cost of "Draft" Compliance

One of the most striking revelations in the SEC’s order is that certain required policies and procedures remained in "draft form" across multiple examination cycles. For years, compliance and IT departments across Wall Street have grappled with resource constraints, sometimes treating internal documentation as a secondary priority compared to revenue-generating operations.

The SEC’s action demonstrates that leaving policies in draft status—or failing to enforce documented procedures—is treated by regulators not as a minor administrative oversight, but as a substantive regulatory breach carrying legal liability. Financial institutions are now on notice that regulatory patience has limits; repeated observations by examination staff must trigger immediate, documented remediation projects.

2. Heightened Scrutiny on ATS and Cyber Resilience

Alternative trading systems operate in a complex regulatory grey area, bridging the gap between traditional exchanges and private broker-dealer networks. As retail and institutional participation in over-the-counter markets has evolved, regulators have steadily tightened the noose around ATS technological governance.

Regulation SCI was originally crafted in the wake of major technological glitches—such as the 2012 Facebook IPO Nasdaq mishap and various high-profile exchange outages—to prevent systemic cascading failures. By applying Regulation SCI standards rigorously to OTC market operators, the SEC is reinforcing the principle that any platform handling significant trade volume must maintain elite-tier cybersecurity and operational resilience.

3. Increased Inter-Division Synergy Within the SEC

The case underscores the seamless operational pipeline between the SEC’s Division of Examinations and the Division of Enforcement. Examination staff act as the "eyes and ears" on the ground, conducting on-site and remote reviews of broker-dealers and ATS platforms.

When examination findings are repeatedly ignored or treated with indifference, the matter is increasingly escalated to enforcement attorneys. This inter-division cooperation means that compliance failures uncovered during routine audits can quickly transform into formal investigations, substantial financial penalties, and public censures.

4. Compliance Culture and Boardroom Accountability

For compliance officers, chief information security officers (CISOs), and executive leadership teams across the financial sector, the OTC Link LLC case serves as a valuable case study in risk management. Boardrooms must ensure that audit findings—whether originating from internal compliance reviews or external regulatory bodies—are met with adequate budgetary resources, executive oversight, and strict accountability.

Firms operating under Regulation SCI must verify not only that their technical controls (such as multi-factor authentication, intrusion detection systems, and vulnerability patch management) are operational, but also that their paper trail—the formal written policies and procedures—accurately reflects and enforces those technical realities.


Conclusion

The SEC’s September 2026 administrative order against OTC Link LLC closes the book on a multi-year chapter of regulatory non-compliance, but it opens a broader conversation about technological governance in modern financial markets. As electronic trading venues continue to expand in complexity and volume, the regulatory tolerance for delayed remediation, unfinalized policies, and unheeded examination warnings is effectively zero.

For OTC Link LLC, the $575,000 penalty and formal censure mark the conclusion of a costly regulatory reckoning. For the rest of the financial industry, the message from Washington is unmistakable: regulatory compliance is not a static checklist to be deferred, but an ongoing, enforceable commitment to the security, integrity, and stability of the global financial system.