SEC Fines OTC Link LLC $575,000 for Nearly a Decade of Regulation SCI Failures
WASHINGTON D.C. — In a regulatory enforcement action underscoring the strict operational mandates governing alternative trading systems, the U.S. Securities and Exchange Commission (SEC) announced today that it has censured New York-based broker-dealer OTC Link LLC. The firm has been ordered to pay a $575,000 civil penalty to resolve charges stemming from systemic and longstanding violations of Regulation Systems Compliance and Integrity (Regulation SCI).
According to the SEC’s settled administrative order, OTC Link LLC—which operates the OTC Link ATS, a prominent electronic alternative trading system (ATS) facilitating transactions in over-the-counter (OTC) securities—neglected core regulatory requirements for nearly nine years. Specifically, the firm failed to establish, maintain, and enforce written policies and procedures crucial for safeguarding its technological infrastructure, including mandates regarding system security, access controls, application vulnerability management, routine testing, and timely remediation.
Despite repeated warnings, examinations, and direct feedback from the SEC’s Division of Examinations, the firm routinely left essential policies in draft form or failed to enforce them altogether. To settle the charges, OTC Link LLC agreed to a cease-and-desist order, a formal censure, and the $575,000 monetary penalty without admitting or denying the SEC’s findings.
Main Facts of the Case
The regulatory action centers on OTC Link LLC’s operation of its alternative trading system, OTC Link ATS, which serves as a critical technological backbone for the over-the-counter equities market. Regulation SCI was adopted by the SEC to strengthen the technological infrastructure of the U.S. securities markets, reducing the frequency and impact of system outages, cyber threats, and technological glitches.
Under Regulation SCI, certain key market participants—referred to as "SCI entities," which include self-regulatory organizations, clearing agencies, alternative trading systems, and major market data processors—must meet rigorous standards. These entities are legally required to establish robust written policies and procedures to ensure their core technological systems possess adequate capacity, integrity, resiliency, availability, and security.
Core Regulatory Breaches
The SEC’s investigation revealed that OTC Link LLC fell short of these mandates across multiple operational categories between August 2016 and March 2025. The core violations include:
- Deficient Written Policies and Procedures: The firm failed to maintain comprehensive, finalized written procedures for system security and access controls, leaving its core platforms vulnerable to unauthorized access and operational disruptions.
- Vulnerability Management Failures: OTC Link LLC neglected to implement adequate standards for application vulnerability management, failing to systematically identify, test, and remediate software and network weaknesses.
- Neglect of Review Mandates: Under Rule 1001(a)(2) of Regulation SCI, entities must periodically review the effectiveness of their required policies and procedures. The firm failed to conduct these necessary evaluations.
- Failure to Remedy Deficiencies: The firm repeatedly failed to take prompt, corrective action to remedy known deficiencies, violating Rule 1001(a)(3).
Despite the sensitive nature of running an electronic marketplace for public securities, OTC Link LLC’s compliance framework suffered from structural neglect that persisted over multiple years, directly challenging the integrity of the alternative trading landscape.
Chronology of Regulatory Oversight and Non-Compliance
The timeline of the enforcement action highlights a prolonged pattern of unheeded warnings from federal regulators. The breakdown of events illustrates how administrative oversight repeatedly identified gaps that the firm failed to close.
August 2016: The Onset of Violations
According to the SEC’s administrative order, the compliance failures began in August 2016. As OTC Link LLC scaled and maintained its electronic trading operations, it neglected to draft and enforce the comprehensive technical policies required under Regulation SCI. These omissions compromised the foundational security and resiliency structures mandated by federal statute.
2016 – 2024: Repeated Examination Findings
Throughout the multi-year period spanning from August 2016 to March 2025, staff from the SEC’s Division of Examinations conducted routine and targeted examinations of OTC Link ATS.
During multiple exam cycles, SEC examiners identified specific regulatory shortfalls. They explicitly flagged required policies and procedures that OTC Link LLC had either entirely omitted or left sitting indefinitely in draft form. Crucially, rather than finalizing and enforcing these documents, the firm allowed the gaps to persist, treating draft documents as acceptable long-term placeholders.
March 2025: Conclusion of the Examination Window
The relevant period of non-compliance formally concluded in March 2025, following ongoing regulatory scrutiny that eventually transitioned from the Division of Examinations to the Division of Enforcement’s Cyber and Emerging Technologies Unit.
September 22, 2026: Formal Settlement and Penalties
The SEC officially announced the settled administrative order. OTC Link LLC agreed to accept the cease-and-desist order, accept the formal censure, and pay the $575,000 civil monetary penalty, bringing a close to the near-decade-long regulatory dispute.
Supporting Data and Regulatory Framework
To fully understand the weight of the SEC’s action against OTC Link LLC, it is necessary to examine the specific regulatory framework governing alternative trading systems and the financial metrics associated with the enforcement outcome.
Key Rules Under Regulation SCI
The enforcement action is anchored on three specific provisions of Regulation SCI:
- Rule 1001(a)(1): Requires SCI entities to establish, maintain, and enforce written policies and procedures reasonably designed to ensure that their SCI systems (and, for security standards, indirect SCI systems) have levels of capacity, integrity, resiliency, availability, and security adequate to maintain their operational capability and promote fair and orderly markets.
- Rule 1001(a)(2): Mandates that SCI entities periodically review the effectiveness of the policies and procedures required under paragraph (a)(1) and take prompt action to remedy any deficiencies.
- Rule 1001(a)(3): Requires entities to establish written policies and procedures to ensure adherence to testing requirements and swift remediation of identified structural or operational vulnerabilities.
Financial and Administrative Summary
- Entity Snatched: OTC Link LLC (New York-based broker-dealer and operator of OTC Link ATS).
- Civil Monetary Penalty: $575,000.
- Duration of Violations: Approximately 8 years and 7 months (August 2016 to March 2025).
- Administrative Sanctions: Cease-and-desist order, formal censure, and civil penalty.
- Admission of Guilt: None (settled without admitting or denying the findings).
Official Responses and Regulatory Posture
The enforcement action drew sharp commentary from senior leadership within the SEC, emphasizing that repeated disregard for examination findings will trigger aggressive punitive measures.
Laura D’Allaird, Chief of the Division of Enforcement’s Cyber and Emerging Technologies Unit, did not mince words when discussing the behavior of OTC Link LLC during the multi-year examination process.
"OTC Link’s continual failure to remediate deficiencies even after they were repeatedly flagged by Division of Examinations staff reflects a disregard for their findings and the overall examinations process and justifies a meaningful penalty," stated Laura D’Allaird.
D’Allaird further underscored the broader expectations the Commission holds for all entities operating within the electronic market infrastructure:
"All SCI entities are expected to take their regulatory responsibilities seriously and promptly fix issues when they’re identified."
The statements highlight a growing regulatory intolerance for firms that treat examination deficiency letters as optional suggestions rather than urgent compliance mandates. By elevating the matter from the Division of Examinations to the Division of Enforcement, the SEC signaled that ignoring iterative regulatory feedback carries severe legal and financial consequences.
Broader Implications for Market Participants
The SEC’s settlement with OTC Link LLC carries profound implications for alternative trading systems, broker-dealers, and other designated SCI entities operating within the United States financial ecosystem.
1. Zero Tolerance for "Draft" Compliance Policies
A critical takeaway from this enforcement action is the unacceptability of maintaining "draft" policies and procedures over extended periods. For years, OTC Link LLC relied on unfinalized documents to satisfy its internal governance frameworks. The SEC’s action makes it unequivocally clear that draft documents do not fulfill the legal requirements of Regulation SCI. Financial institutions must ensure that all mandated policies are fully drafted, formally approved, actively enforced, and regularly audited.
2. The Cost of Ignoring Examination Findings
Examinations conducted by the SEC’s Division of Examinations are designed to be cooperative mechanisms that allow firms to correct operational errors before they result in systemic market failures. When a firm repeatedly ignores examination findings—as OTC Link LLC did over multiple exam cycles—it crosses the line from operational oversight to willful non-compliance. This case serves as a warning that unresolved examination comments can quickly transform into formal enforcement investigations and costly civil penalties.
3. Heightened Focus on Cyber and Technological Resilience
As modern equity and over-the-counter markets rely increasingly on complex digital infrastructure, regulatory bodies like the SEC remain hyper-focused on technological security, access control, and vulnerability management. Alternative trading systems are viewed as critical market utilities. Any vulnerability in their architecture threatens the broader goal of maintaining fair, orderly, and efficient markets.
4. Compliance Culture and Proactive Remediation
For compliance officers across Wall Street and the broader financial services industry, this case reinforces the necessity of building a proactive remediation culture. When internal audits or federal examiners identify gaps in system security, access controls, or risk management frameworks, firms must mobilize immediate resources to close those gaps. Delaying remediation not only compounds regulatory exposure but also invites substantial financial penalties and reputational damage.
As the financial markets continue to digitize, the SEC’s enforcement division has shown that it will vigorously police the technological boundaries of the market, ensuring that entities operating core trading infrastructure are held to the highest standards of system integrity and regulatory accountability.
