SEC Penalizes OTC Link LLC $575,000 for Nearly a Decade of Regulation SCI Violations
WASHINGTON, D.C. — In a regulatory enforcement action underscoring the strict compliance demands placed on critical market infrastructure, the U.S. Securities and Exchange Commission (SEC) announced today that it has censured New York-based broker-dealer OTC Link LLC. The firm has been ordered to pay a $575,000 civil monetary penalty and has agreed to a cease-and-desist order to resolve longstanding violations of Regulation Systems Compliance and Integrity (Regulation SCI).
According to the SEC’s settled administrative order, OTC Link LLC—which operates OTC Link ATS, a prominent alternative trading system (ATS) facilitating transactions in over-the-counter (OTC) securities—systematically failed over a period spanning nearly nine years to establish, maintain, and enforce essential written policies and procedures mandated by federal securities laws. The deficiencies specifically targeted core technological safeguards, including system security, access controls, application vulnerability management, system testing, and timely remediation protocols.
Despite repeated warnings, examinations, and direct feedback from the SEC’s Division of Examinations over multiple cycles, the firm repeatedly left required operational procedures in draft form, failing to finalize, implement, or enforce them. Without admitting or denying the SEC’s findings, OTC Link LLC consented to the regulatory penalties, marking a significant milestone in federal oversight of alternative trading systems and technological resilience in secondary markets.
Main Facts of the Case
The regulatory action centers on OTC Link LLC’s operation of its alternative trading system, OTC Link ATS, which serves as an electronic marketplace connecting broker-dealers to trade unlisted, over-the-counter securities. Because such platforms form the technological backbone of substantial portions of the U.S. financial ecosystem, they are subject to rigorous operational standards designed to prevent technological failures, cyber vulnerabilities, and market disruptions.
Under Regulation SCI—promulgated by the SEC to strengthen the technology infrastructure of the U.S. securities markets—designated entities, known as "SCI entities," must adhere to strict baseline requirements concerning their technological systems. These rules are designed to ensure that core systems possess adequate capacity, integrity, resiliency, availability, and security.
The SEC’s investigation revealed that between August 2016 and March 2025, OTC Link LLC fell short of these mandates in several critical areas:
- System Security and Access Control: The firm failed to maintain comprehensive, written policies governing how access to its SCI systems was granted, monitored, and restricted, leaving potential vulnerabilities exposed.
- Vulnerability Management and Testing: Procedures concerning how application vulnerabilities were identified, tested, patched, and remediated were either missing entirely, incomplete, or left lingering in draft statuses without formal adoption.
- Periodic Review Failures: The company neglected to conduct mandated periodic reviews to assess the operational effectiveness of its existing technological policies and procedures, running afoul of federal requirements to continuously monitor operational readiness.
By operating for nearly a decade with incomplete and unenforced technological safeguards, OTC Link LLC violated multiple provisions of Regulation SCI, specifically Rules 1001(a)(1), 1001(a)(2), and 1001(a)(3).
Chronology of Regulatory Oversight and Failures
The timeline established by the SEC’s administrative order highlights a prolonged pattern of inaction in the face of direct regulatory intervention. The violations were not isolated or fleeting oversight gaps; rather, they persisted across multiple examination cycles over an extended period.
- August 2016: The statutory timeframe of the violations begins. During this period, the baseline requirements of Regulation SCI applied to OTC Link ATS as an active alternative trading system, requiring comprehensive written frameworks for security, capacity, and resiliency.
- Interim Examination Cycles (2016–2024): Across multiple routine examination cycles, staff members from the SEC’s Division of Examinations conducted on-site and remote reviews of OTC Link ATS. During each of these examinations, regulatory examiners identified specific required policies and procedures that the firm had either omitted entirely or left unfinalized in draft form.
- Repeated Feedback and Deficiencies Noted: Examiners repeatedly flagged these gaps to firm management, pointing out that essential security, access control, and vulnerability remediation procedures were missing or lacked enforcement mechanisms. Despite receiving explicit, actionable feedback from federal regulators, OTC Link LLC failed to take prompt or comprehensive corrective action.
- March 2025: The temporal boundary of the ongoing failures concludes, following sustained scrutiny from the SEC that ultimately transitioned from the Division of Examinations to the Division of Enforcement’s Cyber and Emerging Technologies Unit.
- September 22, 2026: The SEC formally releases its settled order, imposing a $575,000 civil penalty, a formal censure, and a cease-and-desist order against OTC Link LLC.
Supporting Data and Regulatory Framework
To fully understand the gravity of the SEC’s action against OTC Link LLC, it is necessary to examine the regulatory architecture governing market technology. Regulation SCI was adopted by the Commission in November 2014 to reduce the frequency and severity of technological outages, cyber incidents, and system compliance failures that have the potential to disrupt fair and orderly markets.
Key Rules Violated Under Regulation SCI:
- Rule 1001(a)(1): Mandates that each SCI entity establish, maintain, and enforce written policies and procedures reasonably designed to ensure that its SCI systems—and, for security standards, its indirect SCI systems—have levels of capacity, integrity, resiliency, availability, and security adequate to maintain the entity’s operational capability and promote the maintenance of fair and orderly markets.
- Rule 1001(a)(2): Requires SCI entities to periodically review the effectiveness of the policies and procedures required under paragraph (a)(1) and to take prompt action to remedy any deficiencies.
- Rule 1001(a)(3): Requires policies and procedures to be designated as such, approved by senior management, and maintained in written form to ensure accountability and continuity.
The $575,000 civil penalty, while modest compared to penalties levied against massive wirehouses or multi-national exchanges, reflects the specific nature of administrative settlements where cooperation and the resolution of ongoing deficiencies are factored into the final sanction. However, the accompanying censure and cease-and-desist order carry significant reputational and compliance weight for a specialized broker-dealer operating in the over-the-counter space.
Official Responses and Regulatory Commentary
The enforcement action drew sharp commentary from senior SEC leadership, emphasizing that regulatory examinations and supervisory feedback cannot be ignored by market participants.
Laura D’Allaird, Chief of the Division of Enforcement’s Cyber and Emerging Technologies Unit, did not mince words regarding OTC Link LLC’s protracted non-compliance.
"OTC Link’s continual failure to remediate deficiencies even after they were repeatedly flagged by Division of Examinations staff reflects a disregard for their findings and the overall examinations process and justifies a meaningful penalty," stated Ms. D’Allaird in the SEC’s official press release. "All SCI entities are expected to take their regulatory responsibilities seriously and promptly fix issues when they’re identified."
The explicit focus on the "disregard for [examinations] findings" highlights a core concern for federal regulators: the integrity of the examination process itself. When firms undergo routine or targeted examinations, the interactive feedback loop between examiners and regulated entities relies on good-faith remediation. By letting flagged deficiencies languish in draft form over multiple examination cycles, OTC Link LLC crossed the line from technical compliance lapses into institutional unresponsiveness.
Representatives for OTC Link LLC consented to the entry of the SEC’s order without admitting or denying the findings, a standard legal mechanism in many administrative settlements. By accepting the censure and financial penalty, the firm effectively brings the administrative proceeding to a close, avoiding protracted litigation while committing to resolve any lingering technological gaps under the watchful eye of its compliance officers.
Broader Implications for Market Infrastructure and Alternative Trading Systems
The SEC’s action against OTC Link LLC carries profound implications for the broader financial technology and alternative trading system landscape. As markets become increasingly digitized, automated, and interconnected, the regulatory perimeter has expanded aggressively to encompass technology governance, cybersecurity, and operational resilience.
1. Zero Tolerance for Laggard Remediation
The clearest takeaway from this enforcement action is that receiving examination findings without immediate follow-up action is a dangerous compliance gamble. Financial institutions subject to Regulation SCI or similar technological mandates can no longer treat examiner feedback as advisory suggestions. Remediation must be prompt, verifiable, and documented.
2. Heightened Scrutiny of OTC and Alternative Trading Systems
While major national securities exchanges (such as the NYSE or Nasdaq) frequently capture headlines regarding market structure and technology, alternative trading systems like OTC Link ATS handle vital segments of liquidity, particularly for microcap, pink sheet, and unlisted securities. Ensuring that these platforms maintain robust access controls and vulnerability management is critical to protecting retail and institutional investors who navigate the over-the-counter markets.
3. The Role of Specialized Enforcement Units
The involvement of the SEC’s Division of Enforcement’s Cyber and Emerging Technologies Unit signals that regulatory enforcement in the fintech and market-structure space is becoming increasingly specialized. As cyber threats, software vulnerabilities, and complex algorithmic routing systems evolve, enforcement divisions are deploying technical expertise to audit not just financial books and records, but the underlying code, access logs, and security protocols of modern financial platforms.
4. Compliance Culture and Governance
For compliance officers and chief technology officers (CTOs) across the financial sector, the case serves as a cautionary tale regarding the dangers of "paper compliance"—leaving vital policies in draft status without operational enforcement. Regulators are increasingly looking past the existence of written documentation to test whether those policies are actively enforced, regularly reviewed, and adapted to emerging technological threats.
As financial markets continue to modernize, the line between technology operations and regulatory compliance has vanished. The SEC’s $575,000 penalty against OTC Link LLC stands as a stark reminder that the digital infrastructure supporting modern trading must meet rigorous, enforceable standards of security, resilience, and accountability.
