
The SEC censured OTC Link LLC and imposed a $575,000 civil penalty after finding that the broker-dealer repeatedly failed to establish, finalize and enforce technology-control policies required by Regulation SCI. The deficiencies affected areas including system security, access controls, network configuration, data-loss prevention and application vulnerability management, with some problems remaining unresolved after multiple SEC examinations.
U.S. Securities and Exchange Commission (SEC)
Official Release:
https://www.sec.gov/newsroom/press-releases/2026-91-sec-censures-otc-link-llc-repeated-compliance-failures-related-regulation-sci
NEWS:
The U.S. Securities and Exchange Commission censured New York-based OTC Link LLC, ordered it to cease and desist from future violations and imposed a $575,000 civil penalty for longstanding failures involving Regulation Systems Compliance and Integrity. OTC Link LLC is a registered broker-dealer, an indirect wholly owned subsidiary of OTC Markets Group Inc. and the operator of several alternative trading systems, including OTC Link ATS, a platform used for over-the-counter securities. According to the SEC's settled order, OTC Link ATS was an entity subject to Regulation SCI throughout the relevant period from August 2016 through March 2025. The Commission found that OTC Link lacked written policies and procedures reasonably designed to provide the capacity, integrity, resiliency, availability and security needed to preserve the platform's operational capability and support fair and orderly markets. The cited deficiencies involved account management, access controls, network-device security configuration, data-loss prevention, application vulnerability testing and remediation. Some required procedures remained in draft form instead of being formally adopted and enforced.
The duration and repetition of the compliance problems make the case more significant than an isolated documentation failure. SEC Division of Examinations staff reviewed OTC Link ATS several times and issued deficiency letters identifying apparent Regulation SCI violations. The order states that problems found during earlier examinations remained unresolved in later reviews. For example, the platform's access-control policy was identified as a draft during a fiscal-year 2016 examination, cited again in deficiency letters issued in 2019 and 2022, and had still not been formally established as of fiscal year 2023. The SEC found that this conduct violated Rules 1001(a)(1), 1001(a)(2) and 1001(a)(3), which require covered entities to maintain specified technology policies, periodically evaluate whether those controls are effective and promptly correct identified weaknesses. OTC Link retained third-party compliance consultants in 2024, and the order acknowledges that the company established additional required policies beginning in March 2025. These included procedures addressing vulnerability management, account and access controls and network-device configuration. OTC Link settled without admitting or denying the findings, except as to SEC jurisdiction and the subject matter of the proceeding.
The enforcement action is important because it focuses on technology governance rather than a publicly identified cyberattack, trading outage or quantified investor loss. Regulation SCI is designed to reduce the likelihood that weaknesses at important market infrastructure providers will develop into broader disruptions, delays, intrusions or market-integrity problems. The case therefore shows that an SCI entity can face enforcement exposure when essential controls remain incomplete or unenforced, even when the order does not attribute the penalty to a specific system failure. For broker-dealers, alternative trading systems and other regulated financial-technology operators, draft policies are not equivalent to operational controls: procedures must be approved, implemented, tested, reviewed and supported by evidence that identified deficiencies were corrected. For investors and issuers using OTC markets, the order does not establish that individual OTC securities or customer accounts were compromised, but it does highlight the importance of the infrastructure behind quotation and trading services. Market participants should distinguish between the risks of an individual OTC issuer and the separate operational, cybersecurity and compliance risks associated with the systems through which its securities are quoted or traded.
KEY POINTS:
- OTC Link LLC agreed to a censure, cease-and-desist order and $575,000 civil penalty.
- The SEC identified Regulation SCI deficiencies extending from August 2016 through March 2025.
- Weaknesses involved access controls, system security, network configuration, data-loss prevention and vulnerability management.
- SEC examiners repeatedly identified deficiencies, but some policies remained unfinished or unenforced for years.
- The order focuses on governance and remediation failures and does not identify a specific cyberattack or investor loss as the basis for the penalty.