SERIES 65 • LAWS, REGULATIONS, AND GUIDELINES

Apply AML And Cybersecurity Rules — Identify AML, cybersecurity, privacy, and business continuity obligations.

Understanding the regulatory framework that protects financial markets from illicit activity, data breaches, and operational disruptions.

Historical Context & Motivation

Financial markets have long been vulnerable to exploitation by criminal enterprises seeking to launder proceeds from illegal activities. The modern framework governing anti-money laundering (AML), cybersecurity, privacy, and business continuity did not emerge all at once; rather, it evolved through a series of legislative responses to national crises, terrorist attacks, and technological disruption. Each major event exposed gaps in the regulatory architecture that demanded new statutes, rules, and supervisory expectations for investment advisers, broker-dealers, and other financial intermediaries.

1970
Bank Secrecy Act (BSA)
Congress enacted the BSA, requiring financial institutions to maintain records and file reports on certain transactions, creating the foundation for AML compliance in the United States.
1999
Gramm-Leach-Bliley Act (GLBA)
The GLBA imposed privacy obligations on financial institutions, requiring them to disclose information-sharing practices and protect consumer nonpublic personal information (NPI).
2001
USA PATRIOT Act
In response to the September 11 attacks, the PATRIOT Act expanded AML requirements to include investment advisers and broker-dealers, mandated Customer Identification Programs (CIPs), and strengthened Suspicious Activity Report (SAR) obligations.
2015
SEC Cybersecurity Guidance
The SEC issued guidance and conducted examinations emphasizing that registered investment advisers must adopt written cybersecurity policies, conduct risk assessments, and protect client data from unauthorized access.
2023
FinCEN AML Rule for Investment Advisers
FinCEN proposed comprehensive AML/CFT rules explicitly covering SEC-registered investment advisers, requiring full AML programs, SAR filings, and compliance with the Customer Due Diligence (CDD) Rule.

This historical trajectory reveals a fundamental question that the Series 65 examination addresses: what specific obligations do investment adviser representatives bear to prevent money laundering, protect client data, safeguard privacy, and ensure operational resilience? Understanding these obligations is not merely an exercise in memorization—it reflects the fiduciary and regulatory expectations that define professional conduct in the modern advisory landscape.

Core Principles & Definitions

The regulatory framework surrounding AML, cybersecurity, privacy, and business continuity rests on several foundational principles that investment advisers and their representatives must internalize. These principles operate as interlocking safeguards: AML rules prevent the financial system from being used as a conduit for illicit funds; cybersecurity obligations protect firms and their clients from data theft and operational sabotage; privacy regulations ensure that sensitive personal information is handled with appropriate care; and business continuity planning guarantees that advisory services can withstand disruptions ranging from natural disasters to cyberattacks.

1

Anti-Money Laundering (AML)

AML encompasses the policies, procedures, and controls designed to detect and prevent the conversion of illegally obtained funds into ostensibly legitimate assets. Key components include Customer Identification Programs (CIP), Customer Due Diligence (CDD), Suspicious Activity Reports (SARs), and Currency Transaction Reports (CTRs).
2

Cybersecurity Obligations

Investment advisers must implement written policies and procedures to protect client data and firm systems from unauthorized access. This includes conducting regular risk assessments, encrypting sensitive data, managing vendor access, training employees, and establishing incident response plans.
3

Privacy (Regulation S-P)

Under Regulation S-P, SEC-registered investment advisers must deliver initial and annual privacy notices to clients describing how they collect, share, and protect nonpublic personal information (NPI). Clients generally have the right to opt out of certain information-sharing arrangements with nonaffiliated third parties.
4

Business Continuity Planning (BCP)

Firms must develop and maintain business continuity plans that address how they will continue to operate during significant disruptions. BCPs typically cover data backup and recovery, alternative communication channels, succession planning for key personnel, and client notification procedures.
KEY TAKEAWAY
Think of these four obligations as the four walls of a vault protecting the financial system. AML is the front door that screens who enters; cybersecurity is the alarm system monitoring for intrusions; privacy is the lock on each individual safety deposit box; and business continuity is the structural reinforcement ensuring the vault remains standing even during an earthquake. Remove any single wall, and the entire structure is compromised. For the Series 65, remember that investment adviser representatives must understand all four obligations as part of their fiduciary and regulatory duties.

The AML Compliance Framework — Visual Overview

This diagram illustrates the sequential AML compliance process that investment advisers must follow: beginning with Customer Identification (CIP) at account opening, proceeding through Customer Due Diligence (CDD), and continuing with ongoing monitoring that either triggers a SAR filing or confirms normal activity requiring continued surveillance.

The AML compliance framework depicted above represents the sequential gatekeeping process that investment adviser representatives must understand. At account opening, the firm collects identifying information under its Customer Identification Program (CIP)—typically requiring the client's name, date of birth, address, and government-issued identification number. The Customer Due Diligence (CDD) phase deepens this inquiry by assessing the client's risk profile, identifying beneficial owners of legal entity accounts (anyone holding 25% or more), and understanding the expected nature and purpose of the account relationship. Ongoing monitoring then ensures that actual transaction patterns align with the client's stated profile. When discrepancies arise—such as unexplained large transfers, structuring below reporting thresholds, or transactions involving sanctioned jurisdictions—the firm must file a Suspicious Activity Report (SAR) with the Financial Crimes Enforcement Network (FinCEN). Critically, investment advisers are prohibited from disclosing the existence of a SAR to the subject of the report—a concept known as the tipping off prohibition.

How the Regulatory Mechanisms Work

AML Program Requirements

Under the Bank Secrecy Act as amended by the USA PATRIOT Act, financial institutions—including investment advisers—must establish and maintain an AML compliance program containing four minimum elements. First, the firm must develop internal policies, procedures, and controls reasonably designed to prevent the firm from being used for money laundering or terrorist financing. Second, it must designate a compliance officer responsible for day-to-day administration of the program. Third, the firm must provide ongoing training to appropriate personnel so they can recognize red flags associated with money laundering. Fourth, the firm must conduct independent testing—either internally by personnel not involved in AML administration or externally through third-party auditors—to verify the program's effectiveness.

Cybersecurity Regulatory Expectations

While the SEC has not promulgated a single comprehensive cybersecurity regulation specifically for investment advisers, the Commission has used its examination authority and enforcement actions to establish clear expectations. The SEC's Office of Compliance Inspections and Examinations (OCIE, now the Division of Examinations) has outlined several pillars of an adequate cybersecurity program: maintaining a written information security policy; conducting periodic risk assessments; implementing access controls and authentication procedures; protecting client data in transit and at rest through encryption; managing third-party vendor cybersecurity risks; establishing an incident response plan; and training employees to recognize phishing, social engineering, and other attack vectors. State securities regulators have issued parallel model rules through NASAA, requiring investment advisers registered at the state level to adopt similar cybersecurity protections.

Privacy Obligations Under Regulation S-P

Regulation S-P, adopted under the authority of the Gramm-Leach-Bliley Act, requires SEC-registered investment advisers to deliver a privacy notice to each client at the time of establishing the advisory relationship and annually thereafter. This notice must clearly describe the categories of nonpublic personal information (NPI) collected, the categories of third parties with whom the information may be shared, and the firm's policies for protecting the confidentiality and security of that information. If the adviser shares NPI with nonaffiliated third parties in ways that fall outside certain exceptions—such as servicing the client's account or complying with legal obligations—the firm must provide clients with a reasonable opportunity to opt out before such sharing occurs. Additionally, Regulation S-P's Safeguards Rule requires firms to adopt written policies and procedures to protect the security and confidentiality of client records and information.

Business Continuity Planning

Business continuity planning ensures that an advisory firm can maintain or rapidly restore critical operations during disruptions. While FINRA Rule 4370 explicitly requires broker-dealers to maintain BCPs, the SEC and state regulators expect investment advisers to maintain comparable plans as part of their fiduciary duty to clients. A robust business continuity plan (BCP) typically addresses data backup and recovery procedures, alternative communication systems for reaching clients and counterparties, relocation plans for employees, financial and operational assessments to determine the firm's ability to operate during disruptions, succession planning for key personnel, and regulatory reporting obligations during crises. The plan should be reviewed and updated at least annually, with material changes communicated to relevant stakeholders.

Red Flags, Reporting Thresholds & Classification

The four pillars of regulatory compliance for investment advisers—AML, Cybersecurity, Privacy, and Business Continuity—each with their key elements, common triggers or threats, governing authorities, and critical reminders.

AML Red Flags in Investment Advisory Practice

For the Series 65 examination, you should be able to recognize common red flags that may indicate money laundering activity. Structuring—also known as "smurfing"—occurs when a client deliberately breaks transactions into amounts below the $10,000 Currency Transaction Report (CTR) threshold to avoid triggering a filing. Other red flags include clients who are reluctant to provide identifying information, clients who engage in frequent wire transfers to or from high-risk jurisdictions, accounts held through complex layered structures of shell entities with no apparent business purpose, and clients whose stated investment objectives are inconsistent with their transaction patterns. A client who claims to be a conservative retiree but initiates rapid, high-volume trading in speculative instruments warrants closer scrutiny. The presence of a red flag does not automatically mean money laundering is occurring, but it does trigger an obligation to investigate and, if warranted, file a SAR.

Key AML reporting obligations and their triggers, deadlines, and filing destinations
Report TypeTrigger ThresholdFiling DeadlineFiled With
Currency Transaction Report (CTR)Cash transactions exceeding $10,00015 calendar daysFinCEN
Suspicious Activity Report (SAR)Suspicious transactions ≥ $5,000 (or any amount if terrorist financing suspected)30 calendar days from detectionFinCEN
OFAC Blocked TransactionAny transaction involving SDN List individuals or entities10 business daysOFAC

Worked Example: Identifying and Responding to a Red Flag

Consider the following scenario that an investment adviser representative might encounter in practice, and observe how the regulatory obligations discussed in this lesson apply in a step-by-step analysis.

Scenario: Unusual Activity in a New Client Account
1
Step 1 — Identify the FactsMarcus, an IAR at a state-registered investment advisory firm, opens an account for a new client, Elena. During onboarding, Elena provides her name and date of birth but is reluctant to provide a Social Security number, offering instead a foreign passport. Within two weeks of opening the account, Elena wires $48,000 from an overseas bank in a jurisdiction known for weak AML controls and immediately requests that $45,000 be wired to a different account held by a third party she describes only as a 'business associate.'
Multiple red flags present: reluctance to provide ID, high-risk jurisdiction wire, rapid third-party transfer.
2
Step 2 — Apply CIP and CDD RequirementsMarcus's firm must verify Elena's identity under its CIP. A foreign passport may be acceptable as a form of identification, but the firm should still attempt to obtain a taxpayer identification number and verify the identity through documentary or non-documentary methods. Under CDD, the firm should assess Elena's risk profile as elevated given the high-risk jurisdiction source of funds and the immediate request for a third-party wire. If Elena is acting on behalf of a legal entity, the firm must also identify any beneficial owners holding 25% or more of the entity.
CIP verification is ongoing; CDD assessment classifies Elena as a high-risk client.
3
Step 3 — Evaluate SAR Filing ObligationThe combination of red flags—reluctance to provide identification, funds originating from a high-risk jurisdiction, and an immediate request to transfer funds to a third party with no clear relationship—constitutes suspicious activity. Because the transaction amount exceeds $5,000, Marcus's firm must file a SAR with FinCEN. The SAR must be filed within 30 calendar days of the date the firm first detects the suspicious activity. Marcus should document all facts supporting the filing and preserve records for at least five years.
SAR filing required within 30 days of detection; records retained for 5 years.
4
Step 4 — Apply the Tipping-Off ProhibitionMarcus must not inform Elena that a SAR has been filed or is being considered. The tipping-off prohibition is a critical component of AML law; disclosing the existence of a SAR to the subject of the report is a federal offense. Marcus may, however, refuse to process the wire transfer if the firm's policies authorize such action, but he should not explain that the refusal is related to a SAR. He should consult with the firm's designated AML compliance officer before taking action.
No disclosure of SAR to Elena—violation of the tipping-off prohibition is a federal offense.
5
Step 5 — Consider Privacy and Cybersecurity DimensionsThroughout this process, Marcus must ensure that Elena's nonpublic personal information remains protected under Regulation S-P. The privacy notice should have been delivered at the time the account was established. All client data—including the SAR-related documentation—must be stored securely in accordance with the firm's cybersecurity policies, with access restricted to authorized personnel. If the firm's investigation reveals that Elena's account was compromised or that a data breach occurred, the incident response plan must be activated.
Privacy notice delivered; SAR documentation secured under cybersecurity protocols; all four pillars engaged.

Comparing Obligations Across Entity Types

One source of confusion on the Series 65 examination is the distinction between obligations that apply to broker-dealers versus those that apply to investment advisers, and between federal and state registration contexts. While the core principles are similar, the specific regulatory requirements and enforcement mechanisms can differ significantly. The table below highlights these distinctions across the four compliance pillars.

Comparison of compliance obligations across entity types
ObligationBroker-DealersSEC-Registered IAsState-Registered IAs
AML ProgramRequired under BSA/PATRIOT Act; supervised by FINRAFinCEN rules expanding AML to RIAs (being finalized); SEC examination focusSubject to state requirements; many states adopt NASAA model rules
SAR FilingMandatory; filed with FinCENExpected under expanding FinCEN rules; voluntary filing currently encouragedVaries by state; voluntary filing encouraged
CybersecurityFINRA rules and SEC examination; Reg S-ID for identity theftSEC Cybersecurity Risk Alert guidance; proposed SEC rulesNASAA cybersecurity model rule; state-specific requirements
Privacy (Reg S-P)Fully applicable; initial and annual notices requiredFully applicable; initial and annual notices requiredState-level equivalents; many mirror Reg S-P requirements
Business ContinuityFINRA Rule 4370 mandates BCPExpected as part of fiduciary duty; SEC examination focusExpected as best practice; some states mandate BCPs
KEY TAKEAWAY
The regulatory landscape for investment advisers is converging with that of broker-dealers. FinCEN's expanding rules and SEC examination priorities are steadily closing the gap between what is expected of broker-dealers and what is expected of investment advisers. For the Series 65, approach these obligations with the understanding that even where a formal rule may not yet exist for state-registered IAs, the fiduciary standard effectively imposes a comparable duty of care regarding AML, cybersecurity, privacy, and business continuity.

Connecting to Advanced Regulatory Theory

The obligations discussed in this lesson form the first layer of a broader regulatory architecture that extends into increasingly sophisticated domains. Understanding how these foundational requirements connect to advanced regulatory theory will deepen your comprehension and prepare you for both the Series 65 examination and professional practice.

How foundational compliance concepts connect to advanced regulatory frameworks
Foundational ConceptAdvanced ExtensionSignificance
CIP / CDDEnhanced Due Diligence (EDD)High-risk clients (PEPs, correspondent banks) require deeper investigation, ongoing monitoring, and senior management approval
SAR FilingFinancial Action Task Force (FATF) RecommendationsInternational AML standards that influence U.S. law; FATF mutual evaluations assess country compliance
Cybersecurity PoliciesSEC Regulation S-ID (Identity Theft Red Flags)Requires firms to develop written identity theft prevention programs to detect, prevent, and mitigate identity theft
Regulation S-P PrivacyState Privacy Laws (CCPA, etc.)State-level consumer privacy statutes may impose additional obligations beyond federal requirements, including data deletion rights
Business ContinuityOperational Resilience FrameworksBroader framework encompassing not just recovery but proactive resilience testing, scenario analysis, and impact tolerance mapping

As you progress beyond the Series 65 into professional practice, you will encounter these advanced frameworks with increasing frequency. The Corporate Transparency Act (CTA) of 2021, for example, introduced a national beneficial ownership registry maintained by FinCEN, fundamentally altering how firms verify the ownership structures of entity clients. Similarly, the SEC's evolving cybersecurity rules—including proposed mandatory incident disclosure requirements—signal that the regulatory burden on investment advisers will continue to intensify. Firms that build robust compliance infrastructure now will be better positioned to adapt to these emerging requirements.

Practice Problems

PROBLEM 1CONCEPTUAL
Under the USA PATRIOT Act, what are the four minimum components that an investment advisory firm must include in its AML compliance program?
PROBLEM 2BASIC CALCULATION
A client deposits $9,500 in cash on Monday, $9,800 in cash on Tuesday, and $9,200 in cash on Wednesday into an investment advisory account. All three deposits appear related. Is a Currency Transaction Report (CTR) required? What about a SAR?
PROBLEM 3INTERMEDIATE
An investment adviser discovers that a former employee copied client account numbers, Social Security numbers, and portfolio balances onto a personal USB drive before leaving the firm. The data has potentially been exposed to unauthorized third parties. Identify the specific regulatory obligations triggered by this event across all four compliance pillars (AML, cybersecurity, privacy, business continuity).
PROBLEM 4APPLIED
Priya is an IAR at a state-registered investment adviser. A longtime client, Mr. Chen, asks Priya to share his account information—including his net worth, account balances, and transaction history—with his adult daughter who is not a joint account holder and has no legal authority over the account. Mr. Chen makes this request verbally over the phone. How should Priya respond, considering the firm's obligations under Regulation S-P and general privacy principles?
PROBLEM 5CRITICAL THINKING
A small state-registered investment advisory firm with five employees experiences a severe cyberattack that encrypts all client data (ransomware). The firm has no formal business continuity plan and no cybersecurity incident response plan. The sole principal of the firm is on vacation overseas and unreachable. Analyze the regulatory failures that preceded this crisis, the immediate obligations the firm faces, and the long-term reforms the firm should implement once the crisis is resolved.

Lesson Summary

Investment adviser representatives must understand four interconnected pillars of regulatory compliance. Anti-Money Laundering (AML) obligations—rooted in the Bank Secrecy Act and expanded by the USA PATRIOT Act—require firms to maintain AML programs with four elements: written policies, a designated compliance officer, employee training, and independent testing. Client onboarding must include Customer Identification (CIP) and Customer Due Diligence (CDD), followed by ongoing monitoring. Suspicious activity above $5,000 triggers a SAR filing with FinCEN within 30 days, and the tipping-off prohibition bars disclosure of the SAR to its subject.

Cybersecurity obligations include written policies, risk assessments, encryption, access controls, vendor management, and incident response plans. Privacy under Regulation S-P requires initial and annual privacy notices, opt-out rights for NPI sharing with nonaffiliated third parties, and the Safeguards Rule protecting client records. Business continuity plans must address data backup, alternative communications, succession planning, and client notification, with annual reviews to ensure preparedness. Together, these four pillars form the comprehensive compliance framework that protects clients, firms, and the integrity of the financial system.

Varsity Tutors • Series 65 • Apply AML And Cybersecurity Rules