FINRA Rule 3120 Annual Report: A Practical Way to Make the Process Defensible

FINRA 3120 General information.

10/3/20265 min read

three people sitting in front of table laughing together
three people sitting in front of table laughing together

For many broker-dealers, the annual FINRA Rule 3120 report is treated as a year-end compliance document. That framing is too small.

A strong Rule 3120 process is not just about producing a report. It is about showing that the firm has a working supervisory control system, that the system was tested against the firm's actual business, and that exceptions led to documented decisions, remediation, or procedure changes.

FINRA Rule 3120 requires member firms to designate one or more principals who establish, maintain, and enforce supervisory control policies and procedures. Those procedures must test and verify whether the firm's supervisory procedures are reasonably designed to achieve compliance with applicable securities laws, regulations, and FINRA rules. When testing identifies a need for change, the firm must create or amend supervisory procedures. The designated principal or principals must submit an annual report to senior management describing the supervisory control system, summarizing test results and significant exceptions, and identifying any additional or amended procedures created in response.

That sounds straightforward on paper. In practice, the hard part is evidence.

The Annual Report Should Tell the Story of Control

A defensible Rule 3120 report should do more than recite the rule. It should explain how the firm actually supervises its business.

That means the report should connect five things:

  1. The firm's supervisory obligations and written supervisory procedures.

  2. The testing plan used during the annual cycle.

  3. The samples, data, reviews, interviews, or other evidence used to perform testing.

  4. The exceptions, observations, and root causes identified.

  5. The remediation, procedure changes, approvals, and closure evidence that followed.

When those pieces are disconnected, the annual report can read like a compliance summary rather than a control record. When they are linked, senior management can see what was tested, why it mattered, what changed, and where residual risk remains.

Start With the Core 3120 Requirements

The checklist begins with the foundation: who owns the Rule 3120 process, whether supervisory control policies and procedures are current, and whether testing was performed to determine if supervisory procedures are reasonably designed for the firm's business and associated persons.

This is where firms should confirm that the designated principal or principals have been formally identified, that the annual report owner is clear, and that the report period, report date, senior management recipient, and evidence location are documented.

For new FINRA members, timing matters as well. Firms within their first 12 months of FINRA membership should confirm that supervisory systems and written supervisory procedures were in place by the membership date and that the first Rule 3120 report was completed within the applicable first-year period.

Treat the Testing Plan as a Risk Document

Rule 3120 does not require every test to look the same. The better approach is risk-based and firm-specific.

A useful testing plan should reflect the firm's business mix, regulatory priorities, customer impact, complaints, prior findings, significant business changes, new products, remote or branch arrangements, technology changes, outsourcing, personnel changes, and disciplinary events.

The checklist also pushes firms to document sampling decisions. That includes the population tested, period reviewed, sample size, selection method, and rationale for any judgmental samples. This level of detail matters because the annual report's conclusion is only as persuasive as the evidence trail behind it.

Separate Findings From Fixes

One common weakness in annual supervisory control reporting is vague exception handling. A finding should not disappear into a sentence that says management reviewed and addressed the matter.

A stronger remediation record captures:

  • The root cause.

  • The severity of the issue.

  • The affected population.

  • Any customer or regulatory impact.

  • Escalation decisions.

  • The remediation owner.

  • Target and actual closure dates.

  • Closure evidence.

This turns the annual report from a static document into a management tool. It also helps avoid the recurring problem of the same issue resurfacing year after year because ownership, timing, or final disposition was never clearly recorded.

Know When the $200 Million Revenue Section Applies

Rule 3120 has additional report content requirements for firms that reported $200 million or more in gross revenue in the prior calendar year, using the rule's FOCUS-report-based calculation.

For those firms, the annual report must include, to the extent applicable, a tabulation of reports pertaining to customer complaints and internal investigations made to FINRA during the preceding year. It must also discuss the preceding year's compliance efforts, including procedures and educational programs, in areas such as trading and market activities, investment banking, antifraud and sales practices, finance and operations, supervision, and anti-money laundering.

Firms below the threshold should still document the applicability analysis rather than simply omitting the section. A clean N/A decision is still an evidence point.

Link Rule 3120 Work to Rule 3130 Certification Support

Rule 3120 and Rule 3130 are distinct, but they often meet in the same evidence room.

Rule 3130 requires the CEO or equivalent officer to certify annually that the firm has processes to establish, maintain, review, test, and modify written compliance policies and written supervisory procedures. The CEO must also have one or more meetings with the CCO during the preceding 12 months to discuss those processes.

The Rule 3120 annual testing cycle can help support that certification, but firms should avoid blurring the two obligations. The checklist treats Rule 3130 items as certification support, not as standalone Rule 3120 requirements. That distinction is important. The CEO certification, CCO consultation, report review, board or audit committee delivery timing, and 3120 testing linkage should be tracked deliberately.

Draft the Report for Senior Management, Not Just the File

The final annual report should be readable by senior management. That means it should explain the actual supervisory control framework, summarize the testing performed, distinguish significant exceptions from minor observations, and describe procedure changes with enough specificity to show what changed.

A useful procedure-change record includes the procedure title, owner, version date, approval status, implementation date, and training impact. This helps senior management understand whether the firm merely identified an issue or actually changed the control environment.

Download the FINRA Rule 3120 Annual Report Checklist

Preparing the annual report is easier when every requirement, evidence item, owner, and remediation step has a place to land.

Use the FINRA Rule 3120 Annual Report Checklist to organize your annual cycle, document applicability decisions, track evidence, and prepare a report package that is easier for senior management, compliance leadership, and reviewers to follow.

Get the FINRA Rule 3120 Annual Report Checklist and use it before your next annual supervisory control review to map requirements, testing evidence, exceptions, remediation, and Rule 3130 certification support in one structured workflow. Reach out to use at info@homersemantics.com

User the Procors SaaS to keep a track of your 3120 work

Homer semantics has built Procors, a secure yet inexpensive compliance file workspace for small broker-dealers / RIAs where they can store checklists, assign evidence, track remediation, and export a clean audit-ready packet. Reach out for a free trial today.

****

Legal Disclaimers

This blog is provided for general informational and educational purposes only. It is not legal advice, financial advice, regulatory advice, compliance advice, or a substitute for advice from qualified legal, compliance, regulatory, accounting, or other professional advisers.

Reading or using this blog does not create an attorney-client, fiduciary, advisory, consultant, or other professional relationship. No representation or warranty is made that the information is complete, current, accurate for any particular firm, or sufficient to satisfy FINRA, SEC, MSRB, state, federal, or other regulatory obligations.

FINRA rules, SEC rules, MSRB rules, federal securities laws, state requirements, regulatory interpretations, enforcement priorities, and firm-specific supervisory obligations may change and may apply differently depending on a firm's business model, registrations, products, customers, personnel, history, and written supervisory procedures.

Before relying on this blog or any checklist, firms should verify current requirements, review their own written supervisory procedures and governance documents, and consult with qualified counsel, compliance leadership, or other appropriate professionals. Use of this material is at the user's sole discretion and risk. The author and publisher disclaim responsibility for any decisions, omissions, actions, losses, liabilities, or damages arising from or relating to use of this material.

This website may use essential and third-party cookies for embedded media, basic site functionality, and performance monitoring.