Financial services compliance software: financial compliance software for investment advisers, broker-dealers and fintech firms
Financial services compliance software is the system of record for a firm regulated by the SEC, FINRA or a state securities division: the policies, the annual review, the supervisory testing, the evidence and the calendar. What separates it from generic GRC tooling is that the obligations are named rules with named deadlines, and an examiner will ask for the artifact by rule number.
The buying mistake is treating a registered investment adviser and a broker-dealer as one market. They are not. An adviser lives under Rule 206(4)-7, which asks for three things and never once mentions branch inspections. A FINRA member lives under Rules 3110, 3120 and 3130, which prescribe inspection cycles, a testing report and a CEO certification with a 45-day clock attached. A dually registered firm owes both, and that is where compliance calendars usually break.
Every rule reference on this page was checked in August 2026 against the current eCFR text of 17 CFR 275.206(4)-7, the published FINRA rulebook and the Federal Register. Where a widely repeated claim is no longer in the source, this page says so and gives the citation that removed it.
Scan your firm's regulatory obligations
Pick your industry and size, then choose the regimes you report against. The scan returns the obligations that apply to a firm like yours, what moved in the last 12 months, and the primary source behind each line. No signup, nothing stored.
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
Four regimes wear the same job title, and they owe different things
"Financial services compliance" covers firms whose obligations barely overlap. Before you compare products, work out which column you are in, because the wrong column buys you a platform full of controls you will never test and leaves out the one artifact your examiner opens first. Dually registered firms sit in two columns at once and need the calendar to know that.
| Firm type | Primary regulator | Core compliance rule | The artifact an exam opens first |
|---|---|---|---|
| SEC-registered investment adviser | SEC, Division of Examinations | 17 CFR 275.206(4)-7 | The compliance manual, plus whatever you have showing the annual review happened and what it changed |
| State-registered investment adviser | State securities division | State rule, usually modeled on 206(4)-7 | The same manual, plus the state-specific net worth, bonding and custody provisions that differ from the federal ones |
| Broker-dealer, FINRA member | FINRA and the SEC | FINRA Rules 3110, 3120, 3130 | Written supervisory procedures, the branch inspection schedule with completed reports, and the 3120 testing report |
| Fintech, payments or lending firm | FinCEN, CFPB, state licensing | 31 CFR 1022 and 1010, plus consumer rules | The AML program with its independent testing, and a compliance management system an examiner recognizes |
That last row is the one most often mis-sold. A payments or lending business is not examined against the Advisers Act at all, and its compliance system needs a different spine. Our bank compliance software page covers the compliance management system an examiner expects from a depository or lending institution, and AML compliance software covers the KYC, sanctions screening and SAR side in detail.
Rule 206(4)-7 asks for three things, and one thing it no longer asks for
The compliance rule for SEC-registered advisers is short enough to read in a minute, and reading it is worth more than any vendor checklist. It makes it unlawful to provide investment advice unless you do three things:
- (a) Policies and procedures. Adopt and implement written policies and procedures reasonably designed to prevent violation, by you and your supervised persons, of the Act and the rules the Commission has adopted under it.
- (b) Annual review. Review, no less frequently than annually, the adequacy of those policies and procedures and the effectiveness of their implementation.
- (c) Chief compliance officer. Designate an individual, who must be a supervised person, responsible for administering the policies and procedures.
Notice what is absent. There is no prescribed policy list, no required review methodology, no testing frequency beyond "annually", and no minimum staffing. The rule is deliberately principles-based, which is why two advisers of the same size can run defensibly different programs. What the SEC enforces is the gap between what your manual says and what your firm actually does, so a manual copied from a template you do not follow is worse than a thinner one you do.
The documentation requirement that was added, then vacated, then removed
A great deal of live content, including material published in 2026, tells advisers that Rule 206(4)-7 requires the annual review to be documented in writing. It did, briefly. The SEC added that requirement in the Private Fund Adviser Rules adopting release published at 88 FR 63386 on 14 September 2023, effective 13 November 2023. On 5 June 2024 the Fifth Circuit vacated those rules in their entirety, holding the Commission had exceeded its authority. The SEC then published technical amendments at 89 FR 91252 on 19 November 2024 removing the vacated text from the CFR.
The current text of 17 CFR 275.206(4)-7 has three paragraphs and no documentation clause. The practical advice does not change: document the review anyway, because exam staff ask for evidence of it and an undocumented review is indistinguishable from one that never happened. But know the difference between a rule and a practice, because vendors sell the former and deliver the latter, and a compliance calendar built on a vacated citation will eventually be audited by someone who checks.
The three FINRA rules that set a broker-dealer's compliance calendar
Where the adviser rule is principles-based, the FINRA supervision rules are specific, and the specificity is the whole reason broker-dealers buy software. These are dated, countable obligations with populations behind them: offices to inspect on a cycle, correspondence to review and evidence, tests to run, a report to deliver, a certification to sign by an anniversary date.
| Rule | What it requires | The deadline or threshold that bites |
|---|---|---|
| 3110 Supervision | Written supervisory procedures, registered principals with real authority, review of incoming and outgoing correspondence and internal communications, internal inspection of every office, an annual compliance meeting for each registered person | OSJs and supervising branch offices inspected at least annually on a calendar-year basis. Non-supervisory branches at least every three years. Non-branch locations on a regular periodic schedule, with a presumption of at least every three years |
| 3120 Supervisory control system | Designated principals establish, maintain and enforce supervisory control policies that test whether the 3110 system works, then report to senior management with a summary of the system, the test results and significant identified exceptions, plus any new or amended procedures | Report no less than annually. A firm with $200 million or more in gross revenue on its FOCUS filings in the prior calendar year must add complaint tabulations and a discussion covering six named business areas |
| 3130 Annual certification | The chief executive officer certifies the firm has processes to establish, maintain, review, test and modify compliance policies, and has met with the chief compliance officer about them | Certify no later than the anniversary date of the previous year's certification. At least one CEO and CCO meeting in the preceding 12 months. The supporting report goes to the board and audit committee at their next scheduled meetings or within 45 days of the certification |
Two things about this table matter when you evaluate software. First, the 3130 certification is an anniversary obligation, not a fiscal-year one, so a platform that only understands calendar quarters will hand you the wrong date the first year and every year after. Second, 3110 and 3120 are a pair that a lot of firms collapse into one exercise. They are not the same test. Doing the supervision and checking that the supervision works are different populations with different evidence, and an exam that finds one report serving both purposes will say so.
The remote inspection question sits on top of all of this and keeps moving, which is a good argument for tracking rule changes at the source rather than trusting a control library to be current. That is what our regulatory change management layer is built to do, and the audit management software page covers the testing and workpaper side that 3120 depends on.
Advisers do not owe a federal AML program until 1 January 2028
This is the single most useful date in adviser compliance right now, and a lot of published material has it wrong in both directions. Some vendors sell RIAs an AML module as if the obligation were already live. Others treat the rule as dead. Neither is right.
FinCEN finalized an AML/CFT program and SAR filing rule covering registered investment advisers and exempt reporting advisers on 4 September 2024, published at 89 FR 72156, with an original effective date of 1 January 2026. In a rule published at 91 FR 36 on 2 January 2026, FinCEN delayed that effective date by two years, to 1 January 2028. The rule is still on the books. It simply does not bite yet.
Three practical consequences. An adviser buying today should not pay for an AML module it cannot use for two years, but should make sure the platform it picks can add one without a migration. An adviser affiliated with a bank or a broker-dealer may already be inside that entity's program and should check rather than assume. And a broker-dealer has owed a written AML program under 31 CFR 1023.210 all along, so for dually registered firms the delay changes nothing at all.
Separately, FinCEN's broader AML/CFT program proposal covering all covered financial institutions, published at 91 FR 18704 on 10 April 2026, was still a proposed rule when this page was last checked on 23 August 2026. Nothing in it is enforceable yet, and any vendor describing its requirements as current is describing a proposal.
Where the software earns its money in a regulated firm
Compliance software does not make a firm compliant. It cannot conduct a branch inspection, sign a 3130 certification or decide that a marketing piece is fair and balanced. What it can remove are the two failure modes that actually generate deficiency letters: evidence that cannot be produced months later, and a policy set that quietly falls out of date while the rules underneath it move.
Worth paying for
- A calendar that understands anniversary obligations, not just quarters, and drives the 3130 certification and the 206(4)-7 annual review from the correct date
- Office and location inventory with the inspection cycle attached to each record, so the three-year population is a query rather than a spreadsheet
- Evidence captured with its source, date and preparer at the moment of review
- Policy versioning that shows what the manual said on the day of the transaction being examined
- Alerting when a rule or an interpretive release changes something a policy already assumed
Not worth paying for
- A generic control library dropped in without mapping to your registrations, which produces controls you do not owe and cannot retire
- An AML module an adviser cannot use before 2028, priced from day one
- A template compliance manual you will not follow, which converts a principles-based rule into a documented gap
- Dashboards that count policies published rather than reviews completed
- Anything sold as SEC certified or FINRA approved compliance software, which does not exist
Nobody in this category publishes a price
Buyers ask constantly whether there are enterprise-grade compliance tools with transparent pricing. The honest answer, checked rather than assumed: on 23 August 2026 we opened the public pricing pages of seven of the most-shortlisted platforms in this category, Vanta, Drata, Secureframe, Sprinto, Hyperproof, Onspring and LogicGate. Every one of them describes tiers or a licensing model. None of the seven shows a dollar figure. Every one routes to a demo or a quote request.
So the transparency available to you is not a vendor rate card. It is aggregated buyer data from recorded purchases, which is why the figures below are worth more than a published list price would be: they are what firms actually paid, not what vendors actually ask.
| Platform | Median annual contract | Recorded range | Average discount off first quote |
|---|---|---|---|
| OneTrust | $11,970 | $1,620 to $48,230 | 20% |
| Vanta | $20,000 | $7,500 to $57,221 | 30% |
| Drata | $25,000 | $9,494 to $67,350 | 23% |
| Onspring | $33,808 | $9,972 to $55,810 | not published |
| Hyperproof | $41,400 | $22,215 to $70,000 | 21% |
| Workiva | $49,420 | $12,736 to $153,365 | 11% |
| LogicGate | $53,783 | $12,294 to $136,130 | 19% |
Medians and ranges from recorded buyer contracts on the Vendr marketplace. Hyperproof and LogicGate re-verified 23 August 2026; the remainder verified 22 August 2026. These figures move, so treat any undated version of them as stale.
The discount spread is the number most procurement teams get wrong. A flat "assume twenty percent off" rule is wrong at both ends: Workiva buyers averaged 11 percent while Vanta buyers averaged 30. Implementation is the other surprise, commonly 30 to 100 percent of first-year license, and it is rarely in the headline quote. Our compliance software pricing comparison carries the full ten-vendor table and the cost lines nobody quotes, and our own pricing is published as a number rather than a form.
Financial services compliance questions
What are the compliance requirements for a registered investment advisor?
Rule 206(4)-7 under the Advisers Act imposes exactly three: adopt and implement written policies and procedures reasonably designed to prevent violations of the Act, review their adequacy and the effectiveness of their implementation no less frequently than annually, and designate a supervised person as chief compliance officer. Everything else an adviser owes flows from other rules, such as the books and records rule, the custody rule and the marketing rule.
Does Rule 206(4)-7 require the annual review to be documented in writing?
Not today, and this is widely misreported. A written documentation requirement was added in September 2023 as part of the Private Fund Adviser Rules and took effect that November. The Fifth Circuit vacated those rules in their entirety on 5 June 2024, and the SEC removed the amendment from the CFR at 89 FR 91252 on 19 November 2024. Documenting the review is still standard practice and exam staff routinely ask for it, but it is practice, not rule text.
Does an RIA need a chief compliance officer?
Yes. Rule 206(4)-7(c) requires every SEC-registered adviser to designate an individual, who must be a supervised person, responsible for administering the compliance policies and procedures. The rule does not require that the role be full time or that the person hold any credential. It does require a real person with actual authority, which is why software can support the role but cannot occupy it.
What is the difference between FINRA Rule 3110 and 3120?
Rule 3110 is the supervision itself: written supervisory procedures, registered principals, correspondence review and office inspections. Rule 3120 is the control layer above it, requiring designated principals to test whether the 3110 system actually works and to report the test results and significant exceptions to senior management at least annually. One does the supervising, the other checks the supervising.
How often must a broker-dealer inspect its branch offices?
Under FINRA Rule 3110(c), offices of supervisory jurisdiction and branch offices that supervise non-branch locations must be inspected at least annually on a calendar-year basis. Non-supervisory branch offices must be inspected at least every three years. Non-branch locations run on a regular periodic schedule, with a general presumption of at least every three years.
What is the annual compliance certification for broker-dealers?
FINRA Rule 3130 requires the chief executive officer to certify annually, no later than the anniversary of the previous certification, that the firm has processes to establish, maintain, review, test and modify its compliance policies and procedures. The CEO must also have held one or more meetings with the chief compliance officer in the preceding 12 months, and the processes must be evidenced in a report given to the board and audit committee within 45 days.
Do registered investment advisers have to have an AML program?
Not yet. FinCEN finalized an AML/CFT program and SAR filing rule for registered investment advisers and exempt reporting advisers on 4 September 2024 at 89 FR 72156, originally effective 1 January 2026. FinCEN delayed it to 1 January 2028 in a rule published 2 January 2026 at 91 FR 36. Advisers affiliated with a bank or broker-dealer may already be covered through that entity.
What does financial services compliance software cost?
Recorded buyer data puts most GRC and compliance platforms between roughly $20,000 and $54,000 a year at the median, with individual contracts ranging from about $7,500 to over $150,000. Vendors in this category almost never publish a price: of seven pricing pages checked on 23 August 2026, none showed a dollar figure. Expect implementation to add 30 to 100 percent of first-year license.
What is investment compliance?
Investment compliance is the function that keeps an advisory or brokerage business inside the rules that govern how it handles client money, gives advice, markets itself and keeps records. In practice it splits into two jobs: pre-trade and post-trade checks against client mandates and regulatory limits, and the firm-level compliance program required by Rule 206(4)-7 or the FINRA supervision rules.
Which firms have to file the extra FINRA 3120 report content?
A member that reported $200 million or more in gross revenue on its FOCUS filings during the prior calendar year, excluding commodities line items, must add specified content to the following year report. That includes a tabulation of customer complaint and internal investigation reports filed with FINRA and a discussion of compliance efforts across trading and market activities, investment banking, antifraud and sales practices, finance and operations, supervision, and anti-money laundering.
Last updated August 2026.
§ 99 · Final entry
Get on the early-access list
Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.
Related registers
- Continuous Compliance Monitoring
- Compliance Monitoring Software
- Compliance Software Cost
- Enterprise Compliance Software for CCOs and CISOs
- GRC Software and Governance Risk Compliance Software
- GDPR Compliance Software
- Compliance Automation Software
- AML Transaction Monitoring Plus Regulatory Watch
- SOC 2 Compliance Software Beyond Audit Readiness
- Policy Compliance Software and Policy Management Tracking
- Regulatory Change Management Software, Tools and Platform
- HIPAA Compliance Software with Security Risk Analysis
- ISO 27001 Software for ISMS Compliance and Audit Evidence
- Vendor Risk Management Software for Third Party Risk
- PCI Compliance Software Tied to PCI DSS 4.0.1
- Audit Management Software for Continuous Readiness
- SOX Compliance
- Segregation of Duties Software
- ITGC Controls Software for SOX IT General Controls Audits
- SOX Compliance Software for SOX 404 Controls
- Best Compliance Software in 2026, Compared
- CMMC Compliance Software for DoD Contractors
- Enterprise Risk Management Software
- Compliance Software Pricing Comparison
- Healthcare Compliance Software for OIG Compliance Programs
- Bank Compliance Software for Financial Institutions, BSA/AML
- AI Compliance Software
- AML Compliance Software with KYC and Sanctions Screening
- Regulatory Compliance Software with Compliance Tracking
- CCPA Compliance Software, Data Privacy Management Software
- Enterprise Risk Assessment Software, Risk Assessment Tools
- Vanta Alternative for Regulatory Change Monitoring
- Drata Alternative Focused on Regulatory Change
- Secureframe Alternative for Regulatory Change
- Sprinto Alternative for Regulatory Change
- AuditBoard Alternative (Now Optro) for Regulatory Change