Most people who search “FINRA audit” are actually asking about one of two different things, and the difference matters before you spend a single hour preparing for the wrong one.
The first is a recurring obligation: the annual audited financial report that broker-dealers must file every year. The second is an event you don’t schedule: a FINRA examination, which many people loosely call an “audit,” where FINRA staff show up to test whether what you filed matches how the firm actually operates. Confusing the two is the most common early mistake. A firm braces for a records request that isn’t coming while missing a filing deadline that is.
This article separates the two, walks through the FINRA audit process step by step, lays out the FINRA audit requirements, and shows how registered investment advisers (RIAs), broker-dealers, and dual-registered firms each fit into FINRA’s oversight.
In other words, you want to stay on their good side.

What Is a FINRA Audit?
The Financial Industry Regulatory Authority (FINRA) is not a government agency like the SEC or a state securities regulator. It’s a private, non-profit self-regulatory organization (SRO) for broker-dealers, operating under SEC oversight, with authority to examine member firms and impose fines and other penalties. FINRA was formed in 2007 through the consolidation of the National Association of Securities Dealers (NASD) and the member-regulation functions of the New York Stock Exchange.
When people say “FINRA audit,” they usually mean one of two things:
The annual audited financial report, filed on Form X-17A-5, Part III, is an audit of the broker-dealer’s finances performed by an independent public accountant registered with the Public Company Accounting Oversight Board (PCAOB). This is required under SEC Rule 17a-5, which FINRA administers as the designated examining authority for most firms.
A FINRA examination is a review conducted by FINRA staff of a member firm’s books, records, supervisory systems, and business conduct. This is what most firms are picturing when they worry about “getting audited.” Throughout this article we use FINRA examination as the precise term, because that’s the language FINRA and the SEC use.
FINRA Audit vs. FINRA Examination: What’s the Difference?
The cleanest way to hold the distinction: one is a filing you own; the other is a review you receive.
The annual audited financial report is your obligation. You engage a PCAOB-registered accountant, the accountant audits your financials, and you file the result on Form X-17A-5. Under SEC Rule 17a-5(d), the annual reports must be filed within 60 calendar days after the end of the broker-dealer’s fiscal year. A firm with a December 31 fiscal year-end therefore files by around the first of March. As of amendments effective for audits filed on or after June 30, 2025, these reports must be submitted electronically through the SEC’s EDGAR system. The SEC no longer accepts paper or email submissions of Form X-17A-5, Part III. Firms facing exceptional circumstances may request an extension from their designated examining authority, but the request must be made in advance, not after the fact.
A FINRA examination is initiated by FINRA. It may be a routine cycle examination, a targeted (or “sweep”) examination focused on a specific practice, or a for-cause examination triggered by a red flag, such as a customer complaint, a regulatory filing, surveillance data, or a tip. The purpose is to confirm that the picture in your filings matches operational reality and to identify any non-compliance with FINRA rules and federal securities laws.
Both matter. But they fail in different ways: you miss the annual report by blowing a deadline; you fail an examination by being unable to show your work when an examiner asks.
Does FINRA Audit RIAs?
This is where the terminology trips people up most.
RIA-only firms are not FINRA member firms. If your firm is a registered investment adviser and nothing else, FINRA does not examine or “audit” you.RIAs are regulated by the SEC or by state securities regulators, depending largely on assets under management (AUM), and their examinations come from those regulators, not FINRA. Your annual regulatory filing as an RIA is Form ADV, filed through the IARD system (which FINRA operates on behalf of the SEC and the states), not Form X-17A-5.
There are two important exceptions:
Broker-dealers are FINRA member firms and are directly subject to FINRA examination and the annual audited report requirement.
Dual registrants and hybrid firms, where the same firm, or an individual within it, is registered both as an investment adviser representative and as a registered representative of a broker-dealer, sit under both regimes. The advisory side answers to the SEC or the state; the brokerage side answers to FINRA. If anyone in your office wears both hats, understanding how a FINRA examination works stops being optional.
So the honest answer to “does FINRA audit RIAs” is: not the RIA itself, but very possibly the broker-dealer or the dual-registered people connected to it.
How Often Does FINRA Audit Broker-Dealers?
There is no fixed calendar. FINRA uses a risk-based examination program, meaning the frequency and depth of a firm’s examinations scale with its risk profile rather than following a uniform every-N-years schedule.
Factors that influence cadence include the firm’s business lines, size and structure, customer base, history of findings or complaints, financial condition, and surveillance signals. A firm carrying customer accounts, holding client funds, or operating in a higher-risk business will generally see more frequent and more intensive examinations than a small firm with a limited, low-risk model. For-cause examinations can happen any time a specific concern surfaces, independent of the routine cycle.
The practical takeaway: you cannot predict the exact date, so the only durable strategy is continuous readiness rather than periodic scramble.
What Happens During a FINRA Audit?
Here is the FINRA audit process, covering what a FINRA examination actually looks like from notice to close-out.
Notification and Document Requests
An examination typically opens with a notice from FINRA that identifies the scope and time period under review and includes a document request list. Requests commonly cover written supervisory procedures, communications with the public, account records, trade blotters, financial records, correspondence, and evidence of supervisory review. For-cause examinations may arrive with narrower, pointed requests tied to a specific concern.
Examination and Testing
FINRA staff review the records and test whether the firm’s controls and supervisory procedures work as written. This is not a paperwork check. Examiners look for evidence that supervision actually happened, including timestamps, reviewer sign-offs, escalation trails, and documentation tied to the firm’s specific risks and business lines. Where a firm’s activities create particular risks (complex products, active trading, or communications at scale), testing concentrates there.
Meetings and Follow-Up Requests
Examiners ask questions and request explanations. Expect follow-up requests for additional documents and supporting evidence behind any exception or anomaly they identify. Clear, prompt, well-organized responses shape the tone of the entire examination.
Exit Meeting
Toward the end, FINRA generally discusses potential findings with the firm. This is the firm’s opportunity to understand what examiners observed, provide context, and correct any misunderstanding before findings are formalized.
Examination Report and Corrective Action
FINRA communicates its findings, and the firm responds, often documenting remediation already underway or planned. Outcomes range from no findings, to a cautionary action, to formal disciplinary referral depending on severity. What examiners consistently want to see is a firm that identifies the gap, fixes it, and documents both.
What Are the FINRA Audit Requirements?
Whether you’re preparing for the annual report or a FINRA examination, the underlying FINRA audit requirements come down to being able to produce, on request, credible evidence across a defined set of areas:
- Financial records and net capital, including accurate books and records, net capital computations, and, for the annual report, audited financial statements prepared by a PCAOB-registered accountant under SEC Rule 17a-5.
- Written supervisory procedures (WSPs), current, tailored to the firm’s actual business, and demonstrably followed.
- Supervisory evidence, proof that reviews, approvals, and escalations occurred, not just that policies exist.
- Communications with the public, advertising and communications retained and reviewed under the applicable content and recordkeeping rules.
- Books and records / retention, records preserved and readily producible under SEC Rules 17a-3 and 17a-4, including electronic communications.
- Standard of conduct, for firms serving retail customers, evidence of compliance with Regulation Best Interest (Reg BI), which replaced the older “suitability” standard for broker-dealers.
- AML program, customer due diligence and monitoring consistent with the firm’s obligations.
- Continuing education, required training for registered personnel completed and documented.
The recurring theme: FINRA examiners increasingly want provable compliance, a timestamped trail showing the firm did what its procedures say it does.
Key FINRA Compliance Requirements to Review
Three FINRA supervision rules form the backbone of what examiners test. Together they mandate that broker-dealers build, test, and take senior-level ownership of a supervisory system appropriate to the firm’s business, size, and structure.
FINRA Rule 3110: Supervision
Rule 3110 requires each member firm to establish and maintain a supervisory system, including written supervisory procedures, reasonably designed to achieve compliance with applicable securities laws and FINRA rules. This is the framework layer: what your supervision is supposed to look like, in writing.
FINRA Rule 3120: Supervisory Control System
Rule 3120 requires a firm to have a system of supervisory control policies and procedures that tests and verifies, at least annually, that its supervisory procedures are reasonably designed to achieve compliance. The firm designates one or more principals to run this testing and produces a report to senior management summarizing the testing, any significant gaps found, and the changes made or planned. In short: 3110 sets the procedures; 3120 tests whether they work.
FINRA Rule 3130: Annual CEO Certification
Rule 3130 requires the firm’s CEO (or equivalent officer) to certify annually that the firm has processes in place to establish, maintain, review, test, and modify its compliance and supervisory policies and procedures. The certification also confirms the CEO has met with the CCO within the preceding 12 months to discuss those controls. Rules 3120 and 3130 are frequently satisfied through a single consolidated report supporting the certification.
What Is FINRA Focusing on in 2026?
FINRA’s priorities are laid out most authoritatively in its 2026 Annual Regulatory Oversight Report, published under its FINRA Forward initiative. The report doesn’t create new rules. It signals where examinations will concentrate and how FINRA interprets existing obligations. Firms should read it as an exam and enforcement roadmap. Areas drawing heightened attention for 2026 include:
- Generative AI (GenAI, for the first time, the report includes a dedicated section on GenAI, urging firms to tailor supervision and controls to manage risks such as hallucinations and bias.
- Cybersecurity and cyber-enabled fraud, treated as a priority, with growing overlap between cybersecurity failures and fraud.
- Third-party / vendor risk, reinforced under FINRA Forward, with the reminder that outsourcing a function does not outsource responsibility for it.
- Communications and recordkeeping, recordkeeping lapses, including electronic communications capture and retention, are among the most frequently cited issues.
- AML, anti-money-laundering testing and customer due diligence remain a standing focus.
- Regulation Best Interest (Reg BI), continues to be front and center for broker-dealers serving retail investors.
- Manipulative trading, including a broadened focus on small-cap, exchange-listed pump-and-dump activity and surveillance gaps.
The throughline for 2026 is unambiguous: FINRA expects compliance to be demonstrable in real time, not merely documented on paper.
How to Prepare for a FINRA Compliance Audit
Preparation for a FINRA compliance audit is less about last-minute document hunts and more about whether your evidence already exists. Use this FINRA audit checklist as a readiness baseline:
- Confirm your filing calendar. Know your fiscal year-end and your 60-day Form X-17A-5 deadline, confirm your PCAOB-registered accountant is engaged well ahead of it, and verify EDGAR filing access.
- Refresh your WSPs. Make sure written supervisory procedures reflect what the firm actually does today — not what it did three business models ago.
- Prove supervision happened. For each supervisory obligation, confirm there is a timestamped record: who reviewed, when, and what they did about exceptions.
- Complete Rule 3120 testing and the Rule 3130 certification. Run the annual supervisory control testing, document gaps and remediation, and complete the CEO certification, including the CEO–CCO meeting.
- Audit your communications capture. Confirm all business communications, including electronic and off-channel messaging, are captured, retained, and reviewable under SEC Rules 17a-3 and 17a-4.
- Pressure-test 2026 focus areas. Review your controls for GenAI usage, cybersecurity, vendor oversight, AML, and Reg BI against the current oversight report.
- Assemble a request-ready evidence set. Keep books and records, financial computations, and supervisory documentation organized so a document request is a retrieval task, not an excavation.
- Run a mock exam. A rehearsed examination surfaces gaps while they’re still cheap to fix.
Staying FINRA Audit-Ready Year-Round
The firms that handle FINRA examinations well are rarely the ones that prepare hardest in the moment. They’re the ones for whom preparation is invisible, because continuous compliance is already how they operate. Findings get remediated and documented as they arise. Supervisory reviews leave a trail by default. WSPs get updated when the business changes, not when an examiner asks.
That’s the shift the 2026 environment rewards: from “panic prep” to a repeatable, evidence-generating system. Compliance requirements change constantly, which is why a growing number of RIAs, broker-dealers, and dual-registered firms rely on compliance management software like Smartria to keep attestations, reviews, and documentation continuously audit-ready rather than reconstructing them under pressure.
This article is for general informational purposes and is not legal or compliance advice. Consult a qualified compliance professional or the primary FINRA and SEC sources for guidance specific to your firm.
FAQs
Not RIA-only firms — those are examined by the SEC or state regulators, not FINRA. But broker-dealers and dual-registered (hybrid) firms are subject to FINRA examination, so if anyone in your firm is also a registered representative, FINRA oversight can apply.
There’s no fixed schedule. FINRA uses a risk-based program, so frequency depends on the firm’s business, size, customer base, financial condition, and history. Higher-risk firms are examined more often, and for-cause examinations can occur any time a concern arises.
The annual audited financial report (Form X-17A-5) is a filing the broker-dealer owns and submits yearly. A FINRA examination is a review FINRA initiates to test whether operations match filings and comply with the rules. People use “audit” for both; “examination” is the precise term for the review.
Under SEC Rule 17a-5(d), within 60 calendar days after the broker-dealer’s fiscal year-end. As of June 30, 2025, Form X-17A-5 Part III must be filed electronically through EDGAR; paper and email submissions are no longer accepted.
Typically: a notice with scope and document requests, review and testing of records and supervisory controls, examiner questions and follow-up requests, an exit meeting to discuss potential findings, and a report to which the firm responds with remediation.
FINRA Rules 3110 (supervision and WSPs), 3120 (annual supervisory-control testing), and 3130 (annual CEO certification) form the core supervisory framework, alongside recordkeeping (SEC Rules 17a-3/17a-4), Reg BI, and AML obligations.
Per the 2026 Annual Regulatory Oversight Report: generative AI, cybersecurity and cyber-enabled fraud, third-party/vendor risk, communications and recordkeeping, AML, Reg BI, and manipulative trading.







