
The takeaway in 30 seconds: Collecting quarterly personal trade reports feels like the compliance task getting done. It’s actually only half of it. Under Rule 204A-1 and the recordkeeping rules, the obligation is not just to collect access person reports. It also requires reviewing those reports against client holdings and restricted lists, and being able to demonstrate that both the reviews and the reports were properly maintained over time. Most firms have the reports. Far fewer have a documented, timestamped record showing the review happened and that the reports weren’t quietly amended after the fact. That second half is where the exam finding lives.
Your access persons submitted their Q2 personal securities transaction reports. They’re in a folder, or an inbox, or a compliance platform. The box is checked. For most firms, that’s where the sense of completion sets in. The reports came in, the deadline was met, and the quarter’s personal trading obligation is handled.
Here’s the uncomfortable question beneath that sense of completion: if an examiner asked you to demonstrate not just that the reports were collected, but that they were reviewed, compared against client holdings and the restricted list, with a record of when that review happened and what it concluded, could you produce it? And could you prove the reports in your file today are the same reports your employees submitted in July, unchanged?
For a lot of firms, the honest answer to both is no. Not because the work wasn’t done, but because collecting is visible and reviewing is not, and because a folder of PDFs doesn’t carry the evidence an exam actually tests.
The Obligation Is Two Duties, Not One
Rule 204A-1, the Code of Ethics Rule, requires access persons to report their personal securities holdings and transactions, and requires the firm to review those reports. That second part is easy to under-weight, because the reporting is the visible, deadline-driven event and the review is the quiet analytical one.
But the review is the actual point. The reason access persons report their trades is so the firm can check for conflicts: front-running client trades, trading in restricted securities, patterns that suggest misuse of client information. Collecting the reports without systematically reviewing them against client activity accomplishes none of that. It produces a pile of data and no supervision.
The recordkeeping rules add the second layer. It is not enough to conduct the review. The firm also has to demonstrate that it did, with a retained record linking the review to a date and an outcome. And the underlying reports have to be preserved in a form that establishes what was actually submitted and when, so that a report can’t be quietly amended after a problem surfaces.
Put together, the obligation is three things stacked: collect the reports, review them against the right benchmarks, and maintain a defensible record of both. Most firms are solid on the first, informal on the second, and exposed on the third.
Failure Mode One: Collection Without Documented Review
The most common gap isn’t a missing report. It’s a report that was collected and never demonstrably reviewed.
Walk through how it happens at a real firm. The quarterly reports come in. The CCO, who is often also the founder or wearing three other hats, glances through them. Nothing jumps out. The reports go into the file. In the CCO’s mind, the review happened: they looked, they saw nothing concerning, they moved on. And functionally, a review of sorts did occur.
But there’s no record of it. No documented comparison against the client holdings the firm managed that quarter. No check against the restricted list memorialized anywhere. No note recording that the review took place, who did it, or what it concluded. The supervision happened in someone’s head and left no trace.
When an examiner asks the question they reliably ask, “Show me how you reviewed personal trading for conflicts this quarter,” the answer cannot be, “I looked, and nothing seemed off.” The examiner isn’t testing whether you looked. They’re testing whether the firm has a systematic, documented process for surfacing conflicts. A glance that produced no record doesn’t demonstrate that process, even when the glance was competent and the conclusion was correct.
This is the trap: the firm did the right thing and can’t prove it, which under exam conditions is treated the same as not having done it.
Failure Mode Two: No Defensible Timestamp Trail
The second gap is subtler and, in some ways, more dangerous. Even firms that document their review often can’t establish the integrity of the underlying reports over time.
Consider what a folder of submitted reports actually proves. It proves the reports exist. It doesn’t prove when each was submitted, whether it’s the original version or one edited later, or that the completion dates weren’t entered after the fact. If the reports live as PDFs in a shared drive or a spreadsheet with manually entered dates, the timeline is reconstructable at best and manipulable at worst, and an examiner knows the difference between a system-generated timestamp and a date someone typed manually.
Why does this matter beyond bureaucratic tidiness? Because the entire point of personal trade surveillance is establishing a timeline. Did the employee’s personal trade precede or follow the client trade? Was the restricted security traded before or after it went on the list? Was the holding disclosed when it should have been, or added to the record after a question arose? Every one of those is a timing question, and a record that can’t establish reliable timing can’t answer them.
A firm whose reports carry immutable, system-generated timestamps can demonstrate exactly what was submitted and when. A firm whose reports live in editable files is asking an examiner to accept its version of the timeline, and “take our word for it” is not a position that holds up during an examination of personal trading. Examiners scrutinize this area closely because the conflicts it is designed to prevent are so significant.
Problem → Solution → Outcome
The problem. Collecting access-person trade reports feels like completing the personal trading obligation, but the obligation is actually three-part: collect, review against client holdings and restricted lists, and maintain a defensible record of both. Most firms collect well, review informally without documentation, and store reports in editable files that can’t establish a reliable timeline. The result is real supervisory work that cannot be proven and a reporting record whose integrity cannot be demonstrated. Those are exactly the two things an examination of personal trading is designed to test.
The shift. The firm moves personal trade monitoring from a collection-and-review process to a system that captures reports with immutable timestamps, compares them against client holdings and restricted lists as a documented step, and retains a record of each review, including who conducted it, when it was completed, and what it concluded. The review no longer lives in the CCO’s head. It lives in a documented record.
The outcome. When an examiner asks how the firm surfaces personal trading conflicts, the answer is a documented, timestamped process: the reports as submitted, the review comparing them against the appropriate benchmarks, and the resulting conclusion, all retained and readily retrievable. The firm can establish the timeline that personal trade surveillance depends on while creating clear evidence of supervision already being performed. Q2 reports become part of a defensible audit trail instead of a pile of PDFs.
This is the kind of workflow Smartria is built to support: access-person reporting captured with system-generated timestamps, systematic comparison against client holdings and restricted lists, and a retained review record across every quarter, so personal trade monitoring produces a paper trail by design instead of one you have to reconstruct when an exam notice arrives.
What to Do With This
Q2’s reports are already in. Before Q3’s arrive, run a quick test on the quarter you just closed.
Pull your Q2 access-person reports and ask three questions:
- Is there a documented record that the reports were reviewed, not just collected, against client holdings and the restricted list? If the review happened but left no documented record, that’s failure mode one.
- Can you establish, from the records themselves, when each report was submitted, with a system-generated timestamp rather than a manually entered date? If the timeline depends on editable files, that’s failure mode two.
- If an examiner asked you to demonstrate your Q2 personal-trading review today, would you produce a record, or reconstruct one from memory and a folder of PDFs?
If all three come back clean, your personal trade monitoring is doing what the rule actually requires, and you can prove it. If any one of them exposes a gap, you’ve found it on your own terms, with a full quarter before Q3’s reports arrive to build the process that closes it.
The reports coming in on time is the part everyone sees. The reviewed, timestamped, defensible trail behind them is the part the exam actually tests. Q2 is a chance to check which one you have.





