Rupert leads FINRA's efforts to increase regulatory coordination, expand information sharing, and strengthen processes and technology to protect investors and maintain market integrity. The following is an edited version of Ruppert's conversation with Compliance Week Editor-in-Chief Aaron Nicodemus.
question: Greg, please tell us a little about your work at FINRA.
answer: I am the Chief Regulatory Affairs Officer at FINRA, a self-regulatory organization founded for nearly 85 years with a mission to protect investors and protect America's capital markets. We recently formed three different groups focused on the operational aspects of regulatory oversight. These are member supervision, market surveillance, and enforcement. We have combined these three programs into one organization called Regulatory Affairs. This allows us to monitor markets, investigate allegations of fraud, conduct inspections, and take enforcement actions. But we also share intelligence and information with and learn from our member companies through our risk monitoring program. This is a great advantage for us as a self-regulatory organization that sits between the government and the securities industry.

Greg Ruppert, Chief Regulatory Affairs Officer, FINRA
question: How does FINRA use artificial intelligence (AI) tools under the oversight of member firms?
(You can listen to the entire conversation about AI tools here)
answer: AI enhances our ability to protect the integrity of U.S. capital markets and protect investors. FINRA has been an early adopter of technology and AI since the early 2000s, particularly to enhance its market surveillance capabilities. We started using AI and algorithms to identify different patterns and help monitor the hundreds of billions of market events generated every day. This allows us to focus on aspects of potential fraud, manipulation, and fraud that could harm investors.
These days, we leverage advanced analytics with centralized ingestion capabilities. We have a central repository that receives investor complaints and regulatory tips from our member companies and others in the industry. By leveraging the machine-reading capabilities of AI, we can now quickly reach different areas of risk and assess whether we are already aware of the risk or whether this is a new issue to investigate.
And now we're also exploring ways to leverage AI into our testing programs. Specifically, one of the use cases we're considering is sentiment analysis, where we review large sets of unstructured data. For example, investor complaint data analysis: You can quickly identify if a complaint is serious about violations of securities rules or laws, or illegal activity. This allows examiners to focus their efforts and complete examinations more quickly.
We also provide resources to member firms through standardized AI use case documentation. We found that there was no common nomenclature for AI use cases, so we created one. Today, there are up to 14 different use cases. One of the great things we've heard from our companies since publishing this book is that they're using it internally as a resource document for internal discussions, so they can see how they're using AI and how other companies are using AI, especially generative AI. This is helpful in compliance discussions and helps avoid confusion or misunderstandings when other regulators or our company use similar language.
question: How does FINRA work to achieve compliance through FINRA Forward?
answer: FINRA Forward is a new initiative focused on increasing support for member firms by strengthening compliance, modernizing rulesets, and discovering tools to help combat the fraud and cybersecurity risks they face. It's our duty to consider everything we can to continually improve, which is the real reason we launched FINRA Forward.
We want to engage with companies on policy, we want to engage with the investor public, and we're really setting the stage for modernization and transformation to better enable compliance for our member companies and enable us to execute our mission with greater impact.
We're powering data insights. We asked ourselves, “How can we provide more proactive data insights to our members? How can we help them identify issues before an inspection or investigation begins?” We publish report cards and actively share information from our oversight activities, including annual regulatory oversight reports, with our members.
We've also focused on streamlining and reducing data requests as we continue to find more ways to leverage existing data. I could hear the members' voices clearly. in Think about how you can save them time and resources so they can focus on day-to-day compliance efforts. We are strengthening the submission process and exams across the board to enhance efficiency and effectiveness for us as well as for them.
question: What are some of the regulatory trends that FINRA has identified, and how can firms strengthen their compliance programs in response to them?
answer: One of the focuses of our annual regulatory oversight report this year is working with member companies on third-party vendor risk. We created a new Cyber and Operational Resilience Program to help us quickly share information about cyber and fraud risks and threats with our members. We work with member firms to gather information about who their critical vendors are, obtain a list of their vendors and third-party providers, and actively monitor vendors for cyber and fraud risks. We monitor changes in risk and additional threats and attacks that occur against those vendors. We then directly and proactively inform member firms about specific risks and threats, how they are identified, how they can be mitigated, and who they can follow up with at FINRA if they need assistance. In the short time since we set this up, we've issued over 11,000 notifications to over 3,400 unique recipients.
Another emerging trend is the use of generative AI. The question is less about how companies use AI and more about how organized crime groups and other criminal elements use generated AI to attack investors and companies.
FINRA has created a Threat Intelligence Product (TIP) that allows you to send us actionable information about these criminal threats in a secure manner. These threats are not published on our website.
TIPs contain specific instructions on how businesses can protect their organizations and customers from these threats. Threats include everything from how criminals use AI to manipulate markets to impersonate individual and business customers.
Another big threat that we've seen evolve over time is the way criminals impersonate corporate executives, even financial luminaries you see on Bloomberg and CNBC, all the way to major hedge funds. Criminals impersonate these individuals, lure potential investors into fake investment clubs and chat rooms, and begin selling low-priced securities. This is a new twist on the old-fashioned pump-and-dump scheme, or ramp-and-dump scheme.
We also began educating investors directly through the FINRA Foundation and began working with third-party social media providers, other regulators, and exchanges. FINRA has decided to take action and provide information about these threats to everyone who may be affected. These tips have been very successful in not only protecting investors, but also protecting the market by providing necessary information to member companies.
question: What challenges and opportunities do you think technology brings to compliance?
answer: The speed of technology, especially AI and generative AI, requires us to react much faster to what we see. But no one should do this on their own. There are industry peers and other resources you can collaborate with to learn and share best practices. If you are a FINRA member firm, you may also contact FINRA.
The real question is how do you leverage your network so that you can assess the situation in terms of what's going to happen, what the problems are, and where you should position yourself? My advice to compliance officers is to learn all you can about what's going on within your company. Assigned to your company's new product committee, you'll be on the front lines of helping introduce new products while keeping risks in mind.
We call it future-proofing. Ask simple questions like how are you using AI when creating contracts and hiring new vendors? What will you use your AI for? Where will your data be stored? Add a clause to your contract that requires vendors to notify you before enabling new AI tools.
Ask your vendor all the basic questions you've had over the years from a technology perspective. Ask your vendor about their use of AI. In addition to third-party risks, you should also pay attention to third-party risks.
Compliance officers also need to network within the organization and develop relationships with technology stakeholders and chief information security officers. Get to know fraud investigators and AML personnel (anti-money laundering).
Bring everyone together and sit down at the table to discuss what the governance looks like for the use of new technology, vendor technology, and the risks and challenges you face.
Develop centralized capabilities to respond and address risks. That way, as a compliance officer, you'll be better prepared if something happens. It's about being proactive rather than being passive.
As a compliance officer, you want to be the person people run to when a problem arises, instead of running away.
