Skip to main content

Financial Crimes – Common Scams and Ways to Fight Back

Business professional types on phone.

Pause, Think, Verify: Helping Clients Avoid Today’s Most Common Scams

Criminals are becoming increasingly sophisticated in their efforts to defraud investors. From impersonating government agencies and financial institutions to leveraging artificial intelligence to mimic voices, emails, and text messages, today’s scams are designed to create urgency, exploit vulnerabilities, and pressure individuals into making quick decisions.

While investor education remains a critical component of fraud prevention, investment advisers and broker-dealers are uniquely positioned to identify red flags, implement preventive measures, and help clients protect their assets before a scam succeeds.

Understanding Today’s Scam Environment

Scammers continually adapt their tactics to take advantage of current events, emerging technologies, and consumers’ trust in familiar institutions. While the methods vary, most scams are designed to create confusion, exploit emotions, and pressure victims into taking immediate action. By creating panic, scammers attempt to prevent victims from stopping to verify the legitimacy of the request. Understanding the most common scam types can help firms educate clients and recognize potential red flags.

Imposter Scams

Imposter scams occur when criminals pose as trusted organizations or individuals, such as government agencies, law enforcement officials, banks, credit card companies, or even family members. Fraudsters often use spoofed phone numbers, realistic emails, or text messages that appear legitimate. Their objective is typically to obtain sensitive personal information, gain access to financial accounts, or persuade victims to send money under false pretenses.

Investment and Affinity Scams

Investment scams frequently promise high returns with little or no risk, often involving products that are difficult to verify or understand. Fraudsters may use social media, online forums, or personal relationships to gain credibility before soliciting funds. Affinity scams are particularly effective because they target members of specific groups, communities, or organizations, leveraging existing trust to encourage participation.

Romance and Social Engineering Scams

Romance scams involve building an online relationship with a victim over weeks or months before requesting money for a fabricated emergency or investment opportunity. More broadly, social engineering scams manipulate victims through trust, fear, sympathy, or urgency. Rather than exploiting technological vulnerabilities, these scams exploit human behavior, making them especially difficult to detect.

Tech Support and Account Security Scams

In these schemes, individuals receive unsolicited calls, emails, or pop-up messages claiming that a computer, bank account, or financial account has been compromised. Victims are urged to provide login credentials, grant remote access to their devices, or transfer funds to supposedly “secure” accounts. In reality, the scammers are seeking direct access to the victim’s assets and information.

Payment and Cryptocurrency Scams

Many fraudsters instruct victims to use unusual payment methods such as gift cards, wire transfers, peer-to-peer payment applications, or cryptocurrency. These payment methods are difficult to reverse and can make recovery of lost funds nearly impossible. Requests for payment through non-traditional channels are often a significant warning sign that a scam may be underway.

What Advisory Firms and Broker-Dealers Can Do

Although firms cannot prevent every attempted fraud, there are several measures that can significantly reduce the risk of client harm.

Obtain Trusted Contact Information

One of the most effective tools available is obtaining a trusted contact person for client accounts. A trusted contact can serve as an important resource when there are concerns about possible financial exploitation, diminished capacity, or unusual account activity.

For broker-dealers, FINRA Rule 4512 requires firms to make reasonable efforts to obtain trusted contact information for retail customer accounts. Investment advisers are also increasingly adopting this practice as part of their overall client protection framework.

By proactively collecting and periodically updating trusted contact information, firms strengthen their ability to respond when suspicious situations arise.

Train Employees to Recognize Red Flags

Front-line personnel are often the first line of defense against fraud. Firms should provide ongoing training to help employees identify warning signs such as:

  1. sudden requests for large or unusual disbursements;
  2. wire transfers to unfamiliar third parties;
  3. increased client anxiety or references to secretive situations;
  4. requests involving cryptocurrency, gift cards, or other atypical payment methods;
  5. clients acting under apparent pressure from an outside party; and
  6. multiple failed attempts to verify account information or instructions.

An employee who recognizes these indicators may be able to intervene before fraudulent transactions occur.

Strengthening Verification Procedures

Verification procedures should be robust enough to address today’s evolving fraud tactics. Firms should consider implementing procedures that require additional verification for high-risk transactions, requests involving changes to account information, or instructions that deviate from established client behavior.

Encouraging clients to independently verify unsolicited requests through known telephone numbers or established communication channels can also help prevent successful impersonation attempts.

Educating Clients Regularly

Client awareness remains one of the strongest defenses against fraud. Regular communications, newsletters, seminars, and website resources can help clients understand current scam trends and recognize warning signs. Simple reminders can be highly effective:

  • pause before acting on urgent requests;
  • verify the identity of anyone requesting money or personal information;
  • be skeptical of unexpected communications; or
  • never assume an email, text message, or phone call is legitimate simply because it appears to come from a trusted source.

Conclusion

As fraud schemes continue to evolve, financial professionals must remain vigilant. A proactive approach that combines employee training, client education, trusted contact information, and strong supervisory controls can significantly reduce the likelihood that clients become victims of financial exploitation.

The most important message firms can share with clients is also the simplest: when faced with an urgent or unexpected request, pause, think, and verify before taking action. Those few moments of caution can make the difference between protecting a lifetime of savings and becoming the next victim of an increasingly sophisticated scam.

Contact RRS for more information.

Summertime is Here! Compliance Can Keep You Cool!

As the summer heat kicks in, while there is little indication that the regulatory “warming trend” will subside any time soon, the typical slowdown in business over the summer months provides opportunities to review your firm’s compliance program. Focusing on selected aspects of your compliance program may also reveal ways to cut costs associated with compliance in the long run. The secret to an efficient review is to focus on the regulatory target areas and not try to do too much.

The Regulatory Focus

The regulatory focus on the retail investor will continue. The SEC and FINRA have enhanced their practices to target the areas of the highest risk to the public. Novel new products such as digital assets, structured securities, and prediction markets are in focus. The updates to Regulation S-P brought renewed focus on firm’s due diligence practices for vendors that host systems and access or store customer data. Piling on all that is the increasing risk of cybercrime – both internal and external – and the increasing use of artificial intelligence tools. If that’s all buttoned up, then you don’t want to get caught off guard with “old school” compliance gaps such as inadequate policies and procedures, recordkeeping, or supervision. There are certainly a wide range of focus areas that can be addressed. Like many firms, the regulators are using AI to assist in their analysis, which provides the ability to cover a wider range of topics in exams.

Identifying the Areas to Review

With the above in mind, the review of your firm’s operations should focus on those areas most relevant to your business. First, assess your products and services from a financial perspective, identifying products and services that generate the most revenue. The compliance review should focus on those areas of your firm’s operations that generate the most business, i.e. revenue. Also, consider looking at the policies and procedures for supervising branch offices and remote locations. Additionally, if there is a product or service that you have not reviewed in some time, or that is new to your firm, the policies and procedures related to those areas should be included in your review. For example, if you’re selling more ETF’s or insurance securities, look at the supervisory and operational procedures for those products. If you recently added digital assets or prediction market access, look at the procedures governing those practices and the training programs in place for the public facing and supervisory personnel.

Second, consider any areas where you rely on third parties to provide a significant support function. The most common for broker-dealers is the clearing function, while RIAs may rely heavily on the custodian or a portfolio valuation service. Create a list of vendors that includes the services they provide, the contact people for the vendor, and the contract date. Larger firms should also add the person(s) internally who own the relationship, such as the financial officer for accounting software, the operations officer for clearing relationships, etc. Consider all services provided by third parties or affiliates (services provided by affiliates are typically considered outsourced) including surveillance and compliance management vendors. In addition to the clearing and custody relationships noted above, many firms use third party vendors to support internet access and email, storage of books and records, payroll processing, and accounting functions. Some other common areas that are often overlooked are the phone systems, technology support, law firms, and consultants.

Conducting the Review

For the areas you’ve selected to review, determine how the business is processed from start to finish. It may be helpful to create a flow diagram of the process that identifies “touch points” where a supervisory procedure or control would/should exist. A good example would be where the representative forwards completed paperwork for a variable annuity transaction to a principal for review. These points could include the representative assembling the paperwork, delivering it to a sales assistant, and the sales assistant forwarding it to the principal or a centralized operations department for review and approval. Your procedures should address a control or supervisory process for each time the paperwork changes hands. Perhaps the sales assistant does a check to ensure all the proper completed paperwork is included, and in the predetermined order, before forwarding to the principal. This simple control will reduce delays in processing paperwork and the time that the principal has to spend reviewing, and supervising, the transaction, thereby saving time and money. When reviewing processes, policies and procedures for new lines of business, be careful not to try to fit a square peg into a round hole. That is, don’t assume that the procedure for supervising an equity security transaction will fit the exchange traded note. You must consider the unique aspects of the product, related disclosures, and the customer’s objectives. This is a simple example and more complex operations require a more in-depth assessment even when processes are automated, we often find data breaks where two or more data feeds are required to complete a process. These need to be carefully mapped out.

If your firm relies on third party vendors and does not have a due diligence process for assessing them, develop one – you are late to the game. Start with the vendor contract to determine if the regulatory requirements are met. For example, Regulation S-P now formally requires notification of a breach within 72 hours. Also, if the vendor is deemed a “Service Bureau” for the purposes of the SEC’s Books and Records Rules, the vendor must agree to make the records available to the Regulators. Similarly consider any AML, business continuity, and privacy issues that may arise from the relationship. For FINRA members, these arrangements may also have to be disclosed before implementation. Depending on the nature of the vendor relationship, your due diligence process should include reviews of the vendor’s internal control reports, business continuity plans, information and technology security, and insurance coverage such as E&O, theft, and professional liability. Ongoing vendor monitoring is critical. While most services can be monitored on an ongoing basis – that is, if the service fails you know it and correct it with a backup plan – it’s a good practice to schedule a formal meeting at least annually with the vendors’ representatives to review the services and reassess the areas covered in the due diligence process.

Correction and Documentation

As you complete each review, create a short, written summary of the review and gap analysis performed, including the corrective steps to be taken, if any. For material deficiencies, consider reviewing with counsel to determine the potential regulatory impact. In addition to amending written policies and procedures, corrective actions should include training employees to ensure that proper procedures are implemented, and the new procedures are adequately communicated.

Conclusion

A compliance review provides a great opportunity to reassess your business operations, not only for compliance purposes, but to identify areas of efficiency and cost savings. This type of review can be incorporated into your annual review requirements and supervisory controls testing. Your review should be reasonable, and you should not try to do too much. Once you start digging, you may find that one issue will take longer than you anticipated completing. It’s better to do a portion at a time and complete a full review on an area than to take on too much and leave items undone.

So, what are your plans this summer? Awaiting the regulatory heat? Or sitting back and enjoying the compliance reliance?

By: Louis Dempsey, CRCP, CSCP


Regulation S-P: Next Steps for Investment Advisers

Business professionals looking at charts.

As the SEC’s amended Regulation S-P requirements become effective for all investment advisers, firms should now be focused on implementation of the requirements, including cybersecurity governance, vendor oversight, use of artificial intelligence (AI), and testing their ability to respond effectively to cyber incidents.

We outline key areas firms should prioritize over the balance of the year.

Implementation Readiness

The Regulation S-P requirements now place greater emphasis on incident response, customer notification, and protection of customer information.

Firms should ensure they have:

  • Written incident response procedures
  • Escalation and breach assessment protocols
  • Customer notification procedures
  • Vendor oversight programs
  • Information security controls
  • Documented employee training
  • Evidence of testing and governance

Recommended Action Items:

  • Conduct at least one tabletop cybersecurity exercise
  • Confirm client notification templates are prepared
  • Test escalation and communication workflows
  • Review vendor incident notification obligations

Key Risk: It is expected that the SEC will focus on firms that cannot demonstrate implementation and testing of their cybersecurity controls.

Artificial Intelligence (AI) Governance

AI usage has expanded rapidly, creating new regulatory and operational risks.

The SEC expects firms to maintain controls over customer information regardless of the technology platform being utilized.

Primary AI Risks:

  • Employees entering confidential client data into public AI systems
  • Unapproved “shadow AI” usage
  • AI-generated inaccuracies
  • Improper use of AI-generated marketing content
  • Vendor AI data retention concerns

Recommended Controls:

  • Establish an AI Governance Policy
  • Maintain an approved AI tools inventory
  • Prohibit entry of customer information into public AI platforms
  • Require human review of AI-generated content
  • Conduct employee AI usage training
  • Include AI vendors in vendor due diligence reviews

Best Practice: Treat AI access and governance similarly to email, cloud storage, and cybersecurity controls.

Cybersecurity & Threat Management

Cyber threats targeting financial services firms continue increasing in sophistication.

Key Threats Firms Should Monitor:

  • AI-powered phishing attacks
  • Business email compromise (BEC)
  • Remote Access Tool (RAT) attacks
  • Ransomware
  • Vendor and supply chain breaches
  • Credential theft and MFA bypass attacks

Recommended Controls:

  • Multi-factor authentication (MFA)
  • Endpoint Detection & Response (EDR)
  • Device encryption
  • Patch management
  • Privileged access restrictions
  • Secure backup testing
  • Employee phishing simulations
  • Wire transfer verification procedures

Best Practice: Cybersecurity should be treated as an enterprise risk management issue, not solely an IT function.

Vendor Oversight & Third-Party Risk Management

The SEC continues to increase focus on vendor oversight. Firms should identify all vendors with access to:

  • Customer information
  • Network infrastructure
  • Email systems
  • Portfolio or trading systems
  • AI or cloud environments

Recommended Vendor Reviews:

  • SOC 2 reports
  • Cybersecurity questionnaires
  • Incident notification obligations
  • Data encryption standards
  • Subcontractor usage
  • Business continuity capabilities
  • Cyber insurance coverage

Best Practice: Require contractual notification obligations for suspected breaches within 72 hours.

SEC Examination Preparedness

Regulators are increasingly requesting evidence of implementation rather than simply reviewing policies.

Firms should be prepared to provide:

  • Evidence of employee training
  • Incident response testing results
  • Vendor due diligence documentation
  • Access review records
  • Cybersecurity governance documentation
  • Risk assessments
  • AI governance documentation
  • Annual review and testing results

Likely SEC Examination Questions:

  • How does the firm identify and classify cyber incidents?
  • How are vendors monitored?
  • How does the firm govern AI usage?
  • What testing has been performed?
  • How would the firm notify clients after a breach?
  • What evidence exists that management reviewed cybersecurity risks?

Employee Training

Many cybersecurity incidents continue to originate from employee actions.

Training should include:

  • Phishing awareness
  • Password and MFA security
  • AI usage restrictions
  • Remote work security
  • Escalation procedures
  • Social engineering risks
  • Data handling procedures

Best Practice: Conduct periodic phishing simulations and maintain evidence of employee participation.

Governance & Documentation

One of the most important themes for 2026 is documentation.

If an action is not documented, regulators may assume it did not occur.

Firms should maintain documentation related to:

  • Testing activities
  • Vendor reviews
  • Employee training
  • Risk assessments
  • Incident response exercises
  • AI governance reviews
  • Cybersecurity committee or management discussions

Best Practice: Maintain centralized cybersecurity and compliance evidence repositories.

Final Takeaways

For the remainder of 2026, investment advisers should focus on five core themes:

  1. Implementation and Awareness
  2. Cybersecurity Governance
  3. AI Oversight and Controls
  4. Vendor Risk Management
  5. Testing and Documentation

The firms best positioned for SEC examinations will be those able to demonstrate that cybersecurity, AI governance, and operational controls are active, tested, and supported by management oversight.

Regulation S-P should now be viewed as a broader operational and cybersecurity framework rather than solely a privacy rule.

Strengthening Your Broker-Dealer Compliance Program with Support from RRS

Broker Dealer Compliance Program and FINRA Compliance Review

Broker-dealers operate in one of the most highly regulated areas of the financial services industry. Regulatory oversight from the SEC, FINRA, and other self-regulatory organizations requires firms to maintain strong compliance controls and supervisory systems. As a result, firms must implement a comprehensive broker dealer compliance program that addresses supervisory responsibilities, internal controls, regulatory reporting, and periodic compliance testing.

Continue reading

How RRS Helps Firms Build an Investment Adviser Compliance Program

Investment adviser compliance program review and regulatory testing

Investment advisers operate in a complex regulatory environment where maintaining a strong investment adviser compliance program is essential. The Securities and Exchange Commission (SEC) requires advisers to establish and maintain formal compliance systems designed to prevent regulatory violations and protect investors.

Continue reading