Wednesday, June 16, 2010

New Stock-by-Stock Circuit Breaker Rules

Last week US SEC approved the new stock-by-stock "circuit breaker" rules. The rules, which were proposed by the national securities exchanges and FINRA and published for public comment, come in response to the market disruption of May 6.

SEC anticipates that the exchanges and FINRA will begin implementing the newly-adopted rules as early as Friday, June 11.

Under the rules, trading in a stock would pause across U.S. equity markets for a five-minute period in the event that the stock experiences a 10% change in price over the preceding five minutes. The pause, which would apply to stocks in the S&P 500 Index, would give the markets the opportunity to attract new trading interest in an affected stock, establish a reasonable market price, and resume trading in a fair and orderly fashion. Initially, these new rules would be in effect on a pilot basis through December 10, 2010.

The markets will use the pilot period to make appropriate adjustments to the parameters or operation of the circuit breakers as warranted based on their experience, and to expand the scope to securities beyond the S&P 500 (including ETFs) as soon as practicable.

At Chairman Schapiro's request, the SEC staff also will:
  • Consider ways to address the risks of market orders and their potential to contribute to sudden price moves.
  • Consider steps to deter or prohibit the use by market makers of "stub" quotes, which are not intended to indicate actual trading interest.
  • Study the impact of other trading protocols at the exchanges, including the use of trading pauses and self-help rules.
  • Continue to work with the exchanges and FINRA to improve the process for breaking erroneous trades, by assuring speed and consistency across markets.
SEC staff is working with the markets to consider recalibrating market-wide circuit breakers currently on the books — none of which were triggered on May 6. These circuit breakers apply across all equity trading venues and the futures markets.

Jack's comment: When the market is getting more "emotional", the circuit breaker may be an effective way to let investors cool down, especially if the emotion is triggered by error or manipulative orders.

Wednesday, June 09, 2010

SFC Concluded the Proposals to Enhance Investor Protection

Two weeks ago SFC has concluded the consultation on those proposals to enhance investor protection. The new measures include a consolidated product handbook with revised product codes for unit trusts and mutual funds and for investment-linked assurance schemes as well as a new product code for unlisted structured investment products. There are also requirements for product key facts statements to summarise the key features and risks of investment products, issuers to provide a post-sale "cooling-off" or "unwind" right for certain unlisted structured investment products to give investors a window to exit these investments, and conduct requirements for intermediaries to enhance selling practices relating to the sale of investment products.

In December 2009, I summitted the comments on the consultation paper on behalf of the Hong Kong Chapter of the International Academy of Financial Management (IAFM). The finalized measures relating to conduct of intermediaries are largely conforming to my expectations. My brief comments on the conclusions are set out as follows:
  • Investor Characterization: It remains a subjective process for intermediaries to judge whether the client has derivative knowledge. In order to solicit more new clients for structured products, I expect the intermediaries will organize or sponsor "derivative training courses" for retail investors. 
  • Professional Investors: As I've said, the proposal of increasing the portfolio requirement for professional investors is useless and finally scrapped by SFC. To ensure that a professional investor has the relevant product knowledge, again intermediaries had better provide free training sessions to them.
  • Pre-Sale Disclosure of Monetary and Non-Monetary Benefits: As expected, SFC has compromised by requiring only the disclosure of the percentage ceiling, between the two extremes of specical disclosure in exact percentage and generic disclosure.
  • Use of Gifts by Distributors in Promoting a Specific Investment Product: Non-bank intermediaries should have raised strong objection to the use of gifts for product promotion and SFC has no pressure to impose this restriction.
  • Sales Disclosure Document: This proposal is probably the least controversial one.
  • Audio Recording: Again non-bank intermediaries should have raised strong objection to mandatory audio recording as this is not practical. Banks are unfortunately forced by HKMA to do so.
  • Post Sale Arrangements – Refund by Distributors Under a Cooling-Off Period: SFC has quite insisted on implementing the post-investment cooling-off period even though it is costly. Again banks are unfortunately required by HKMA to implement pre-investment cooling-off period as well.

Wednesday, June 02, 2010

SFC fines Merrill Lynch for systems and controls failings

SFC recently fined Merrill Lynch (Asia Pacific) Limited and Merrill Lynch Futures (Hong Kong) Limited (collectively Merrill Lynch) $3,500,000 for systems and controls failings associated with the mis-marking activities in a trading book. Such kind of cases has been common in overseas countries over the past years but appears to be the first one in Hong Kong.

SFC's investigation found that during the period from December 2007 to October 2008, a managing director of Merrill Lynch had mis-marked a trading book in exotics options (Book) by manipulating the volatility marks in the valuation model, and accessed the computer system without authority to alter pricing parameters on various occasions. The mis-marking activities, which did not apply to any other books, resulted in the value of the Book being inflated by approximately US$25 million and caused the actual loss in the Book to be wrongly reported internally.

SFC found that Merrill Lynch did not have adequate internal controls procedures in place to manage the risks associated with mis-marking, in that:
  • there was uncertainty as to supervisory responsibilities over the trader and the Book;
  • the price verification mechanism applied to other trading books was not applied to the Book;
  • there were inadequate checks and balances over the Book to mitigate operation risks including risks associated with fraud and dishonest activities;
  • there was insufficient safeguard over information security and integrity as regards the Book;
  • trading and valuation policies were not sufficiently implemented over the Book; and
  • senior management failed to adequately manage the risks associated with the Book.
Merrill Lynch accepts that its systems and controls fell short of those expected in respect of the Book. SFC accepts that Merrill Lynch's misconduct was not intentional (!) and Merrill Lynch has taken remedial steps to address the compliance weaknesses.

This case is no doubt a scandal in Hong Kong's risk management industry. Would the managing director and other key personnel of Merrill Lynch be personally liable?

Wednesday, May 26, 2010

Pre-Investment Cooling-off Period

Last week HKMA eventually announced the implementation of pre-investment cooling-off period (PICOP) in the sales of non-listed derivative products to retail investors since 1 January 2011.

Under the PICOP arrangements, after a bank has ensured that a non-listed derivative product is suitable for an eligible customer and adequately disclosed material product information to the customer, it should allow the customer at least 2 calendar days (of which the last day should be a business day) to understand the product, consider the appropriateness of the investment and consult with family members and friends. The price and terms of transaction will be fixed on the day when the customer gives instruction to the bank to confirm placement of an order (i.e. upon the end of the PICOP). The bank must arrange the customer to give specific confirmation of order placement on the execution day, supported by proper audit trail. Under no circumstances should the bank allow the customer to confirm the order before the execution day.  Taking T as the sales day, execution day should be a business day on T+2 at the earliest.

It appears that if the customer keeps silent (i.e. no confirmation of the order) upon the end of the PICOP, the order would not be placed.

In determining whether PICOP should be applied to a particular dealing with a retail customer, the bank should consider the customer's age, asset concentrationand whether he/she is a first-time buyer of the same type of product as follows:
  • For an elderly customer (aged 65 or above), PICOP should be mandatory except that the customer will be allowed to opt out from the PICOP arrangement if (i) the customer's asset concentration is below 20% and (ii) he/she is not a first-time buyer of the type of product in question.
  • For a non-elderly customer, PICOP is not necessary except if (i) the customer's asset concentration is 20% or above and (ii) he/she is a first-time buyer of the type of product in question.
Asset concentration is the percentage of the customer's total net worth (excluding real estate properties) to be invested in the relevant transaction. The bank may rely on the customer's self-declaration to ascertain asset concentration.

Even one particular transaction does not exceed 20%, how about if the customer's total portfolio has been occupied by more than 20% by non-listed derivative products (including his/her previous transactions)?

In determining whether a customer is a "first-time buyer" of a particular type of product, a bank may take into account his/her actual investment(s) executed through the bank or another intermediary. If the customer has such investment experience with another intermediary, the bank should gather from the customer the relevant documentary proof (e.g. contract notes or monthly statements) and retain a copy for record purpose. Moreover, the bank should obtain the customer's signed declaration that he/she has such investment experience.

Wednesday, May 19, 2010

Systemic Short Sale Violations

Recently US FINRA fined FINRA fined New York's Deutsche Bank Securities $575,000 and Boston's National Financial Services (NFS) $350,000 for executing numerous short sale orders in violation of Regulation SHO and for related supervisory violations.

Regulation SHO requires that a broker or dealer may not accept or effect a short sale order in an equity security without reasonable grounds to believe that the security can be borrowed, so that it can be delivered on the date delivery is due. Identifying a source from which to borrow such security is generally referred to as obtaining a "locate." Locates must be obtained and documented prior to effecting a short sale.

Both Deutsche Bank and NFS implemented Direct Market Access trading systems for their customers that were designed to block the execution of short sale orders unless a "locate" had been obtained and documented. But FINRA found that Deutsche Bank disabled its system in certain instances and NFS created a separate system for certain customers – so that in both instances, the systems no longer blocked some short sale orders that did not have valid, associated locates.

FINRA's review of a sample of short sale orders at both firms revealed that some short sale orders entered through the Direct Market Access trading systems were released for execution without any evidence that a locate had actually been obtained.

In Deutsche Bank's case, the firm's systems sometimes experienced outages that prevented the importing of locate data and, as a result, short sale orders placed for execution were automatically rejected, even when a client had already obtained a valid and properly documented locate. FINRA found that during these system outages, Deutsche Bank disabled the system's automatic block, permitting client short sale orders to automatically proceed for execution without first confirming the presence of an associated locate.

In addition to its automated process, NFS created a separate manual locate request and approval process for approximately 12 of the firm's prime brokerage clients, which preferred to obtain locates in multiple securities prior to commencement of the trading day. Requests for, and approvals of, the multiple simultaneous locates were transmitted via email exchanges with account representatives on the firm's Prime Services Desk, and were not required to be entered into the firm's stock loan system at the time of approval. Further, prime clients were allowed to enter and execute their orders through automated platforms that did not have the functionality to automatically block execution of a short sale order that did not have a valid and documented locate.

Neither Deutsche Bank nor NFS performed a meaningful post-trade date review of short sale orders to identify short sale orders executed without a valid, associated locate having been obtained or documented.

Further, both firms implemented inadequate supervisory systems in connection with their Regulation SHO compliance. Deutsche Bank was aware that its system to block short sale orders in the absence of locates was periodically disabled over a period of more than four years (from January 2005 through September 2009), but failed to devise or implement a replacement procedure. Similarly, NFS created a flawed system for certain customers that failed to ensure that certain short sale orders had valid and timely locates associated with them. NFS's flawed system operated for nearly four years (from January 2005 through August 2008).

Wednesday, May 12, 2010

Churning and Other Trading Malpractices

Last week US FINRA has ordered Westpark Capital, Inc. to pay a total of $400,000 for supervisory system failures, and has suspended two officers for failing to supervise brokers in two now-closed Long Island branches who churned customer accounts and engaged in unauthorized and unsuitable trading in multiple accounts. The monetary sanction includes a $100,000 fine and $300,000 in restitution to affected customers.


FINRA suspended Westpark's former Chief Compliance Officer, William A. Morgan, for four months in any principal capacity and ordered him to pay a $5,000 fine. Chief Operations Officer Jason S. Stern has been suspended for three months in any principal capacity and fined $20,000.

In related actions, FINRA has barred and/or fined two brokers and a branch manager who were previously employed in Westpark's Long Island branch offices, and has filed a complaint against another former broker involved in the misconduct, charging him with churning accounts and other violations. Two additional former brokers involved have already been barred, by FINRA or SEC, for misconduct at other firms prior to or after their employment with Westpark.

Several of the brokers involved came to Westpark from broker-dealers that had lengthy disciplinary records and that FINRA has expelled from the securities industry, such as Stratton Oakmont, Inc., LH Ross & Co., Salomon Grey Financial Corp. and Continental Broker-Dealer Corp. When Westpark hired them, several of the brokers themselves had histories that included multiple customer complaints and/or disciplinary actions.



In its action against Westpark, Morgan and Stern, FINRA found that between February 2006 and July 2007, the firm failed to establish and maintain an adequate system for supervising its brokers. Among the supervisory system's deficiencies:
  • Westpark failed to restrict the activities of certain Long Island brokers and failed to monitor their customer account activities, even though they had disciplinary histories and customer complaints that included unauthorized, unsuitable and excessive trading;
  • The firm performed inadequate monitoring of excessive trading, failed to have standards for what constituted excessive trading and failed to prescribe any steps that would be taken if excessive trading were suspected; and
  • The firm's system assigned front line supervisory responsibility to branch office managers, even though the Long Island managers were inexperienced or had previously been disciplined for failure to supervise.
Ddespite the fact that Westpark had placed all of the brokers in question on "heightened supervision," Morgan and Stern failed to supervise several brokers who committed serious sales practice violations – including unauthorized, unsuitable and excessive trading involving at least 19 customer accounts.


Morgan and Stern failed to adequately scrutinize the conduct of the Long Island brokers and to address red flags, including disciplinary and employment histories, customer complaints and questionable account activity, such as evidence of excessive trading, a high level of margin and frequent concentration of customer accounts in a single security.

In related actions, FINRA has taken the following actions against a former branch manager and former brokers at Westpark's former Long Island branches:
  • Robert A. Bellia, Jr., a former branch manager, was barred permanently from association with any securities firm in a principal capacity and ordered to pay a $10,000 fine. Bellia failed to supervise three Westpark brokers who churned and executed unsuitable and unauthorized trades in at least 12 customer accounts.
  • Dale R. Menendez, Jr., a former broker, was barred permanently from the industry by a FINRA Hearing Officer and ordered to pay over $110,000 in restitution to his customers. Menendez engaged in excessive and unauthorized trading, mischaracterized customer transactions to his firm and failed to appear for testimony during the FINRA investigation of his conduct.
  • Michael Quattalaro, a former broker, was barred permanently from the securities industry. Quattalaro churned and engaged in excessively unsuitable trading in two customer accounts and exercised discretion in those accounts without prior written customer authority.
  • Chanse K. Menendez, Sr., a former broker, has been charged in a FINRA complaint with excessive trading and churning activity in two customer accounts. Menendez mischaracterized "solicited" trades as "unsolicited" trades in an apparent attempt to conceal his misconduct in those accounts, as well as in a third account. In addition, the complaint alleges that Menendez failed to appear for testimony and provide documents during the FINRA investigation of his conduct. The case is pending.

Wednesday, May 05, 2010

Failure to Protect Clients from Hackers

Recently US FINRA fined D.A. Davidson & Co., $375,000 for its failure to protect confidential customer information by allowing an international crime group to improperly access and hack the confidential information of approximately 192,000 customers.


Prior to January 2008, D.A. Davidson did not employ adequate safeguards to protect the security and confidentiality of customer records and information stored in a database housed on a computer Web server with a constant open Internet connection. The unprotected information included customer account numbers, social security numbers, names, addresses, dates of birth and other confidential data. Furthermore, the firm's procedures for protecting that information were deficient in that the database was not encrypted and the firm never activated a password, thereby leaving the default blank password in place.

On 25 and 26 December 2007, D.A. Davidson's database was compromised when an unidentified third party downloaded confidential customer information through a sophisticated network intrusion. To breach D.A. Davidson's system, the hacker employed a mechanism called "SQL injection," an attack in which computer code is repeatedly inserted into a Web page for the purpose of extracting information from a database. The hacker was able to access and download the affected customers' confidential information. While these attacks were visible on Web server logs, the firm failed to review those logs.

Between April 2006 and October 2007, the firm had retained independent auditors and outside security consultants to review and/or audit its network security. During the course of those consultations, the firm received recommendations for enhancements to its security systems. Although the firm implemented the majority of those recommendations, it failed to implement a recommendation, made in or about April 2006, that it install an intrusion detection system. The firm had not implemented such a system at the time the hack occurred in December 2007.

The breach was discovered through an email that was sent by the hacker on 16 January 2008, blackmailing the firm. Upon receiving the threat, D.A. Davidson reported the incident to law enforcement and assisted the Secret Service in identifying four members of an international group suspected of participating in the hacking attack of the firm. Three of those individuals have been extradited from Eastern Europe, arrested and are facing charges in federal court in Montana.

FINRA took into consideration the firm's quick response to protect its customers and cooperation with law enforcement authorities and the fact that do date, no customer has suffered any instance of identity theft when assessing the fine in this matter.

IT security risk is quite high today. Recently SFC also issued a circular on IT management to all licensed corporations, suggesting some control techniques and procedures in respect of the following key ideas:
  • Information security policy;
  • Access control;
  • Encryption;
  • Change management;
  • User activities monitoring; and
  • Data backup and continuity planning