Cheat sheet: review support for Canadian Securities Institute CSI Canadian Compliance Course (CCC) candidates covering regulation, registration, supervision, conflicts, AML, complaints, and conduct controls.
This independent quick review is for candidates preparing for the Canadian Securities Institute CSI Canadian Compliance Course (CCC), exam code CCC. Use it to refresh core compliance concepts before moving into topic drills, mock exams, and detailed explanations.
This page is independent exam-prep support and is not affiliated with, endorsed by, or sponsored by the Canadian Securities Institute.
Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.
Scope and study context
Focus your review on:
Who regulates what: CSA, provincial commissions, CIRO, FINTRAC, OBSI, CIPF.
Who is accountable: UDP, CCO, supervisors, registered individuals, boards/senior management.
What controls are expected: policies, supervision, monitoring, escalation, remediation, records.
Exam scenarios: identify the regulatory issue, choose the first control action, escalate correctly.
Scan the tables first. The CCC rewards practical recognition: who is responsible, what must be documented, when to escalate, and what controls reduce risk.
Convert each heading into questions. Example: “What makes a conflict material?” “When is suitability triggered?” “What evidence would compliance expect?”
Practice immediately after review. Use original practice questions and topic drills to test whether you can apply the rule, not just remember the phrase.
Treat current CSI materials as the authority. Regulatory terminology, instruments, and procedures can change; use this page as a high-yield companion, not a substitute for the official course.
If it was not documented, the firm may struggle to prove supervision.
Regulatory Bodies and Their Roles
Body / organization
What it does
What it does not do
Exam traps
Provincial and territorial securities regulators
Administer securities legislation, registration, prospectus/disclosure, exemptions, investigations, enforcement
They are not a single national securities commission
Know that securities regulation in Canada is primarily provincial/territorial.
Canadian Securities Administrators (CSA)
Coordinates harmonized rules, national instruments, policy initiatives, notices
Not itself a direct single regulator replacing provincial commissions
CSA guidance influences interpretation but distinguish guidance from binding law.
Canadian Investment Regulatory Organization (CIRO)
Self-regulatory organization for dealer members and market integrity rules, including member conduct, prudential oversight, surveillance, and discipline
Does not replace securities commissions or FINTRAC
Current exam framing may use CIRO; legacy IIROC/MFDA references may appear only in context.
FINTRAC
Federal AML/ATF intelligence unit and compliance regulator under AML legislation
Does not decide securities suitability or approve investments
AML reporting and securities complaint handling are separate workflows.
OBSI
Independent dispute-resolution service for eligible banking/investment complaints
Not a securities regulator or court
A complaint file can involve both internal complaint handling and external dispute resolution information.
Canadian Investor Protection Fund (CIPF)
Protects eligible client property if a member firm becomes insolvent
Does not protect against market losses, bad advice, or normal investment risk
Insolvency protection is not performance insurance.
OSFI
Prudential regulator for federally regulated financial institutions
Does not regulate most securities dealer conduct
Do not confuse banking prudential oversight with securities sales conduct.
Courts / law enforcement
Criminal, civil, and statutory proceedings
Not routine day-to-day compliance supervision
Serious misconduct may trigger regulatory, civil, and criminal consequences.
Canadian Securities Institute
Education and exam provider for the CSI Canadian Compliance Course (CCC)
Not the securities regulator or SRO
Course provider identity is separate from regulatory authority.
“My supervisor approved it” does not excuse misconduct.
Compliance System Lifecycle
flowchart LR
A[Governance and risk appetite] --> B[Risk assessment]
B --> C[Policies and procedures]
C --> D[Training and communication]
D --> E[Supervision and monitoring]
E --> F[Exceptions and escalation]
F --> G[Remediation and discipline]
G --> H[Testing / audit / reporting]
H --> B
Exam trap: registration is not just entry permission. It is an ongoing status tied to proficiency, integrity, solvency, scope of activity, and disclosure.
Client Lifecycle Controls
Stage
Key controls
Common failure
Prospecting
Fair marketing, approved titles/designations, no misleading performance claims
Rep exaggerates credentials or downplays risk.
Account opening
Identity verification, AML risk rating, KYC, account type, RDI, conflicts, referral disclosure, trusted contact where applicable
Account opened before required information is complete.
Product approval
KYP due diligence, risk rating, target client, conflicts, shelf approval
Product sold because it is popular or profitable, not because it is understood.
Client type for whom product may or may not be appropriate
Ongoing obligations
Monitoring, disclosure, valuation, reporting
Suitability: High-Yield Rule
A suitability assessment is not a box-ticking exercise. It asks whether the action is appropriate for the client based on KYC, product knowledge, costs, risks, alternatives, and conflicts.
Situation
Suitability concern
Concentrated position
Even a quality security may be unsuitable if it dominates the portfolio
Frequent trading
Costs and strategy must make sense for the client
Leverage or margin
Losses can exceed comfort level or financial capacity
Complex products
Client understanding and product risk must be documented
Illiquid investment
Must match time horizon and liquidity needs
High-fee switch
Must justify benefit versus cost
Unsolicited order
Does not erase other compliance duties; know the required warning/escalation process
Order-execution-only context
Advice and suitability obligations differ; do not accidentally provide recommendations
Suitability Exam Traps
“Client requested it” does not automatically make it suitable.
“Client signed the disclosure” does not cure an unsuitable recommendation.
“The product is approved” does not mean it is suitable for every client.
“The client is wealthy” does not mean the client has high risk tolerance.
“The investment performed well” does not prove the recommendation was suitable when made.
“The account is small” does not eliminate compliance obligations.
Client-Focused Conflict Management
Conflict source
Why it matters
Expected compliance response
Proprietary products
Firm earns more or has issuer relationship
KYP due diligence, shelf governance, disclosure, suitability controls, alternatives review
Compensation grids
Rep may favour higher-paying products or activity
Supervision of recommendations, compensation review, conflict disclosure
Referral arrangements
Client may not understand who pays whom and for what
Written arrangement, disclosure, approval, records, suitability boundaries
Outside activities
Divided loyalty, client confusion, misuse of position
Pre-approval, conflict assessment, supervision, prohibition if unmanageable
Gifts and entertainment
Influence over recommendations or allocations
Limits, pre-approval, logs, escalation
Personal financial dealings with clients
Exploitation, undue influence, conflicts
Generally high-risk; prohibit or tightly control under firm policy
Related/connected issuers
Biased recommendation or disclosure gap
Clear relationship disclosure and suitability review
Look for vulnerable clients, incomplete KYC, leverage, concentration, conflicts
Market integrity
No manipulation, deceptive trading, insider trading, front-running, unfair allocation
Look for suspicious timing, unusual volume, information advantages
Firm integrity
Effective supervision, escalation, records, controls, training
Look for weak policies, undocumented approvals, ignored red flags
Regulatory accountability
Registration, reporting, cooperation with regulators, books and records
Look for late reporting, missing evidence, unapproved activity
Risk-based oversight
Controls should match the risk of clients, products, branches, reps, and activity
Higher risk requires more supervision, not less
Notes and examples
The Default Exam Answer Pattern
When the facts show uncertainty or risk, the safest compliance sequence is usually:
Identify the issue.
Pause or restrict the activity if needed.
Gather facts and documents.
Escalate to the appropriate supervisor/compliance officer.
Assess the rule, client impact, and firm policy.
Document the decision and rationale.
Remediate, report, train, or discipline where required.
Monitor for recurrence.
Avoid answers that rely on informal approval, verbal assurances, “industry practice,” or client consent alone.
Regulatory Framework at a Glance
The CCC focuses on how securities compliance works in Canada. Know the relationship between legislation, regulators, self-regulatory organizations, firm policies, and internal supervision.
Participant / source
High-yield role
Exam trap
Provincial and territorial securities regulators
Administer securities legislation in their jurisdictions
Assuming Canada has one single securities regulator for all purposes
Canadian Securities Administrators
Coordinated forum for securities regulators; develops harmonized instruments and policies
Treating CSA guidance as optional when it is incorporated into firm procedures
Canadian Investment Regulatory Organization
Self-regulatory organization for investment dealers, mutual fund dealers, and marketplace integrity within its mandate
Confusing firm policy with SRO rules; ignoring both
Canadian Securities Institute
Official provider of the CSI Canadian Compliance Course (CCC)
Assuming course provider equals regulator
Dealer member / registered firm
Must build and maintain a compliance system
Thinking compliance duties belong only to the compliance department
Registered individuals
Must meet registration, proficiency, conduct, disclosure, and supervision requirements
Assuming the firm’s registration cures an individual’s misconduct
Compliance staff
Advise, monitor, test, escalate, and support remediation
Treating compliance as a substitute for business-line supervision
Supervisors / branch managers
Day-to-day supervision of representatives and account activity
Assuming post-trade review alone is enough for high-risk activity
Senior management / UDP / CCO roles
Promote compliance culture and maintain effective controls
Treating accountability as delegable without oversight
Notes and examples
Rule Hierarchy: Practical Exam View
Level
Examples
How to apply it
Securities legislation and regulations
Provincial/territorial securities acts, regulations, national instruments
Internal standard; can be stricter than external rules
Branch/team procedures
Local workflows and evidence files
Must be consistent with firm and regulatory requirements
Individual conduct
Rep, supervisor, compliance actions
“I did not know” is rarely a strong defence if training and policies existed
Fast Decision Rule
If an answer choice says “do nothing because the client agreed”, be skeptical. Client consent may support disclosure, but it usually does not eliminate suitability, conflicts, supervision, AML, market conduct, or recordkeeping obligations.
Dealer Compliance Governance
A strong compliance program is risk-based, documented, tested, and supported by senior management.
Key Roles and Responsibilities
Role
Main responsibility
What the exam may test
Board / senior management
Set risk appetite, allocate resources, oversee compliance culture
Whether management can ignore known control gaps
Ultimate Designated Person
Promotes a culture of compliance and supervises firm activities at a high level
Accountability even when tasks are delegated
Chief Compliance Officer
Establishes and maintains compliance policies, monitors adherence, reports issues
Independence, escalation, evidence of review
Business supervisors
Supervise registered individuals and business activity
First-line responsibility; cannot rely entirely on compliance
Must be disclosed, reviewed, approved where required, and supervised for conflicts
“It is unrelated to securities” does not automatically mean irrelevant
Referral arrangements
Require proper review, disclosure, and controls
Paying or receiving referral fees informally
Changes in information
Registration information must be kept current
Delayed updates can be a compliance issue
Misconduct history
Must be reviewed for fitness and risk
Ignoring prior discipline or client complaints
Personal financial dealings
High conflict risk with clients
Borrowing from, lending to, or sharing profits with clients without approval
Notes and examples
Conduct Principles to Remember
Act honestly, fairly, and in good faith with clients.
Know when a communication becomes a recommendation.
Do not mislead by omission.
Do not use firm resources or client information for outside activity.
Escalate conflicts before acting.
Document client instructions, approvals, warnings, and supervision.
Conflicts of Interest
Conflicts are central to modern securities compliance. A conflict exists when the firm’s or representative’s interests may be inconsistent with the client’s interests.
Identify, disclose, supervise, avoid if not manageable
Proprietary product
Firm earns more from in-house products
Product due diligence, disclosure, suitability review
Outside activity
Rep’s outside business competes with client interests
Prior review, approval, monitoring
Referral arrangement
Client referred for compensation
Written arrangement, disclosure, supervision
Personal trading
Rep trades ahead of clients or alongside orders
Pre-clearance, restricted lists, surveillance
Gifts and entertainment
Influence over recommendations or order flow
Limits, logs, approvals
Allocation conflict
Limited investment opportunity
Fair allocation policy and evidence
Related issuer / connected issuer
Firm has relationship with issuer
Disclosure and review before recommendation
Notes and examples
Conflict Decision Rule
Is there a conflict or potential conflict?
Is it material?
Can it be addressed in the client’s interest?
Is disclosure clear, specific, and timely?
Is disclosure enough, or must the firm avoid or prohibit the activity?
Is the decision documented and supervised?
Disclosure is important, but disclosure alone is often not enough.
AML/ATF, Sanctions, and Financial Crime
Anti-money laundering and anti-terrorist financing controls are compliance essentials. The exam may test whether you recognize red flags and escalation obligations.
Area
Review point
Red flags
Client identification
Verify identity according to firm procedures
Reluctance to provide documentation
Beneficial ownership
Understand who owns or controls the account/entity
Complex structure with no clear business purpose
Third-party determination
Identify whether someone else controls or benefits
Instructions from non-account holder
Politically exposed persons / high-risk clients
Enhanced review may be required
Unusual source of funds or public-office connection
Source of funds / wealth
Must make sense for the client profile
Large deposits inconsistent with occupation
Suspicious transactions
Escalate internally and report where required
Layering, rapid in/out transfers, no investment rationale
Sanctions / terrorist property
Screen and escalate promptly
Name match, high-risk jurisdiction
Ongoing monitoring
Risk profile can change
Sudden dormant-account activity
Recordkeeping
Evidence of identification, review, escalation
Missing file notes after red flags
Notes and examples
AML Exam Traps
Do not tip off the client about suspicious transaction reporting.
Do not accept vague explanations when activity is inconsistent with the profile.
Do not treat one completed ID document as the entire AML program.
Do not ignore third-party instructions.
Do not assume wealthy or long-standing clients are low risk forever.
Communications, Advertising, and Social Media
All client-facing communications must be fair, balanced, and not misleading.
Communication issue
Compliance expectation
Performance claims
Must be accurate, supportable, and not selectively presented
Guarantees
Avoid implying guaranteed returns unless legally and factually correct
Titles and designations
Must not exaggerate proficiency or services
Testimonials / endorsements
Require careful review under applicable policy
Social media
Business use must be supervised and retained where required
Email / messaging
Use approved channels; preserve records
Research / recommendations
Conflicts and assumptions should be disclosed
Sales literature
Approval process before use
Client presentations
Same standards as written advertising if used for business
Trap Language
Be cautious with phrases such as:
“Safe and guaranteed”
“No downside”
“Regulator-approved investment”
“Suitable for all investors”
“Insider opportunity”
“Act now before public announcement”
“Off the record”
“Use my personal email”
Complaints, Investigations, and Enforcement
A complaint is not just a client service issue. It can reveal supervisory, suitability, disclosure, fraud, or control failures.
Step
What should happen
Identify
Recognize oral and written complaints; do not dismiss informal wording
Acknowledge
Follow firm procedures and required timelines
Preserve
Secure emails, notes, order records, account documents
Investigate
Use objective evidence; do not let the accused rep control the process
Involve compliance, legal, senior management, or regulators where required
Respond
Provide clear response through approved channels
Remediate
Correct client impact, update controls, train, discipline if needed
Track
Look for repeated issues by rep, branch, product, or process
Notes and examples
Enforcement Concepts
Regulators and SROs may use tools such as requests for information, reviews, investigations, settlements, terms and conditions, suspensions, fines, or bans. For the CCC, focus less on memorizing sanction labels and more on what conduct triggers escalation and what evidence supports the firm’s response.
Privacy, Cybersecurity, Outsourcing, and Business Continuity
Compliance extends beyond trading rules. Client data, technology, vendors, and operational resilience all matter.
Area
High-yield controls
Privacy
Collect only needed information, use it for proper purposes, protect it, disclose only as authorized
Confidentiality
Restrict access to client and firm information
Cybersecurity
Strong authentication, access controls, incident response, training
Remote work
Approved devices, secure networks, recordkeeping
Outsourcing
Due diligence, written agreements, monitoring, confidentiality, business continuity
Cloud / vendors
Know where data is, who accesses it, and how incidents are handled
Business continuity
Plans for disruptions, client access, trading, records, communications
Incident response
Escalate, contain, document, notify where required
Privacy Trap
A client relationship does not permit unlimited information use. Client information should be used for legitimate business and compliance purposes, shared only through approved channels, and protected from unauthorized access.
Books, Records, and Evidence
In compliance, if it is not documented, it is hard to prove.
Record type
Why it matters
Account documents
Proves KYC, approvals, authority, risk profile
Order records
Shows instructions, timing, suitability context
Trade blotters
Supports surveillance and reconstruction
Communications
Evidence of recommendations, disclosures, complaints
Supervisory notes
Shows review, escalation, rationale
Exception reports
Shows monitoring and resolution
Training records
Shows staff were informed
Policies and versions
Shows rules in effect at the time
Complaint files
Shows objective investigation and response
AML files
Shows identification, risk assessment, escalation
Approvals
Shows authority for outside activities, ads, accounts, products
Recordkeeping Traps
Verbal approval without a file note.
Backdated documents.
Incomplete KYC updates.
Missing rationale for high-risk trades.
Exception report closed with no explanation.
Client instructions recorded after a complaint arises.
Business conducted through unapproved personal devices or accounts.
Financial Compliance and Operational Risk
The CCC may test how operational failures become compliance failures.
Area
Compliance concern
Capital adequacy
Firm must maintain financial resources required for its business
Segregation / custody
Client assets must be protected according to applicable rules
Margin
Leverage increases client and firm risk; supervision is required
Settlement
Failed trades and aged items can signal operational weakness
Do not treat operations as “back office only.” Weak operations can cause client harm, inaccurate records, regulatory breaches, and reputational damage.
Use this workflow when a question describes a suspicious event, complaint, possible breach, or control failure.
flowchart TD
A[Issue or red flag identified] --> B{Client, market, AML, privacy, or firm risk?}
B -->|Yes| C[Preserve records and gather facts]
B -->|No obvious risk| D[Document review and monitor]
C --> E{Immediate harm or prohibited activity possible?}
E -->|Yes| F[Pause, restrict, or escalate urgently]
E -->|No| G[Escalate through normal compliance path]
F --> H[Assess rule, policy, client impact]
G --> H
H --> I{Report or notify required?}
I -->|Yes| J[Report through approved channels]
I -->|No| K[Document rationale]
J --> L[Remediate and monitor recurrence]
K --> L
“If You See This, Think That” Exam Table
Fact pattern
Think
Client wants a high-risk trade inconsistent with KYC
Suitability, warning, escalation, documentation
Rep uses personal email for client business
Recordkeeping, supervision, privacy
Sales contest for one product
Conflict of interest and compensation bias
Large deposits inconsistent with client profile
AML red flag and source of funds
Rep trades before client block order
Front-running / personal trading controls
Complaint sent only to the rep
Complaint handling failure
Branch repeatedly clears exceptions without notes
Supervision failure
Client signs complex disclosure but lacks understanding
Disclosure may be insufficient
Outside business with firm clients
Outside activity, conflicts, approval
Unclear beneficial owner of corporate account
AML/KYC deficiency
High account turnover with commissions
Churning / suitability / supervision
Proprietary product recommended to many clients
Conflict, KYP, suitability, concentration
Rumour-based trading
Market integrity and misleading information
Client controlled by family member without authority
Choosing the fastest business solution instead of the compliant solution. The exam often rewards escalation and documentation over convenience.
Assuming disclosure solves every issue. Some conflicts or unsuitable activities must be avoided or restricted.
Ignoring supervision evidence. A correct review that leaves no evidence is a weak control.
Confusing compliance with legal only. Compliance includes policies, training, supervision, testing, and culture.
Treating KYC as static. Material changes require review and possible updates.
Overlooking firm policy. Firm rules can be stricter than external minimums.
Letting client sophistication override the facts. Sophisticated clients still require fair dealing and proper controls.
Missing AML red flags because the transaction is profitable.
Allowing reps to handle complaints about themselves.
Forgetting conflicts created by compensation, referrals, outside activities, and proprietary products.
Last-Minute Review Checklist
Before your CCC practice exam, make sure you can answer these quickly:
Who are the main Canadian securities regulatory participants?
What are the roles of senior management, UDP, CCO, supervisors, reps, and compliance?
What makes a compliance system effective?
What must be collected and updated for KYC?
How do KYC, KYP, and suitability connect?
When is disclosure insufficient?
What are common material conflicts?
What are red flags for money laundering or terrorist financing?
What is the correct complaint-handling sequence?
What records prove supervision occurred?
What is the difference between pre-approval, post-trade review, and enhanced supervision?
What conduct threatens market integrity?
How do privacy, cybersecurity, outsourcing, and business continuity fit into compliance?
When should an issue be escalated or reported?
Practice Strategy for the CCC
Use this Cheat Sheet as a launchpad, then move into active practice:
Topic drills: Start with KYC/suitability, conflicts, supervision, AML, and complaints.
Mixed sets: Practice switching between regulatory framework, client lifecycle, market conduct, and operations.
Mock exams: Build timing and stamina.
Detailed explanations: Review every missed question and identify whether the miss was a rule gap, fact-pattern miss, or decision-rule error.
Error log: Track recurring mistakes such as “picked disclosure only,” “missed escalation,” or “ignored documentation.”
For the best next step, work through original practice questions by topic, then use a question bank with detailed explanations to confirm you can apply CCC compliance concepts under exam-style pressure.