Most community banks offer investment and insurance products through a third-party broker-dealer. The representatives may be employees of that firm, or dual employees, and the trades, the supervision, and the securities licensing all run through an organization the bank does not control.
Which produces the central problem in this area: the bank is not the broker-dealer, and the bank owns the customer relationship, the premises, the name on the door, and a specific set of regulatory obligations that do not transfer. When a customer believes they bought a bank product, when a complaint arrives at the branch, or when an examiner asks how the program is overseen, the answer has to come from the bank.
This post is about that oversight. Our post on securities licensing covers who needs which registration, and insurance licensing covers the insurance side.
A third-party networking arrangement is the common community bank model: an unaffiliated broker-dealer provides representatives and supervision, operating on bank premises under an agreement, with compensation shared under defined terms.
A dual-employee arrangement, where the representative is employed by both the bank and the broker-dealer, which increases the bank's involvement and its exposure.
A bank-owned or affiliated broker-dealer, which puts supervision inside the organization and is uncommon below a certain size.
The bank's obligations attach in all three. It remains responsible for the required nondeposit product disclosures, for the physical and operational arrangements that keep the products distinguishable from deposits, for the conduct of its own unlicensed employees, for the handling of complaints its customers make to it, for the privacy treatment of customer information shared with the program, and for third-party oversight of the arrangement generally.
Everything the bank can see and do about the program is in the contract, and community bank agreements are frequently the broker-dealer's standard form with nothing added.
Terms worth having, and worth reopening at renewal:
Supervisory responsibility stated explicitly — who supervises the representatives, what that supervision consists of, and what the bank is and is not responsible for.
Information flow to the bank. This is the most important and most commonly missing item. The bank should receive, on a defined cadence: complaints involving its customers, sales activity data sufficient to identify concentrations and patterns, examination and audit findings affecting the program, disciplinary history and any regulatory action involving assigned representatives, and notice of representative changes. A bank that receives only a monthly revenue statement cannot oversee anything.
The right to remove a representative from the bank's premises, without needing to establish cause to the broker-dealer's satisfaction.
The bank's inspection and audit rights, and access for its regulators.
Complaint handling protocol — how a complaint received at a branch is transmitted, tracked, and reported back with resolution.
Compensation terms and their disclosure, including anything paid to bank staff for referrals.
Use of the bank's name and marks, and advertising approval, so nothing goes out under the bank's brand without review.
Indemnification, and termination provisions addressing customer notification and account transition — because a program change is a customer event and an unplanned one damages relationships.
Where nondeposit investment products are sold to retail customers on bank premises, the interagency requirements call for clear disclosure that the products are:
These must be provided in a manner and at a time that makes them meaningful — orally and in writing at or before the sale, and in advertising and promotional material, with the customer's written acknowledgment obtained and retained.
The failure mode is not usually the absence of the disclosure. It is that the disclosure was given as a form among forms while everything else about the setting — the branch, the bank's logo, the employee the customer has banked with for a decade — communicated the opposite. Misrepresentation of insured status, whether express or by implication, is the highest-severity issue in this area, and "by implication" is where banks fail.
Related operational requirements: conducting the activity in a distinct area to the extent practicable, not using the same personnel to take deposits and sell investment products where avoidable, avoiding product names similar to the bank's own in ways that suggest a bank obligation, and reviewing advertising so nothing implies insurance or guarantee.
The distinction that trips institutions: the broker-dealer supervises the representatives' securities activities. The bank still has to oversee the arrangement and its own people.
Its own unlicensed employees. Referral practices, what branch staff say, and referral compensation that must remain nominal and not contingent on a sale. This is entirely the bank's responsibility and it is where the most common violations occur.
Complaint capture. Customers complain to the bank. A complaint about the investment program received by a branch manager is a complaint the bank has received, and it belongs in the bank's complaint data, its categorization, its root cause analysis, and its trend reporting — regardless of who investigates it. Institutions that route program complaints to the broker-dealer and record nothing have a gap in their compliance management system, as described in our compliance management system post.
Patterns visible only from the bank's side. The bank can see things the broker-dealer cannot: a certificate of deposit closed and immediately followed by an annuity purchase, a home equity draw preceding an investment, an older customer's deposit relationship being systematically converted. Those source-of-funds patterns are among the most informative sales practice indicators available and they exist in the bank's data.
Incentive design, including referral compensation for bank staff and any bank-side goals tied to program revenue. The same principle applies here as everywhere: paying for volume produces volume, including referrals and sales that should not have happened.
Advertising and premises, which are the bank's.
In rough order of severity and frequency:
Misrepresentation of insured or guaranteed status, express or implied.
Unsuitable annuity sales, particularly where a long surrender period is mismatched to the customer's time horizon or liquidity needs.
Replacements of existing annuities or policies, which is the single most examined transaction type and requires documented analysis of surrender charges, benefits lost, and new surrender periods.
Source-of-funds concerns — deposits, certificates, home equity, or retirement rollovers converted into commissioned products, where the question is whether the customer is better off.
Older and vulnerable customers, addressed below.
Complex or high-cost products sold to customers whose situation does not call for them.
Unauthorized or excessive trading, which the bank will typically learn about through a complaint rather than through data.
Seminars and events, particularly those aimed at retirees, where the content and the follow-up practices are the exposure.
The area where a bank's investment program and its own fraud function should be integrated and usually are not.
The bank sees the deposit side: unusual withdrawals, a new person accompanying the customer, confusion, changes in behavior. The program sees the investment side: a large purchase, a surrender, a beneficiary change. Neither sees the whole picture unless someone connects them, and financial exploitation of older adults frequently shows up as a pattern spanning both.
Practical elements of a program that works:
Red flag training for both bank and program staff, with the same list, so escalation criteria match.
A trusted contact collected where permitted, which gives staff someone to call who is not the person potentially causing harm.
Defined escalation to a named person with the authority to slow a transaction down, and clarity about what staff may and may not do.
Holds where permitted. Authority to delay a disbursement in suspected exploitation cases exists in various forms under state law and industry rules, and knowing what the institution may actually do — and for how long — before an incident is what allows anyone to act during one.
Reporting. Suspicious activity reporting obligations apply to suspected elder financial exploitation, and state adult protective services reporting may also be required. There are protections for good-faith reporting in various frameworks, and the applicable ones should be confirmed rather than assumed.
A joint review, periodically, of the older-customer population's activity across both the bank and the program — which is the only way the connected pattern becomes visible.
Structured coverage is available through the Certificate in Fraud Prevention, CFPB Laws: Preventing UDAAP and Other Violations, the Certified Regulatory Vendor Program Manager program, and Privacy/Information Sharing.
Sharing bank customer information with the investment program is a compliance decision, not an operational convenience.
The privacy framework governs what may be shared with whom, what notice is required, and what opt-out rights apply — with distinct treatment for affiliates, for nonaffiliated third parties, and for joint marketing arrangements. A program built on the bank generating lists from deposit data and providing them to representatives needs to be reviewed against those requirements, and the review should be documented.
The related operational point: the program is handling the bank's customer information, which puts it inside the bank's information security program and its third-party risk program, with the contract terms to match.
Reporting sufficient for oversight rather than a revenue line:
The framing that holds: a bank cannot outsource the part of this business that creates its exposure. The broker-dealer supervises trades. The bank owns the customer's belief about who they were dealing with, and that belief is formed by the branch, the brand, and the employee — none of which belong to the vendor.
The required nondeposit product disclosures, the arrangements that keep the products distinguishable from deposits, the conduct of its own unlicensed employees including referral practices and compensation, handling of complaints its customers make to it, the privacy treatment of customer information shared with the program, and third-party oversight of the arrangement. None of those transfer to the broker-dealer.
That the products are not FDIC insured, not deposits or obligations of the bank and not guaranteed by it, and subject to investment risk including possible loss of principal — provided orally and in writing at or before the sale and in advertising, with written customer acknowledgment obtained and retained.
Misrepresentation of insured or guaranteed status, expressly or by implication. The disclosure is usually present; the failure is that everything else about the setting — the branch, the logo, the familiar employee — communicated the opposite, and implication is sufficient.
Yes, when the customer makes them to the bank. They belong in the bank's complaint capture, categorization, root cause analysis, and trend reporting regardless of who investigates them. Routing them to the broker-dealer and recording nothing leaves a gap in the compliance management system.
Source-of-funds patterns — a certificate closed and immediately followed by an annuity purchase, a home equity draw preceding an investment, an older customer's deposit relationship being systematically converted. These are among the most informative indicators available and they exist only in the bank's data.
Shared red flag training so escalation criteria match across the bank and the program, a trusted contact collected where permitted, defined escalation to someone with authority to slow a transaction, clarity in advance about what holds the institution may place and for how long, suspicious activity and adult protective services reporting where required, and a periodic joint review of older-customer activity across both sides — which is the only way a connected pattern becomes visible.


