The Financial Industry Regulatory Authority has censured and fined Ceros Financial Services $75,000 for business email-related infractions, including reps' using personal emails to conduct business and for failing to review emails from employees' personal email addresses to safeguard customer information.
According to FINRA's order, from January 2018 through June 2021, the Rockville, Maryland-based Ceros did not have a reasonable supervisory system for business-related communications.
Ceros' written supervisory procedures prohibited registered reps from communicating with customers from their personal email addresses. However, at least one of the firm's registered reps was regularly using personal email for business-related communications.
After being notified by FINRA about the issue, the firm created a list of employee personal email addresses and sent automated warning emails when incoming emails to the firm's system were sent from emails on that list, the order explains.
The employee personal email list contained 16 email addresses of the firm's 88 associated individuals as of June 2021.
If an email was sent from the firm system to an email on the personal email address list, no automated warning was sent. This process was not documented in any written procedures.
During the relevant period, Ceros sent at least 67 automated warnings to individuals, with some individuals receiving repeated warnings.
"However, the firm did not review communications sent from or to emails on the employee personal email list unless those emails happened to meet other firm supervisory email review criteria. The firm also did not treat those communications as red flags that other external business-related communications might not be captured by the firm's system."
Other than automated warning emails, and one warning letter sent as a result of routine email review, the firm did not take steps to prevent associated persons from using external email.
Nor did the firm take reasonable steps to ensure all business-related communications were preserved and retained.