The US Securities and Exchange Commission is proposing a sweeping overhaul of the securities transfer agent regulatory framework, which has largely remained unchanged since the mid-1970s.
The existing rules were built around a paperwork-based system and have failed to keep pace with the sweeping technological changes that have transformed financial markets over the past five decades.
Many of the proposed changes are designed to technologically neutralise the rules for adaptation to the modern environment, including the utilisation of distributed ledger technology.
The proposal would rescind Rule 17ad-4, eliminating exemptions for turnaround, processing, and recordkeeping requirements for interests in registered open-end funds, limited partnerships, and dividend reinvestment plans.
Fund advisers and their transfer agents are being urged to pay close attention to several specific changes that carry significant operational and compliance implications.
The SEC is also proposing modifications to Rule 17ad-17 to introduce the new concept of an “inactive securityholder,” which would impose fresh notification requirements on transfer agents based on account activity.
This change is designed to protect investors against an increased risk of escheatment of securities, a growing concern as dormant accounts become more prevalent across the industry.
A new Rule 17ad-31 would require safeguards for the placement and removal of restrictive legends on unregistered securities, including the designation of authorised personnel and a reasonable-basis belief requirement that no violation of Section 5 of the Securities Act is occurring.
The proposal addresses what the Commission describes as a gap in cybersecurity, information security, disaster recovery, and operational risk oversight across the transfer agent sector.
Revised Rule 17ad-12 would require transfer agents to adopt written policies and procedures that safeguard funds and securities, identify and mitigate material operational and cybersecurity risks, and segregate customer funds in “for the benefit of” accounts.
Transfer agents would also be required to maintain an annually tested business continuity plan under the revised standards proposed by the Commission.
The proposal would additionally update the electronic recordkeeping rule 17ad-7 to align with modern information-security standards, reflecting how dramatically data management has evolved since the original framework was established.
The SEC is seeking public comment on whether to introduce more prescriptive requirements, including mandatory cybersecurity incident reporting or independent security assessments conducted by third parties.
Broader amendments are also proposed to rules addressing definitions, turnaround timeframes, limitations on business expansion, record retention, prompt posting, and lost securityholder search obligations across the industry.

