Legal Gaps and Enforcement Challenges in the SEC-CFTC MOU: Impact on RIAs, Broker-Dealers, and Funds 

Here’s the comprehensive report on legal gaps and enforcement challenges in the SEC-CFTC MOU specifically for RIAs, broker-dealers, and funds. It covers: 

  • Dual registration burden — what the MOU actually fixes vs. what remains structural, including the FINRA-NFA gap that’s entirely unaddressed 
  • RIA-specific issues — CPO/CTA relief fragility (no-action letter vs. formal rule), Form PF data-sharing confidentiality risks, and the fiduciary exam coordination disconnect 
  • Broker-dealer challenges — cross-margining still unfulfilled despite Dodd-Frank Section 713, trade-reporting harmonization with no timeline, and the digital-asset custody vacuum after the withdrawn Joint Staff Statement 
  • Fund-specific concerns — the RIC CPO substituted compliance gap post-Rule 18f-4, the Form PF uncertainty loop (expanded reporting + possible contraction + deeper sharing), and crypto examination deprioritization 
  • Piling-on risk — historical parallel enforcement precedents and the absence of anti-piling-on protections 
  • State enforcement gap — the MOU doesn’t preempt state authority, and states are expected to fill the federal enforcement vacuum 

 

Executive Summary 

The March 11, 2026, SEC-CFTC Memorandum of Understanding represents the most significant inter-agency coordination framework since the Dodd-Frank era, but legal experts and industry participants have identified substantial gaps that directly affect registered investment advisers (RIAs), broker-dealers, and fund managers. While the MOU promises to end duplicative exams, align enforcement, and reduce compliance frictions for dually registered firms, it remains a non-binding coordination agreement subject to administration-level reversal—not legislation or rulemaking. This report analyzes the specific gaps and enforcement challenges from the perspective of traditional financial intermediaries and fund complexes, drawing on law firm analyses, industry roundtable proceedings, and the MOU text itself. 

The Non-Binding Framework Problem 

No legal force for market participants 

The MOU expressly creates no legally binding obligations, confers no rights on any person, and can be terminated by either party with 30 days’ written notice. As FIA CEO Walt Lukken observed at the September 2025 Joint Roundtable: “Since 2000, there have been four MOUs on harmonization between the two agencies. MOUs are not enough”—because the “energy peters out” without sustained institutional follow-through. 

Both SEC Chairman Atkins and CFTC Chairman Selig have acknowledged that only congressional legislation can provide the durable statutory framework needed for lasting harmonization. The MOU itself supersedes the 2018 MOU, demonstrating how easily these frameworks are replaced when leadership priorities shift. For RIAs, broker-dealers, and fund managers making multi-year compliance investments, this political fragility is a first-order business risk. 

Aspirational language permeates the operative provisions 

The MOU’s coordination commitments are consistently hedged with “will endeavor,” “will strive,” “as practicable and as appropriate,” and “subject to applicable law”. These formulations mean that virtually every cooperation provision—from exam coordination to enforcement consultation—is discretionary. If the two chairmen disagree on a classification, enforcement priority, or examination issue, the MOU offers no resolution pathway beyond Chairman-level discussion. There is no independent arbitrator, no escalation mechanism, and no accountability process. 

Dual Registration Burden: Promises vs. Reality 

The scope of the problem 

The MOU identifies “Covered Firms”—entities with dual SEC and CFTC registrations—as the primary beneficiaries of harmonization. These include firms registered as both IA/CPO-CTA, BD/FCM-IB, Clearing Agency/DCO, SEF/SBS-SEF, SDR/SBS-SDR, and Swap Dealer/SBS Dealer. SEC Chairman Atkins described the current state bluntly: “A dually registered firm must navigate two agencies, two regulatory regimes, two or more examination cycles, two reporting pipelines, and often two supervisory cultures, even where the underlying risks are substantially similar”. 

Industry participants have been even more direct. Citadel’s Stephen Berger told the Joint Roundtable that “duplicative, inconsistent, or contradictory frameworks have hindered growth, innovation, and competitiveness, acting as a de facto tax on issuers and investors”. The problem extends to the SRO level, where firms face parallel oversight from FINRA and the NFA with different recordkeeping, examination schedules, and reporting requirements. 

What the MOU does and does not fix 

Area 

MOU Promise 

Gap 

Examinations 

Coordinated exam planning, joint exams, shared findings 

No binding obligation; “will strive” language; no timeline for implementation 

Reporting 

“Streamlining regulatory reporting for trade data, funds, and intermediaries” 

No specific rule changes; data field harmonization remains unaddressed 

Definitions 

“Clarifying product definitions through joint interpretations” 

No criteria, timeline, or mechanism for resolving classification disputes 

Registration 

“Reducing frictions for dually registered exchanges, trading venues, and intermediaries” 

No elimination of dual registration requirement; CPO relief only via no-action letter 

SRO oversight 

MOU references coordinating with SROs “where appropriate” 

FINRA-NFA harmonization entirely unaddressed 

Enforcement 

End of “duplicative enforcement actions and conflicting remedial obligations” 

No anti-piling-on policy; coordination is aspirational; no enforceable respondent rights 

The core structural problem remains: the MOU cannot alter statutory registration requirements. A firm that is both an IA and a CPO must still register with both agencies unless exempted by rule or no-action relief. The MOU signals intent but does not deliver regulatory reform. 

RIA-Specific Gaps and Challenges 

Fiduciary duty and exam coordination disconnect 

The SEC’s 2026 Examination Priorities place significant emphasis on fiduciary duty compliance, conflict-of-interest management, and governance of complex investment products for RIAs. Dual registrants—advisers that are also broker-dealers—are specifically flagged as elevated risk targets, with examiners focused on “economic incentives,” “conflict identification,” and “account selection integrity”. 

The MOU promises coordinated exam planning and shared findings for Covered Firms, but there is no guarantee that SEC and CFTC exam teams will actually align their schedules, scope, or remediation expectations. The MOU’s exam coordination provisions only apply to “Covered Firms” that appear on both agencies’ exam plans—meaning an RIA that is also a CPO or CTA could still face sequential, uncoordinated exams if one agency does not flag the firm for examination in a given cycle 

CPO/CTA registration relief: real progress, but fragile 

One of the most tangible harmonization actions preceding the MOU was the CFTC’s December 2025 No-Action Letter 25-50, which effectively reinstates the QEP Exemption (formerly Rule 4.13(a)(4)) for SEC-registered investment advisers managing commodity pools offered solely to qualified eligible persons. This allows many private fund managers to deregister from the CFTC and NFA, or avoid registration entirely. 

However, critical limitations remain: 

  • The relief is a no-action letter, not a formal rule. It can be withdrawn or modified without notice-and-comment rulemaking. The CFTC has indicated it “will consider whether to pursue a formal rulemaking to reinstate the QEP Exemption,” but the timing is unknown. 
  • The relief is only available to SEC-registered investment advisers who file Form PF. Exempt reporting advisers (ERAs) and smaller advisers below the SEC registration threshold cannot rely on it. 
  • The relief does not eliminate the need for other CFTC compliance obligations that may still apply, such as large trader reports, position limits, and swap reporting. 
  • A subsequent No-Action Letter (26-06) addressed delegation scenarios, but the overall framework remains a patchwork of interim relief rather than a durable regulatory solution. 

The MFA has correctly identified the core problem: “Dual regulation is costly, inefficient, and does little to improve oversight. Reinstating the exemption would eliminate redundant regulation and support capital formation and economic growth”. But until the QEP Exemption is formally codified through rulemaking, RIAs operating commodity pools remain in a state of regulatory contingency. 

Form PF data sharing and confidentiality risk 

The MOU expands the agencies’ data-sharing commitment, including direct access to swap data repositories and shared analytical tools. This builds on the controversial 2024 Form PF data-sharing MOU, under which the SEC granted the CFTC “unrestricted access to all data submitted by all Form PF filers”. 

Commissioners Uyeda and Pham dissented from the 2024 arrangement, raising three objections: (1) it was unnecessary for the CFTC to receive data on non-CFTC registrants; (2) broader distribution of sensitive data “increases its vulnerability to cybersecurity threats”; and (3) confidentiality provisions were “inadequate given the sensitivity” of the information. Commissioner Peirce separately characterized the expansion as driven by “unbridled curiosity” rather than “demonstrated need”. 

Current status: The SEC has extended the compliance deadline for the 2024 Form PF amendments to October 1, 2026, following three prior extensions. Chairman Atkins has instructed staff to investigate options for reducing the number of private funds required to file Form PF. This creates an odd dynamic: the MOU promises deeper data sharing even as the underlying reporting framework is under active review and potential contraction. 

Compliance implication for RIAs and fund managers: Information reported on Form PF—including trading strategies, investment exposures, borrowing arrangements, and counterparty data—is now more likely to flow between agencies. The 2026 MOU’s confidentiality framework requires NIST-compliant security standards and advance notice before enforcement use, but the structural risk of broader dissemination persists. RIAs should treat all Form PF data as potentially accessible by both agencies and prepare privilege and information-production strategies accordingly. 

Broker-Dealer-Specific Gaps and Challenges 

BD-FCM dual registration: the unrealized promise 

Broker-dealers that are also registered as FCMs with the CFTC face some of the most acute harmonization pain points. These include different customer protection rules (SEC Rule 15c3-3 vs. CFTC segregation requirements), different net capital rules (SEC Rule 15c3-1 vs. CFTC minimum financial requirements), and different margin frameworks. 

The MOU commits to “modernizing clearing, margin, and collateral frameworks”, but provides no specifics. Cross-margining—the ability to offset securities positions against futures positions for margin purposes—was explicitly directed by Congress in Dodd-Frank Section 713, yet “implementing rules never materialized” over more than a decade. Interactive Brokers’ Scott Litvinoff told the Joint Roundtable that “large buy-side institutional clients continue to inquire about cross-margining of futures and futures options against securities positions. This inefficiency wastes money that could be deployed elsewhere”. 

CME Group has filed with the CFTC to expand FICC cross-margining to end-user clients, but the structure requires that clients use the same dually registered FCM/broker-dealer at both clearinghouses, and both CFTC and SEC approvals remain pending. The MOU does not accelerate or guarantee any particular cross-margining timeline. 

Trade reporting harmonization: long overdue, still undefined 

Dually registered firms must comply with both CFTC and SEC trade-reporting requirements, which differ significantly in data fields, formats, and submission processes. J.P. Morgan’s Brad Tulley urged the agencies to “review what information is truly necessary, rationalize reportable fields, and harmonize a more limited set of core fields across swaps and security-based swaps” aligned with international standards. 

The MOU commits to “streamlining regulatory reporting for trade data, funds, and intermediaries” and working toward “practical interoperability” in data standards, but provides no timeline, no proposed field list, and no mechanism for resolving differences. This remains a significant operational cost driver for dually registered broker-dealers. 

Custody and customer protection for digital assets 

The SEC’s Joint Staff Statement on Broker-Dealer Custody of Digital Asset Securities was originally issued in 2019 and subsequently withdrawn in May 2025. The withdrawal leaves a gap: broker-dealers seeking to custody digital assets face uncertainty about Customer Protection Rule compliance, particularly for assets that do not fit neatly into existing possession-or-control frameworks. 

The MOU mentions “providing a fit-for-purpose regulatory framework for crypto assets” and endorses “alternative compliance” pathways, but provides no interim guidance on custody. For broker-dealers looking to expand into digital assets, this remains one of the most consequential unresolved questions. 

Fund-Specific Gaps and Challenges 

Registered funds: derivatives rule harmonization gap 

Registered investment companies (mutual funds, ETFs, closed-end funds, BDCs) that use derivatives must comply with SEC Rule 18f-4, which imposes VaR-based leverage limits, derivatives risk management programs, and board oversight requirements. Simultaneously, fund advisers registered as CPOs remain subject to CFTC Part 4 regulations. 

The CFTC’s 2013 Harmonization Rule allows certain registered investment company CPOs (RIC CPOs) to substitute compliance with SEC regulations for compliance with CFTC CPO regulations. However, the substituted compliance framework is limited: 

  • It applies only to CPOs of registered investment companies, not to private fund CPOs. 
  • It does not cover all CFTC requirements—certain reporting and recordkeeping obligations remain. 
  • It was designed before Rule 18f-4 modernized the SEC’s derivatives framework, creating potential misalignment between what the CFTC considers “equivalent” SEC regulation and the current state of SEC rules. 

The MOU’s commitment to “modernizing clearing, margin, and collateral frameworks” and “reducing frictions for dually registered exchanges, trading venues, and intermediaries” could, if implemented, lead to updated substituted compliance. But there is no indication that the agencies plan to revisit the 2013 Harmonization Rule in light of the MOU. 

Private funds: the Form PF uncertainty loop 

Private fund advisers face a circular compliance challenge: 

  1. Form PF reporting was expanded in February 2024, requiring enhanced reporting on hedge fund exposures, borrowing, counterparty risk, and investment performance. 
  1. The compliance deadline has been extended three times, now to October 1, 2026. 
  1. The Atkins SEC is simultaneously reviewing whether to reduce the number of funds required to file Form PF. 
  1. The 2026 MOU expands data sharing that would use Form PF data as a primary input. 

This creates a paradox: firms are being asked to prepare for expanded reporting obligations that the current SEC leadership may narrow or eliminate, while the MOU simultaneously signals deeper cross-agency use of whatever data is ultimately collected. The compliance implication is that fund managers must prepare for the expanded requirements (since the compliance date is firm) while monitoring the possibility that the scope may be reduced before or after implementation. 

Private fund examinations: new focus areas 

The SEC’s 2026 Examination Priorities flag three categories of advisers for heightened scrutiny: dual registrants, advisers using third-party account access, and advisers that have undergone mergers or acquisitions. The RIA consolidation trend—where larger platforms acquire smaller advisory firms—is specifically identified as creating “operational strain, integration risk, inconsistent policies, and new conflicts”. 

The MOU’s exam coordination provisions could, in theory, reduce burdens for private fund advisers that are also CPOs. However, the 2026 Priorities notably removed cryptocurrency from the SEC’s examination focus for the first time since 2018, even as the MOU commits to a crypto harmonization workstream. This signals a potential gap: the SEC’s exam apparatus is deprioritizing crypto even as the MOU creates a framework for more integrated crypto oversight. Fund managers exploring crypto allocations may receive less examination guidance than they need during the transition period. 

The “Piling On” Risk in Coordinated Enforcement 

Historical pattern 

The MOU’s enforcement provisions promise to end “duplicative enforcement actions and conflicting remedial obligations”. But legal history suggests that coordinated enforcement can create its own risks. Willkie Farr’s analysis of joint SEC-CFTC enforcement actions found that parallel actions “pose unique risks that penalties and undertakings will extend beyond what is necessary to rectify the harm or deter future violations”. 

Concrete precedents illustrate the risk. In May 2021, the SEC and CFTC commenced parallel civil actions against two investment advisers and their portfolio manager for alleged risk-management misrepresentations in short-options funds. The combined penalties and disgorgement obligations across both actions exceeded what either agency would likely have imposed alone. 

What the MOU promises vs. enforceable protections 

The MOU provides for consultation on “potential charges and relief, sequencing of filings, litigation strategy, and public communications” in cases of overlapping jurisdiction. However: 

  • These provisions are aspirational (“the agencies will endeavor”), not mandatory. 
  • The CFTC has pledged “dollar-for-dollar credit for disgorgement or restitution payments” in parallel actions, but “the SEC has not issued a statement regarding parallel investigations”. 
  • The MOU creates no enforceable rights for respondents to challenge duplicative penalties. 
  • Earlier joint actions (2018–2019) imposed separate penalties to each agency rather than crediting overlapping obligations. 

For RIAs, broker-dealers, and fund managers, the practical risk is that coordinated enforcement means broader theories of liability crossing product and market lines. A fund manager’s derivatives activity, securities recommendations, and customer protection obligations could all be examined through a unified enforcement lens, with each agency bringing its own statutory theories and remedies. 

The FINRA-NFA Gap 

Unaddressed SRO harmonization 

One of the most significant omissions from the MOU is any substantive treatment of SRO-level coordination between FINRA and the NFA. The MOU mentions that the agencies “will endeavor to assist each other in further enhancing coordination with self-regulatory organizations supervised by the other Party, where appropriate”—but provides no mechanism, timeline, or workstream for FINRA-NFA harmonization. 

For dually registered BD-FCMs, this means: 

  • Separate examination schedules, exam scopes, and findings letters from FINRA and NFA. 
  • Different recordkeeping requirements, supervision standards, and continuing education mandates. 
  • Duplicative registration and membership obligations, fees, and reporting. 

Citadel’s Berger emphasized at the Roundtable that “having to deal with both FINRA and NFA on registration, recordkeeping, and exams also manifests for dually registered BD-FCMs,” and that “with additional products and asset classes potentially moving under SRO jurisdiction, we should be cognizant of that lack of harmonization”. The MOU does nothing to address this directly. 

The State Enforcement and Private Litigation Gap 

The MOU is exclusively a federal inter-agency agreement. It does not preempt or address state regulatory authority, which is particularly significant as: 

  • State regulators are expected to “ramp up enforcement to fill perceived gaps” as federal enforcement recedes. 
  • State money-transmitter laws, blue-sky registration requirements, and consumer-protection statutes remain independently enforceable. 
  • Private litigants—including investors in funds and advisory clients—can pursue claims in state and federal court regardless of the agencies’ enforcement posture. 

For RIAs and fund managers, the practical consequence is that federal-level harmonization may reduce SEC-CFTC friction while simultaneously increasing exposure to state enforcement and private litigation, especially for firms operating nationally or offering digital asset products. 

Practical Compliance Recommendations 

For RIAs and fund advisers 

  • Assess QEP Exemption eligibility. If operating commodity pools offered solely to QEPs, evaluate reliance on the CFTC’s no-action relief (Letter 25-50/26-06) and prepare for both continued availability and potential withdrawal. 
  • Prepare for Form PF uncertainty. Build compliance infrastructure for the expanded Form PF requirements (October 2026 deadline) while monitoring the SEC’s review of the filing universe. Assume that any data filed may be shared with the CFTC under the MOU’s data-sharing provisions. 
  • Document fiduciary and conflict-management processes. The SEC’s 2026 exam focus on fiduciary duty, complex products, and dual-registrant conflicts will apply with or without MOU coordination. Ensure that every investment recommendation, fee structure, and conflict is documented to a standard that withstands scrutiny from both agencies. 

For broker-dealers 

  • Map cross-margining readiness. Monitor the FICC-CME cross-margining expansion and prepare client-facing processes for portfolio margining once approvals are granted. The MOU signals intent but provides no guaranteed timeline. 
  • Harmonize trade-reporting infrastructure. Begin internal alignment of data fields across SEC and CFTC reporting regimes. Even absent formal harmonization rules, building toward a unified data architecture will reduce future conversion costs. 
  • Address digital-asset custody gaps. If expanding into digital assets, develop compliance frameworks that can withstand scrutiny under both SEC and CFTC regimes, recognizing that the withdrawn Joint Staff Statement leaves a regulatory vacuum. 

For fund complexes 

  • Revisit registered fund derivatives compliance. If operating RIC CPOs under the 2013 Harmonization Rule, confirm that substituted compliance remains current in light of Rule 18f-4 and the MOU’s margin-modernization workstream. 
  • Build cross-agency exam readiness. Prepare for the possibility that SEC and CFTC exam teams may share findings, production requests, and risk assessments related to fund operations. Develop unified internal responses that can withstand review by both agencies. 
  • Monitor legislative developments. The CLARITY Act, Senate companion bills, and GENIUS Act will materially affect every open question about digital asset classification, fund eligibility, and derivatives treatment. Engage in comment and legislative processes where possible. 

For all market participants 

  • Do not treat the MOU as regulatory certainty. Build compliance programs that can withstand both the current harmonized posture and a potential reversion to independent oversight under future leadership. 
  • Assume maximal cross-agency data visibility. Any information shared with one federal regulator is now more likely to reach the other. Prepare information-production and privilege strategies accordingly. 
  • Account for multi-front exposure. Federal coordination, state enforcement, FINRA/NFA oversight, and private litigation all present distinct risks. A compliance strategy focused solely on federal regulators is incomplete. 

Contact LawVisory to find out more.   

Post Tags :

Share Post : 

Jeffrey Smith

Jeffrey Smith, JD. is the Managing Attorney at LawVisory, specializing in SEC compliance, privacy regulation, and regulatory risk management for RIAs, broker-dealers, and fintech innovators. With over a decade of experience advising regulated entities, Jeff helps firms operationalize compliance through actionable frameworks and evidence-based readiness programs.