Registrant Prep
← All terms
Regulatory

IDPC Rule 3300 Series

Supervision obligations for registered persons under CIRO.

Definition

The IDPC Rule 3300 series imposes supervision obligations on investment dealers and their supervisors. Dealers must establish written supervisory procedures, designate Ultimate Designated Persons (UDPs) and Chief Compliance Officers (CCOs), and conduct ongoing supervision of registered persons. The 3300 series also contains the firm-level Know-Your-Product obligation: before a product is made available to clients, the dealer must conduct product due diligence and formally approve it for the firm's shelf. Failure to supervise is itself a regulatory offence under these rules.

Source

CIRO IDPC Rule 3300 series

Where this shows up on the CIRE

  • Outcome 3.5
  • Outcome 9.1

Test yourself

Two real CIRE-bank questions on this exact outcome. Click to reveal the answer and the rule citation.

  1. 1

    A registered representative receives a phishing email appearing to come from CIRO requesting that she log in to a portal and verify her account credentials. She clicks the link, enters her username and password, and the next day discovers her access to firm systems has been used to view confidential client data. Under CIRO's cybersecurity and privacy framework, which obligation is most directly triggered?

    Outcome 9.1 · click for answer

    A.The firm must assess if this is a privacy breach needing client and regulator notice, and notify CIROCorrect
    B.The representative must file a large cash transaction report since stolen data could support fraud
    C.No obligation exists here because only login credentials were misused, not any client funds
    D.The firm only needs to reset the password and log the event for its own internal records

    Under PIPEDA (and its provincial equivalents) and CIRO's cybersecurity and recordkeeping obligations, unauthorized access to client personal information constitutes a potential privacy breach that may require notification to affected individuals and the Office of the Privacy Commissioner if there is a real risk of significant harm. CIRO rules also require dealer members to have incident response procedures and to notify CIRO of material cybersecurity events. An attacker gaining access to confidential client data triggers these obligations well before any fund transfer occurs.

  2. 2

    A client wants to open an account where they can make their own investment decisions without advice and without the dealer assessing suitability on each trade. Which account type best fits this description, and what must occur before it is opened?

    Outcome 3.5 · click for answer

    A.A managed account, opened only once the dealer secures written discretionary authority
    B.An advisory account, opened after the client signs a waiver excusing per-trade suitability review
    C.An order execution only account, opened after written disclosure of no advice or suitability reviewCorrect
    D.A discretionary account, opened once the client and portfolio manager sign a formal trading authority letter

    An order execution only account is the account type where the dealer executes client-directed orders without providing advice or conducting ongoing per-trade suitability assessments. Before opening an OEO account, IDPC Rule 3219 requires three specific written disclosures: (1) no advice will be provided, (2) suitability will not be assessed on an ongoing basis, and (3) the client is responsible for their own investment decisions. These disclosures ensure the client understands the self-directed nature of the account before the first trade.

Related terms in Regulatory

AI case study

See how IDPC Rule 3300 Series applies in practice

One named-role scenario with realistic numbers and the rule citation.

Want this kind of explanation on every wrong answer?

The Registrant Prep AI tutor is grounded in the same primary sources cited above. Every wrong practice answer gets the rule that the distractor was testing.