The National Futures Association is the self-regulatory organization for the U.S. derivatives industry, including on-exchange traded futures, retail off-exchange foreign currency, and OTC derivatives.
Adhere to ethical standards fair dealing practices and disclosure requirements in all business activities.
Establish and uphold high ethical standards and ensure fair treatment of all clients and counterparties.
Establish and maintain a written policy outlining ethical standards for all personnel.
Implement procedures to ensure fair dealing with customers and counterparties.
Adhere to all regulatory obligations related to providing necessary information to clients.
Comply with all NFA rules and CFTC regulations regarding disclosure of information to customers.
Meet minimum capital requirements and maintain accurate financial records as mandated by the NFA.
Ensure the firm possesses sufficient capital to meet its financial obligations and regulatory requirements.
Maintain capital levels at or above the minimum requirements set by the NFA.
Establish and maintain comprehensive and accurate records of all financial transactions and activities.
Maintain accurate and complete financial records in accordance with NFA rules.
Implement robust compliance and supervisory systems to ensure adherence to NFA rules and CFTC regulations.
Develop and maintain documented procedures that outline the supervisory responsibilities within the firm.
Develop and implement written supervisory procedures outlining the responsibilities of supervisory personnel.
Establish a schedule and methodology for reviewing the effectiveness of the firm's supervisory framework.
Conduct regular reviews of the firm's supervisory systems to identify and address potential compliance issues.
Establish and maintain an Information Systems Security Program (ISSP) to protect sensitive information and systems.
Implement a comprehensive program designed to protect the confidentiality integrity and availability of the firm's information assets.
Develop a written ISSP that addresses risk assessment security controls incident response and employee training.
Conduct regular assessments to identify and evaluate cybersecurity risks to the firm's systems and data.
Develop and maintain an incident response plan to address cybersecurity incidents.
Provide regular cybersecurity awareness training to all employees.
Establish and maintain a written business continuity plan to ensure operational resilience in the event of disruptions.
Create and regularly update a plan that enables the firm to continue operating or quickly recover from significant disruptions.
Develop a comprehensive written business continuity plan identifying procedures for responding to emergencies and significant business disruptions.
Implement procedures for regular data backup and recovery of mission-critical systems and information.
Develop a plan for alternate communication methods between the firm customers and employees during a disruption.
Establish and maintain an AML program to prevent the firm from being used for money laundering or terrorist financing.
Implement a program with policies procedures and controls designed to prevent detect and report money laundering activities.
Develop a written AML program that includes internal policies procedures and controls.
Implement a Customer Identification Program to verify the identity of each customer.
Establish procedures for identifying and reporting suspicious activity to the appropriate authorities.