← All terms
Compliance

Record Retention

The general 5-year retention rule for dealer records, extended to 7 years for client identification records under PCMLTFA.

Definition

CIRO IDPC Rules require investment dealers to retain records of client accounts, transactions, and communications for a minimum of 7 years, with some categories of records (such as account-opening documentation and KYC forms) retained for the life of the account plus 7 years. Under PCMLTFA separately, records related to client identity verification must be retained for 7 years from the date the account is closed or the transaction occurs. The longer of these periods applies when they overlap. Records must be retrievable within a reasonable time and may be stored electronically provided the dealer can produce them in readable form on request by CIRO or FINTRAC.

Source

CIRO IDPC Rules, recordkeeping provisions; PCMLTFA Regulations s.36

Where this shows up on the CIRE

  • Outcome 9.1

Test yourself

Two real CIRE-bank questions on this exact outcome. Click to reveal the answer and the rule citation.

  1. 1

    A registered representative receives a phishing email appearing to come from CIRO requesting that she log in to a portal and verify her account credentials. She clicks the link, enters her username and password, and the next day discovers her access to firm systems has been used to view confidential client data. Under CIRO's cybersecurity and privacy framework, which obligation is most directly triggered?

    Outcome 9.1 · click for answer

    A.The representative must file a large cash transaction report because client data may have been used for financial gain.
    B.The dealer member must assess whether the incident constitutes a privacy breach requiring notification to affected clients and potentially to the Office of the Privacy Commissioner, in addition to notifying CIRO of the cybersecurity incident per applicable CIRO requirements.Correct
    C.No regulatory obligation arises unless the attacker actually transfers client funds.
    D.The obligation is limited to resetting the representative's password and documenting the incident internally.

    Under PIPEDA (and its provincial equivalents) and CIRO's cybersecurity and recordkeeping obligations, unauthorized access to client personal information constitutes a potential privacy breach that may require notification to affected individuals and the Office of the Privacy Commissioner if there is a real risk of significant harm. CIRO rules also require dealer members to have incident response procedures and to notify CIRO of material cybersecurity events. An attacker gaining access to confidential client data triggers these obligations well before any fund transfer occurs.

  2. 2

    A registrant's dealer is subject to IDPC Rule 1406 ('most stringent prevails'). A provincial securities regulator publishes a rule requiring a shorter complaint resolution timeline than the timeline specified in IDPC Rule 3700. Which timeline applies?

    Outcome 9.1 · click for answer

    A.The IDPC Rule 3700 timeline applies because CIRO rules supersede provincial rules for its members.
    B.Both timelines apply simultaneously, requiring dual reporting to CIRO and the provincial regulator.
    C.The dealer may choose either timeline at its discretion.
    D.The provincial rule applies because it is more stringent, and IDPC Rule 1406 requires compliance with whichever requirement is most stringent.Correct

    IDPC Rule 1406 establishes that where a provincial or territorial requirement is more stringent than the corresponding CIRO requirement, the member must comply with the more stringent standard. CIRO rules set a floor, not a ceiling. If a provincial regulator mandates a shorter complaint resolution period, the dealer must meet that shorter deadline. There is no discretion to choose the less stringent standard, and the rule does not require dual reporting; it simply requires compliance with whichever standard is higher.

Related terms in Compliance

AI case study

See how Record Retention applies in practice

One named-role scenario with realistic numbers and the rule citation.

Want this kind of explanation on every wrong answer?

The Ciroexam AI tutor is grounded in the same primary sources cited above. Every wrong practice answer gets the rule that the distractor was testing.