Securities and capital-markets intermediation
Dealing in, arranging or advising on securities and other capital-markets products, or managing money on behalf of clients.
- Published jurisdictions
- United States, Singapore
- Regulators involved
- 2 distinct authorities
Scope
What this permission family covers
Regulators assess the activity, not the product name. This is the activity that brings a business inside this family.
Dealing in, arranging or advising on securities and other capital-markets products, or managing money on behalf of clients.
Instruments in this family
Broker-dealer registration and self-regulatory organisation membership
United States · US Securities and Exchange Commission with the relevant self-regulatory organisation and state regulators
Capital Markets Services (CMS) licence
Singapore · Monetary Authority of Singapore
Fit
Who needs this, and who does not
The negative list matters as much as the positive one. Businesses waste months applying for permissions they do not need.
Typically needed by
- Brokerage and trading platforms offering securities to clients
- Firms arranging investments or introducing clients to counterparties for a fee
- Asset and portfolio managers taking discretionary mandates
Usually not needed by
- Businesses raising capital only for themselves
- Information or analytics products with no dealing, arranging or advising activity
Jurisdiction variant
The instrument depends on where you are authorised
Broker / capital markets is not a single permission. Choose a jurisdiction to see the instrument that applies there, the regulator that grants it, and what that regulator examines.
Broker-dealer registration and self-regulatory organisation membership
- Regulator
- US Securities and Exchange Commission with the relevant self-regulatory organisation and state regulators
- Scope of the authorisation
- Effecting transactions in securities for the account of others, or dealing for one's own account, within the registered permissions.
What this regulator examines
6Each area below is assessed against your actual business. Open one for the detail and the evidence normally expected.
Governance, fitness and propriety of controllersMandatory
Regulators assess who owns and runs the business: the board and senior management, the fitness and propriety of each controller, and the reporting lines that make the arrangement credible. Principals must hold the qualifications and registrations the self-regulatory organisation requires.
- Evidence: Organisational chart with reporting lines
- Evidence: Controller questionnaires and identity evidence
- Evidence: Curriculum vitae and regulatory history for senior appointments
Financial-crime frameworkMandatory
A documented framework covering customer due diligence, sanctions and PEP screening, transaction monitoring, suspicious-activity reporting and record keeping — proportionate to the business model and geography.
- Evidence: AML/CFT policy and procedures
- Evidence: Risk assessment covering customer, product, geography and channel
- Evidence: Named compliance officer and reporting arrangement
Business plan and financial projectionsMandatory
A regulator-grade business plan: the model, target customers, distribution, volumes, cost base and funding, with projections that reconcile to the capital and liquidity position.
- Evidence: Business plan
- Evidence: Financial projections
- Evidence: Funding and capital evidence
Written supervisory proceduresMandatory
Supervisory procedures covering each registered activity, with named supervisors and evidence of review.
Net capital and customer-protection complianceMandatory
Continuous net-capital compliance and, where customer assets are held, the customer-protection arrangements the rules require.
Operational resilience and technology controlsMandatory
Information security, change management, outsourcing oversight, business continuity and incident reporting arrangements appropriate to the permission being sought.
After authorisation
Authorisation begins a supervisory relationship. These obligations continue for as long as the permission is held.
- Periodic financial and operational reporting
- Annual audit by an independent accountant
- Continuing education and registration maintenance for registered persons
- Examination readiness with the self-regulatory organisation
Project model
How the programme runs
Three of these stages belong to the regulator. The platform records what the regulator has recorded and never anticipates a determination.
Readiness and gap analysis
YouStructured questions establish which requirement areas you already satisfy and which are open. The result is a gap list, not an assessment of whether a regulator will authorise you.
Scoping with a licensing specialist
Qualified providerA qualified licensing provider reviews the gap list, confirms the target permission and scopes the work into a proposal.
Application programme
Qualified providerPolicies, governance arrangements, controls documentation and the application pack are produced against the regulator's published requirements, tracked as milestones with document requirements.
Submission to the regulator
Qualified providerThe provider submits the application and records the submission evidence. From this point the state shown reflects the regulator's position.
Regulatory assessment
External authorityOutcome not controlled by ZKCAPThe regulator reviews the application and normally raises information requests. Each request appears as a first-class item with a response path, not as an email thread.
Determination
External authorityOutcome not controlled by ZKCAPThe regulator authorises, refuses, or authorises with conditions or limitations. The platform records whichever determination is issued, including refusal and its remediation path.
Ongoing supervision and renewals
External authorityOutcome not controlled by ZKCAPAuthorisation begins a supervisory relationship: reporting, notifications, attestations and periodic fees become tracked obligations.
Where this comes from
How this information is maintained
Boundary
Who is responsible, and who decides
A readiness assessment is not an application.