Federal lawmakers are urging FINRA to strengthen protections surrounding brokerage account transfers through the Automated Customer Account Transfer Service, commonly known as ACATS.

The request follows concerns that fraudsters can use stolen information to initiate unauthorized transfers before investors realize their assets have left the original firm. No new requirements have been adopted, but the issue places greater attention on firms’ transfer controls, customer notifications, and authentication practices.

What Is the Concern?

ACATS is operated by the National Securities Clearing Corporation and allows customers to transfer securities and cash between brokerage firms.

Under FINRA Rule 11870, firms generally have one business day to validate or reject an ACATS request and three business days to complete an approved transfer. According to the lawmakers’ announcement, that short timeline may allow fraudsters using stolen information to transfer assets before the account holder detects the activity.

Their review raised several potential gaps:

  • Customers may not be notified before assets leave their accounts.
  • Transfer-lock options are not consistently available across firms.
  • Electronic verification may not confirm the request directly with the outgoing account holder.
  • Authentication methods may still be vulnerable to phishing or stolen credentials.

These concerns do not establish that every unauthorized transfer resulted from a compliance failure. They do highlight how differences in firm controls may affect how quickly suspicious activity is identified and stopped.

What Changes Are Being Requested?

The lawmakers asked FINRA to strengthen ACATS protections by requiring:

  • Customer notifications when transfer requests are submitted
  • Phishing-resistant multifactor authentication, including passkeys
  • Stronger access to controls that block outgoing transfers

These measures are intended to help customers identify and stop unauthorized transfers before assets leave their accounts. FINRA has not adopted the requested changes, so firms should monitor for future guidance or rulemaking.

What Can Compliance Teams Take Away?

Even without a new FINRA requirement, firms can use the discussion to review how their current controls address unauthorized account transfers.

Compliance teams should consider:

  • Reviewing ACATS procedures: Map how requests are received, authenticated, validated, approved, and escalated.
  • Evaluating customer notifications: Determine whether customers receive prompt alerts through more than one communication channel.
  • Assessing authentication controls: Review whether higher-risk account activity triggers stronger identity verification.
  • Testing escalation procedures: Confirm that employees know how to respond when customers report unauthorized or suspicious transfers.

Compliance, cybersecurity, operations, and fraud-prevention teams should understand how their respective controls work together. Firms should also review complaints, canceled transfers, identity-verification failures, and other indicators that may reveal weaknesses in the process. The lawmakers’ request has not changed firms’ regulatory obligations, but it signals increased attention to the protections surrounding ACATS transfers.