Widening the Net: SEC Fines Six Credit Rating Agencies
October 4th, 2024
Paul Cottee, Director, Regulatory Compliance, NICE Actimize

On Wednesday 4 September, the U.S. Securities and Exchange Commission (SEC) fined six Nationally Recognized Statistical Rating Organizations (NRSROs)—aka ratings agencies—for failures to properly maintain and preserve electronic communications, a breach of federal securities laws. In addition to paying substantial fines, four of the firms will also be required to retain a compliance consultant. The actions by the SEC were not unexpected. The SEC and the Commodity Futures Trading Commission (CFTC) have imposed over $3.3bn in fines on financial firms since late-2021. This latest action signals that the SEC is now widening the net beyond financial firms, to include other federally regulated companies. This is not the first time the SEC has sanctioned ratings agencies. In recent years, firms have been sanctioned for lapses of controls related to ratings adjustments, or mismanagement of conflicts of interest. But the recent fines are generally larger. And the fact that several of the latest fines were announced simultaneously seems to signal that the SEC is now putting ratings firms on notice. The fact that the SEC now has rating agencies in its sights shouldn’t come as a surprise. It’s well known that ratings agencies are subject to specific recordkeeping regulations. While the provisions related to ratings agencies (SEC Rule 17g-2)are distinct from recordkeeping provisions governing financial firms ((Rule 17a-4), the reasoning behind both sets of provisions is similar: communications of employees who work for both financial institutions and ratings agencies frequently involve highly sensitive data which, if released into the public domain, could affect a security’s price or market. Ratings agencies bring added concerns. For example, because a change in a listed company’s credit rating could affect the company’s share price, ratings agencies are expected to have controls around their ratings methodologies, internal discussions about changes, misuse of material non-public information [MNPI], and conflicts of interest. One control is the requirement for ratings agencies to record and retain communications related to “initiating, determining, maintaining, monitoring, changing, or withdrawing a credit rating.” The SEC also relies on records of telephone and electronic communications to determine if ratings agencies have engaged in conflict-of-interest breaches. So clearly, not recording off-channel communications could deprive the regulator of evidence they would need to investigate suspected breaches.