Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› FINRA Rule 2090
Governance, Ownership & Risk

FINRA Rule 2090

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Governance, Ownership & Risk

FINRA Rule 2090 is the broker-dealer obligation to use reasonable diligence in learning and retaining essential facts about each customer and anyone authorized to act for them. The rule is a continuing KYC requirement, covering account opening, authority verification, profile maintenance, and ongoing monitoring across the life of the relationship.

What FINRA Rule 2090 Requires in Practice

FINRA Rule 2090 is a continuing customer-knowledge obligation, not a one-time onboarding checklist. It requires a broker-dealer to learn and retain the essential facts needed to service the account, including who the customer is and who is authorized to act for the customer.

The rule matters because “essential facts” are relationship-dependent. A firm may need different facts for a retail investor, an institutional customer, a trading representative, a trustee, an attorney-in-fact, or another authorized person acting on the account.

Why Essential Facts Matter for Account Authority

Rule 2090 is closely tied to authority verification. If a firm does not understand who may place instructions, move assets, change settings, or approve activity, it cannot reliably know whether an instruction is proper for that account.

This is why the obligation reaches beyond basic identity capture. The firm must retain facts that help distinguish the customer from people or entities acting on the customer’s behalf, and it must keep that understanding current as circumstances change.

In practice, that means the rule supports accurate handling of powers of attorney, entity signatories, guardians, fiduciaries, and other third-party actors whose authority can expand, narrow, or expire over time.

How the Rule Connects to Ongoing Surveillance and Records

Because the duty is continuing, firms need processes that preserve customer facts across the full relationship lifecycle. NIST Cybersecurity Framework 2.0 is useful here as a broad control lens for governing, identifying, protecting, detecting, responding, and recovering around the information a firm relies on to service accounts.

The operational point is not just storing a profile, but keeping it usable. If customer information is stale, incomplete, or fragmented across systems, the firm may make decisions on outdated authority assumptions, which weakens supervision and increases the chance of improper account action.

Good records also support review, escalation, and exception handling. The rule is often implemented alongside other customer and account control processes so that changes in ownership, authorization, trading authority, or contact structure are reflected quickly enough to matter.

Where Firms Commonly Misread the Rule

A common mistake is treating Rule 2090 as equivalent to static customer identification. It is broader than identity collection, because the rule is about learning and retaining the facts that are necessary to understand the relationship and act appropriately on the customer’s instructions.

Another mistake is assuming that authority validation happens only at account opening. In reality, authority can change after onboarding through updated documents, corporate actions, role changes, death, incapacity, or new delegation, so the essential facts must be refreshed when those changes occur.

That is why the rule works best when supported by reliable account governance, clear ownership of profile maintenance, and disciplined review of records that affect who may act and under what conditions.

Risk and Threat Considerations

When essential facts are missing or stale, the main risk is improper account action, including unauthorized trading, misdirected instructions, wrongful disbursement, or failure to detect a change in who can legitimately control the account. The weakness is usually not a sophisticated exploit, but an authority gap created by incomplete or outdated records.

Failure mechanism: Staff rely on obsolete account information, fail to verify changing authority, or treat a prior authorization as still valid after the underlying relationship has changed.

Impact: The firm may execute instructions it should have rejected, expose customer assets, undermine supervision, and create dispute, restitution, and conduct risk.

Practical controls are also important for third-party manipulation. A false or expired authorization can be enough to move value if the firm’s records do not clearly show who may act, when that authority started, and when it ended.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-03 — Roles, Responsibilities, and AuthoritiesRule 2090 depends on clear ownership of customer-fact maintenance and authority verification.
ID.AM-01 — Physical Devices and Systems InventoriedThe rule’s continuing recordkeeping depends on keeping authoritative account records current.
Recommendation — Assign accountable ownership for maintaining essential customer and authority facts. Maintain an accurate inventory of customer and account records that affect permitted action.
NIST SP 800-53 Rev 5AC-2 — Account ManagementFINRA Rule 2090 requires lifecycle control over who is authorized to act for an account.
IA-4 — Identifier ManagementThe rule relies on knowing which natural persons or entities are authorized to act.
AU-6 — Audit Record Review, Analysis, and ReportingOngoing monitoring of essential facts benefits from review of account changes and exceptions.
Recommendation — Validate and update account-authority records whenever customer authority changes. Tie account permissions and authorization records to verified, current identity information. Review account-change events and authority exceptions for stale or inconsistent records.
ISO/IEC 27001:2022A.5.15 — Access controlThe rule centers on who may act for a customer and under what authority.
A.5.16 — Identity managementEssential facts include the identities of customers and authorized third parties.
Recommendation — Define and enforce access and authority rules for customer account actions. Maintain verified identity records for customers and authorized representatives.

Practitioner Guidance

Governance implication: Firms should treat essential-facts maintenance as an owned control, not an informal service task. The account record needs a clear accountable process for updates, review, and escalation when authority-related facts change.

What to watch for: Inconsistent signer records, outdated powers of attorney, unresolved exceptions, and account notes that do not match current instructions are strong indicators that Rule 2090 controls may be drifting. The most useful discipline is to keep authority evidence current enough that operations can rely on it without guesswork.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org