LawFlash

SEC Proposes Comprehensive Modernization of Transfer Agent Rules, Signals Further Progress on Framework for Tokenized Securities

September 08, 2026

The US Securities and Exchange Commission (SEC) has proposed a broad modernization of the federal regulatory framework governing registered transfer agents (Proposal). The Proposal would update existing registration, reporting, operational, recordkeeping, and safeguarding requirements that were largely adopted decades ago for a paper-certificate market, while also introducing new compliance obligations and enhanced reporting requirements.

The Proposal would accelerate certain transfer-processing deadlines, eliminate existing exemptions relied upon by certain transfer agents, establish a transfer agent compliance program requirement, establish standards governing the removal of restrictive legends, and significantly revise Forms TA‑1 and TA‑2 to require more detailed disclosures regarding transfer agent ownership, affiliates, operations, and activities.

The SEC is seeking public comment on the Proposal, with comments due 60 days after publication in the Federal Register.

BACKGROUND

Transfer agents perform a central role in the securities clearance and settlement system by maintaining issuers’ official records of security ownership, registering transfers, monitoring issuances, and facilitating the issuance and cancellation of securities.

The Proposal represents a significant update to a regulatory framework whose core processing, recordkeeping, and safeguarding requirements date back to the late 1970s and early 1980s, reflecting a market where securities were represented by physical certificates and transactions and related records were processed manually. The SEC’s stated objective is to align those requirements with modern electronic securities markets, including the increasing use of distributed-ledger technology and tokenized securities.[1]

The Proposal would revise numerous transfer agent registration, reporting, processing, recordkeeping, and safeguarding rules under the Securities Exchange Act of 1934 (Exchange Act), including Forms TA-1 and TA-2, rescind Rule 17ad-4 under the Exchange Act, and adopt new Exchange Act Rules 17ad-30 and 17ad-31.[2]

AREAS OF SIGNIFICANCE

Accelerated Turnaround and Prompt Posting – Rules 17ad-2 and 17ad-10

Proposed Rules 17ad-2 and 17ad-10 would move core transfer and record-posting functions to a one-business-day framework tied directly to the standard settlement cycle. Proposed Rule 17ad-2 would replace the current requirement to turn around at least 90% of routine items within three business days and require written policies and procedures reasonably designed to ensure that all routine items are turned around within the shorter of one business day or the period specified in Exchange Act Rule 15c6-1(a), which is currently T+1.

The Proposal would eliminate the existing noon cutoff; an item received electronically at any point during a business day would be treated as received that day. Outside registrars similarly would move from a 90% performance standard to a policies-and-procedures framework designed to ensure processing within the rule’s existing next-day timeframes.[3]

Further, the definition of “item,” as proposed to be amended, would include the phrase “an electronic system controlled, operated, or enabled by the transfer agent.” This would ensure that instructions transmitted by or through both existing technologies, such as blockchains and other distributed ledger-based platforms, and new, even unforeseen, technologies are captured.[4]

These amendments would help ensure that Rule 17ad-2’s turnaround and processing requirements apply uniformly to certificated and uncertificated securities, regardless of the specific technology used to issue, transfer, or custody the securities.

Proposed Rule 17ad-10 would apply the same “shorter of one business day or Rule 15c6-1(a)” standard to posting debits and credits to the master securityholder file following an issuance, purchase, transfer, or redemption. The SEC emphasizes that, for uncertificated securities, prompt posting and turnaround are effectively the same event.

The Proposal would reduce the time for a co-transfer agent to provide transfer records to the recordkeeping transfer agent from two business days to one, and the time to respond to related inquiries from five business days to one.[5]

These changes would likely require transfer agents to evaluate whether existing staffing models, automation tools, exception-management processes, and service-provider arrangements are sufficient to meet the shortened processing timelines. The Proposal is particularly significant because the required turnaround period would remain linked to the settlement cycle under Rule 15c6-1(a), meaning that a future shortening of the settlement cycle could automatically shorten the applicable transfer agent turnaround and posting deadlines.

While the SEC would continue to use a policies-and-procedures framework rather than strict liability for individual misses, transfer agents would remain subject to performance-based notification and operational consequences if processing levels fall below prescribed thresholds. Firms will need to consider the operational feasibility of the shortened processing timelines, the impact of the elimination of the noon cutoff, and the treatment of complex transactions and certificated securities.

Rescission of Rule 17ad-4

The SEC proposes to rescind Rule 17ad-4 in its entirety, concluding that modern automated processing and electronic recordkeeping have eliminated much of the burden that originally justified the exemptions.[6] Rule 17ad-4 currently exempts transfer agents processing limited partnership interests, dividend reinvestment plans (DRIPs), and redeemable securities of registered open-end investment companies from specified turnaround, processing, and recordkeeping requirements.

It also provides a similar exemption for certain small transfer agents that receive fewer than 500 items for transfer and fewer than 500 items for processing during a consecutive six-month period.

The rescission’s context magnifies its significance. A transfer agent that currently relies on Rule 17ad-4 would not become subject to the existing general rules; it would become subject to the newly accelerated Rule 17ad-2 standards, the revised Rule 17ad-3 performance thresholds, and the modernized Rule 17ad-6 recordkeeping requirements at the same time.

The SEC estimates that approximately 200 registered transfer agents may currently fall within Rule 17ad-4, although that figure includes firms that may outsource all transfer agent activity or may not be actively providing services.[7] The SEC also proposes to remove the related Rule 17ad-13(d)(2) exemption, which it estimates would require additional transfer agents to obtain an annual independent-accountant report on internal controls.[8]

The Proposal may have a particularly significant impact on transfer agents servicing investment companies, DRIPs, and other products that historically benefited from tailored regulatory treatment. The SEC specifically requests comment on whether certain investment company transactions warrant accommodations following the rescission of Rule 17ad-4 and whether product-specific operational differences continue to justify differentiated treatment.

For smaller transfer agents, the rescission could be significant because it would subject firms that previously relied on the exemption to the Proposal’s broader operational, recordkeeping, reporting, and internal-control requirements. The SEC specifically seeks comment on whether these additional obligations could contribute to industry consolidation or otherwise affect competition and issuer choice. Firms currently relying on Rule 17ad-4 should evaluate the rescission in conjunction with the Proposal’s other new requirements rather than as a standalone change.

Comprehensive Risk Management – Rule 17ad-12

Proposed Rule 17ad-12 would recast the existing safeguarding rule as a comprehensive risk-management requirement. Every registered transfer agent would need written policies and procedures reasonably designed to protect the funds and securities in its possession, control, or custody against theft, loss, misappropriation, misuse, damage, destruction, and improper or unauthorized access, and to identify, measure, monitor, and mitigate material custody, operational, cybersecurity, and other risks associated with its business.

The rule would require transfer agents to maintain all issuer, securityholder, and other third-party funds in a bank account designated as a “for the benefit of” (FBO) account, which would be separate from the transfer agent’s other bank accounts, although client-by-client segregation would not be required.

Additionally, each transfer agent would need a written business continuity plan that addresses significant disruption risks, record recovery, resumption of operations, and fulfillment of obligations, and that is tested, reviewed, and updated at least annually.[9]

The Proposal would substantially expand the concept of “safeguarding” beyond the physical custody of securities and funds to encompass operational resilience, cybersecurity, unauthorized access, and other business risks. As a result, transfer agents may need to evaluate whether their governance, technology, vendor-management, and incident-response frameworks are sufficient to satisfy the proposed risk-management standard.

The proposed FBO-account requirement could require firms to review existing banking arrangements, account structures, reconciliation practices, and agreements with issuers and financial institutions. According to the SEC, the requirement is intended to reduce commingling risk and provide greater protection for third-party funds in the event of a transfer agent insolvency.

The business continuity provisions likewise would raise the regulatory baseline by requiring regular testing and review of recovery and operational-resumption procedures. Firms that rely on service providers, cloud-based systems, or distributed-ledger infrastructure should assess whether those relationships and related contractual arrangements adequately support compliance with the proposed requirements.

The SEC has requested comment on several issues that could make the final rule more prescriptive, including whether cybersecurity incidents and operational disruptions should be reportable events, whether independent assessments should be required, and how the rule should apply to emerging technologies and digital asset–related arrangements.

Compliance Programs and Governance – Rule 17ad-30

Proposed Rule 17ad-30 would require every registered transfer agent to establish, maintain, and enforce written policies and procedures reasonably designed to achieve compliance with applicable federal securities laws and regulations, including identifying and timely remediating instances of noncompliance.

The transfer agent’s board of directors or similar governing body would have to review and approve the policies and procedures at least annually in addition to reviews required following material changes to the transfer agent’s operations or applicable federal securities laws and regulations. The SEC views the Proposal as a means of establishing a baseline compliance framework across the transfer agent industry and promoting more consistent controls, oversight, and accountability.

While the proposed rule is principles based, its practical implications could be significant. Transfer agents would need to assess the risks associated with their business and implement written compliance controls designed to address those risks. Compliance with the proposed rule, if finalized, will require firms to formalize compliance testing, exception management, training, vendor oversight, documentation practices, and governance processes that have historically been maintained on a less structured basis.

In sum, under the proposed rule, a transfer agent’s failure to maintain appropriate written policies and procedures could serve as an independent violation of the rule. That requirement is in addition to demonstrating effective compliance controls around processing timelines, recordkeeping, safeguarding obligations, and cybersecurity risks. Smaller transfer agents, in particular, may need to devote additional resources to compliance personnel, governance, and internal-control infrastructure if the Proposal is adopted.

Restrictive Legends and Section 5 Gatekeeping – Rule 17ad-31

Proposed Rule 17ad-31 would create an express federal gatekeeping obligation for transfer agents in connection with unregistered securities transactions. For each issuer serviced, a transfer agent would need to obtain and maintain a current list of issuer employees authorized to provide instructions concerning the issuance of securities and the placement and removal of restrictive legends and only act on instructions from a person on that list.

More importantly, the transfer agent would be required to refrain from facilitating any unregistered securities transaction unless it has a reasonable basis to believe that the transaction does not violate, or is not part of a chain of transactions that would violate, Section 5(a) of the Securities Act of 1933, as amended (the Securities Act).

The proposed rule identifies original unregistered issuances, requests to remove restrictive legends or stop orders, and purchases, sales, or transfers by issuer affiliates, officers, or directors as examples of transactions within its scope.[10]

The Proposal would significantly expand the transfer agent’s role in assessing compliance with Section 5 of the Securities Act. While many transfer agents currently have policies and procedures in place to maintain accurate books and records for issuers, such as the identification of authorized individuals at issuers and requirements for legend-removal requests, transfer agents would be required to substantively evaluate a broader range of unregistered securities transactions and develop a reasonable basis for concluding that a proposed transaction is not an illegal distribution.

The Proposal includes a nonexclusive safe harbor under which a transfer agent could establish the reasonable basis standard either by obtaining a qualifying opinion of counsel or by conducting and documenting its own exemption analysis.

If relying on the former, the Proposal would only permit reliance on an opinion of counsel who is not an affiliate, officer, director, or employee of the issuer or the individual or entity seeking to resell the shares. While many legend removal opinions are typically issued by external counsel, there are, for example, public companies with in-house legal teams that wish to handle such opinions without the assistance of external counsel.

The Proposal would eliminate that avenue entirely, which could increase costs and expenses for issuers and require an issuer to modify its existing policies and procedures for legend removals. While the proposing release does identify examples of enforcement actions brought against transfer agents for facilitating violations of Section 5, it does not clarify unique concerns that the SEC has with respect to a transfer agent’s reliance on an issuer’s in-house counsel for legend removal opinions.

With respect to the latter approach, the Proposal would require a transfer agent to memorialize a written determination identifying the applicable exemption, supporting facts, and management approval.

Notably, the SEC would not permit blind reliance on either approach. Transfer agents would be expected to investigate potential “red flags” and make further inquiry when circumstances suggest that a transaction may be part of an unlawful distribution. In this respect, the Proposal identifies examples of red flags, including, for example, trading suspensions, inconsistent reporting, sudden demand for thinly traded securities as well as issuers with several name changes, business combinations or recapitalizations, and large reverse splits.

While some of these events could signal suspicious activity, there may also be legitimate business reasons for their occurrence or may be no direct correlation or connection to the transaction at hand. The Proposal would require a transfer agent to make complex legal determinations regarding the validity of a transaction based on facts of which it may not have complete knowledge. As a practical matter, firms may need to adopt more formal diligence, escalation, documentation, and review procedures for transactions involving restricted securities.

The Proposal also raises practical questions about completing required Section 5 diligence while meeting the Proposal’s shortened turnaround and other processing timelines. Transfer agents may need to revise service agreements, issuer procedures, and internal workflows to ensure that the information necessary to evaluate exemptions can be obtained and reviewed without disrupting processing requirements.

Because Proposed Rule 17ad-31 would impose a direct regulatory obligation on transfer agents, issuer instructions or contractual indemnification would not substitute for the transfer agent’s own compliance determination. The SEC specifically requests comment on the scope of the proposed gatekeeping obligation, including whether original issuances should be covered, whether the safe-harbor conditions are appropriately calibrated, and whether additional documentation or diligence requirements should apply.

OTHER NOTABLE CHANGES

In addition to the changes described above, the Proposal would significantly expand Form TA-1 and TA-2 reporting requirements, modernize recordkeeping rules for electronic and tokenized securities, require electronic maintenance of the master securityholder file, and establish new requirements relating to inactive securityholders. Collectively, these amendments are intended to provide the SEC with greater visibility into transfer agent operations while updating a regulatory framework that was originally developed for a paper-based securities market.

The Proposal reflects the SEC’s effort to modernize the transfer agent regulatory framework for distributed-ledger technology and tokenized securities. The proposed amendments would update definitions and recordkeeping requirements to expressly contemplate electronic ownership records, distributed-ledger systems, and tokenized securities, while requiring transfer agents maintaining ownership records through such systems to satisfy the same core recordkeeping, safeguarding, and operational standards applicable to traditional securities records.

While the Proposal does not establish a separate regulatory framework for blockchain-based securities, it signals the SEC’s expectation that existing transfer agent obligations will apply regardless of the technology used to record or transfer ownership interests.

COMMENT PERIOD

Comments are due 60 days after publication of the Proposal in the Federal Register. Regarding the four areas discussed above, the SEC has the following operational feasibility and calibration concerns:

  • whether the one-business-day standards work for late-day, certificated, complex, or fund transactions;
  • whether Rule 17ad-4 should be modified rather than rescinded and whether smaller firms need transition or scaled relief;
  • how “material” risk, incident reporting, independent assessments, and permitted forms of segregated funds should be addressed under Rule 17ad-12; and
  • how far Rule 17ad-31 should extend beyond legend removal, including original issuances, red-flag inquiry, opinion requirements, and transfer agent self-determinations.

The SEC also asks for quantitative information, not only legal or policy views. Comment letters may be more effective if they provide concrete data on item volumes and time-of-day receipt patterns, exception and rejection rates, investment company and other specialized workflows, systems-upgrade costs, existing FBO and business continuity practices, cybersecurity or operational-risk assessments, and the volume and cost of restrictive-legend opinions and exemption analyses.

HOW WE CAN HELP

Transfer agents, issuers, investment companies, broker-dealers, service providers, and other market participants may wish to evaluate how the Proposal would affect their existing processing, recordkeeping, safeguarding, compliance, and legend removal practices and should consider whether to submit comments on the Proposal.

Contacts

If you have questions about how the Proposal may affect you, or if you are interested in submitting a comment letter, please contact the authors of this LawFlash or another Morgan Lewis lawyer.

Authors
Todd P. Zerega (Pittsburgh)
Erin E. Martin (Washington, DC / New York)
Margaret R. Blake (Washington, DC)
Alice S. Hrdy (Washington, DC)
Joseph Stuart Healy (Washington, DC)
Megan E. Kilduff (Washington, DC)

[1] Release, page 9.

[2] The Proposal would amend Exchange Act Rules 17ac2-1, 17ac2-2, 17ad-1, 17ad-2, 17ad-3, 17ad-6, 17ad-7, 17ad-9, 17ad-10, 17ad-12, and 17ad-17, among other conforming changes.

[3] Release, pages 107–117 and 167–175.

[4] Release, page 73.

[5] Release, pages 168–172.

[6] Release, pages 121–126.

[7] Release, page 228, fn. 414.

[8] Release, pages 228 and 275–283.

[9] Release, pages 176–187; see also pages 298–303.

[10] Release, pages 202–210; see also pages 313–317.