Quick Answer
Covered institutions report lost, stolen, missing, and counterfeit certificates on Form X-17F-1A through the designated program. Evaluate all inquiry exceptions, including the
Quick Answer: Covered institutions report lost, stolen, missing, and counterfeit certificates on Form X-17F-1A through the designated program. Evaluate all inquiry exceptions, including the $10,000 aggregate-transaction exception. When inquiry is required, complete it within five business days after receipt and before sale, pledge, or forwarding.
The lost / stolen / counterfeit securities rule is the SEC's certificate surveillance rule:
- Before electronic settlement, certificate fraud was a significant problem: thieves would steal certificates, then resell them through unsuspecting firms or to retail buyers
- The SIC database, run as the SEC's designee, lets the industry query in real time whether a certificate has been reported lost, stolen, or counterfeit, within the required window after receiving it and before the firm sells, pledges, or forwards it
- The rule sits at the operational layer of the financial-responsibility framework: it does not regulate net capital or customer protection directly, but it prevents the firm from accepting tainted certificates that would create downstream problems
Reporting Institutions and Reporting Triggers
A "reporting institution" under the rule includes:
- Broker-dealers
- Banks
- Transfer agents
- Other entities specified in the rule
A reporting institution must report to the SIC any securities certificate that is:
- Missing or lost (cannot be located after a diligent search, including a certificate shipped but not received, or in transit and not arrived)
- Stolen (taken without authorization)
- Counterfeit (forged or fabricated)
Form X-17F-1A
Reports are filed on Form X-17F-1A. The form captures:
- Type of security
- Issuer
- Certificate number
- Denomination / face amount
- Circumstances of the loss / theft / discovery
Concurrent reports are filed:
- With the transfer agent for the affected security (so the transfer agent can flag the certificate in its records)
- With the FBI for suspected criminal loss or theft, and for discovered counterfeits without an additional suspicion condition
Timing
Counterfeit discoveries and theft or loss with a substantial basis for suspected criminal activity must be reported within one business day of discovery. An ordinary noncriminal missing or lost certificate is generally reported within one business day after it has been missing for two business days. Transit losses and other specified cases have separate timing provisions. Choose the deadline from the facts rather than applying one generic clock to every report.
Exam Tip: Gotchas
- Make the required program and transfer-agent reports. FBI reporting also applies to suspected criminal loss or theft and to counterfeits. One required recipient does not replace another.
- The reporting institutions include BDs, banks, AND transfer agents. A transfer agent that discovers a lost certificate has the same reporting obligation as the BD. The exam may probe whether transfer agents are "reporters" under this rule; they are.
The $10,000 Inquiry Threshold
The small-transaction exception covers securities with an aggregate value of $10,000 or less, using face value for bonds and market value for stocks. Do not apply the exception separately to each certificate in one larger transaction.
Other inquiry exceptions include direct receipt from the issuer at issuance, another reporting institution, or a Federal Reserve Bank or branch; qualifying receipt from a customer where the securities are registered in that customer's name or were previously sold to that customer by the institution; and specified transfer-agent checks of its own records. Evaluate the exact conditions before concluding an inquiry is required.
When no exception applies, inquire within five business days after receipt and before selling, pledging, or forwarding the certificate.
How the Inquiry Works
The institution queries the SIC database to verify the certificate is not flagged as lost, stolen, missing, or counterfeit. The firm may take possession of the certificate first; the query must be completed within five business days after the certificate comes into the firm's possession, and before the firm sells, pledges, or forwards it.
If the query returns:
- No match: the certificate appears clean; the firm may proceed to sell, pledge, or forward it as normal (subject to other due diligence)
- Match: the certificate is flagged; the firm must NOT sell, pledge, or forward it, and must follow up appropriately (involve law enforcement, return to source, etc.)
What Counts as "Accepting" a Certificate
Subject to the inquiry exceptions, receipt scenarios can include:
- A customer depositing a certificate to fund a new account
- A firm receiving a certificate as part of a securities transfer
- A firm receiving a certificate as collateral or pledge
Independent Liability for Failure to Inquire
A firm that misses a required inquiry within the prescribed window can violate the rule independently of whether the certificate proves stolen. Mere receipt before inquiry is not automatically a violation: the five-business-day limit and the requirement to inquire before sale, pledge, or forwarding control.
Example: A customer deposits a $25,000 bearer bond in a transaction with no inquiry exception. The firm forwards it without inquiry. That misses the pre-forwarding requirement even if the customer is well known. If the certificate is stolen, additional ownership or liability issues must be assessed separately rather than automatically counting two violations.
Exam Tip: Gotchas
- Transaction value and all other inquiry exceptions matter. A batch above $10,000 may still qualify through direct receipt from another reporting institution. Several individually small certificates in one nonexempt transaction do not each receive a separate $10,000 allowance.
The Securities Information Center (SIC)
The Securities Information Center is the SEC's designee for the Lost and Stolen Securities Program. The SIC:
- Maintains the central database of reported lost / stolen / counterfeit certificates
- Receives reports from reporting institutions on Form X-17F-1A
- Responds to inquiries from reporting institutions in real time
- Distributes data to law enforcement and industry participants as appropriate
SIC Database Operation
The SIC operates as a continuously-updated central registry. When a reporting institution files a Form X-17F-1A, the certificate's details are added to the database. When another reporting institution queries the database after receiving a certificate, before selling, pledging, or forwarding it, the database returns a match if any reporter has flagged that certificate.
The system depends on rapid reporting by the loss-discoverer and rapid querying by the certificate-receiver. A certificate stolen yesterday and not yet reported is not in the database and would not be flagged by an inquiry today. Once it is reported, every subsequent inquiry catches it.
Exam Tip: Gotchas
- The SIC is the SEC's DESIGNEE for the Lost and Stolen Securities Program; it is not part of the SEC itself. The exam may probe whether lost-securities reports go directly to the SEC; they do not. They go to the SIC, which the SEC has designated to operate the program.
What Should You Check on Exam Day?
- Can you name the three types of reporting institutions under this rule: broker-dealers, banks, and transfer agents?
- Do you know the dollar threshold that triggers a mandatory SIC database inquiry, and the window for making it after the firm takes possession of a certificate?
- Can you state where lost or stolen certificate reports go: the Securities Information Center, the transfer agent, and law enforcement when criminal activity is suspected?
- Can you distinguish independent lost-securities-rule liability for skipping the inquiry from liability for accepting a genuinely stolen certificate?