Internal Controls, Business Continuity, and Supervisory Testing

Review WSP controls, annual testing, exception reporting, business continuity, and compliance-certification topics in Series 26.

This section covers the framework that keeps supervision reliable after the first review is finished. Series 26 expects the principal to understand written supervisory procedures, supervisory controls, annual testing, exception reporting, business continuity planning, system reliability, and related certification obligations. The point is not memorizing a list of internal-control terms. The point is knowing how a firm proves that packaged-products supervision actually works over time.

The exam often uses a recurring error to test whether the candidate can distinguish between correction and control. Correcting one bad breakpoint calculation is not enough if the exception report is weak, the procedure is outdated, or the same error keeps resurfacing. A strong principal response fixes the customer problem and then asks what in the system failed to catch it earlier.

Control tools and what they are supposed to prove

Control elementWhat it is designed to catch or confirmBetter supervisory response
Written supervisory proceduresWhether the firm has a defined process for review, escalation, and documentation.Update procedures when practice changes instead of relying on informal office custom.
Supervisory controlsWhether the review system itself is independently tested and not just assumed to work.Use control reviews to challenge weak patterns, not just check a box.
Exception reportsWhether outliers, missing items, or repeated errors are visible quickly enough to investigate.Escalate repeated exceptions to root-cause review rather than treating each one as isolated.
Annual testing and reviewWhether the firm evaluates procedures, technology, and evidence of supervision on a scheduled basis.Retest the high-risk areas that produce customer harm or recurring errors.
Business continuity planningWhether the firm can continue core supervisory and servicing functions during disruption.Focus on critical packaged-products workflows, customer access, and record availability.
Certification and senior-management oversightWhether leadership has evidence that required controls exist and are reviewed.Support certification with documented testing and remediation, not assumptions.

Series 26 repeatedly rewards the answer that treats the control environment as a living system. If the same issue appears more than once, the principal should think about supervision design, training, and exception visibility.

Exception-to-remediation workflow

    flowchart TD
	    A["Recurring exception, processing error, or system breakdown appears"] --> B{"Is this an isolated one-off?"}
	    B -- "Yes" --> C["Correct the item and document the review"]
	    B -- "No or unclear" --> D["Escalate to supervisory-control or compliance review"]
	    D --> E["Identify the root cause in procedure, training, technology, or oversight"]
	    E --> F["Revise the procedure, report, control, or training path"]
	    F --> G["Retest the affected process and retain evidence"]
	    G --> H["Report results to the appropriate supervisory level"]
	    C --> I{"Does the same issue appear again?"}
	    I -- "Yes" --> D
	    I -- "No" --> J["Close the item with documented resolution"]
	    H --> J

This is the mindset Series 26 wants. One-off correction is acceptable only when the record supports that it really was one-off. Once the same weakness repeats, the question becomes whether the firm’s supervisory design is adequate.

What the exam usually rewards

  • Strengthening exception review is usually better than reminding representatives to “be more careful.”
  • Business continuity questions are not only about disaster recovery. They test whether supervision, customer service, and record access survive disruption.
  • Annual testing matters because a control that is never challenged can become ceremonial.
  • The safer answer is usually the one that produces evidence of review, remediation, and retesting.

Sample exam question

A firm’s breakpoint report has missed the same share-class pricing issue twice in one quarter. Both affected customers were reimbursed, and the representative has been reminded to review the prospectus more carefully. What is the best next step for the principal?

  1. Close the matter because the customers were made whole.
  2. Wait to see whether the issue happens a third time before changing procedures.
  3. Escalate the matter for control review, determine why the exception reporting failed, and document remediation and retesting.
  4. Reassign the representative’s accounts to another representative.

Correct answer: 3.

Series 26 is testing the difference between a customer correction and a control correction. The reimbursement matters, but repeated misses mean the supervisory system itself needs to be reviewed and strengthened.

Revised on Thursday, April 23, 2026