By Philip C. Marshall and Charles E. Wallace Jr.
The full essay is available here as a PDF.
Charles E. Wallace Jr. spent three years reconstructing what had happened to his mother’s money. She had dementia. Her caregiver had access, trust, and time — and by the time anyone noticed the pattern of withdrawals, more than a million dollars was gone. What that investigation exposed is the argument of this essay: the system did not fail his mother because no one had the authority to act. It failed her because no one had verified that anything was wrong before authority became the only question anyone thought to ask.
Congress is already responding to half of this problem. On June 25, 2026 the House of Representatives passed H.R. 2478, the Financial Exploitation Prevention Act of 2025 by a vote of 414 to 2 — codifying the authority of open-end investment companies and their transfer agents to delay redemptions for up to fifteen business days, and up to twenty-five upon a determination of exploitation, when financial exploitation of an adult 65 or older, or an adult 18 or older with a reasonably believed mental or physical impairment, is suspected. That population is broader than FINRA Rule 2165’s coverage. But the authority granted is narrower than it may first appear: it reaches only “direct-at-fund” accounts held directly with a mutual fund company and serviced by a transfer agent — not brokerage accounts, and not the general retail banking relationships where most exploitation occurs. The bill’s Senate companion, S.2840, contains identical language and is now pending before the Banking Committee — the same committee where a nearly identical predecessor died without a vote in 2023, after passing the House 419 to 0.
Both bills are elective at two levels. A fund and its transfer agent must first affirmatively opt in by notifying the SEC — this is adoptable infrastructure, not an industry-wide floor, and stands in contrast to FINRA Rule 2165, which already binds every FINRA member firm without an opt-in step. Even after a firm elects to participate, the postponement authority itself is permissive: the statute says a firm “may postpone” a redemption, not that it must. Both bills require an internal review before an initial fifteen-day hold can be extended by an additional ten business days — but that review is conducted by the same institution that made the original exploitation determination. Both anticipate a hard case Congress has clearly already considered: a firm need not notify a designated contact of an extension if the firm reasonably believes that contact is the one committing the exploitation. Congress, in other words, has recognized twice now — in this bill and its 2023 predecessor — that the person a client names as their trusted contact can be the threat. What neither version provides is an independent party to verify that recognition. The review remains internal to the same firm exercising the hold authority in the first place.
Both bills also direct the SEC to report to Congress within one year, in consultation with FINRA and six other federal and state regulators, on further legislative and regulatory changes needed.
Whether this version reaches the President’s desk depends entirely on whether the Senate acts where it did not before. There is no reconciliation to negotiate. There is only a vote the Senate has already declined to take once.
The question the Act answers is whether firms may pause. The question it leaves open is what happens next: once the hold is in place, who provides the independent verification that determines whether it is lifted? Too often, the answer is the same person exercising legal authority over the client — the attorney-in-fact, trustee, or other fiduciary whose conduct may itself be the reason the hold was placed.
Every well-designed control system distinguishes between authority and verification. A loan officer can recommend approval, but another party underwrites it. An auditor can examine another firm's books, but not its own. A co-trustee can direct investments, but the custodian holds the assets independently. Throughout financial services, resilience depends upon assigning different control functions to different people.
This separation is so fundamental that we rarely stop to notice it. Yet the person possessing legal authority — the attorney-in-fact, trustee, guardian, or other fiduciary — frequently becomes both the individual empowered to act and the individual whose judgment resolves questions about whether that authority is being exercised appropriately.
Those are not the same function. One grants authority. The other provides independent verification. Confusing them creates a concentration of control precisely when independent judgment matters most.
The scale of the problem Congress acted to address is significant. U.S. households hold $80.4 trillion in liquid assets and $54.1 trillion in retirement assets — wealth that flows through the very capital markets infrastructure this article addresses (SIFMA, 2026). Americans 70 and older hold more than $56 trillion of that household wealth alone — the largest intergenerational transfer of assets in history, and the largest pool of financial resources ever exposed to exploitation (Federal Reserve, 2024). AARP’s first-of-its-kind methodology estimates that older adults over 60 lose at least $28.3 billion annually to elder financial exploitation — of which $20.3 billion is attributable to known perpetrators: family members, trusted caregivers, and others already in the victim’s life (Gunther, 2023). Fraud by strangers, significant as it is, tells only part of the story. The FTC reports that older adults’ aggregate fraud losses skyrocketed from approximately $600 million in 2020 to $2.4 billion in 2024 — with the overall cost of fraud estimated between $10.1 billion and $81.5 billion when unreported cases are factored in (Federal Trade Commission, 2025). The distinction between stranger fraud and exploitation by trusted others matters because the regulatory architecture has been built primarily to address the former. This article addresses the latter.
The Financial Exploitation Prevention Act codifies the hold. It extends to open-end investment companies and their transfer agents — mutual funds and their administrative agents — complementing but not replacing the FINRA Rule 2165 framework that governs broker-dealers, and leaving banks, credit unions, and other financial institutions largely outside both frameworks. The Act also requires the SEC to make recommendations to address financial exploitation of these adults — an opening for the architectural question raised here to reach the regulatory agenda. What follows addresses what the hold is for, what the current architecture still leaves unresolved, and what a modest, non-statutory enhancement could do to close the gap.
Rule 2165 Solved an Important Problem
FINRA Rule 2165 was an important advance in investor protection because it recognized that firms sometimes need time to determine whether financial exploitation may be occurring. The authority to place a temporary hold on suspicious disbursements gives compliance professionals an opportunity to gather facts before assets leave an account. The rule addresses detection well.
Rule 2165 did not arrive alone. FINRA Rule 4512, adopted alongside it, requires broker-dealers to make reasonable efforts to obtain the name and contact information of a trusted contact person for each non-institutional customer account. The trusted contact carries no legal authority — they cannot direct transactions, access account information, or override fiduciaries. Their role is narrower: to be a person the firm can reach when it has concerns about the client’s health, safety, or possible financial exploitation. Rule 4512 builds the contact. Rule 2165 activates it — permitting the firm to notify the trusted contact about a hold and the underlying concern.
Together, the two rules represent the regulatory architecture’s most developed recognition that an independent voice outside the legal authority structure may be needed when exploitation is suspected. Together, they also illustrate that architecture's limits: the trusted contact must be designated in advance, receives notification rather than consultation rights, and applies only to FINRA-member broker-dealers rather than banks, credit unions, or other financial institutions operating under different regulatory frameworks. The rule itself anticipates the hardest case: a firm need not notify the trusted contact if it “reasonably believes that the Trusted Contact Person(s) has engaged, is engaged, or will engage in the financial exploitation of the Specified Adult” (Financial Industry Regulatory Authority, 2022). FINRA recognized this problem before Congress did. Neither has yet built an independent party to verify the recognition.
The consequences of surveillance failures within that architecture can be severe. In July 2026, the SEC fined Merrill Lynch $7.5 million for failing to file hundreds of suspicious activity reports over more than four years — the result of a surveillance threshold so high that transactions scoring below a risk score of 20 were never automatically investigated, even after Merrill's own internal analysis identified the gap in 2020 (Longo, 2026). It was the third time the SEC had sanctioned Merrill for the same category of failure — following settled proceedings in 2017 and 2023. The case illustrates the detection half of the problem with precision: when the architecture designed to flag suspicious activity fails, the hold is never placed. This article addresses the other half — what happens when the detection works, the hold is placed, and the question of who provides independent verification remains unanswered.
Once the hold has been placed, however, firms encounter a second challenge that the rule does not attempt to solve.
Who should provide the information that allows the hold to be lifted?
Too often, the answer becomes the same person already exercising legal authority over the client. That approach may be entirely appropriate. It may also eliminate the independence that makes a control effective.
FINRA itself has been moving on parts of this architecture. In January 2026, the regulator proposed amendments to Rules 2165 and 4512, and a new Rule 2166, in Regulatory Notice 26-02 — proposals that, as of this writing, are being refined for submission to the SEC and have not yet been finalized. The proposed framework would extend the maximum temporary hold period from its current structure — an initial 15 business days, extendable by 10 more if an internal review supports the firm's belief, and by a further 30 if the firm has also reported to a state regulator or court, for a maximum of 55 business days — to as much as 145 business days in three 30-business-day increments. It would also permit firms to use the optional term “emergency contact” alongside “trusted contact,” and allow a customer to designate a single trusted contact across all of their accounts with the firm — while still requiring the firm to offer the customer the choice to designate account-by-account instead (Financial Industry Regulatory Authority, 2026).
These are meaningful improvements, and they respond to a real problem: FINRA's own 2020 member firm survey found that 28 percent of firms encountered matters that took more than 50 business days to resolve — a gap the proposed extension to 145 business days is meant to close, and one that FINRA's own notice ties directly to the average length of an APS investigation, consistent with independent research finding that average at 54.6 days (Snyder et al., 2023).
But none of these proposed changes address who provides independent verification once a hold is in place. Neither does proposed Rule 2166, FINRA's parallel "speed bump" mechanism for suspected fraud affecting customers of any age: it permits a five-business-day delay on the same authority-without-verification basis, and like Rule 2165, excuses the firm from notifying a party it reasonably believes is involved in the fraud. FINRA has recognized, in a third instance now, that the person closest to an account can be the threat. It has not yet built an independent verification role to answer that recognition. The proposals extend the clock and extend the rule's reach. They do not change who is allowed to look at either one.
Authority Is Necessary. Verification Is Different.
Nothing in this article argues against powers of attorney, trustees, guardians, or other fiduciaries.
Most perform their responsibilities honorably and faithfully. The issue is not whether fiduciaries deserve trust. The issue is whether control systems should ever rely exclusively upon one individual when credible concerns already exist.
Financial institutions answer that question every day in other contexts. They separate initiation from approval, execution from review, and authority from verification. That same principle deserves application here in protecting older adults.
Two Cases, One Architectural Lesson
Charles E. Wallace, Jr.’s family encountered this issue when a brokerage firm appropriately identified suspicious caregiver payments from his mother’s account and invoked Rule 2165. Compliance acted exactly as intended. During its review, however, the firm relied upon the attorney-in-fact—the individual responsible for approving the questioned payments—to resolve the matter. Documentation was supplied, the hold was lifted, and the payments continued.
The Wallace family’s experience is documented in The Caregiver’s Game: Unraveling Financial Deceit in the Shadows of Dementia — a firsthand account of how a predatory caregiver methodically gained control of an older adult’s financial life while the person holding power of attorney failed to question what the brokerage statements showed. The book’s central question — why didn’t the person with legal authority ask? — is precisely the question that independent verification is designed to answer.
Years earlier, before Rule 2165 existed, Brooke Astor’s grandson Philip Marshall petitioned successfully to place her under guardianship after discovering that her son, Anthony Marshall — who held powers of attorney and health care authority — had been exploiting her. Anthony Marshall was later convicted of crimes arising from that exploitation. Although the regulatory framework differed, the underlying architectural issue was remarkably similar. The legal authority intended to protect the vulnerable individual had itself become compromised.
The common lesson is not about two families. It is about system design. Neither case demonstrates that powers of attorney are inherently flawed. Both illustrate what can happen when authority and independent verification collapse into the same hands.
Independence of custody is not the same as independence of judgment. The custodian holds the assets. No one in the current architecture is assigned to evaluate whether the instructions directing those assets reflect the client’s genuine interests — or to ask the person most likely to know.
A Modest Enhancement to an Effective Framework
Rule 2165 does not require reinvention, nor does it require significantly broader regulatory authority. It may benefit from a stronger mechanism for independent verification.
Rule 4512’s trusted contact concept points in the right direction. What it does not yet provide is a verification role — a structured opportunity for the trusted contact, or a similarly designated independent person, to contribute substantive context when a hold is under review, rather than simply receiving notification that a hold has been placed.
One practical approach would be encouraging clients, while they retain capacity, to identify a small network of trusted, non-authoritative contacts — Independent Concerned Persons. In practice, two or three individuals would be the maximum that is sustainable from a compliance standpoint — enough to provide genuine independent perspective without creating an unwieldy verification process.
These individuals would possess no legal authority. They would not approve transactions, direct investments, or override fiduciaries. Their role would be narrower — and more consistent with sound control architecture. They would provide independent context when compliance professionals are evaluating suspicious activity involving a vulnerable client.
This concept complements both Rule 2165 and the Trusted Contact Person framework. Rather than competing with fiduciary authority, it strengthens the verification process whenever legitimate concerns arise. It also addresses the gap the two rules together leave open: the person who actually raised the alarm — the neighbor who called the bank, the adult child who flagged the unusual transactions — may not be the trusted contact on file. The Independent Concerned Person framework would give that person a recognized role, not merely a phone number to call.
Like any account relationship, the designated contacts should be reviewed and updated by the client at regular intervals — at minimum every five years — to ensure the information remains current and the people named remain the right people to call. Circumstances change. Relationships evolve. The Independent Concerned Person who was the right designee at account opening may not be the right one five years later. Building in a regular review cycle addresses this directly, and aligns the framework with sound account maintenance practice already familiar to compliance professionals.
A Risk Management Opportunity
Compliance professionals routinely ask whether controls are sufficiently independent. The same question deserves application here.
When reviewing suspected financial exploitation:
· Are we relying exclusively upon the person with legal authority?
· Is there an independent source of information identified by the client?
· Does the documentation independently verify the transaction, or merely reflect it?
· If the fiduciary were the source of concern, would our review process detect it?
· Is the trusted contact on file the person most likely to have relevant, independent knowledge — or simply the person the client named years ago under different circumstances?
These are not questions about trust. They are questions about control design.
Rule 2165 represented a significant advance in investor protection. Rule 4512 extended that advance by building an independent contact into the account relationship before a problem arises. The next advance may come from recognizing a principle already embedded throughout financial services:
Authority and independent verification perform different control functions.
Investor protection is strongest when both are present.
Philip C. Marshall is the founder of BeyondBrooke.org, Professor Emeritus at Roger Williams University, and a nationally recognized elder justice advocate.
Charles E. Wallace, Jr. is a financial professional and author of The Caregiver’s Game: Unraveling Financial Deceit in the Shadows of Dementia.
Sources
Note to editor: Regulatory Notice 26-02 remains a proposal as of this writing. FINRA's comment period closed March 9, 2026, and the proposed amendments are being refined for submission to the SEC; they had not been finalized or adopted as of June 2026. Please confirm status before publication in case final rules have since been issued.
Bentsen, K. E., Jr. (2026, June 29). America at 250: The enduring strength of US capital markets. SIFMA. https://www.sifma.org/resources/news/america-at-250-the-enduring-strength-of-us-capital-markets/
Federal Reserve Board. (2024). Financial accounts of the United States: Distribution of household wealth.Board of Governors of the Federal Reserve System. https://www.federalreserve.gov/releases/z1/dataviz/z1/balance_sheet/chart/
Federal Trade Commission. (2025). Protecting older consumers 2024–2025: A report of the Federal Trade Commission. Federal Trade Commission. https://www.ftc.gov/system/files/ftc_gov/pdf/P144400-OlderAdultsReportDec2025.pdf
Financial Industry Regulatory Authority. (2022). FINRA Rule 2165: Financial exploitation of specified adults (as amended, effective March 17, 2022). FINRA. https://www.finra.org/rules-guidance/rulebooks/finra-rules/2165
Financial Industry Regulatory Authority. (2019). FINRA Rule 4512: Customer account information (as amended, effective May 8, 2019). FINRA. https://www.finra.org/rules-guidance/rulebooks/finra-rules/4512
Financial Industry Regulatory Authority. (2026, January 8). Regulatory Notice 26-02: FINRA requests comment on rule revisions to help member firms protect senior investors from financial exploitation and all investors from fraud. FINRA. https://www.finra.org/rules-guidance/notices/26-02
Gunther, J. (2023). The scope of elder financial exploitation: What it costs victims. AARP Public Policy Institute. https://www.aarp.org/content/dam/aarp/money/scams-and-fraud/2023/true-cost-elder-financial-exploitation.doi.10.26419-2Fppi.00194.001.pdf
Gunther, J. (2025, June 17). Testimony before the United States Senate Judiciary Committee. AARP. https://www.judiciary.senate.gov/imo/media/doc/84ee3646-af4c-fdf8-0cdd-cd39f5936f38/2025-06-17%20-%20Testimony%20-%20Gunther.pdf
House Financial Services Committee. (2026, June 25). House passes committee bill to combat financial fraud and scams. https://financialservices.house.gov/news/documentsingle.aspx?DocumentID=411183
H.R. 2478, Financial Exploitation Prevention Act of 2025, 119th Cong. (2025). https://www.congress.gov/bill/119th-congress/house-bill/2478
Longo, T. (2026, July 1). SEC fines Merrill Lynch $7.5 million over anti-money laundering reporting failures.Financial Advisor. https://www.fa-mag.com/news/sec-fines-merrill-lynch--7-5-million-over-anti-money-laundering-reporting-failures-87603.html
S. 2840, Financial Exploitation Prevention Act of 2025, 119th Cong. (2025) (as introduced). https://www.congress.gov/bill/119th-congress/senate-bill/2840/text
Snyder, J., Hinz, L., & Marshall, P. C. (2023). All in this together: Adult Protective Services and financial institutions’ efforts to combat elder financial exploitation. National Adult Protective Services Association, Financial Exploitation Advisory Board. https://files.constantcontact.com/d414bd01101/7e770288-4814-4d7b-a87d-f552762c11d1.pdf
Wallace, C. E., Jr. (2025). The Caregiver’s Game: Unraveling financial deceit in the shadows of dementia.https://thecaregiversgame.com