Broker Protocol Compliance Guide for Breakaway Advisors (2026 Edition)

The Protocol for Broker Recruiting is the document that turned breakaway moves from a litigation gauntlet into a manageable transition — but only for advisors and firms that follow it exactly. The 2026 reality: roughly 1,800 firms remain Protocol signatories, the original wirehouse signatories (Morgan Stanley, UBS, Citi) are gone, and the difference between a clean exit and a temporary restraining order is whether the departing advisor follows the five-point Protocol checklist on resignation day, not in the weeks after.
Here's what the Protocol permits in 2026, what it doesn't, and the compliance steps that have to happen before — not after — you resign.
What the Broker Protocol Actually Permits
The Protocol, formally the Protocol for Broker Recruiting, was signed in 2004 by Merrill Lynch, Smith Barney, and UBS Painewebber. It permits a departing advisor to take exactly five categories of client information when moving between two signatory firms:
- Client name
- Client address
- Client phone number
- Client email address
- Account title (the type of account, not the assets or holdings)
That's it. No account numbers, no balances, no Social Security numbers, no holdings data, no performance history, no internal notes, no fee schedules. The Protocol's whole purpose is to permit normal client contact after the move while protecting the firm's confidential business information.
When followed exactly, the Protocol provides a safe harbor: the departing firm waives non-solicitation claims, and the receiving firm waives raiding claims. Step outside the five permitted fields and the safe harbor collapses — and so does your transition timeline.
The 2026 Signatory Landscape: Smaller, More Selective
In 2017, Morgan Stanley and UBS withdrew from the Protocol. Citi followed in 2018. That removed three of the four original wirehouse signatories and triggered a wave of pre-departure litigation that hadn't existed in the prior decade.
As of 2026, roughly 1,800 firms remain Protocol signatories — predominantly independent broker-dealers, RIAs, and smaller wirehouses. The current list is maintained by Bressler, Amery & Ross. Both the departing firm AND the receiving firm have to be signatories for the Protocol's safe harbor to apply. If either side is not on the list, the move is governed by the advisor's employment agreement and applicable state law — typically a much harsher regime.
For advisors leaving Morgan Stanley, UBS, or Citi, the Protocol does not apply. The employment agreement, the non-solicit, and TRO risk become the entire framework. This dramatically changes the pre-departure compliance work required.
The Five-Point Resignation Day Compliance Checklist
For a Protocol-compliant move between two signatory firms, the resignation day sequence has to follow this exact order. Deviation in any step has a documented history of becoming the basis for a TRO.
Step 1: Deliver written resignation to the branch manager in person. Email or voicemail alone is not sufficient. The resignation has to be in writing, signed, and delivered to the individual designated under the Protocol's language. Same-day, in-person delivery is the standard.
Step 2: Submit the Protocol list simultaneously. The list of clients you intend to contact must be delivered to the firm at the same time as the resignation. The Protocol calls for a list of clients "the registered representative serviced while at the firm." Withholding the list, submitting it after the fact, or padding the list with clients you didn't actually service all collapse the safe harbor.
Step 3: Take only the five permitted fields. The information you bring with you can include only client name, address, phone, email, and account type. No account numbers, no asset details, no statements, no internal CRM exports beyond those five fields. Many violations stem from advisors exporting their entire CRM "just in case" — that single export is sufficient to void Protocol protection.
Step 4: No solicitation before resignation. The Protocol permits post-resignation contact, not pre-resignation solicitation. Calls, emails, or in-person conversations with clients about your move that happen before resignation day are not protected. This includes "social" conversations that drift into business territory.
Step 5: Don't take anything else. Sample forms, proprietary research, client meeting notes, fee schedules, marketing materials, internal training documents — none of this is covered by the Protocol. Many post-departure lawsuits target taken materials, not taken clients.
Pre-Departure Compliance Work That Has to Happen First
The most consequential compliance work happens 60–90 days before resignation, not on the day itself. Three workstreams have to be in motion.
Form U4 / U5 review. Your Form U4 disclosures and the upcoming Form U5 termination notice from the departing firm need to be clean. Any open issues — customer complaints, regulatory matters, financial disclosures — need to be resolved or properly disclosed before the move, because the U5 narrative the departing firm files will follow you to the new firm and to the public BrokerCheck record.
Receiving-firm registration. Your Series 7, Series 66, and any state-specific licenses need to transfer cleanly through CRD. The receiving broker-dealer or RIA's compliance team will do the heavy lifting, but you need to be responsive on documentation requests. License transfers that aren't pre-staged add weeks to the dark period when you're unable to service clients.
Privacy and Reg S-P compliance. Even when the Protocol applies, Reg S-P (the SEC's privacy rule) governs how client information moves. The receiving firm needs documented compliance procedures for receiving and storing the permitted Protocol information. RIAs without established procedures here often face state regulator inquiries even when the Protocol covers the broker-dealer side of the move.
What "Solicitation" Means in 2026 Enforcement
Courts and arbitration panels have refined the definition of solicitation considerably since the Protocol was signed. In 2026, the working definition includes:
- Any communication initiated by you to a client between the day you began planning the move and resignation day
- Public announcements (LinkedIn posts, press releases, firm directory listings) that name your former firm before resignation
- Indirect contact through assistants, junior advisors, or family members
- Pre-positioning conversations that don't explicitly ask for the business but make the move known
Post-resignation, contact initiated by you to clients on the Protocol list is permitted. Contact with clients not on the list is not, and the Protocol's "list completeness" requirement is where many otherwise-clean moves fall apart in arbitration.
How Automated Repapering Fits Into Protocol Compliance
The Protocol governs what client information you can take. It does not govern how you process the new account paperwork at the receiving firm — but the speed and accuracy of that processing determines whether the Protocol's clean-exit benefit actually translates into AUM retention.
A Protocol-compliant move that takes 90 days to repaper sees client attrition driven by the timeline, not by any compliance issue. A Protocol-compliant move that completes repapering in 3 weeks captures the full benefit of the safe harbor. The compliance work and the operational work compound — automation on the receiving-firm side is what converts compliance correctness into client retention.
FastTrackr AI handles the post-Protocol repapering automation — generating correct-version forms for the receiving custodian, validating client data against current requirements before submission, and coordinating signature collection across the full book in parallel. The 95% NIGO reduction matters because the alternative — a 25% NIGO rate on a 500-account book — produces 125 rejection cycles that the Protocol's safe harbor doesn't prevent.
Common Protocol Mistakes That Trigger TROs
Reviewing the last five years of Protocol-related litigation, four recurring patterns emerge.
Mistake 1: Pre-resignation social media activity. Updating LinkedIn to remove the current firm before formal resignation is the most common Protocol-violating act in the modern era. Courts have treated this as both a solicitation and a tortious act independent of the Protocol.
Mistake 2: Incomplete client list. Submitting a list that doesn't include every client serviced — including small accounts, dormant accounts, and accounts originated by a teammate — collapses the safe harbor on every contact that follows.
Mistake 3: Coordinated team departures without separate compliance. When multiple advisors leave together, each one needs independent Protocol compliance. A single team member's violation can taint the entire group.
Mistake 4: Bringing CRM data beyond the five fields. Exporting full CRM records to a personal device, even temporarily, has been used as evidence of misappropriation in arbitration even when the advisor never used the data.
Frequently Asked Questions
What client information can a breakaway advisor take under the Broker Protocol in 2026?
The Broker Protocol permits a departing advisor to take exactly five categories of client information: client name, client address, client phone number, client email address, and account title (account type, not assets or holdings). No account numbers, balances, Social Security numbers, holdings data, or internal notes are permitted. Taking anything beyond these five fields voids the Protocol's safe harbor and exposes the advisor to non-solicitation and misappropriation claims.
Is Morgan Stanley still part of the Broker Protocol?
No. Morgan Stanley withdrew from the Broker Protocol in October 2017, followed by UBS the same month and Citi in 2018. For advisors leaving Morgan Stanley, UBS, or Citi in 2026, the Protocol does not apply. The departing employment agreement, any non-solicit covenants, and applicable state law govern the move — typically a much harsher legal framework than the Protocol's safe harbor.
How many firms are signatories to the Broker Protocol in 2026?
Roughly 1,800 firms remain Broker Protocol signatories in 2026, predominantly independent broker-dealers, RIAs, and smaller wirehouses. The current list is maintained by Bressler, Amery & Ross at thebrokerprotocol.com. For the Protocol's safe harbor to apply to a move, both the departing firm and the receiving firm must be on the signatory list.
What is the correct order of events on a Protocol-compliant resignation day?
Deliver written resignation to the branch manager in person, submit the Protocol client list simultaneously with the resignation, take only the five permitted client information fields, ensure no client solicitation occurred before resignation, and take no firm materials beyond the permitted information. All five steps have to happen on the same day in this sequence — any deviation creates a basis for a TRO.
What counts as "solicitation" under the Broker Protocol?
Solicitation under the Protocol includes any communication initiated by the advisor to a client between the time the move was planned and the resignation day, public announcements naming the former firm before resignation, indirect contact through assistants or family members, and pre-positioning conversations that make the move known. Post-resignation outreach to clients on the Protocol list is permitted; pre-resignation contact of any kind is not.
How does Reg S-P interact with the Broker Protocol?
Reg S-P, the SEC's privacy rule, governs how client information moves between firms regardless of whether the Broker Protocol applies. Even for Protocol-compliant moves, the receiving firm must have documented procedures for receiving and storing the permitted client information. RIAs without established Reg S-P compliance procedures sometimes face state regulator inquiries even when the broker-dealer side of the move is fully Protocol-compliant.
Can social media activity violate the Broker Protocol?
Yes. Updating LinkedIn to remove the current firm before formal resignation is the most common Protocol-violating act in the modern era. Courts have treated pre-resignation public announcements as both solicitation and a tortious act independent of the Protocol. All public-facing changes — LinkedIn, firm directories, professional bios — should happen only after the resignation is delivered.
What happens if a Protocol violation occurs?
A Protocol violation typically triggers a temporary restraining order (TRO) from the departing firm within 24–72 hours of discovery. The TRO restricts client contact, suspends the use of the taken information, and forces emergency arbitration. Even when the eventual arbitration outcome favors the advisor, the TRO period — typically 3–6 months — coincides exactly with the critical post-departure client retention window, causing substantial AUM bleed.
The Protocol is a powerful tool when followed correctly and a serious liability when followed approximately. The pre-departure compliance work, the resignation-day sequence, and the post-resignation operational work are three separate workstreams that have to be planned independently and executed together. Get all three right and a breakaway transition is a structured operational project. Get any one of them wrong and it becomes a litigation problem.
Related: Meeting Assistant · For Transition Consultants


