Written by a human
What are the voice recordkeeping requirements for financial services?
Many business collaboration and communication platforms have integrated voice features, which could introduce new risks. How can firms ensure their voice compliance meets regulatory requirements?
In brief:
- While much of business is conducted via text-based messaging, firms should not overlook risks hidden within voice chats and audio conversations
- Regulators require that firms capture and retain communications relating to “business as such,” including voice channels
- Effective voice oversight is essential to monitor a range of financial and non-financial misconduct
Text and electronic messaging may have become the default for business communications, but voice communications are still essential, especially in financial services where decisions need to take place in real-time on the trading floor.
Traditionally, voice communications posed unique challenges for compliance and monitoring teams. But with regulators requiring firms to capture all business-related communications, and firms increasingly expected to monitor for signs of both financial and non-financial misconduct, getting voice compliance right is a business imperative.
What compliance challenges did voice channels present?
Digital communication platforms are now ubiquitous in the financial industry. While channels like WhatsApp, Teams, and Slack are primarily used for their instant messaging (IM) features, they also have built-in voice chat capabilities. Previously, these channels have often been cited in enforcement actions for off-channel communication violations, although these primarily focused on text-based exchanges.
On Microsoft Teams, users can initiate a one-to-one or group call with contacts. Similarly, WhatsApp allows users to utilize voice chat in real-time or leave recorded voice notes. LinkedIn allows users to record voice messages. And of course, “traditional” mobile devices or voice-over-internet-protocol (VOIP) devices and services like Zoom or Cisco are specifically designed for voice communication.
Voice capture hasn’t always been as straightforward as digital capture, which previously posed challenges for compliance teams, including:
- Scale: The sheer number of voice conversations and size of voice files made capturing and storing them expensive and logistically challenging.
- Transcription: Automated transcription was of variable quality, meaning that firms would need to spend resources “cleaning up” call records.
- Translation: Calls occurring across global offices required either compliance review by native speakers or costly outsourced translation services.
- Random sampling: Manually monitoring every call in its entirety was unfeasible, meaning firms relied on reviewing randomly selected recordings and could have overlooked signs of risk.
- Quality and content: Poor call recording quality or substantial background noise could make it difficult to transcribe calls, and the use of slang terms or jargon could obfuscate misconduct from reviewers.
Advances in voice capture and monitoring technology have made many of these challenges a thing of the past, but as technology evolves, so do the risks. AI platforms allow bad actors to create “deepfakes” and mimic voices to mislead clients. Additionally, employees are using AI-enabled note takers to summarize calls and meetings, which compliance teams will need to bring within the scope of their communications data capture.
What are the regulatory requirements for voice capture?
Recordkeeping expectations in the U.S.
U.S. regulators’ approach to communications compliance has shifted. Where financial regulators like the Commodity Futures Trading Commission (CFTC) have previously issued a series of enforcements for off-channel communications, they are currently more focused on minimizing financial crime and encouraging firms to engage in proactive self-reporting and collaboration.
While enforcement focus on off-channel communications has lowered, regulations themselves still require that firms capture and retain voice data. For example, the Financial Industry Regulatory Authority’s Books and Records guidelines state that firms are required to retain “communications relating to their ‘business as such.’”
In its Rules and Guidance on social media, FINRA clarified that the “business as such” requirement is not based on the type of device that is used to communicate, but on the content of communications that relate to any aspect of a firm’s business. Channels like WhatsApp and SMS are not explicitly named in FINRA’s definitions either but have become regularly referenced within recordkeeping failure enforcements.
CFTC regulations have outlined expectations for maintaining audio records, such as the Dodd-Frank Act, which promotes transparency and accountability in the financial system. This Act targets the swaps market due to the number of transactions that happen over voice channels, and outlines requirements for audio recordings:
“Although the CFTC requires registrants to make and keep records of all oral communications pertaining to pre-execution trade information, including telephone calls, the Commission’s record retention rule applies only to recordings of telephone calls, i.e., those voluntarily made by the registrant.”
CFTC Rule 1.31 and 1.35 require firms to record oral communications that lead to a commodity interest transaction, “including oral communications conveying quotes, solicitations, bids, offers, instructions, trading and prices communicated by telephone, voicemail, mobile device or other digital or electronic media.”
Recordkeeping expectations in the U.K. and EU
Compliance teams at EU-based firms have a commitment to capture voice communications. The EU’s MiFID II Rule details the breadth of communications that firms are expected to capture, including electronic, telephone, and mobile communications. The rule requires investment firms to “tape calls that have the intention of leading to a transaction.” Upon recording these conversations, firms are required to store them for a period of five years.
The U.K. has implemented MiFID II requirements into national law, meaning that the country operates under nearly parallel requirements. Like EU-regulated firms, firms in the U.K. are expected to record all telephone conversations and retain a copy of electronic conversations that relate to an order, including those intended to result in transactions.
As an extension of MiFID II, the U.K. also established a voice retention requirement under its Senior Management Arrangements, Systems and Controls (SYSC). Under SYSC 10A, firms are required to capture telephone conversations and electronic communications that pertain to financial instruments.
Don’t miss the call
Recordkeeping enforcements may have scaled back, but firms shouldn’t take this to mean expectations have lowered. Regulators still expect firms to maintain high levels of data completeness in their records and proactively identify and mitigate all kinds of misconduct.
Voice channels may have been difficult to capture and monitor in the past, but voice retention and monitoring technology are advancing fast. New tools are giving firms the ability to accurately transcribe audio recordings in their entirety. With full oversight of voice conversations that are happening across the business, including every channel and location, firms can build a more complete picture of their communications data and ensure they don’t miss the call when it comes to communications compliance.
When it comes to communications recordkeeping, regulators are serious about complete compliance, whether it’s happening over IM, text, social media, or voice channels. Capture all your business interactions with a single solution vendor that can retain all your data in a structured, easy-to-access archive.