Written by a human

Recordkeeping Compliance in Financial Services

Global Relay Compliant business communications archiving, messaging, supervision, and eDiscovery
11 mins read 17 August 2026

In brief:

  • What it is: firms’ obligation to capture, retain, and produce their business records, including electronic communications, in a complete, accurate, and tamperproof archive
  • Why it matters: improper recordkeeping and off-channel communications use have resulted in over 100 enforcement actions and more than $3 billion in combined SEC and CFTC penalties since 2021.
  • The core rules: SEC Rules 17a-3 and 17a-4, Advisers Act Rule 204-2, FINRA Rules 4511 and 3110, and MiFID II in the EU/UK.
  • The hard part: capturing every channel, which includes: email, chat, mobile, voice, collaboration tools, completely and immutably.
  • Who’s affected: broker-dealers, investment advisers, banks, and other regulated firms.

What it is · Why it matters · The rules · What records and for how long · Off-channel communications · Which channels to capture · What a defensible system looks like · Recordkeeping, surveillance & eDiscovery · How to approach it · FAQ

Recordkeeping compliance is regulated firms’ obligation to create, capture, retain, and produce their business records in a form that is complete, accurate, readily accessible, and tamperproof. In financial services, it is one of the foundational compliance requirements. Regulators cannot supervise a market, investigate misconduct, or protect investors if the underlying records do not exist or cannot be trusted.

In practice, recordkeeping compliance consists of two main elements. The first is capturing communications and transactions as they happen and across every channel employees use to conduct business. The second is securely storing those records for defined retention periods, with an audit trail that proves they have not been altered, and the ability to retrieve them rapidly when a regulator inquiry arises. A firm that captures communications but cannot prove their integrity, or that stores records it cannot produce on demand, has not met the standard.

Why does recordkeeping compliance matter?

Complete and accurate books and records are one of the securities industry’s fundamental pillars, and the main reason is because they uphold investor protection. Regulators rely on firms’ records to reconstruct events, test for misconduct, and hold firms accountable. When records are missing, the regulator does not have a complete picture, which is why recordkeeping failures are treated as serious violations in their own right, even where there is no underlying misconduct.

The financial consequences have been striking. Since late 2021, regulators have made the failure to capture off-channel communications one of the most heavily penalized compliance failures. Across the sweep, the SEC and CFTC have charged more than 100 firms and imposed over $3 billion in combined penalties, beginning with a $125 million SEC fine against JPMorgan in December 2021. Regulators emphasized that recordkeeping and supervision requirements are fundamental, and firms that fail to meet them do so at their own peril.

Which rules govern recordkeeping?

Recordkeeping is governed by a web of rules that vary by firm type and jurisdiction. The most important for financial services firms are:

SEC Rules 17a-3 and 17a-4 (US broker-dealers). Rule 17a-3 sets out the records a broker-dealer must make, while Rule 17a-4 sets out how long they must be preserved and in what form. For a full breakdown, see our guide to SEC Rules 17a-4 and 17a-3.

Advisers Act Rule 204-2 (US investment advisers). The recordkeeping rule for registered investment advisers, with a narrower but substantial set of communications retention requirements, including recommendations and advice.

CFTC requirements. Recordkeeping and supervision obligations for swap dealers and other registrants, enforced in parallel with the SEC across the off-channel sweep.

What records must firms keep, and for how long?

The precise categories and retention periods depend on the applicable rule, but the underlying expectations are consistent. Firms must retain business communications and transaction records — whether that be emails, instant messages, texts, voice, social media, or collaboration tool messages — along with trade, account, and financial records outlined in the relevant rule.

Retention periods are measured in years. Under SEC Rule 17a-4, for example, many records must be preserved for a defined number of years in an easily accessible place. Records must remain complete, accessible, and reproducible for the full retention term.

The SEC’s Rule 17a-4 underwent a significant change in October 2022 for the first time in around 25 years. The amendments moved away from mandating a strict write-once, read-many (WORM) storage format and introduced an audit-trail alternative. Firms may instead use systems that preserve a complete, time-stamped record of every change, so an original can be recreated even if it was later modified or deleted. The amendments also revised the third-party access requirements. For a fuller explanation, see our analysis of the Rule 17a-4 amendments and how to prepare.

What is off-channel communication, and why is it the biggest risk?

Off-channel communication is any business communication that takes place on a channel the firm does not capture and retain. Most commonly, they happen on personal devices and unapproved messaging apps, such as WhatsApp, iMessage, Signal, and WeChat. It is the single largest source of recordkeeping enforcement risk, because a firm cannot preserve what it never captured, and cannot supervise what it cannot see.

The regulatory sweep that began in 2021 turned this from a gap into a multi-billion-dollar liability. Regulators fined various firms after uncovering that personnel, including senior managers, conduct business on unapproved channels, depriving regulators of records they needed for investigations. Firms that self-reported and remediated generally received significantly reduced penalties, a pattern regulators have actively encouraged.

Which communication channels need to be captured?

The governing test is not the channel, but whether the communication occurring on that channel relates to business. If it does, it must be captured. In practice that means firms must be able to capture and retain across:

  • Email — still core and a source of enforcement where capture is incomplete.
  • Instant messaging and chat — including enterprise platforms and consumer apps used for business.
  • Mobile and SMS — including text on personal devices under BYOD arrangements.
  • Voice and video — calls and meetings, where MiFID II and other rules require recording.
  • Social media — corporate and, where relevant, individual business use.
  • Collaboration tools — Slack, Microsoft Teams, and similar platforms whose messages can slip past legacy archiving.
  • Messaging apps — WhatsApp, iMessage, Signal, WeChat, and other channels at the center of off-channel enforcement.
  • Generative AI — an emerging channel that regulators, including via the DOJ’s updated compliance-program guidance, expect firms to account for.

What does a defensible recordkeeping system look like?

Regulators do not prescribe a single technology, but they consistently expect the same qualities. A defensible recordkeeping system:

  • Captures at source. Data is captured directly from each channel, so there aren’t gaps between what employees send and what the firm retains.
  • Preserves integrity. Records are stored in a WORM-compliant or audit-trail-based format that proves they have not been altered, with continuous integrity checks.
  • Maintains chain of custody. Every action on a record is logged in an unalterable audit trail, from capture to disposition.
  • Applies retention and disposition policies. Records are kept for the required period and disposed of consistently afterward.
  • Enables prompt retrieval. Records are indexed and searchable so the firm can produce complete, reconstructed conversations quickly when a regulator or court asks.
  • Supports supervision. The same records feed the review and surveillance programs required by rules such as FINRA 3110.

How does recordkeeping connect to surveillance and eDiscovery?

Recordkeeping is the foundation the rest of the compliance stack is built on. A complete, trustworthy archive is what makes everything else possible. Firms can’t supervise communications they did not capture, run a defensible investigation, or produce records in litigation from an incomplete data set.

This relationship sits at the heart of digital communications governance, which brings recordkeeping together with communications surveillance, investigations, and wider conduct oversight.

How should firms approach recordkeeping compliance?

A practical way to structure a recordkeeping program:

  • Map every channel employees use for business, both approved and unapproved, and identify where capture gaps exist.
  • Close the gaps at source, enabling compliant capture for each channel rather than relying on manual exports or policy alone.
  • Set clear communications policies defining approved channels and prohibiting business use of uncaptured ones — and enforce them.
  • Store records defensibly in a WORM-compliant or audit-trail format with chain of custody and continuous integrity checks.
  • Apply retention and legal-hold policies aligned to each applicable rule and jurisdiction.
  • Make records retrievable, so complete conversations can be reconstructed and produced promptly.
  • Supervise and review the captured communications as required, and document that you do.

Frequently asked questions

What is recordkeeping compliance in financial services?

It is firms’ obligation to create, capture, retain, and produce their business records in a complete, accurate, accessible, and tamperproof form, so regulators can supervise the firm and protect investors.

What is SEC Rule 17a-4?

Rule 17a-4 sets out how long US broker-dealers must preserve their records and in what form. Since the October 2022 amendments, firms can use either a WORM format or a compliant audit-trail system that lets an original record be recreated even if later altered.

What are off-channel communications?

Business communications that take place on channels the firm does not capture, typically personal devices and unapproved apps such as WhatsApp, iMessage, or Signal. They are the leading source of recordkeeping enforcement risk because they cannot be preserved or supervised.

How long do firms have to keep records?

It depends on the rule, but retention is generally measured in years, with the most recent records kept in an easily accessible place. The key requirement is that records stay complete, accessible, and reproducible for the full retention term.

Which communication channels have to be captured?

Any channel used for business, including email, chat, mobile and SMS, voice, social media, and collaboration tools such as Slack and Teams. The test is whether the communication relates to the firm’s business, not which app it used.

Is WORM storage still required?

Not exclusively. Since the 2022 SEC amendments, WORM is one acceptable approach, though firms can also use an audit-trail-based system that preserves a complete record of changes.

What happens if a firm fails to keep proper records?

Recordkeeping failures are enforceable violations in their own right. Since 2021, regulators have imposed more than $3 billion in combined penalties across 100-plus firms, alongside censures and remediation requirements.

How Global Relay helps

Recordkeeping compliance comes down to capturing everything, proving its integrity, and producing it on demand. Global Relay Archive captures and normalizes communications from 100+ channels into a single, WORM-compliant, tamper-evident system of record with full chain of custody — and compliant communications capture closes the channel gaps that lead to off-channel violations. Explore Global Relay’s recordkeeping compliance solution.

Related reading:

Global Relay Compliant business communications archiving, messaging, supervision, and eDiscovery
11 mins read 17 August 2026