Written by a human

Sheridan's Signals — SIFMA's Suggested Recordkeeping Rulebook Modernizations 

SIFMA has shared recommendations on how the SEC could modernize its recordkeeping requirements to reduce the compliance burden on firms and provide increased clarity.

Ryan Sheridan Senior Manager, Regulatory Intelligence
6 mins read 21 September 2026

If there were a prediction market for potential changes to Securities and Exchange Commission (SEC) rulemaking, what would the odds look like?

With Chairman Paul Atkins expressing an interest in modernizing decades-old regulations, the Securities Industry and Financial Markets Association (SIFMA) has wasted little time in putting possible communications recordkeeping reform squarely on the agenda.

SIFMA has since strengthened its case with data submitted to the SEC in May 2026. Drawing on informal surveys of broker-dealers, dual registrants, and investment advisers, SIFMA reported substantial volumes of communications being retained, including as many as 28 million communications on a typical weekday at some large firms.

Firms also reported annual communications-storage costs, ranging from tens of thousands of dollars to tens of millions of dollars. SIFMA argues that these figures demonstrate how the current framework encourages defensive over-retention and diverts resources toward storing and processing communications that may have limited regulatory value. 

Not every recommendation is likely to make it into the final rulebook, but some seem to align closely with the SEC’s broader push to reduce unnecessary compliance burdens and modernize regulation while preserving investor protection.

But which of SIFMA’s recommendations are most likely to make it into a final set of modernized rules — and might stay at the ideas phase?

Clarifying what counts as “business communication”

The SEC’s current recordkeeping rules were written for an era where business communication was dominated by email. In 2022, the SEC made significant amendments to its broker-dealer electronic recordkeeping requirements, updating a framework in which foundational electronic-storage provisions dated back to 1997.

SIFMA recommends that the SEC revise its communications capture rules by adjusting the retention obligation to focus on client-facing business communications related to investment, securities advice, and transactions to align with the original intent of the rules.

Narrowing retention requirements to client-facing communications related to securities activity feels like the most natural modernization. It simplifies compliance without undermining the underlying investor protection objective.

However, this leaves firms in something of a gray area where firms will have to decide what could be deemed to be “substantive,” and even with a narrower focus, will still be required to keep a considerable volume of communications records. Many may feel that it is “better to have it and not need it, than need it and not have it,” and continue with current recordkeeping practices to ensure they are covered.

Streamlined retention periods

Maintaining different record retention periods for broker-dealers and investment advisers has become increasingly difficult for dual registrants operating on integrated technology platforms.

Harmonizing to a single three-year standard for all organizations is a relatively low-friction change that reduces operational complexity without fundamentally changing supervisory expectations.

Providing safe harbor for firms with reasonable policies and procedures

This proposal may have broad industry appeal because it shifts the conversation from perfect compliance to demonstrably effective compliance programs.

The challenge with this proposal is defining what “reasonable” means in practice. While communications compliance controls aren’t infallible, firms must take steps to clarify expectations, perform audits, and educate personnel. If adopted, expect the SEC to pair any safe harbor with heightened expectations around governance, surveillance, training, and testing.

Key to being able to demonstrate effectiveness will be firms’ ability to evidence that they have a full written set of policies and procedures alongside a complete record of essential data. After all, having a document declaring you are surveilling communications for signs of misconduct is one thing, but being unable to substantiate this with the data may result in a rocky reception.

Broad categorical exclusions that provide no investor protection

Excluding ministerial messages, unsolicited inbound communications, emojis, AI-generated meeting transcripts, and collaboration artifacts may seem straightforward, but drawing clear boundaries is more challenging than it first appears.

An emoji that seems innocuous today could become significant evidence in an enforcement action when viewed in its full context. For example, a thumbs up emoji could be interpreted as acknowledgement of a message on one hand, or as confirmation to enter into a contractual agreement on the other.

Advances in technology have made it increasingly feasible to capture, retain, and analyze these types of content, making it difficult to ignore their potential relevance.

One alternative would be for the SEC to favor principles-based guidance over broad categorical exemptions, allowing firms to evaluate communications based on their substance and regulatory risk rather than their format alone.

The Wild Card: AI

The recommendation to exclude AI-generated meeting transcripts is particularly interesting because it highlights a broader question: what constitutes official business records in an AI-assisted workplace?

The Financial Industry Regulatory Authority (FINRA) flagged that firms have begun piloting generative AI tools for various content generation and data enhancement use cases. At what point do AI-generated outputs become something that firms have to capture?

As organizations increasingly rely on AI to summarize meetings, draft communications, and capture action items, regulators will need to distinguish between source communications, AI-generated artifacts, and official records.

Final Predictions

If the SEC takes up these recommendations, the more plausible path would be targeted amendments rather than wholesale adoption of SIFMA’s package. The strongest options for consideration appear to be clearer definitions of covered communications and greater harmonization of retention periods. More sweeping categorical exclusions, particularly around AI-generated records, raise harder questions about scope and supervisory responsibility.

That would reflect a broader shift from regulating every communication channel to regulating the communications that meaningfully impact investors and markets — but would put the pressure on organizations to make the judgement call around what should be preserved to meet the new definition, and whether they may be better off continuing with current practices to “belt and brace” their compliance.

Whether changes to the SEC’s recordkeeping rules mean narrowing the retention obligations or streamlining “business as such” requirements, communications capture remains a constant pillar of compliance. Firms that implement compliance technologies that capture all modern channels through which business communications occur will be ahead of the game, and in the best position to identify and address risk as the industry evolves.

If prediction markets existed for SEC rulemaking, my bet would be that simplification wins – but only with the right guardrails.

Ryan Sheridan Senior Manager, Regulatory Intelligence
6 mins read 21 September 2026