While the headline-grabbing enforcement actions by the United States Securities and Exchange Commission (SEC) concerning off-channel communications have recently seen a decrease in frequency, the scrutiny on recordkeeping and supervision remains a persistent and critical area of focus for firms regulated by the Financial Industry Regulatory Authority (FINRA). FINRA’s ongoing examinations continue to highlight persistent weaknesses in how financial firms retain electronic communications, detect business activities conducted through unapproved platforms, and execute effective supervisory reviews. These are not new regulatory demands; rather, their continued prominence in FINRA examinations underscores the ongoing challenge firms face in translating established obligations into robust, demonstrable, and consistently applied controls.
A Shifting Enforcement Landscape: From SEC Headlines to FINRA Examinations
Under the leadership of SEC Chair Gary Gensler, the agency’s enforcement division made significant waves in the financial industry, particularly concerning book-and-record violations related to the failure to maintain and preserve off-channel communications. Between fiscal year 2022 and the period leading up to the shift in leadership, the SEC initiated 95 enforcement actions, resulting in approximately $2.3 billion in total penalties. These high-profile actions brought unprecedented public attention to the communications recordkeeping and supervision practices of financial firms, compelling many to re-evaluate and bolster their compliance frameworks.
However, following the appointment of SEC Chair Paul Atkins, a discernible shift in enforcement priorities has occurred. The pace of broad, firm-level SEC enforcement actions concerning recordkeeping has subsequently declined. The agency has strategically pivoted its focus towards individual accountability, addressing cross-border misconduct, and enhancing investor protection. This recalibration signifies a move away from the widespread, systemic penalties that characterized the preceding era, towards a more targeted approach.
Despite this evolution in SEC enforcement visibility, FINRA’s robust examination program has maintained its unwavering commitment to assessing how its member firms retain and supervise business communications. Much of this critical oversight occurs away from the public spotlight, within the routine examination process. These examinations typically result in remediation requirements or supervisory actions rather than public disciplinary proceedings, yet their cumulative impact on firm compliance remains substantial. FINRA’s consistent examination focus ensures that while the nature of regulatory headlines may change, the fundamental obligation for firms to maintain compliant communication practices endures.
FINRA’s Persistent Examination Priorities: Unpacking the Findings
A clear barometer of FINRA’s ongoing regulatory priorities can be found in its Annual Regulatory Oversight Report. The most recent reports consistently identify recurring deficiencies in firms’ communications practices. These findings paint a consistent picture of systemic challenges that transcend individual firms and represent a broader industry concern. Key areas of persistent weakness include:
- Inadequate Retention of Electronic Communications: Firms continue to struggle with ensuring that all business-related electronic communications are captured and retained in accordance with regulatory requirements. This includes not only emails but also messages from instant messaging platforms, collaboration tools, and other electronic communication channels.
- Detection of Unapproved Communication Channels: A significant challenge lies in identifying and preventing business-related communications that occur on unapproved or "off-channel" platforms. Employees may resort to personal messaging apps or other informal channels for business discussions, creating blind spots for compliance departments and increasing the risk of regulatory breaches.
- Effectiveness of Supervisory Reviews: Even when communications are captured, the effectiveness of the supervisory reviews designed to monitor these communications is frequently found wanting. This can stem from a lack of adequate training for supervisors, insufficient tools to identify suspicious activity, or a failure to escalate and act upon red flags identified during reviews.
These findings collectively point to significant gaps within the broader communications control environment. It is not uncommon for firms to have well-documented policies and sophisticated technological systems in place, yet still fail to achieve complete coverage across all communication channels or provide sufficient demonstrable evidence that their controls are operating effectively and as intended. This disconnect between policy and practice represents a critical vulnerability.
The complexity of this challenge is further amplified by the ever-expanding array of communication channels that employees utilize for business purposes. As technology evolves and collaboration tools proliferate, firms are faced with a dynamic and increasingly fragmented communication landscape, making comprehensive oversight a moving target.
The Growing Chasm: Legacy Systems Confront Modern Communication
The modern business environment is characterized by a fluid and multi-platform approach to communication. A single business conversation can easily span multiple channels, creating intricate data trails that are challenging to track and manage. For instance, a discussion might commence on a platform like Slack, transition to email exchanges, and culminate in a virtual meeting conducted via Microsoft Teams, where sensitive documents are shared. When these communications pertain to firm business, every component – the initial Slack messages, the email correspondence, the meeting content, and the shared documents – becomes subject to the firm’s stringent recordkeeping and supervisory obligations.
The limitations of legacy communication surveillance systems, originally designed to monitor more traditional channels such as corporate email, become starkly apparent in this new paradigm. These older systems often lack the capacity to effectively monitor, capture, and retain the full context of communications occurring on the diverse range of modern messaging and collaboration platforms. As business communications have increasingly migrated beyond these traditional conduits, many firms have developed significant gaps in their ability to maintain a holistic and compliant view of employee interactions. Addressing these gaps is not merely a matter of technological upgrade; it is a critical imperative as FINRA continues its rigorous scrutiny of firms’ recordkeeping and communications supervision practices. The inability to adequately capture and monitor these evolving communication methods directly impedes a firm’s ability to demonstrate compliance.
From Policy Frameworks to Verifiable Proof: Demonstrating Control Effectiveness
For compliance leaders, the core question has shifted from simply possessing a communications policy to being able to definitively prove that the firm’s policies, systems, and supervisory processes are not only in place but also function cohesively and effectively. This requires a proactive and demonstrable approach to compliance. Key elements that are crucial for demonstrating effective controls include:
- Comprehensive Communication Channel Coverage: Firms must ensure that their capture and surveillance systems encompass all approved communication channels used by employees for business purposes. This necessitates a thorough and ongoing inventory of the platforms and tools employees are utilizing.
- Effective Content Monitoring and Analysis: Beyond mere capture, firms need robust capabilities to monitor the content of communications for potential violations, such as insider trading, market manipulation, or other misconduct. This involves sophisticated analytics and keyword monitoring to identify suspicious patterns and keywords.
- Timely and Accurate Record Retention: The ability to retain all relevant business communications for the statutorily required periods is paramount. This includes ensuring data integrity, preventing data loss, and maintaining an auditable trail of all captured records.
- Robust Supervisory Procedures and Training: Supervisory processes must be clearly defined, consistently applied, and regularly reviewed for effectiveness. Supervisors need to be adequately trained to identify red flags, conduct thorough investigations, and take appropriate remedial actions. The training must extend to understanding the nuances of modern communication platforms and the potential risks associated with them.
- Demonstrable Linkages to Wider Compliance Programs: Communications data should not be viewed in isolation. Firms must demonstrate how communications records integrate with other areas of compliance oversight. For example, a specific message might be a crucial piece of evidence in a broader review involving employee trading activity, the disclosure of outside business activities, a review of public disclosures, or an ongoing internal investigation.
A deficiency in any single element of this interconnected process can significantly undermine the overall effectiveness of the firm’s broader supervisory program. The interconnectedness of these elements highlights that a siloed approach to compliance is no longer tenable.
An Enduring Supervisory Challenge for the Financial Industry
While the volume of high-profile SEC enforcement actions related to communications compliance may have subsided from its peak, the issue remains a highly active and critical area of FINRA examination scrutiny. The regulatory requirements themselves are well-established and have been in place for a considerable period. The persistent challenge for financial firms lies in ensuring that their internal controls and surveillance mechanisms evolve in tandem with the rapidly expanding landscape of communication channels.
Firms must not only keep pace with new technologies and communication methods but also proactively develop sophisticated strategies to detect business conducted outside of approved platforms. This requires a continuous commitment to adapting to new ways of communicating while simultaneously demonstrating effective oversight across the entire employee communications lifecycle. Ultimately, the goal is to ensure that communications controls operate not as standalone functions, but as an integral and cohesive component of the firm’s overarching compliance framework. The ongoing diligence required in this area underscores its fundamental importance to maintaining regulatory integrity and safeguarding investor interests in the modern financial ecosystem.
ABOUT THE AUTHOR:
Sean Sullivan is VP of Product, eComms, at MCO (MyComplianceOffice).
Photo credit: Ajay Suresh/Wikimedia Commons








