What Off-Channel Communications Are and Why the Term Outlived the Sweep

George
By George
6 October 2026
Off channel communications bypassing compliant archive

Off-channel communications are business-related messages sent or received on a tool the firm has not authorized for business use, which is the definition FINRA uses in its 2026 report. The phrase describes the gap between where a firm's archive is pointed and where its people actually talk: a client's text to an advisor's personal phone, a WhatsApp thread with a custodian contact, a LinkedIn direct message about an account, or a chat inside a video meeting that nobody configured for retention.

The concept survives the end of the SEC initiative because it was never an enforcement theory, it was a description of a recordkeeping failure. If a message that the rules require the firm to keep exists only on a device the firm cannot search, the record does not exist for regulatory purposes, and the supervisor who was supposed to review it never saw it. That failure is the same in a quiet enforcement year as in a loud one.

What the Sweep Did and Did Not Change

The initiative began with a $125 million penalty against a single broker-dealer in December 2021, expanded to sixteen firms and more than $1.1 billion in September 2022, and continued in waves of settlements through 2023 and 2024 before the January 2025 group. The orders followed a pattern: firms had written policies prohibiting unapproved channels, provided training, and collected attestations, and their people used personal devices for business anyway, at every level including senior management. Every order found two violations together, failure to preserve the communications and failure to reasonably supervise.

Industry groups have asked the SEC to narrow and harmonize the rules, and SIFMA petitioned for exactly that in October 2025, but no amendment had been adopted at the time of writing. The practical position in 2026 is that the obligations are unchanged, the federal enforcement appetite has cooled, and the records a firm failed to keep in 2024 and 2025 are still missing when the next examination asks for them.

FINRA Picked Up Where the SEC Left Off

For broker-dealers and the hybrid firms that combine an RIA with a brokerage affiliate, FINRA's cycle examination was always the more likely encounter, and FINRA did not pause. In June 2025 it censured and fined a clearing firm $1.3 million for a set of failures that included more than 10,000 unretained business messages on an unapproved chat app, sent by senior staff after compliance had told them to stop.

On January 30, 2026 it censured and fined a St. Louis broker-dealer $750,000 because representatives, including a senior executive, had sent at least 3,560 business texts through unapproved apps on personal phones, at a firm whose written procedures prohibited exactly that. The second case is the argument of this article in a single enforcement action: the policy existed, the monitoring did not, and the messages were never captured.

The 2026 Annual Regulatory Oversight Report, published December 9, 2025, treats the issue as an ordinary examination finding rather than a headline. Its books and records section lists failures to retain non-email electronic communications, inadequate review sampling, and untested third-party archiving vendors among the deficiencies examiners found. Its effective practices include watching for a drop in activity on approved channels as a sign that conversations moved elsewhere, refreshing surveillance keywords often, and simulating a regulator's records request to confirm the vendor can actually produce what it stores. Our guide to FINRA cybersecurity compliance covers the rest of that report's technology expectations, including the amended Regulation S-P, whose compliance date for smaller entities passed on June 3, 2026.

What the Recordkeeping Rules Actually Require

The obligations differ by registration type, and a hybrid firm carries both sets. An SEC-registered investment adviser works under Advisers Act Rule 204-2(a)(7), which covers written communications relating to advice, funds and securities, orders, and performance, kept for at least five years from the end of the fiscal year of the last entry, with the first two years in an appropriate office of the adviser.

A broker-dealer works under Exchange Act Rule 17a-4(b)(4), which covers all communications relating to its business as such, kept for at least three years with the first two in an easily accessible place. A FINRA member firm layers Rules 4511 and 3110 on top of those, which means a six-year default for records with no stated period, storage in a format that meets Rule 17a-4, and supervisory review of correspondence. The sections below explain what each of those sentences means in practice.

Financial communications recordkeeping retention timelines

Investment Advisers: Rule 204-2(a)(7)

The adviser rule is narrower than people assume and broader than they hope. It does not require an RIA to keep every message its employees send. It requires originals of written communications received and copies of written communications sent that relate to four subjects: recommendations made or advice given, receipt, disbursement, or delivery of funds or securities, the placing or execution of orders, and performance of managed accounts or recommendations. A text saying "let's move the rebalance to Monday" is squarely inside the rule. A text about where to meet for lunch is not.

The retention period is five years from the end of the fiscal year in which the last entry was made, with the first two years in an appropriate office of the adviser, and the rule permits electronic storage as long as the records are protected from alteration and can be produced promptly. The enforcement orders against standalone advisers, including the 2024 settlement that first confirmed advisers were within the sweep's scope, turned on exactly this language: messages about advice and orders, sent on personal devices, never captured.

Broker-Dealers: Rule 17a-4(b)(4) and FINRA Rules 4511 and 3110

The broker-dealer rule is wider. Rule 17a-4(b)(4) reaches all communications relating to the firm's business as such, which is why the largest penalties landed on broker-dealers and dually registered firms. Records must be kept at least three years, the first two in an easily accessible place, and since May 3, 2023 electronic records may be preserved either in a non-rewriteable, non-erasable format or under the audit-trail alternative that lets a firm reconstruct an original if it is changed or deleted.

FINRA Rule 4511 incorporates those SEC requirements and supplies a six-year default for records with no stated period, and Rule 3110 requires supervisory procedures that include review of correspondence. That combination is what makes a ban insufficient on its own: a channel the firm cannot see is a channel the firm cannot supervise, and the supervision failure is charged alongside the preservation failure.

State-Registered Advisers and Hybrid Firms

Advisers below the SEC registration threshold answer to the state. In California that is the Department of Financial Protection and Innovation, whose books and records requirements largely track the federal categories but carry their own citations and examination practices, and a firm should confirm the specifics with compliance counsel rather than assume the federal rule is the whole story. Hybrid firms face the harder version of the problem, because the same advisor's text message may be an adviser record under one rule and a broker-dealer record under another, with different retention clocks.

The Test Is the Content, Not the App

Neither the SEC nor FINRA wrote a separate rule for texting, WhatsApp, or chat. A message is a record because of what it says, and the application that carried it is irrelevant except for one practical fact: if the firm cannot capture messages from that application, every business message sent through it is a missing record. That is why compliant firms think in terms of capture rather than prohibition. WhatsApp is not forbidden; un-archived WhatsApp is.

Why "We Prohibit Texting" Is Not a Record

Nearly every firm charged in the sweep had a policy. Many had annual attestations, training decks, and disciplinary procedures, and the orders recite them before finding that the communications were not preserved anyway. The lesson regulators drew, and repeated in FINRA's effective practices, is that a written prohibition with no technical mechanism behind it does not satisfy the recordkeeping obligation, because the messages still happened and the records still do not exist.

There is a commercial reason the bans fail. Clients text. A client who sends "sell the Apple position before earnings" to an advisor's personal number has created a record the moment the advisor reads it, and an advisor who replies "call me" has created another. Telling clients to use email instead works with some and fails with the rest, and the firm's compliance posture cannot depend on the behavior of people it does not employ.

Personal texting bypasses official compliance archive

The Three Realistic Postures

A small firm chooses among three postures, and the choice should be written into the firm's compliance and risk management program rather than left to habit. The first is prohibit and enforce: business texting is banned, firm-managed devices block the prohibited apps, personal devices are kept out of client work by policy and by mobile device management, and the firm accepts that some clients will be redirected. The second is permit and capture: the firm provides an approved texting channel, archives it, and supervises it like email. The third, which most firms end up with, is hybrid: approved channels are captured, everything else is blocked where technically possible and prohibited where not, and the firm monitors for signs that conversations have drifted.

What does not work is the fourth posture, prohibit without enforcement, which is the one the orders describe. A policy is the starting point of a control, not the control itself.

How a Small Advisory Firm Captures Texts and Chat Without an Enterprise Budget

The large firms charged in the sweep had compliance technology budgets that a twelve-person RIA will never have, which is sometimes offered as a reason small firms cannot comply. The opposite is closer to the truth. A small firm has fewer channels, fewer devices, and fewer people, and the tools that capture mobile and chat communications are sold per user at prices a small firm can absorb. The work is in choosing the posture and configuring the pieces to match it.

Start With a Channel Inventory

Before buying anything, list every channel through which business communication actually happens, approved or not. For most firms the list includes firm email, Microsoft Teams or Slack, the firm phone system, mobile text messages and iMessage, WhatsApp or Signal with certain clients, LinkedIn and social media direct messages, chat inside video meetings, messaging built into the client portal or planning software, and, newly, AI assistants and notetakers that generate summaries of client calls. Against each one, record whether it is captured today, by what system, and who reviews it.

The inventory usually surfaces a surprise or two, most often a video platform's chat and the messaging feature inside a client portal, both of which generate records nobody has ever looked at. It also surfaces the texting question directly, because the honest entry for mobile SMS at most small firms is "not captured."

Compliant business texting and channel inventory

Give People a Compliant Way to Text

The cleanest answer to mobile messaging is to give advisors a firm number that can be archived. A cloud-based business phone system with business texting routes SMS through a platform that retains and exports messages, so an advisor can text a client from a number the firm controls and the archive captures both sides. On personal phones, a mobile archiving app installed through mobile device management captures SMS and supported messaging apps from a managed work profile, which keeps the firm out of the employee's personal messages while retaining the business ones.

Whichever route the firm chooses, the client-facing number must be the captured one. A firm that issues archived numbers and then lets clients keep texting personal cell phones has built a compliant channel nobody uses, which is the hybrid posture failing in the field rather than on paper.

Capture Microsoft 365 Properly

Most small advisory firms run on Microsoft 365, and the platform can hold the records the rules require if it is configured to. Email is the easy part: journaling or an archive connector sends a copy of every message to a compliance archive that cannot be edited. Teams chat is where firms slip, because chat messages are not retained for recordkeeping purposes unless a retention policy is applied to them, and the default is that a user can delete a message and it is gone. Retention policies that cover Teams chats and channel messages, along with Exchange, SharePoint, and OneDrive, are included with Business Premium and the enterprise plans and should be set to at least the longest period the firm's data retention policy requires.

Firms that need the records held in a regulator-compliant format typically add a third-party archiving service that ingests Microsoft 365 content along with mobile messages and social media, stores everything in a compliant format, and provides the supervision workflow. The tenant's own retention settings remain the safety net underneath that service, which is why both should be configured and documented together.

The archive is distinct from preservation for litigation, and the licensing is different as well. The legal hold features that stop deletion during a dispute depend on mailbox plan level in a way that surprises firms on the business tier, so a firm that assumes its archive doubles as a hold, or that its hold doubles as an archive, has usually got one of them wrong.

Put the Personal Device Under a Policy

Personal phones are where most off-channel records live, and they are the hardest place to reach. A firm that permits personal devices for any business use needs three things: a written policy that defines which apps may be used for business, a mobile device management enrollment that installs the approved apps and the archiving agent in a managed profile, and an annual attestation by each user that business communications happened only in captured channels. The policy without the enrollment is the posture the orders criticized, and the attestation alone was present at nearly every firm that was fined.

The security case for device management overlaps almost entirely with the recordkeeping case, since the same enrollment that captures messages also enforces a passcode, encryption, and remote wipe. Firms weighing the tradeoffs can start with our guide to BYOD security risks, which covers the privacy boundaries that make a managed profile acceptable to staff.

Supervise What You Capture

Capture satisfies preservation; it does not satisfy supervision. A firm needs a written procedure for reviewing captured communications, whether by keyword lexicon, by random sampling, or both, and a record of each review. FINRA's 2026 report criticized reviews that sampled too little, used stale keywords, or skipped communications in languages the firm does business in, and it recommended revising surveillance terms regularly and tailoring them to the firm's actual business. For a small firm this is a monthly calendar task for the chief compliance officer, supported by the archive's review tools, and the evidence is the log of reviews completed.

Prove the Archive Works Before Anyone Asks

The final step is the one the report calls simulating a regulator's request: pick an advisor, pick a six-month window, and ask the archive to produce every text, chat, and email from that person in that window, including deleted items. If the export takes days, misses a channel, or returns messages that cannot be authenticated, the firm has learned something while it was still cheap to learn.

The same exercise confirms that the third-party vendor can meet the access and production obligations the rules place on it, which examiners have begun to test directly. Configuring the tenant for retention, journaling, and hold at the same time and then testing the result is ordinary work for a provider that delivers Microsoft 365 support in Los Angeles to regulated firms, and it should be done once and documented rather than revisited after every exam.

Historical communication retrieved from compliant archive

Where Small Firms Most Often Get Off-Channel Communications Wrong

The failures in small firms are predictable and mostly cheap to fix. The same seven show up in nearly every review:

  • A texting ban in the compliance manual with no device management or archiving behind it
  • Archived firm numbers that clients never adopted because the advisor's personal cell was already in their contacts
  • Teams chat with no retention policy, so messages vanish when deleted
  • Video meeting chat, client portal messaging, and AI meeting summaries left out of the channel inventory
  • Annual attestations treated as evidence of compliance rather than as a reminder of the policy
  • Supervisory reviews performed inconsistently, or not logged, so they cannot be shown to an examiner
  • An archiving vendor that has never been asked to produce a complete export on a deadline

None of these requires new law to become a finding. They are the same gaps the orders described, scaled down to a firm where one person wears the compliance hat part of the week.

What This Looks Like for an Advisory Firm in Los Angeles

The advisory market served by managed IT services in Los Angeles is full of firms that fit this profile: an RIA founded by a team that left a wirehouse, a hybrid firm with a small brokerage affiliate, a family office with registered staff, all running on Microsoft 365, all with advisors whose clients text them. Many built their compliance programs during the sweep, under enforcement pressure, and some have quietly let them lapse since the headlines stopped. FINRA's examiners and arbitration panels have not stopped asking.

GlobeVM works with financial firms on the technology half of this problem, the tenant configuration, the device management, the archiving integration, and the evidence that the controls actually run, while the firm's compliance counsel owns the policy half. The two have to fit together, which is why the conversation usually starts with the channel inventory and the firm's chosen posture rather than with a product.

The same controls carry more than recordkeeping. Our overview of IT and cybersecurity for financial firms describes how communications archiving, data security, and the amended Regulation S-P obligations end up sharing the same device management, identity, and monitoring foundation, which is the practical reason to build them as one program rather than three.

Build the Record Before Anyone Asks for It

The sweep ended, the rules did not, and the examiner who reviews a small firm's books in 2026 is looking for the same thing the SEC's orders described: records that exist, in every channel where business happened, reviewed by someone who can prove it. A firm that inventories its channels, picks a posture, gives its advisors a captured way to text, configures Microsoft 365 for retention, manages the personal devices it allows, and tests its archive has built that record for a fraction of what a single finding costs in remediation. If your firm's texting policy is still the only control standing between a client's message and a missing record, a short review of the channels you actually use is the right place to start, and GlobeVM can run it alongside your compliance counsel.

Frequently Asked Questions

A business-related message sent or received on a tool the firm has not authorized for business use, such as a text on a personal phone, a WhatsApp thread, a social media direct message, or a chat inside a video meeting that is not being retained. The test is the content of the message, not the app, so any channel carrying communications the recordkeeping rules cover is off-channel if the firm cannot capture it.
Yes, the SEC announced its last wave of settlements on January 13, 2025, and its current leadership has criticized the initiative and brought no comparable actions since. The underlying rules are unchanged, FINRA continued to sanction firms and individuals through 2025 and 2026, and the 2026 FINRA oversight report lists off-channel use among its examination findings.
Under Rule 204-2, communications relating to advice, funds and securities, orders, and performance must be kept at least five years from the end of the fiscal year of the last entry, with the first two years in an appropriate office of the adviser. Broker-dealers keep communications relating to their business for at least three years under Rule 17a-4, and FINRA Rule 4511 applies a six-year default where no period is specified.
No, and nearly every firm charged in the sweep had such a policy along with training and attestations. A prohibition counts only when it is enforced technically, through device management and blocked apps, or replaced by an approved texting channel that the firm captures and supervises.
They can if the firm captures and supervises those channels through a mobile archiving solution, because the rules regulate the record rather than the application. Un-archived use of any messaging app for business communication is the problem, and a firm that cannot capture a channel should block it and give advisors a captured alternative.

Comments

0 Comments