Two regulators decide how financial firms keep their business records: FINRA and the SEC. The rules are strict, the audits are real, and firms still pay heavy fines for getting records wrong. The good news is that most of these failures come from capturing, retaining, and supervising communications the right way, all of which are fixable problems. This guide will cover strategies and solutions you can implement to get on top of your FINRA and SEC compliance.
Here’s what you’ll learn:
- What the FINRA compliance requirements under SEC Rule 17a-4 actually involve
- Why WORM is no longer the only compliant storage method
- How much recent non-compliance has cost firms
- Why texts and messaging apps now carry more risk than email
- The features your archiving system needs to pass a FINRA exam
What Is FINRA Compliance?
The Financial Industry Regulatory Authority (FINRA) is a non-governmental body that regulates the U.S. securities industry. It oversees how broker-dealers conduct business with customers and how they keep their records, with the goal of protecting investors and keeping the securities market fair.
Every FINRA-member firm has to follow a defined set of rules.
They fall into four broad areas:
- Licensing — Firms and their representatives must be properly registered to operate in the securities market.
- Communications — Messages to the public must be accurate and not misleading.
- Recordkeeping — Firms must keep accurate records of transactions, client information, and communications.
- Enforcement — FINRA investigates market manipulation, insider trading, and other violations.
FINRA reports to the Securities and Exchange Commission (SEC). For recordkeeping and communications, no rule matters more than SEC Rule 17a-4.
What Is SEC Rule 17a-4?
SEC Rule 17a-4 sets the requirements broker-dealers follow to preserve their records. It works alongside Rule 17a-3: where 17a-3 says which records you have to create, 17a-4 governs how you store and maintain them.
The rule has four working parts:
- Recordkeeping — Firms archive records of business activities, transactions, and communications for audits and investigations.
- Retention periods — Different record types carry different minimum retention windows. Many core records must be kept for six years.
- Accessibility — Archived records must be retrievable quickly when the SEC or FINRA asks for them.
- Storage integrity — The system must protect records from alteration or deletion during their retention period.
One point deserves attention because it changed.
For years, firms had to store electronic records in a non-rewritable, non-erasable format called Write-Once-Read-Many (WORM). That was the only option, but it isn’t anymore.
WORM vs. the Audit-Trail Alternative
The SEC updated Rule 17a-4 back in 2022, and the change is easy to miss if you learned the rule earlier.
For years, firms had only one way to store electronic records, and that used to be the WORM format, which locks records so they can’t be rewritten or erased. The update kept WORM on the table and added a second option called the audit-trail alternative.
The audit-trail alternative works differently. Instead of locking the record, the system keeps a full log of any change and can rebuild the original if a record is later altered or deleted. Firms now choose whichever of the two methods fits their setup.
Here’s how the two compare:
| Method | How it works | Trade-off |
| WORM | Records are written to storage that can’t be altered or erased. | Simple to prove integrity, but historically needs dedicated immutable storage. |
| Audit-trail alternative | The system logs every change and can reconstruct the original record. | Lets firms use existing systems, but requires technology that can reliably recreate records and their audit trail. |
The audit-trail alternative was added so firms wouldn’t have to run a separate compliance-only system.
Both methods are valid, and the right choice depends on your existing infrastructure, your budget, and how quickly you need to respond to a regulator. Whichever you pick, the underlying obligation is the same: produce a true, complete record on demand.
A related detail matters for exam readiness.
Rule 17a-4 requires records from the first two years of retention to be producible on the same business day an examiner asks for them. That means your archive has to be searchable and accessible without waiting on a vendor export or a support ticket.
What the Rule Asks of Your Storage System
Retaining records is only half the obligation.
For the retention itself to count as compliant, the system holding those records has to meet a set of technical standards laid out in subsection (f)(2)(ii) of the rule. These requirements sit underneath whichever method a firm chooses, so they apply just as much to a WORM setup as they do to one built on the audit-trail alternative.
A compliant system needs to handle the following:
- Store records under either the WORM standard or the audit-trail alternative, so that a record can’t be quietly altered or erased during its retention window
- Protect message data integrity so that what goes into the archive is what comes back out
- Verify the quality and accuracy of the storing process on its own, without someone checking by hand
- Serialize records and apply a time-and-date stamp that holds for the full retention period
- Keep records indexed and easy to locate when an examiner asks
- Allow records to be deleted once their retention period runs out
- Download and transfer records, along with the audit trail where one applies, in a readable format
- Hold a redundant copy, either through a backup system or another form of duplication, in case the primary archive goes down
Taken together, these standards are what let the market keep the accurate books and records that FINRA expects under its Rule 4511 general requirements. Fall short on them, and the penalties follow.
What FINRA Non-Compliance Costs
Recordkeeping failures are expensive, and the numbers have climbed.
The SEC’s 2024 fiscal year set a record, with 583 enforcement actions and $8.2 billion in financial remedies, the highest total in the agency’s history.
That headline needs context, and firms should read it honestly.
Roughly 56% of that $8.2 billion traces back to a single crypto fraud judgment against Terraform Labs and its founder. Set that one case aside and the year looks less like a steady climb and more like one very large judgment sitting on top of an otherwise busy year.
Total remedies the prior year came to $4.9 billion, so the trend has been uneven rather than a clean upward line.
For a compliance officer, the top-line figure is a distraction. The real signal is the recordkeeping sweep, and it has kept producing penalties long after the headline cases faded:
- JPMorgan Chase — Fined $4 million after accidentally deleting roughly 47 million electronic messages it was required to keep.
- The off-channel sweep — Regulators charged more than 100 firms and collected more than $2 billion in penalties for failing to capture business messages sent on personal devices and messaging apps.
- A 26-firm action — In one coordinated sweep, 26 firms paid a combined total of more than $390 million, with several large firms paying $50 million each.
- A 12-firm action — Another group settled for $63 million combined, ranging from $4 million to $12 million per firm. One firm that self-reported paid $600,000.
The important part for 2026 is that this didn’t end with the big institutional cases.
Early this year, FINRA fined and censured a broker-dealer $750,000 for failing to supervise and retain business text messages, after finding at least 3,560 messages that were never captured, with the true number likely higher.
FINRA has also gone after individuals, fining and suspending brokers for messaging on personal devices and then deleting the evidence, and in one case barring a person from the industry entirely for off-channel use.
That last shift matters because while the earlier sweep mostly hit large institutions, FINRA is now holding individual brokers personally accountable. Personal devices can carry real liability for the individuals using them, not just their firms. In nearly every case, the cause was the same, and it boiled down to business messages that slipped through because no system was capturing them.
Email Is No Longer the Only Risk
For years, “FINRA compliance” was more or less another way of saying email archiving, but that understanding no longer matches where the real exposure lies.
The firms swept up in the off-channel cases were caught over texts, WhatsApp, Signal, iMessage, and personal email accounts, while their corporate inboxes had little to do with it, and there are two reasons this deserves a closer look.
The first is that prohibiting a channel isn’t the same as protecting yourself from it.
Many of the firms in the sweep had already banned the apps their employees turned out to be using, so what actually created the liability was the missing record rather than the absence of a rule against it.
FINRA Rule 4511 ties the obligation to the communication itself, which means that when someone reaches for an unapproved app and nothing gets captured, the firm is left with nothing to show an examiner, no matter what its policy said. FINRA rarely stops at the recordkeeping rules in these cases, since a failure under Rule 17a-4 and Rule 4511 is also treated as a violation of Rule 2010, its broad standard of commercial honor and just and equitable principles of trade.
The second is that the enforcement spotlight has moved even though the underlying risk hasn’t gone anywhere.
Under new leadership, the SEC has pulled back from technical recordkeeping cases and stayed quiet on off-channel actions for a while, but FINRA has gone in the other direction.
It continues to issue its own penalties, among them a $500,000 fine against Velox Clearing, whose senior leadership had routinely conducted client business over an unapproved messaging app while compliance warnings went unheeded. Recordkeeping also earned a spot on the priority list in its latest Annual Regulatory Oversight Report, which flagged electronic communications capture failures dozens of times.
The lesson for broker-dealers, and particularly for mid-market firms that always treated the SEC’s billion-dollar settlements as somebody else’s problem, is that a quieter SEC doesn’t add up to a lighter rulebook. Since FINRA runs most broker-dealer exams and the question it keeps returning to hasn’t softened at all, the one worth sitting with is whether you could actually produce records for every channel your people use.
SEC 17a-4 Compliance Checklist
Use this as a starting point, not a finish line. Each item needs real follow-up work with your legal and IT teams.
- Assign a compliance officer. Give one or more people ownership of FINRA compliance and data protection. They should work closely with IT and communications teams and have top-level access to the archive.
- Map the data you have to keep. Identify first-party and third-party data and every channel it moves across. Match each type to the retention period the rules require.
- Train your staff. Everyone who handles sensitive communications should know the procedures and understand that unauthorized disclosure creates legal trouble for the firm.
- Back up sensitive information. Plan for hacks, deletions, and system failures. Backups should restore lost data in its original format, quickly, without disrupting the business.
- Prepare for ediscovery. Everything in the archive should be searchable and organized so that requested records surface fast and can be shown to be untampered with.
- Meet the storage-integrity standard. Confirm your archive can hold records under either WORM or the audit-trail alternative, apply legal holds, support different retention schedules, produce records in their original state, and prevent alteration or deletion during the retention period.
- Let compliance supervise activity. Restrict archive access to authorized personnel, and keep a clear record of who used it and why.
Retention Periods at a Glance
Retention rules vary by record type. This table covers the requirements firms ask about most often. Confirm the specifics for your firm with counsel, since some record types carry their own rules.
| Record type | Minimum retention | Source |
| Core books and records (many categories) | 6 years | SEC Rule 17a-4 |
| Certain records (e.g., some communications) | 3 years | SEC Rule 17a-4(b) |
| Same-day production standard | First 2 years of retention | SEC Rule 17a-4 |
| General recordkeeping obligation | Per record type | FINRA Rule 4511 |
| Social media business communications | At least 3 years | SEC Rule 17a-4(b); FINRA Notices 10-06, 11-39 |
FINRA’s Regulatory Notices 10-06 and 11-39 address social media and recordkeeping directly. They make clear that business communications on social platforms are records, and they have to be preserved like any other.
Must-Have Features in a FINRA Archiving System
The archive you choose is the single biggest factor in staying compliant. Look for these capabilities:
- Multi-channel capture — Email is one channel. A compliant system also captures text messages, social media, and messaging apps, including edits and deletions. Running a separate tool for every channel rarely holds together.
- Indexing — Records must be indexed so retrieval works and stored in a format that meets 17a-4.
- Custom retention policies — Set rules per data type, apply them automatically to incoming records, and delete records automatically when their window expires.
- Legal hold — Preserve specific records past their retention period when you expect an audit, investigation, or litigation.
- Advanced search and filtering — Boolean, wildcard, proximity, and keyword search let reviewers find the right records fast and prioritize the ones that matter.
- Monitoring and supervision — Keyword warnings, audit trails, and violation previews help catch problems without opening every message by hand.
- Review tracking and export — Track review status and actions, and export samples to auditors with the full review history.
- Conversation threading — Review related messages and email chains together instead of piecing them back manually.
How Jatheon Sets You Up for FINRA and 17a-4 Compliance
Jatheon is a FINRA-compliant archiving solution that connects to your email server and automatically captures and indexes incoming and outgoing email.
Email is only the starting point.
Jatheon pulls social media, text messages, iMessage, WhatsApp, and Bloomberg messages into the same central archive, which speaks directly to the off-channel risk driving current enforcement. The channels examiners now ask about are the ones firms most often miss, and the connector list has kept pace with where business conversations actually happen.
Recent additions bring collaboration and public-facing sources into the same archive, including SharePoint files, website archiving that captures published pages with their text and version history, YouTube video details and comments, and even conversational AI through a Claude connector that retrieves past interactions, attachments, and deleted chats.


You manage every source from one connectors’ dashboard rather than running a separate tool for each channel.
Once the data is in, Unified Search covers it with a single query, returning email, social, and files in one result list instead of forcing a separate search per source.

It supports the precision tools reviewers rely on:
- Boolean search: Combine keywords with AND, OR, and NOT.
- Wildcard and proximity operators: Search with partial terms.
- Fuzzy search: Account for spelling errors.
- Keyword search: Find specific terms across a dataset.
Liya, the built-in AI assistant, sits alongside search and lets reviewers work through archived content across those sources from one place, which shortens the early stages of an audit or an ediscovery request.

Custom retention lives in Jatheon as Tags, which apply automatically to incoming messages and delete them once their retention period ends.
That gives you a way to manage the archive on autopilot while staying inside the rules. When a matter arises, Legal Hold tags preserve specific records past their normal retention window, and case tagging now spans email, social, and files, so everything tied to one investigation stays organized together.
Every captured message is written to a compliant format, and the integrity-check feature proves a record wasn’t altered. With custom roles, monitoring, and supervision, you keep archive access to authorized staff and can show exactly who used it and for what.
Conclusion
FINRA and SEC Rule 17a-4 decide how financial firms keep their records, and the cost of getting it wrong runs into the millions. The rules have moved in two ways worth internalizing: WORM is now one of two valid storage methods, and the real enforcement risk has shifted from email to texts and messaging apps, with FINRA carrying that fight even as the SEC has eased off. Firms that treat this as an email-only, WORM-only problem are protecting against yesterday’s exam. A system that captures every channel, retains records to standard, and produces them on demand is what keeps you compliant now.
FAQ
Is WORM still required under SEC Rule 17a-4?
No. Firms can now store electronic records using either WORM or the audit-trail alternative, and the better choice depends on your setup. WORM tends to suit firms that want the simplest way to prove a record was never touched, while the audit-trail alternative fits those who would rather use their existing systems and can reliably reconstruct a record if it changes. Both satisfy the rule.
Does FINRA require firms to archive text messages and WhatsApp?
Yes. If employees use those channels for business, the messages are records that have to be preserved, and a policy banning the channel doesn’t remove that obligation. Under FINRA Rule 4511, the duty attaches to the communication itself, so when someone uses an unapproved app and nothing gets captured, the firm has nothing to show an examiner.
Is off-channel enforcement still active?
Yes. The SEC has eased off technical recordkeeping cases under new leadership, but FINRA has kept pursuing them. It has issued its own off-channel fines, gone as far as barring individuals from the industry, and in one case penalized a firm after finding thousands of business text messages that were never captured. A quieter SEC does not mean the rules have changed.
What are FINRA books and records requirements?
They require firms to make and preserve records of transactions, communications, and customer accounts as defined by FINRA Rule 4511, and to store them in a format that meets SEC Rule 17a-4.
Are broker-dealers required to record phone calls?
Under FINRA Rule 3170, the Taping Rule, certain firms must install taping systems to record conversations with registered persons and existing or potential customers. It applies to firms that meet specific thresholds tied to their hiring of representatives from disciplined firms.
What is the penalty for violating FINRA rules?
Penalties include fines, suspensions, and, in serious cases, bars from the industry. Amounts depend on the severity of the violation and whether it was intentional. Fines can range from a few thousand dollars for small firms to millions for large ones.
Read Next:Bloomberg Archiving on Jatheon Cloud (+ More Updates) |











