FINRA Rule 3110 is FINRA’s core supervision rule. It requires member broker-dealers to keep a supervisory system reasonably designed to achieve compliance with securities laws and FINRA rules, backed by written supervisory procedures (WSPs) and qualified registered principals.
Rule 3110(b)(4) adds a specific duty: a registered principal must review incoming, outgoing and internal communications and evidence that review in writing. Final responsibility for supervision rests with the member firm.
What Getting FINRA Rule 3110 Wrong Costs
A censure and a $750,000 fine settled FINRA’s case against Benjamin F. Edwards & Co., Inc. on January 30, 2026. The St. Louis firm had about 560 registered representatives in more than 100 branches. Its WSPs banned business texting except through firm-approved capture software.
FINRA’s Letter of Acceptance, Waiver and Consent (AWC) says the firm had “no process or procedures, written or otherwise, for monitoring for compliance with its text messaging policies.”
At least five registered representatives, including one senior executive, exchanged at least 3,560 business texts on personal devices. They included investment directives, sensitive customer personal information and investment advice.
FINRA found supervision violations of Rules 3110(a), 3110(b) and 2010. The same $750,000 fine covers recordkeeping violations under Securities Exchange Act (SEA) Rule 17a-4 and FINRA Rule 4511. It also covers a separate discovery violation.
FINRA cited the firm’s 2019 arbitration discovery sanctions as an ignored red flag. The firm retained a consultant only in May 2023. If your WSPs ban a channel and nobody checks compliance, you have a supervision gap. FINRA Rule 3110 supervision isn’t satisfied by policy alone: the firm has to show it monitored for compliance.
Edwards isn’t an outlier. SEC and CFTC penalties for off-channel communications have topped $3 billion since late 2021, and FINRA cases like Edwards cite Rule 3110 supervision alongside FINRA Rule 4511 recordkeeping. Our roundup of FINRA and SEC texting fines tracks the biggest cases.
Rule 3110 also covers office inspections, transaction review and background checks on new hires. This article focuses on the part that governs your communications.
What FINRA Rule 3110 Supervision Requires
FINRA Rule 3110(a) lists what a “reasonably designed” supervisory system needs. The parts that bear on communications review are:
- Written supervisory procedures
- A registered principal for each type of business requiring broker-dealer registration
- A registered supervisor for every registered person
- Reasonable efforts to confirm supervisors are qualified by experience or training
The rule adds: “Final responsibility for proper supervision shall rest with the member.”
Written Supervisory Procedures Under Rule 3110(b)
Rule 3110(b)(1) says you must “establish, maintain, and enforce” written procedures. The Edwards case shows what happens when enforcement is missing.
For communications review, your written supervisory procedures must also cover:
- Capturing, acknowledging and responding to all written customer complaints under (b)(5), which correspondence review must flag
- Bans on self-supervision and reporting to someone you supervise, with documented small-firm exceptions
- Conflicts-of-interest procedures
- A WSP copy at each OSJ and supervisory location under (b)(7), amended promptly when rules or your system change
Communicate changes to affected staff. Supplementary Material .11 allows electronic delivery if you keep prior versions under SEA Rule 17a-4(e)(7). In practice, every channel or tool you approve should trigger a WSP update.
Rule 3110(b)(4): Reviewing Correspondence and Internal Communications
FINRA Rule 3110(b)(4) requires procedures for reviewing incoming and outgoing correspondence and internal communications. Correspondence review must identify customer complaints, instructions, funds and securities, and regulated subject matter. Internal communications get the same subject-matter review.
A registered principal does the review, evidenced in writing on paper or electronically. Your procedures must be “appropriate for the member’s business, size, structure, and customers.”
Regulatory Notice 07-59 bases supervision on “the content and audience of the message, rather than the electronic form of the communication.” Texts, chat apps and collaboration tools used for business are in scope.
Why Email-Only Review No Longer Satisfies Rule 3110
Many review programs were built for email. Rule 3110(b)(4) never limited review to email, and Notice 07-59’s content-and-audience standard means the obligation follows the business conversation onto every channel your reps use. Today, that includes:
- Mobile messaging: SMS/MMS, iMessage and WhatsApp on firm-issued and personal phones
- Collaboration platforms: Microsoft Teams and Slack chats and channels
- Video meetings: Zoom and Teams meeting chat, plus any recordings or transcripts you keep as business records
- Social media: LinkedIn and other sites where reps talk to customers
- AI tools: assistants and notetakers that draft, summarize or send business messages
Every channel you approve needs capture, a WSP update and a review process. Every channel you ban needs monitoring for compliance with the ban. Edwards had the ban but not the monitoring. A review program that only sees email leaves every other channel unsupervised.
How Firms Evidence Rule 3110 Communications Review
Risk-based review and sampling
Supplementary Material .06 allows a risk-based review scope. If you don’t pre-review all correspondence, your procedures must provide for training, documented training and “surveillance and follow-up.”
Notice 07-59 pairs lexicon reviews with random sampling. It adds: “There is no prescribed minimum or fixed percentage that is required by regulation.” People with disciplinary history may warrant a higher sample.
That leaves the question many compliance teams ask: is a 5% random sample still defensible? No rule says 5% is enough or too little. What matters is whether your number follows from your risk assessment. A flat 5% across every rep and channel is hard to defend if it ignores reps with disciplinary history, new hires or high-risk channels like personal mobile messaging.
Tier your sampling by risk, raise it where Notice 07-59 suggests heightened review and write the rationale into your WSPs. Then check whether the sample is surfacing issues, and adjust it when it isn’t.
Lexicons miss encrypted attachments, image files and deliberate wording workarounds. Review correspondence in every language you do business in. Under Regulatory Notice 24-09, AI review policies should cover model risk management, data privacy and integrity, and model reliability and accuracy.
What counts as evidence of review
Under .07, your record must identify the reviewer, the communication, the review date and actions taken on significant regulatory issues. FINRA is explicit: “Merely opening a communication is not sufficient review.”
Evidence should also show escalation. When a reviewer flags a message, the record should show who it went to, what they decided and when the matter closed.
Under .08, you can delegate review to unregistered persons, but the supervisor or principal “remains ultimately responsible.” Under .09, retention follows SEA Rule 17a-4(b), with preparer and reviewer names ascertainable.
Where Rule 3110 Supervision Breaks Down
Watch for four gaps:
- A channel ban with no monitoring, as in the Edwards AWC
- Alerts closed without review
- WSPs not amended after you adopt a new channel or tool
- Review records that don’t show who reviewed what, when and what action followed
Alerts are the gap firms underestimate. Morrison Foerster reported a case where FINRA fined Velocity Clearing $1,000,000 under Rule 3110 after the firm closed more than 147,000 of nearly 150,000 surveillance alerts without investigation. That case involved trade surveillance, but the same logic applies to communications alerts: an alert nobody reviews is a supervision failure.
How Jatheon Supports FINRA Rule 3110 Supervision
Jatheon has archived 21B+ messages for 500+ customers worldwide, and EOG Resources monitors 8000+ active mailboxes on the platform. Here’s how it supports capture, review and evidence.
Capture business texts from every device
Reps text clients from personal phones, and a written ban doesn’t put those messages before a reviewer. Jatheon Data Connectors capture iMessage, WhatsApp, SMS/MMS and Microsoft Teams with metadata and threading. Capture covers employer-issued and personal phones, so business messages land in one archive for principal review.
Spend review time on risky communications
Reviewers lose time to newsletters and auto-replies. AI data classification filters newsletters, promotions, out-of-office replies and bounced messages out of review sets. AI sentiment analysis tags tone across five levels: very positive, positive, neutral, negative and very negative.
The AI Dashboard puts high-priority, sensitive and potentially risky items in one view. Principals spend review time where the risk is.
For sampling, supervision rules support random percentage sampling and sample-and-hit rules, so you can match review depth to the risk tiers in your WSPs. Configurable alerts notify reviewers when a message matches a policy, so flagged items don’t sit unreviewed.

Produce defensible records on request
When an examiner asks who reviewed a message and when, you need records that answer. Jatheon Cloud keeps records in WORM storage with retention policies and role-based access with 60+ permissions. Tamper-proof Audit Logs records searches, exports, policy changes and user activity, and AI actions are logged with justification reports.
Unified Search finds every message from a rep or about a customer across all captured channels in one query. Cases keep the messages tied to a review or investigation together, so the record of what was reviewed, by whom and what followed stays in one place.
Liya, Jatheon’s conversational AI copilot, can summarize a long thread for the reviewer. Exports to PDF, PST, EML and CSV give examiners usable formats. When FINRA asks, you can produce defensible records and an activity history.






