RIA compliance is the set of SEC rules a registered investment adviser (RIA) has to follow under the Investment Advisers Act of 1940.
The core RIA compliance requirements are an up-to-date Form ADV, written compliance policies under Rule 206(4)-7, a named chief compliance officer, a code of ethics, an annual review of the compliance program, and books and records kept under Rule 204-2.
The parts that touch communications are recordkeeping and supervision.
Rule 204-2 requires advisers to keep written communications about advice, recommendations, trade orders, and client funds or securities for at least five years, with the first two years in an appropriate office of the adviser.
The rule follows the content of a message, so a text or WhatsApp message about a client trade has to be kept the same way an email would be.
What SEC Exams Actually Ask RIAs to Produce
An SEC exam is where RIA compliance gets tested against your records.
The Division of Examinations reviews about 15% of registered advisers each year, according to its September 2023 risk alert on how exams are scoped. Most exams open with a letter and an initial request list, and unannounced exams can start with a request handed over on arrival.
The initial request goes well past Form ADV.
The risk alert’s attachment lists the compliance policies in effect during the exam period, annual and interim compliance reviews, the record of compliance exceptions, and client complaints and correspondence. It also asks how the firm monitors that correspondence, including electronic communication, and for marketing materials posted on websites, blogs, and social media.
Rule 204-2(g) sets the pace.
Advisers that keep records electronically have to index them so any single record can be found, and produce copies promptly when examiners ask. A firm that has to pull texts from individual phones, or ask former staff for their chat history, will struggle to meet that standard.
The SEC’s off-channel sweep showed what falling short can cost.
Since fiscal year 2022, the SEC brought 95 actions and $2.3 billion in penalties against firms that failed to keep off-channel communications, according to its fiscal year 2025 enforcement results. Current SEC leadership has criticized that approach, but the rule those cases enforced is still in force and still on the exam request list.
RIA Compliance Requirements for Recordkeeping Under Rule 204-2
Rule 204-2 lists the books and records every SEC-registered adviser has to keep “true, accurate and current.” The list runs from ledgers and trade memos to advertising, performance, and code of ethics records.
For communications, the paragraph that matters most is 204-2(a)(7).
Which communications advisers have to keep
Rule 204-2(a)(7) covers written communications the adviser sends or receives that relate to:
- Any recommendation or advice given, or proposed to be given
- Receipt, disbursement, or delivery of client funds or securities
- Placing or executing an order to buy or sell a security
- Predecessor performance, or the performance of accounts, portfolios, or recommendations
This scope is narrower than SEC Rule 17a-4, which requires broker-dealers to keep communications relating to their business as such.
Kirkland & Ellis makes the same point in its review of the off-channel cases. The narrower scope only helps if the firm can show which messages fell within it, which in practice means capturing every business channel first and classifying messages afterward.
Retention periods and where records live
| Record | Rule 204-2 paragraph | Retention requirement |
| Written communications about advice, orders, client funds, and performance | (a)(7) | 5 years from the end of the fiscal year of the last entry, the first 2 years in an appropriate office of the adviser |
| Advertisements and communications sent to 10 or more people | (a)(11) | 5 years from the end of the fiscal year the material was last disseminated, the first 2 years in an appropriate office |
| Records supporting performance calculations | (a)(16) | 5 years from the end of the fiscal year the material was last disseminated, the first 2 years in an appropriate office |
| Records documenting the annual compliance review | (a)(17)(ii) | 5 years from the end of the fiscal year of the last entry, the first 2 years in an appropriate office |
| Compliance policies and code of ethics | (a)(17)(i), (a)(12)(i) | Every version in effect at any time in the past 5 years |
| Partnership articles, charters, and minute books | (e)(2) | In the principal office until at least 3 years after the business ends |
The first-two-years requirement matters most for cloud tools. For an electronic archive, plan for the most recent two years to be retrievable from the office on demand, without a vendor ticket or a restore job.
Conditions for electronic records
Rule 204-2(g) allows electronic storage without naming a technology. It does set four conditions. Advisers have to:
- Arrange and index records so any single record can be located and retrieved
- Give examiners a true and complete copy, a printout, or the means to view and print records
- Store a separate duplicate copy for the full retention period
- Keep procedures that protect records from loss, alteration, or destruction and limit access to authorized staff and the SEC
Why Personal-Device Texting Is the Live Off-Channel Risk for RIAs
Off-channel communications are business messages sent on channels the firm doesn’t capture, such as personal text messages, iMessage, WhatsApp, and Signal.
The SEC’s off-channel sweep began with broker-dealers in December 2021 and reached standalone advisers in April 2024, when Senvest Management agreed to a $6.5 million penalty.
The Senvest order is worth reading because the firm had already banned the behavior. Employees acknowledged in writing each year that texts and iMessage were off-limits for business. Staff at various levels still sent thousands of business messages from personal devices between January 2019 and December 2021, including messages about recommendations and advice.
Two details in the order apply to almost any RIA.
At least three senior officers had their phones set to delete messages after 30 days, so neither the firm nor SEC staff could count what was lost. The firm also never checked whether staff followed its own ban, and the SEC charged that gap as a separate violation of Rule 206(4)-7, the compliance rule, and as a failure to supervise.
Where enforcement stands now
The SEC’s posture has changed since the January 2025 settlements.
In its April 2026 enforcement results, the current Commission said the off-channel cases identified no direct investor harm and called them a misallocation of resources. Its regulatory agenda now lists a deregulatory project to propose amendments to Rule 204-2 covering the scope of electronic communications advisers must keep, with a proposal targeted for October 2026. As K&L Gates points out, the rule stays in force as written until it’s amended, and examiners will expect advisers to follow it.
Even the narrowest version on the table keeps client texts in scope.
The industry’s own reform request, a SIFMA letter to SEC Chairman Paul Atkins, asks the SEC to limit adviser retention to communications with clients and other outside parties that relate substantively to investment advice. A client texting an adviser’s personal phone about a trade falls inside that definition, which keeps personal-device texting the live risk whichever way the rule goes.
RIA Compliance Checklist for Recordkeeping and the Annual Review
Rule 206(4)-7 requires advisers to review their compliance policies at least once a year, covering both whether the policies are adequate and how well they’re implemented.
The rule doesn’t prescribe a written report, but Rule 204-2(a)(17)(ii) requires advisers to keep any records documenting the review, and examiners ask for those reviews along with any reports prepared.
Work through the checklist below during the review and file the evidence for each item.
Records to keep
- Written communications about advice, recommendations, trades, and client funds or securities, from every channel staff use with clients
- Advertisements and other marketing material, plus the records behind any performance figures they show
- Every version of the compliance policies and code of ethics in effect in the past five years, with signed staff acknowledgments
- Records documenting each annual compliance review
- Regulation S-P incident response policies and records of how any unauthorized access to customer information was handled
Storage and retrieval
- Retention settings checked against the Rule 204-2 periods in the table above
- A duplicate copy stored separately, with a test restore from it
- Access rights reviewed and limited to staff who need them
- A legal hold process that stops deletion for records tied to an exam, complaint, or dispute
Off-channel controls
- A written policy naming the channels approved for client communication, with dated staff attestations and training records
- Capture in place for every texting and messaging app staff use with clients, including personal phones used for business
- Monitoring that checks whether staff follow the policy, with the lexicon or sampling rules documented
- A log of business messages found outside approved channels, how each was recovered, and the retraining or discipline that followed
Annual review evidence
- A channel inventory showing every client channel and whether it’s captured
- Capture tests that trace sample messages from each channel into the archive, dated and signed off
- Surveillance results showing the alerts reviewed and how exceptions were closed
- A timed retrieval drill showing the firm can find and produce a specific record on request
How Jatheon Handles RIA Recordkeeping and Off-Channel Capture
A written ban on texting doesn’t create a record, and a client who texts an adviser’s personal phone isn’t going to switch to a separate app.
Jatheon captures iMessage and WhatsApp natively, with no wrapper app for advisers or clients to adopt. Edits and deletions are stored alongside the original messages, so anything Jatheon has captured stays in the archive even after a 30-day auto-delete setting clears it from the phone.
Exam requests rarely stop at one channel. Jatheon’s Data Connectors bring email, chat, social media, voice, and files from more than 25 channels into one archive, and Unified Search runs a single query across all of them. When examiners ask for every communication with a client over a set period, the compliance team runs one search and exports one result set instead of collecting from each system.

Rule 204-2 retention periods differ by record type, and a deleted record can’t be recovered once an exam starts. Retention Tags apply the right period to each record type automatically, and Legal Hold suspends deletion for anything tied to an exam, complaint, or dispute. Audit Logs record user actions in the archive, including searches and exports, which gives the annual compliance review a dated evidence trail without a separate tracking spreadsheet.







