Key takeaways
- SEC and FINRA treat business text messages as records that must be captured and retained, regardless of the device or app used.
- Retention periods run five years under the Investment Advisers Act and at least three years (with certain records requiring six years) under SEC Rule 17a-4 and FINRA Rule 4511, all in a tamper-evident, easily accessible format.
- The SEC’s off-channel sweep has ended. The Commission brought 95 actions and assessed $2.3 billion in penalties from fiscal year 2022 onward, then publicly disavowed the approach. The underlying rules didn’t change, and FINRA has taken over as the primary enforcement pressure into 2026.
- Secure-texting apps only capture messages sent inside the app. Real compliance means capturing off-channel iMessage, WhatsApp, and SMS on BYOD and corporate devices too.
- The right text message archiving platform captures every channel into one searchable, tamper-proof archive with legal hold, audit trails, and fast ediscovery.
Introduction
Texting has become a primary communication channel between financial advisors and their clients. Clients expect quick responses, and email often lags behind the immediacy that mobile messaging provides.
Yet many advisory firms hesitate to embrace texting because they fear the compliance implications, and those fears aren’t unfounded.
Regulators treat text messages the same way they treat emails, phone calls, and written correspondence: as business records that must be captured, retained, and produced on demand.
When firms fail to archive these communications, the consequences range from exam findings and reputational damage to eight- and nine-figure penalties. The answer isn’t to ban texting but to capture and archive it properly.
In this guide, you’ll learn:
- Which SEC and FINRA rules apply to text message archiving for financial advisors
- How long you must retain text messages under each regulatory framework
- How to text clients compliantly while meeting BYOD and consent requirements
- Why native apps and carrier backups fall short of regulatory expectations
- What to look for in a compliant text message archiving solution
What Text Message Archiving Means for Financial Advisors
Text message archiving is the process of automatically capturing, indexing, and retaining SMS, MMS, iMessage, WhatsApp messages, voice calls, and voicemails in an evidentiary format that regulators and courts will accept.
How it works
A compliant archiving system intercepts messages at the device or network level and writes them to immutable storage.
Each message is time-stamped, threaded, and enriched with metadata (sender, recipient, device, carrier) so that it can be searched, exported, and authenticated later.
What makes a message a business record is its content, not the device it was sent from.
A text about a client’s portfolio sent from a personal iPhone carries the same retention obligation as an email sent from a corporate workstation. That means personal-device (BYOD) communications are in scope whenever they concern firm business.
Text message archiving isn’t the same thing as backup or CRM logging.
Backups are built for disaster recovery and aren’t indexed for search. CRM logs may capture notes about a conversation but rarely capture the original message in its native format with full metadata.
Neither one meets the evidentiary integrity and accessibility standards regulators expect.
Why Text Message Archiving Matters for Financial Advisors
Clients increasingly prefer texting over email and phone calls.
Response times are faster, and the channel fits the way people communicate in their personal lives. Banning client texting outright is hard to enforce and often ignored in practice, which leaves firms exposed to the very risk they were trying to avoid.
How the gap usually opens
The problem rarely starts with anyone deciding to break a rule. An advisor gave a client their mobile number years ago, because that’s how the relationship worked, and the client has used it ever since.
Most of those messages are logistics.
Then one afternoon the client texts to say they want to move a large position before the end of the week, and the advisor replies with a view on timing.
That exchange is a business record from the moment it’s sent. It sits on two phones and nowhere else, and nobody at the firm knows it happened.
The gap doesn’t announce itself, and it usually surfaces two years later, when an arbitration claim or an examination request arrives asking for all communications with that client over a defined period. The firm produces email and whatever its approved texting platform holds, the client produces screenshots of a thread that doesn’t appear anywhere in the production, and the conversation shifts from the underlying dispute to why the firm can’t account for its own records.
By that point, the advisor may have replaced the handset, and the messages may be genuinely unrecoverable. Retention policies exist to keep firms out of exactly that position, which is why it’s worth understanding what they require before shopping for a tool.
Enforcement reality
The SEC’s recordkeeping crackdown went into force in September 2022, when regulators charged 16 firms (15 broker-dealers and one affiliated investment adviser) for failing to maintain required records of off-channel communications.
Combined penalties exceeded $1.1 billion, with several major banks paying $125 million each, and the message was clear: regulators wouldn’t be treating these failures as administrative oversights.
Enforcement continued through 2023 and 2024. The final major wave came in January 2025, when the SEC charged nine investment advisers and three broker-dealers. Those 12 firms agreed to pay combined civil penalties of $63.1 million, with individual penalties ranging from $600,000 for a firm that self-reported up to $12 million.
The SEC’s fiscal year 2025 enforcement results, released April 7, 2026, tallied 95 actions and $2.3 billion in penalties for off-channel recordkeeping failures since fiscal year 2022, and then criticized that entire line of enforcement.
The Commission characterized those cases as identifying no direct investor harm and representing a misallocation of resources, and no new off-channel actions have followed.
That shift in posture doesn’t reduce anyone’s obligations, and it would be a costly misreading to treat it as though it does.
The rules themselves haven’t changed. What changed is which regulator holds the spotlight, and FINRA has taken it up. FINRA’s 2026 Annual Regulatory Oversight Report, published in December 2025, lists electronic communications capture failures, off-channel use, and inadequate supervision procedures among findings from recent examinations, and flags recordkeeping lapses more than 50 times across the document.
The report directs firms to monitor for unapproved channel use, refresh communications surveillance keywords, and extend supervision to every contributor of firm records, including part-time and outsourced personnel.
For mid-market advisory firms, this arguably raises exposure rather than lowering it.
The SEC’s billion-dollar waves landed mostly on large Wall Street institutions, whereas routine FINRA cycle examinations reach everyone.
Business impact
Beyond fines, recordkeeping failures create operational and legal exposure.
Firms face exam findings, remediation costs, reputational damage, and an inability to defend themselves in customer disputes or litigation.
When a regulator or opposing counsel requests text messages and the firm can’t produce them in a complete, tamper-evident format, the inference is rarely favorable.
Which Regulations Require Text Message Archiving
Several overlapping rules govern recordkeeping for broker-dealers and investment advisors. The table below summarizes the key frameworks, and the subsections that follow explain each in detail.
| Regulation | Applies to | Minimum retention period | Key requirements |
|---|---|---|---|
| SEC Rule 17a-4 | Broker-dealers | 3 years for most business communications (first 2 years in an easily accessible place); 6 years for certain core accounting and transaction records | WORM storage or complete, time-stamped audit trail |
| FINRA Rule 4511 | Broker-dealers | 6 years (default for books and records where no other period is specified) | Format must comply with SEC Rule 17a-4 |
| Investment Advisers Act, 17 CFR 275.204-2 | SEC-registered RIAs | 5 years (first 2 years in an appropriate office of the adviser) | Retention clock runs from the end of the fiscal year of the last entry |
| FCA Handbook SYSC 9.1.2 / SYSC 10A | MiFID firms with UK/EU business | 5 years (extendable to 7 for voice recordings) | Applies to firms with international reach |
SEC Rule 17a-4
SEC Rule 17a-4 requires broker-dealers to create and preserve records of their business, including communications related to their business as broker-dealers. Text messages that discuss recommendations, orders, or client accounts fall within this scope.
Most business communications have to be retained for a minimum of three years, with the first two years in an easily accessible place. Certain core accounting and transaction records, such as blotters, ledgers, and account records, require six years of retention.
In October 2022, the SEC adopted an amendment to Rule 17a-4 that added an alternative to the traditional write-once-read-many (WORM) storage requirement.
Firms can now use electronic recordkeeping systems that maintain a complete, time-stamped audit trail of every record modification, provided the system meets specified integrity criteria. WORM storage is still a valid option, since the amendment expanded the available choices rather than replacing the prior standard. The amendment took effect in January 2023.
FINRA Rule 4511
FINRA Rule 4511 requires member firms to make and preserve books and records as required under FINRA rules, the Securities Exchange Act of 1934, and the applicable SEC rules.
Where no specific retention period is stated, the default is six years. Records have to be stored in a format that complies with SEC Rule 17a-4.
Because Rule 4511 incorporates the SEC’s recordkeeping requirements by reference, broker-dealers subject to FINRA must meet both the SEC and FINRA standards at the same time.
Investment Advisers Act (17 CFR 275.204-2)
SEC-registered investment advisors are governed by a separate recordkeeping rule under the Investment Advisers Act of 1940. Under 17 CFR 275.204-2, advisors have to retain most records, including written communications relating to recommendations, advice, or the placing of orders, for at least five years.
The first two years of that period must be maintained in an appropriate office of the investment adviser.
The five-year clock begins at the end of the fiscal year in which the last entry was made in the record.
International frameworks
Firms with operations that extend into the United Kingdom or European Union face additional requirements.
The FCA Handbook (SYSC 9.1.2) requires common platform firms engaged in MiFID business to retain records for at least five years. Voice and electronic communications recordings fall under SYSC 10A and have to be kept for five years, extendable to seven at the regulator’s request.
Advisors operating across borders should map each jurisdiction’s requirements and apply the longest applicable retention period.
How Financial Advisors Can Text Clients Compliantly
Meeting recordkeeping obligations doesn’t require banning text messages. The point is to implement controls that capture, retain, and supervise those messages automatically.
The following best practices apply whether staff use employer-issued devices, corporate-owned/personally-enabled (COPE) devices, or bring-your-own-device (BYOD) arrangements.
- Establish a written texting policy. Define which messaging channels are permitted, what types of communications can happen over text, and what’s prohibited. The policy should be part of the firm’s broader written supervisory procedures.
- Obtain documented client consent. Before texting clients, get their consent to communicate via text and document it. This supports both regulatory expectations and privacy considerations.
- Capture and archive automatically. Deploy an archiving solution that intercepts and stores messages at the point of transmission. Manual export or periodic backup isn’t enough for compliance purposes.
- Set retention schedules per rule. Configure the archiving system to retain records for the periods the applicable regulations require. Build in buffer time to account for the “end of fiscal year” start date under the Investment Advisers Act.
- Supervise and monitor. Use the archiving platform’s review and alerting capabilities to flag high-risk content, such as personal securities transactions, complaints, or potential misconduct. Supervision is a regulatory expectation, not an optional add-on, and FINRA’s 2026 report specifically warns against setting surveillance lexicons once and then leaving them untouched.
- Train staff. Make sure all registered representatives and advisory personnel understand the texting policy, the consequences of off-channel communications, and how the capture technology works on their devices.
- Maintain compliance records. Document policy acknowledgments, training completion, supervision reviews, and any remediation actions. These records demonstrate a culture of compliance during examinations.
BYOD vs. corporate-owned devices
Text message archiving has to cover every device used for business communications, personal or corporate.
On employer-issued devices, firms have full control over installed applications and can mandate an archiving agent. On BYOD devices, the archiving solution needs to work without asking employees to surrender personal privacy, and modern platforms do this by capturing only business communications through a lightweight app or network-level integration.
The key is carrier- and device-agnostic capture.
Whether the employee uses an iPhone, Android, Verizon, AT&T, or T-Mobile, the archiving system has to intercept and retain business messages without gaps.
Why Native and Secure-Texting Apps Aren’t Enough
Many firms deploy secure-texting or CRM-integrated messaging applications and assume the compliance box is checked.
These tools have value, but they solve only part of the problem.
The capture gap
Secure-texting apps capture messages sent and received inside the app.
They don’t capture messages sent via the device’s native SMS, iMessage, or WhatsApp applications. When a client texts an advisor’s personal number or sends a WhatsApp message, that communication never touches the secure-texting platform and never gets archived.
Regulators don’t distinguish between in-app and off-channel messages.
If a business communication happened, it has to be retained, regardless of which application the client chose to use.
Carrier backups and phone exports
Some firms try to close the gap by relying on carrier records or periodic phone exports.
Neither approach meets compliance standards:
- Carrier records typically include only metadata (sender, recipient, timestamp) and may not include message content. Retention periods vary and aren’t aligned with regulatory requirements.
- Phone exports (manual or via MDM) aren’t tamper-evident, aren’t indexed for search, and aren’t practical for ediscovery at scale.
What compliant capture requires
A compliant text message archiving solution has to be carrier-agnostic, device-agnostic, and ownership-model-agnostic.
It needs to capture SMS, MMS, iMessage, WhatsApp, and other messaging apps used for business, regardless of whether the device is employer-issued, COPE, or BYOD. Captured messages have to be written to immutable storage, threaded for context, and searchable within seconds.
What to Look for in Text Message Archiving for Financial Advisors
Evaluating text message archiving platforms comes down to mapping vendor capabilities against regulatory requirements.
The following criteria reflect what advisors and compliance officers should prioritize.
- Multi-channel capture. The platform should capture SMS, MMS, RCS, iMessage, WhatsApp, Signal, and voice/voicemail across all device ownership models (BYOD, COPE, employer-issued) and all major carriers. Gaps in channel coverage create gaps in compliance.
- Evidentiary integrity. Messages have to be stored in a tamper-proof format, either WORM storage or a system with a complete, time-stamped audit trail that satisfies the SEC’s 2022 amendment to Rule 17a-4. Message threading and full metadata preservation are essential for authenticity.
- Retention policy automation. The system should enforce retention schedules automatically, applying the correct period to each record type and preventing premature deletion.
- Legal hold. When litigation or regulatory inquiry arises, the platform has to support legal hold to suspend deletion and preserve relevant records.
- Fast search and ediscovery. Examiners expect rapid production of responsive records. The platform should return search results in seconds, support complex queries, and export in formats regulators and courts will accept.
- Role-based access and audit logs. Access controls make sure that only authorized personnel can view, export, or modify records. Audit logs track every action for accountability.
- Security certifications. Look for SOC 2, ISO 27001, and, where applicable, HIPAA and GDPR readiness. These certifications validate the platform’s security controls.
- AI-powered supervision. Advanced platforms incorporate AI classification, sentiment analysis, and copilot tools to prioritize items for review, reduce false positives, and surface emerging risks proactively.
- Exit terms. It’s worth asking what it costs to leave. Per-gigabyte extraction fees and export limits are common, and they turn a future migration into a budget line item, so free and unrestricted export should be written into the contract.
Where Jatheon Differs
Jatheon Cloud is built against every criterion above: multi-channel capture across devices and carriers, WORM-backed evidentiary integrity with full metadata and threading, automated retention policies, legal hold, advanced search across more than 60 criteria that combs a million records in under a second, regulator-ready exports, granular role-based access with redaction and audit logs, and SOC 2, ISO 27001, HIPAA, and GDPR readiness on AWS with multi-zone redundancy.
Three things are worth calling out specifically, because they’re where the platform diverges from the category norm rather than just meeting it.
A choice of capture method, including no-app carrier capture
Where most vendors offer a single deployment path, Jatheon offers three:
- direct carrier capture at the network level with no app installation for company-owned phones
- a lightweight background app for Android across BYOD and employer-issued devices
- an enterprise-number method using a secondary virtual number that works on both iOS and Android
Firms with mixed device fleets and mixed ownership models can combine methods instead of forcing every user into one.
Liya, a conversational copilot for the archive
Rather than surfacing AI as a scoring layer buried in a review queue, Jatheon lets compliance officers use Liya, a conversational copilot, to query archived communications directly in natural language, generating summaries, asking follow-up questions, and clarifying what a conversation actually meant without leaving the archive.
Liya runs inside Unified Search, so a single query returns results across text, email, social, and files instead of requiring a separate search per channel, which is the shape most exam and arbitration requests actually take.
It works together with AI-driven classification and sentiment analysis that filter routine noise out of review queues. For a small compliance team, that turns ad hoc investigation from a search-syntax exercise into a conversation.
Migration in, and the freedom to migrate out
Jatheon provides automated migration from major legacy and competitor archives, so switching systems doesn’t mean a gap in your compliance record, backed by 24/7 in-house technical support rather than outsourced tiers.
That matters given how often archiving contracts become traps, and Jatheon doesn’t impose extraction fees or export limits on the way out.
Where This Leaves Your Firm
The firms that ran into trouble over the past four years mostly weren’t firms that treated recordkeeping as optional. They had a policy, an approved messaging tool, and a reasonable belief that the question was settled. The gap sat between what the policy covered and where the conversations actually happened.
That space hasn’t narrowed, and the obligation hasn’t changed. Only the source of the pressure has, shifting from an SEC that stepped back to FINRA examiners who reach the mid-market firms those billion-dollar sweeps never touched.
So the decision isn’t whether to allow client texting, since your clients made that one already. It’s whether you find out where your gaps are on your own schedule, while they’re still fixable, or two years into an arbitration claim, when the thread everyone needs is on a handset that no longer exists.
FAQ
Do financial advisors have to archive text messages?
Yes, whenever the message concerns firm business. Neither the SEC nor FINRA wrote a separate rule for texting. Text messages fall under the same recordkeeping provisions that already covered email and written correspondence, which means the test is what the message says rather than which app carried it.
How long do financial advisors have to keep text messages?
It depends on which framework applies. SEC-registered advisers work to a five-year floor under 17 CFR 275.204-2. Broker-dealers work to three years for most communications under Rule 17a-4, six years for certain records, and a six-year default under FINRA Rule 4511. The detail firms most often get wrong is the start date: under the Advisers Act, the clock runs from the end of the fiscal year containing the last entry, not from the date of the message, so real-world retention usually runs past five years.
Do texts on a personal (BYOD) phone need to be archived?
Yes. If the message concerns firm business, it has to be captured and retained even if it was sent or received on a personal device.
Do conversations with prospects count, or only clients?
Prospects count. Both frameworks define records by content rather than by relationship. Rule 17a-4 reaches communications relating to the firm’s business as such, with no client qualifier, and the Advisers Act rule reaches written communications about recommendations made or proposed and advice given or proposed, whoever receives them. Texts to prospects can carry a second obligation as well, since a message promoting advisory services may qualify as an advertisement and require retention on that basis.
Do internal texts between employees need to be archived?
For broker-dealers, yes, and explicitly so: Rule 17a-4(b)(4) covers communications “including inter-office memoranda and communications” relating to the firm’s business. For SEC-registered advisers, it’s less settled, because the Advisers Act rule has no equivalent language and industry groups have argued it doesn’t reach purely internal messages. The SEC read it more broadly during the off-channel sweep. Most firms capture internal messaging anyway, since the question is unresolved and internal threads about recommendations rarely separate cleanly from what the rules plainly cover.
Can financial advisors text clients?
Yes, provided the firm has a texting policy, documented client consent, and a system that captures and archives every business message automatically.
Can we just prohibit texting instead of archiving it?
A prohibition is a policy rather than a control, and on its own it hasn’t protected firms. Many of those penalized in the off-channel sweep already had written policies banning unapproved channels. What the orders turned on was that the messages happened anyway and nobody at the firm was positioned to detect it. If a business communication takes place, the record obligation attaches whether or not the firm authorized the channel. A ban also has to be supervised to be reasonable, which means having some way to detect violations, and in practice that means capture.
What happens to text records when an advisor leaves the firm?
The retention obligation belongs to the firm and survives the departure, measured from the fiscal year of the last entry rather than from the exit date. The practical risk sits with BYOD, because if capture depended on an app installed on a personal handset, access to the record can leave with the device. Capturing at the point of transmission into a firm-controlled archive avoids that, since the record then exists independently of the phone. FINRA’s 2026 report reinforces the point by directing firms to extend supervision to everyone who contributes to firm records.
Does text message archiving capture iMessage and WhatsApp?
Only if the platform is built for it. iMessage runs on Apple’s own protocol rather than the carrier’s SMS network, so it never passes through the infrastructure that carrier-level capture monitors, and WhatsApp behaves similarly with its own encrypted transport. Both need dedicated capture rather than a general mobile archiving feature, and secure-texting apps miss them entirely because the conversation happens outside the app. When evaluating vendors, ask which specific protocols they capture instead of accepting “mobile archiving” as a single capability.
Has the SEC stopped enforcing off-channel communications rules?
The SEC has stopped bringing new off-channel sweep actions and has publicly criticized the prior enforcement approach. The recordkeeping rules themselves haven’t changed and remain fully in force. FINRA continues to examine for off-channel capture and supervision failures, so the practical compliance obligation is what it was before.











