Feature Regulatory Compliance
Your Firm's Personal Device Policy Isn't Working. What $2 Billion in SEC and CFTC Penalties Reveals About Off-Channel Communications Compliance.
Since December 2021, the SEC and CFTC have collected more than $2 billion from broker-dealers and investment advisers for off-channel communications violations. The pattern is identical every time: a written policy, zero enforcement, and years of communications that were never captured. Here's what a compliant program actually looks like.
Table of Contents
TL;DR
- The SEC and CFTC have collected more than $2 billion from broker-dealers and investment advisers for off-channel communications violations since December 2021, in a coordinated enforcement wave with no sign of stopping.
- The violation pattern is the same in every case: employees used WhatsApp, iMessage, Signal, or similar personal messaging apps for business communications that were never captured in the firm’s record-keeping system — violating Exchange Act Rules 17a-3 and 17a-4.
- A written policy prohibiting off-channel communications is not a defense. Examiners look at whether the policy was actually enforced, whether supervisors complied with it, and whether the firm had technical controls in place to make it real.
- Every registered broker-dealer and investment adviser needs to treat this as an active examination risk — not a problem solved by having a policy on the books.
When the SEC and CFTC announced a $200 million combined penalty against J.P. Morgan Securities in December 2021, the compliance community took notice. When the same regulators announced more than $1.1 billion in combined penalties against fifteen additional firms nine months later, it became clear this was not an isolated enforcement action — it was a systematic examination priority with no obvious endpoint.
By any measure, the off-channel communications enforcement wave is one of the most sustained and financially significant regulatory campaigns in securities industry history. And yet, the underlying legal obligation that drives it — the requirement to preserve all business-related written communications — has been on the books for decades.
That’s the uncomfortable reality this enforcement wave reveals. The firms that paid nine-figure penalties weren’t caught off guard by a new rule. They were caught off guard by a regulator who decided to actually enforce an old one.
What Exchange Act Rule 17a-4 Actually Says
Section 17(a) of the Securities Exchange Act of 1934 grants the SEC authority to require broker-dealers to make and keep records and to submit reports. Exchange Act Rule 17a-3 specifies what records broker-dealers must create — including records of all communications relating to their business. Exchange Act Rule 17a-4 specifies how long those records must be kept: at least three years for most business records, with the first two years in an easily accessible location.
The rule’s application to electronic communications is not a recent development. The SEC extended Rule 17a-4’s requirements to email in the 1990s. Text messages, instant messages, and chat platforms are electronic communications. They are records relating to the firm’s business. The rule applies.
FINRA Rule 4511, which requires FINRA member firms to make and preserve books and records, similarly covers electronic communications on any platform. Rule 4511 expressly applies to electronic communications, and FINRA has consistently enforced it in coordination with SEC requirements.
For investment advisers, the parallel obligation comes from Advisers Act Rule 204-2, which requires investment advisers to preserve copies of all written communications, including electronic communications related to investment advice and recommendations.
The legal framework is not complicated. What changed in December 2021 was not the rule — it was the enforcement posture.
The Enforcement Wave: From JP Morgan to the Present
December 2021: J.P. Morgan Securities — $200 million
The SEC charged J.P. Morgan Securities LLC with widespread and longstanding failures to maintain and preserve electronic communications required by Rule 17a-4 and FINRA Rule 4511. The violations were not limited to junior employees. Senior employees, including managing directors, routinely used WhatsApp and personal devices to conduct business communications about securities transactions, investment strategies, and client matters — none of which were ever captured in the firm’s record-keeping system.
J.P. Morgan’s written policy prohibited personal device use for firm business. That policy did not prevent the violations. It did not prevent the $125 million SEC penalty, the $75 million CFTC penalty, or the requirement to retain an independent compliance consultant.
September 2022: The $1.1 Billion Coordinated Action
Nine months later, the SEC and CFTC announced a coordinated enforcement action against fifteen broker-dealers and one affiliated investment adviser, resulting in approximately $1.1 billion in combined SEC and CFTC penalties. The firms charged included major Wall Street institutions: Barclays Capital, Bank of America Securities, Citigroup Global Markets, Credit Suisse Securities, Deutsche Bank Securities, Goldman Sachs, Jefferies, Morgan Stanley, Nomura Securities, and UBS Securities, among others.
Every single firm charged had a written policy prohibiting the use of unapproved communications methods for business communications. Every single firm charged had employees — including supervisors and senior managers — who used WhatsApp, iMessage, Signal, or other personal messaging apps for business communications that were never preserved.
The SEC’s language in the orders was direct: the violations were “widespread and longstanding” — in some cases spanning years. Senior employees knew the rules. They violated them anyway. And supervisors who were themselves violating the policy did not enforce it against their teams.
2023 Onward: More Firms, More Penalties
The enforcement wave did not stop in 2022. In 2023 and 2024, the SEC and CFTC continued charging additional firms, including regional broker-dealers, investment banks, and registered investment advisers. The total combined penalties across all off-channel communications enforcement actions exceeded $2 billion.
The regulators have been explicit about why: they are not done. Every new action comes with the same finding — widespread off-channel use, supervisors involved, and written policies that existed only on paper.
The Pattern That Connects Every Case
Reading through the enforcement orders, the violations share a structure that is worth understanding, because it’s the structure your compliance program needs to break.
Step 1: Written policy exists. Every penalized firm had a policy. In most cases, the policy was reviewed annually. Employees attested to reading it.
Step 2: No technical controls enforce it. The firms generally had not implemented mobile device management (MDM) tools, approved messaging platforms, or technical controls that would either capture personal device communications or block them from being used for firm business. The policy was a document. It wasn’t a program.
Step 3: Supervisors were among the violators. This is the element that makes the enforcement posture particularly aggressive. When supervisors and managers are themselves using WhatsApp for business communications, the supervisory structure that is supposed to enforce the policy is simultaneously undermining it. The regulatory finding is not just “employees violated the policy” — it’s “supervisors failed to enforce a policy they were personally violating.”
Step 4: Examiners find it anyway. One of the consistent features of these cases is that the off-channel communications often surfaced during examinations for other purposes — investigations into unrelated matters that led examiners to request communications records, which firms couldn’t produce because they had never been captured.
The implication: you may not know what’s happening on your employees’ personal phones. Your next examination might.
What “Supervision” Actually Requires After This Enforcement Wave
The standard reading of the off-channel communications cases is that they’re about records. That’s technically correct, but it understates the enforcement risk.
The deeper problem in many of these cases was supervisory failure. FINRA Rule 3110 requires member firms to establish and maintain a system to supervise the activities of each associated person — and Exchange Act Rule 17a-4 is part of that supervisory system. When supervisors use unapproved channels for business communications, they are simultaneously violating records requirements and demonstrating that the firm’s supervisory system doesn’t function.
The post-enforcement consent orders consistently require penalized firms to enhance their supervisory procedures specifically for electronic communications — not just enhance their written policy. The distinction is important. A supervisory procedure for electronic communications means:
- Regular spot checks of employee devices (with the appropriate consent and legal framework)
- Supervisors required to pre-approve or monitor employee communications channels
- Annual affirmative certification from supervisors that their teams are compliant, based on actual monitoring activity — not just a policy attestation
- Clear escalation procedures when off-channel use is detected
This maps directly to the larger compliance program design question of whether your supervisors are actually supervising, or simply attesting. The off-channel communications enforcement wave, read carefully, is partly an enforcement action about supervisory culture.
For a related perspective on how personal liability attaches to compliance officers who fail to supervise, see our earlier analysis of CCO personal liability in SEC and FINRA enforcement actions.
Remediation: What the Consent Orders Require
Understanding what penalized firms had to do helps clarify what a compliant program looks like before the exam:
Independent compliance consultant. Every major penalized firm was required to retain an independent compliance consultant to review and assess the firm’s policies and procedures related to electronic communications and records preservation. The consultant’s findings and recommendations were submitted to regulators.
Revised policies and procedures. Not just a policy update — a substantive revision of the policies governing electronic communications, approved channels, prohibited channels, and the consequences of violations.
Enhanced training. Annual training specifically on off-channel communications obligations, with documented completion records.
Technical controls. Implementation of mobile device management or approved messaging platforms that capture business communications from any device used for firm business. Or, alternatively, prohibition of personal device use for business communications enforced through technical controls.
Supervisory procedures. Specific procedures for supervisors to monitor employee compliance, not just a requirement that supervisors attest to compliance.
Annual certifications. Senior management certification that the firm has implemented compliant policies and procedures and that it is in compliance with those procedures.
This list is, functionally, a compliance program design checklist. If your firm’s current program checks all of these boxes, it’s better positioned than the firms that paid nine-figure penalties. If it doesn’t — if your “program” is a policy document that employees sign once a year — the gap between your current state and a compliant program is the gap that regulators are specifically looking for.
For more on how examiners evaluate supervisory program gaps and escalation failures, see our coverage of SEC insider trading and MNPI controls.
The Technology Question: MDM, Approved Platforms, or Prohibition?
Firms have taken three primary approaches to the technical controls problem:
Mobile device management (MDM). MDM tools allow firms to capture and archive communications on personal devices enrolled in the firm’s MDM system. The challenge: employee enrollment rates. In many firms, employees on BYOD (bring-your-own-device) programs can decline enrollment, which means MDM doesn’t solve the problem unless enrollment is required.
Approved messaging platforms. Platforms like Movius, Wickr, Symphony, or specialized compliance messaging tools that integrate with firm record-keeping systems. Communications on these platforms are automatically captured and archived. The challenge: if the approved platform is less convenient than WhatsApp, employees use WhatsApp.
Personal device prohibition. Some firms have moved to prohibiting any use of personal devices for firm business — requiring employees to use firm-issued devices only. This is the most technically enforceable approach but the hardest to operationalize for a workforce accustomed to BYOD.
There is no universally correct answer. What regulators look for is evidence that the firm made a deliberate choice about its approach, implemented technical controls consistent with that choice, and enforces those controls in practice — not just on paper.
So What?
The off-channel communications enforcement wave is not slowing down. The SEC and CFTC have established the framework, have proven they can find the violations, and have shown no inclination to ease up on the penalties. The question is not whether your firm will face scrutiny on this — it’s whether it will be able to demonstrate that its program is real.
The practical action items are straightforward, even if executing them isn’t easy:
Audit your current state. Do you know which messaging apps your employees are using on personal devices? Do you have any actual data on this, beyond annual attestations? If the answer is “no,” that’s the starting point.
Test your supervisory procedures. Are your supervisors actually monitoring for off-channel use, or are they signing attestations that assume it isn’t happening? Those are not the same thing.
Review your technical controls. Does your MDM cover all personal devices used for work, or only some? Are there gaps between what your policy says and what your technical controls enforce?
Document the program choices. If an examiner asks why your firm chose its current approach over alternatives, can you produce a documented rationale? The firms that have fared best in regulatory scrutiny are the ones that can show the deliberate design process, not just the current output.
The SEC has stated that the books and records requirements are foundational to market integrity — that examiners and investigators can’t do their work if communications are missing. From that framing, the enforcement wave isn’t going to stop until the industry demonstrates that the records actually exist.
External Sources:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are 'off-channel communications' in the context of SEC and FINRA enforcement?
Which rules require broker-dealers to preserve electronic communications?
What was the JP Morgan case that started this enforcement wave?
Does this apply to investment advisers, not just broker-dealers?
What does a compliant off-channel communications program actually require?
Can employees use personal devices for work at all without creating a recordkeeping problem?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
FINRA Rule 3290 Approved: Rebuild Your Outside Activities Program Before the Effective Date
FINRA Rule 3290 is approved. See what changes for outside activities, private securities transactions, supervision, records, and implementation.
Sep 17, 2026
Regulatory Compliance
SEC Innovation Exemption: The Control Blueprint for Tokenized Stock Trading
The SEC Innovation Exemption opens tokenized stock trading under strict volume, issuer-rights, disclosure, cyber, and recordkeeping controls.
Sep 17, 2026
Regulatory Compliance
SEC Rule 14a-8 Rescission Proposal: What Proxy Teams Need to Do Now
The SEC proposed rescinding Rule 14a-8 and rewriting proxy solicitation rules. See what changes, what stays, and how to prepare.
Sep 16, 2026