Skip to content
RiskTemplates · The Daily Brief Thursday, September 17, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Regulatory Compliance

Your Firm's Personal Device Policy Isn't Working. What $2 Billion in SEC and CFTC Penalties Reveals About Off-Channel Communications Compliance.

Since December 2021, the SEC and CFTC have collected more than $2 billion from broker-dealers and investment advisers for off-channel communications violations. The pattern is identical every time: a written policy, zero enforcement, and years of communications that were never captured. Here's what a compliant program actually looks like.

By Rebecca Leung · September 17, 2026 ·
Table of Contents

TL;DR

  • The SEC and CFTC have collected more than $2 billion from broker-dealers and investment advisers for off-channel communications violations since December 2021, in a coordinated enforcement wave with no sign of stopping.
  • The violation pattern is the same in every case: employees used WhatsApp, iMessage, Signal, or similar personal messaging apps for business communications that were never captured in the firm’s record-keeping system — violating Exchange Act Rules 17a-3 and 17a-4.
  • A written policy prohibiting off-channel communications is not a defense. Examiners look at whether the policy was actually enforced, whether supervisors complied with it, and whether the firm had technical controls in place to make it real.
  • Every registered broker-dealer and investment adviser needs to treat this as an active examination risk — not a problem solved by having a policy on the books.

When the SEC and CFTC announced a $200 million combined penalty against J.P. Morgan Securities in December 2021, the compliance community took notice. When the same regulators announced more than $1.1 billion in combined penalties against fifteen additional firms nine months later, it became clear this was not an isolated enforcement action — it was a systematic examination priority with no obvious endpoint.

By any measure, the off-channel communications enforcement wave is one of the most sustained and financially significant regulatory campaigns in securities industry history. And yet, the underlying legal obligation that drives it — the requirement to preserve all business-related written communications — has been on the books for decades.

That’s the uncomfortable reality this enforcement wave reveals. The firms that paid nine-figure penalties weren’t caught off guard by a new rule. They were caught off guard by a regulator who decided to actually enforce an old one.

What Exchange Act Rule 17a-4 Actually Says

Section 17(a) of the Securities Exchange Act of 1934 grants the SEC authority to require broker-dealers to make and keep records and to submit reports. Exchange Act Rule 17a-3 specifies what records broker-dealers must create — including records of all communications relating to their business. Exchange Act Rule 17a-4 specifies how long those records must be kept: at least three years for most business records, with the first two years in an easily accessible location.

The rule’s application to electronic communications is not a recent development. The SEC extended Rule 17a-4’s requirements to email in the 1990s. Text messages, instant messages, and chat platforms are electronic communications. They are records relating to the firm’s business. The rule applies.

FINRA Rule 4511, which requires FINRA member firms to make and preserve books and records, similarly covers electronic communications on any platform. Rule 4511 expressly applies to electronic communications, and FINRA has consistently enforced it in coordination with SEC requirements.

For investment advisers, the parallel obligation comes from Advisers Act Rule 204-2, which requires investment advisers to preserve copies of all written communications, including electronic communications related to investment advice and recommendations.

The legal framework is not complicated. What changed in December 2021 was not the rule — it was the enforcement posture.

The Enforcement Wave: From JP Morgan to the Present

December 2021: J.P. Morgan Securities — $200 million

The SEC charged J.P. Morgan Securities LLC with widespread and longstanding failures to maintain and preserve electronic communications required by Rule 17a-4 and FINRA Rule 4511. The violations were not limited to junior employees. Senior employees, including managing directors, routinely used WhatsApp and personal devices to conduct business communications about securities transactions, investment strategies, and client matters — none of which were ever captured in the firm’s record-keeping system.

J.P. Morgan’s written policy prohibited personal device use for firm business. That policy did not prevent the violations. It did not prevent the $125 million SEC penalty, the $75 million CFTC penalty, or the requirement to retain an independent compliance consultant.

September 2022: The $1.1 Billion Coordinated Action

Nine months later, the SEC and CFTC announced a coordinated enforcement action against fifteen broker-dealers and one affiliated investment adviser, resulting in approximately $1.1 billion in combined SEC and CFTC penalties. The firms charged included major Wall Street institutions: Barclays Capital, Bank of America Securities, Citigroup Global Markets, Credit Suisse Securities, Deutsche Bank Securities, Goldman Sachs, Jefferies, Morgan Stanley, Nomura Securities, and UBS Securities, among others.

Every single firm charged had a written policy prohibiting the use of unapproved communications methods for business communications. Every single firm charged had employees — including supervisors and senior managers — who used WhatsApp, iMessage, Signal, or other personal messaging apps for business communications that were never preserved.

The SEC’s language in the orders was direct: the violations were “widespread and longstanding” — in some cases spanning years. Senior employees knew the rules. They violated them anyway. And supervisors who were themselves violating the policy did not enforce it against their teams.

2023 Onward: More Firms, More Penalties

The enforcement wave did not stop in 2022. In 2023 and 2024, the SEC and CFTC continued charging additional firms, including regional broker-dealers, investment banks, and registered investment advisers. The total combined penalties across all off-channel communications enforcement actions exceeded $2 billion.

The regulators have been explicit about why: they are not done. Every new action comes with the same finding — widespread off-channel use, supervisors involved, and written policies that existed only on paper.

The Pattern That Connects Every Case

Reading through the enforcement orders, the violations share a structure that is worth understanding, because it’s the structure your compliance program needs to break.

Step 1: Written policy exists. Every penalized firm had a policy. In most cases, the policy was reviewed annually. Employees attested to reading it.

Step 2: No technical controls enforce it. The firms generally had not implemented mobile device management (MDM) tools, approved messaging platforms, or technical controls that would either capture personal device communications or block them from being used for firm business. The policy was a document. It wasn’t a program.

Step 3: Supervisors were among the violators. This is the element that makes the enforcement posture particularly aggressive. When supervisors and managers are themselves using WhatsApp for business communications, the supervisory structure that is supposed to enforce the policy is simultaneously undermining it. The regulatory finding is not just “employees violated the policy” — it’s “supervisors failed to enforce a policy they were personally violating.”

Step 4: Examiners find it anyway. One of the consistent features of these cases is that the off-channel communications often surfaced during examinations for other purposes — investigations into unrelated matters that led examiners to request communications records, which firms couldn’t produce because they had never been captured.

The implication: you may not know what’s happening on your employees’ personal phones. Your next examination might.

What “Supervision” Actually Requires After This Enforcement Wave

The standard reading of the off-channel communications cases is that they’re about records. That’s technically correct, but it understates the enforcement risk.

The deeper problem in many of these cases was supervisory failure. FINRA Rule 3110 requires member firms to establish and maintain a system to supervise the activities of each associated person — and Exchange Act Rule 17a-4 is part of that supervisory system. When supervisors use unapproved channels for business communications, they are simultaneously violating records requirements and demonstrating that the firm’s supervisory system doesn’t function.

The post-enforcement consent orders consistently require penalized firms to enhance their supervisory procedures specifically for electronic communications — not just enhance their written policy. The distinction is important. A supervisory procedure for electronic communications means:

  • Regular spot checks of employee devices (with the appropriate consent and legal framework)
  • Supervisors required to pre-approve or monitor employee communications channels
  • Annual affirmative certification from supervisors that their teams are compliant, based on actual monitoring activity — not just a policy attestation
  • Clear escalation procedures when off-channel use is detected

This maps directly to the larger compliance program design question of whether your supervisors are actually supervising, or simply attesting. The off-channel communications enforcement wave, read carefully, is partly an enforcement action about supervisory culture.

For a related perspective on how personal liability attaches to compliance officers who fail to supervise, see our earlier analysis of CCO personal liability in SEC and FINRA enforcement actions.

Understanding what penalized firms had to do helps clarify what a compliant program looks like before the exam:

Independent compliance consultant. Every major penalized firm was required to retain an independent compliance consultant to review and assess the firm’s policies and procedures related to electronic communications and records preservation. The consultant’s findings and recommendations were submitted to regulators.

Revised policies and procedures. Not just a policy update — a substantive revision of the policies governing electronic communications, approved channels, prohibited channels, and the consequences of violations.

Enhanced training. Annual training specifically on off-channel communications obligations, with documented completion records.

Technical controls. Implementation of mobile device management or approved messaging platforms that capture business communications from any device used for firm business. Or, alternatively, prohibition of personal device use for business communications enforced through technical controls.

Supervisory procedures. Specific procedures for supervisors to monitor employee compliance, not just a requirement that supervisors attest to compliance.

Annual certifications. Senior management certification that the firm has implemented compliant policies and procedures and that it is in compliance with those procedures.

This list is, functionally, a compliance program design checklist. If your firm’s current program checks all of these boxes, it’s better positioned than the firms that paid nine-figure penalties. If it doesn’t — if your “program” is a policy document that employees sign once a year — the gap between your current state and a compliant program is the gap that regulators are specifically looking for.

For more on how examiners evaluate supervisory program gaps and escalation failures, see our coverage of SEC insider trading and MNPI controls.

The Technology Question: MDM, Approved Platforms, or Prohibition?

Firms have taken three primary approaches to the technical controls problem:

Mobile device management (MDM). MDM tools allow firms to capture and archive communications on personal devices enrolled in the firm’s MDM system. The challenge: employee enrollment rates. In many firms, employees on BYOD (bring-your-own-device) programs can decline enrollment, which means MDM doesn’t solve the problem unless enrollment is required.

Approved messaging platforms. Platforms like Movius, Wickr, Symphony, or specialized compliance messaging tools that integrate with firm record-keeping systems. Communications on these platforms are automatically captured and archived. The challenge: if the approved platform is less convenient than WhatsApp, employees use WhatsApp.

Personal device prohibition. Some firms have moved to prohibiting any use of personal devices for firm business — requiring employees to use firm-issued devices only. This is the most technically enforceable approach but the hardest to operationalize for a workforce accustomed to BYOD.

There is no universally correct answer. What regulators look for is evidence that the firm made a deliberate choice about its approach, implemented technical controls consistent with that choice, and enforces those controls in practice — not just on paper.

So What?

The off-channel communications enforcement wave is not slowing down. The SEC and CFTC have established the framework, have proven they can find the violations, and have shown no inclination to ease up on the penalties. The question is not whether your firm will face scrutiny on this — it’s whether it will be able to demonstrate that its program is real.

The practical action items are straightforward, even if executing them isn’t easy:

Audit your current state. Do you know which messaging apps your employees are using on personal devices? Do you have any actual data on this, beyond annual attestations? If the answer is “no,” that’s the starting point.

Test your supervisory procedures. Are your supervisors actually monitoring for off-channel use, or are they signing attestations that assume it isn’t happening? Those are not the same thing.

Review your technical controls. Does your MDM cover all personal devices used for work, or only some? Are there gaps between what your policy says and what your technical controls enforce?

Document the program choices. If an examiner asks why your firm chose its current approach over alternatives, can you produce a documented rationale? The firms that have fared best in regulatory scrutiny are the ones that can show the deliberate design process, not just the current output.

The SEC has stated that the books and records requirements are foundational to market integrity — that examiners and investigators can’t do their work if communications are missing. From that framing, the enforcement wave isn’t going to stop until the industry demonstrates that the records actually exist.


External Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are 'off-channel communications' in the context of SEC and FINRA enforcement?
Off-channel communications are work-related communications conducted through methods not captured in a firm's required books and records systems — most commonly WhatsApp, iMessage, Signal, and other personal messaging apps on employees' personal devices. Exchange Act Rule 17a-4 requires broker-dealers to preserve all business-related written communications. When employees use personal messaging apps that aren't captured and preserved, every message is an independent recordkeeping violation.
Which rules require broker-dealers to preserve electronic communications?
Three primary rules: (1) Exchange Act Rule 17a-3 requires broker-dealers to create records of all communications relating to their business; (2) Exchange Act Rule 17a-4 requires broker-dealers to preserve those records for at least three years, with the first two years easily accessible; and (3) FINRA Rule 4511 requires FINRA member firms to make and preserve books and records in conformity with Exchange Act requirements. Together, these create an obligation to capture and preserve all business-related electronic communications, regardless of the platform or device.
What was the JP Morgan case that started this enforcement wave?
In December 2021, the SEC and CFTC announced a combined $200 million penalty against J.P. Morgan Securities LLC for widespread and longstanding failures to maintain and preserve electronic communications. Employees at all levels — including senior managing directors — had routinely used personal devices and WhatsApp to conduct business communications that were never preserved. The case established that the existing records rules applied in full to personal messaging apps and set the template for every enforcement action that followed.
Does this apply to investment advisers, not just broker-dealers?
Yes. Investment Advisers Act Rule 204-2 (the books and records rule for investment advisers) requires preservation of business-related communications, including electronic communications. The same obligation to capture and preserve applies. Several investment adviser firms were included in the September 2022 coordinated enforcement action, and the SEC has been explicit that the rules apply equally to registered investment advisers.
What does a compliant off-channel communications program actually require?
A compliant program has five elements: (1) a written policy clearly stating which channels are approved and which are prohibited; (2) technical controls, such as mobile device management or approved messaging platforms, that make the policy enforceable; (3) annual employee training and attestation that employees have read, understood, and will comply with the policy; (4) supervisory procedures requiring managers to actively monitor for off-channel use, not just attest it isn't happening; and (5) a meaningful consequence framework — not just a theoretical one — that employees know is enforced.
Can employees use personal devices for work at all without creating a recordkeeping problem?
Yes, with clear boundaries. Most firms have adopted a channel-boundary approach: firm-related business communications — anything about client accounts, securities transactions, research, advisory activity, or firm business — must occur exclusively on firm-approved channels. Personal devices can be used for purely personal communications. The compliance problem arises when those boundaries blur, which they do constantly: a text to a colleague about a meeting morphs into a discussion of a client position. That's why the technical enforcement of approved channels matters more than the written policy.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.