CudaraCudara
Request a Demo
← Back to blog

What SEC and FINRA Actually Expect From Your Communications Archive

Published on March 1, 2025·Author: Cudara Team·4 min read

If you're an RIA or broker-dealer, you know you have to archive communications. But what exactly do the SEC and FINRA expect—and how do you prove you're compliant when examiners show up?

This guide breaks down the real requirements: Rule 17a-4, WORM storage, readily accessible, and the edge cases that trip firms up (email, chat, social, personal devices).

Communications archive requirements


The short version

  • SEC Rule 17a-4 (and related rules) requires broker-dealers to preserve certain records in a non-rewriteable, non-erasable format (WORM) and to keep them readily accessible for the duration of the retention period.
  • RIAs are subject to Advisers Act record-keeping rules that overlap in spirit: you must keep and retain records in a way that supports examination and cannot be altered or deleted to hide misconduct.
  • "Readily accessible" means examiners can get what they need without you rebuilding or restoring from backups—so your archive must be searchable and producible in a reasonable time.

What is WORM, and why does it matter?

WORM = Write Once, Read Many. Regulators want to ensure that once a communication is captured, it can't be overwritten or erased. That protects the integrity of the record and supports enforcement.

RequirementWhat it means in practice
Non-rewriteableRecords can't be edited after capture.
Non-erasableRecords can't be deleted before the end of the retention period.
Readily accessibleYou can search and produce them for examiners without undue delay.
Retention periodTypically 3–6+ years depending on record type; know your obligations.

If your "archive" is just a shared drive or inbox that admins can delete from, you're not meeting the standard. You need a system that enforces immutability and retention.


What has to be archived?

Coverage depends on whether you're an RIA, broker-dealer, or both. In general, business-related communications that relate to recommendations, orders, or advice need to be captured.

ChannelOften in scopeEdge cases
EmailYes—business email used for firm businessPersonal email used for firm business; forwarding to personal.
Instant message / chatYes—if used for businessOff-channel (e.g. WhatsApp, iMessage) used for client or order-related talk.
Social mediaYes—posts and DMs that are business-relatedWho posts (firm vs rep), what counts as an ad vs. personal.
Video / meetingsIncreasingly in scopeRecordings, links, and summaries may need to be retained.

Edge case: personal devices. If reps use personal phones or email for firm business, those communications are still subject to the same rules. Your policies and technology need to account for that (e.g. capture at the firm level or require business-only channels).


Readily accessible: what examiners want

"Readily accessible" doesn't just mean "we have it somewhere." It means:

  • Searchable — By date, person, topic, or other criteria examiners care about.
  • Producible — You can export or provide access in a format they can use.
  • Timely — No "we'll need two weeks to restore from backup." Your archive should support same-day or next-day production for exam requests.

If you can't run a targeted search and produce results within a reasonable window, you're at risk of being cited for record-keeping failures.


FAQ

Do we need to archive every Slack message?
If Slack (or similar) is used for business-related communications that relate to recommendations, orders, or advice, then yes—those messages need to be captured and retained per your applicable rules.

What if we use personal email for some client communication?
If it's firm business, it's subject to the same retention and accessibility requirements. Best practice is to use firm-captured channels or a solution that captures copies of sent/received business communication.

How long do we have to keep communications?
It varies by record type and regulator. Broker-dealer 17a-4 has specific retention periods (e.g. 3 or 6 years). RIAs have their own retention rules. Confirm with your compliance lead or counsel and document your retention schedule.

Can we use the cloud?
Yes. Cloud storage can meet WORM and retention requirements if the provider and configuration support non-rewriteable, non-erasable storage and your ability to search and produce is maintained.


Bottom line

SEC and FINRA expect your communications archive to be complete (all in-scope channels), immutable (WORM), retained for the required period, and readily accessible for examination. Getting this right reduces exam risk and gives you confidence when examiners ask for records.

See how Cudara keeps your communications archive audit-ready — capture, retain, and produce with the controls examiners expect.

Stay on top of compliance

See how Cudara helps advisory firms stay audit-ready and save thousands of hours.

Request a Demo

More posts

  • The Best AI Compliance Tools for Financial Services & Insurance in 2026

    We compare leading AI compliance platforms—Greenboard, Norm AI, Blee, Hadrius, Warrant, and Cudara—so you can choose the right fit for advisers and broker-dealers.

    February 15, 2026

  • How We Think About Building Compliance Software for Advisers

    Cudara's point of view: why we focus on archiving, employee compliance, and filings—and the trade-offs we made so we don't become another bloated suite.

    July 1, 2025

  • Frequently Asked Questions About SEC and FINRA Communications Compliance

    One place for common questions: retention, channels, exams, vendors, 'readily accessible,' and mistakes to avoid.

    June 15, 2025

Don't let outdated tools put your firm at risk

Request a Demo
Cudara

Copyright © 2026 Cudara. All rights reserved.

Product

  • Communications Archive→
  • Employee Compliance→
  • Marketing Compliance→
  • Firm Compliance→
  • Third Party Compliance→
  • Financial Compliance→

Solutions

  • Financial Advisors→
  • Private Funds→
  • Hedge Funds→
  • Broker Dealers→
  • RIAs→
  • Service Partners→

Company

  • About→

Resources

  • Blog→
  • Terms of Service→
  • Privacy Policy→

Copyright © 2026 Cudara. All rights reserved.