BYOD Messaging Compliance

Your employees are using personal devices. That doesn't change your obligations.

FINRA is explicit: the recordkeeping obligation follows the communication, not the device.

Bring Your Own Device (BYOD) refers to employees using personal phones, tablets, or laptops for business activity. In financial services, the compliance question isn’t whether to allow it it’s whether business communications on personal devices are being captured and retained.

FINRA Regulatory Notice 11-39 is unambiguous:

“Firms may permit their associated persons to use any personal communication device… the firm must be able to retain, retrieve and supervise business communications regardless of whether they are conducted from a device owned by the firm or by the associated person.” FINRA Regulatory Notice 11-39

The obligation follows the communication. A client conversation on a personal iPhone is subject to the same recordkeeping requirements as one on a firm-issued device.

The enforcement gap

Most firms fined in the SEC and FINRA off-channel sweep had BYOD policies. The policy wasn’t the problem. The missing record was.

Under SEC Rule 17a-4 and FINRA Rule 4511, every business communication must be captured at point of delivery, retained in WORM-compliant storage for 6 years, and producible on demand.

A policy that prohibits personal device use without a mechanism to detect violations or capture when use occurs anyway doesn’t satisfy these requirements.

For compliance officers: what your WSPs need to cover

FINRA Rule 3110 requires Written Supervisory Procedures that specifically address BYOD. Examiners will ask:

What your WSPs must include:

What gets you cited:

The stronger position: document that business communications on personal devices are captured automatically regardless of channel. Examiners care about records, not prohibitions.

For IT and operations: what capture actually requires

The challenge with personal devices isn’t policy it’s architecture. Standard approaches have significant gaps.

MDM (Mobile Device Management) can enforce policies and wipe devices, but doesn’t capture message content from apps like WhatsApp, Signal, or iMessage. It tells you what apps are installed. It doesn’t archive what was said.

Backup-based archiving misses messages deleted before the next backup runs, or sent while the device was offline. Gaps in backup timing are gaps in the record.

Capture at point of delivery is the compliant path. Comma captures business communications as an authorized participant in the conversation at point of delivery, before any backup or device dependency. Only messages with business contacts are captured. Personal conversations are not touched.

This means employees use their own devices normally, no MDM enrollment is required, and business communications are captured automatically regardless of device settings or backup schedules.

The privacy question

The most common objection to BYOD capture is employee privacy. It’s a legitimate concern and it’s why the distinction between business and personal communications matters.

Comma captures by contact, not by device. If a message is with a business contact, it’s captured. If it’s with a family member, it isn’t. Employees keep full control over personal conversations. That distinction is what makes BYOD compliance workable without eroding employee trust.

What examiners check

During a BYOD-related examination, expect:

Internal alignment

Most BYOD compliance projects stall before they reach a vendor. The blocker is internal. At some point, every compliance officer brings capture to HR and legal and hits the same three objections. Here’s how to answer them.

“What about personal messages?”

Capture is contact-based, not device-based. Messages with designated business contacts are archived. Messages to personal contacts are not retained — they aren’t held, reviewed, or stored as business records. One edge case worth flagging: if a group chat includes both business and personal contacts, that conversation is captured because a business contact is present. Employees can see exactly which contacts are marked as business in the platform.

“This feels like surveillance.”

Email has been archived at every regulated firm for 20 years. No one calls that surveillance. WhatsApp used for client communication is the same category: a business channel with a recordkeeping obligation attached. The question isn’t whether to monitor — it’s whether to comply. Firms that have treated messaging differently from email are the ones paying eight-figure fines.

“What’s our liability if we capture and get breached?”

Weigh it against the alternative. The firms fined in the SEC and FINRA off-channel sweep faced hundreds of millions in penalties — not for being breached, but for having no records at all. Captured data stored in WORM-compliant, encrypted archives with strict access controls is a manageable risk. Missing records during a regulatory examination are not. Legal’s job is to weigh liability in both directions. Every firm that has been fined wishes it had captured. None has been fined for capturing.

FAQ

FAQ about BYOD Messaging Compliance

Does FINRA require firms to prohibit personal devices?
No. FINRA requires firms to capture and retain business communications regardless of which device they occur on. Prohibition is one option. Capture is another and a stronger compliance position.
What if an employee refuses to enroll their device in MDM?
This is why device-level approaches create friction. Capture that operates at the application layer not the device level doesn't require MDM enrollment. Employees keep control of their devices.
Do these rules apply to RIAs as well as broker-dealers?
Yes. RIAs are governed by the Investment Advisers Act and SEC Rule 204-2, which carry equivalent recordkeeping obligations. The BYOD obligation is the same.
What happens if an employee deletes a message before it's captured?
Point-of-delivery capture eliminates this risk. The message is captured when it arrives before any backup cycle, before any deletion. The record exists independent of what happens on the device afterward.

Related reading

See how Comma handles BYOD compliance

Comma captures business communications on personal devices without MDM enrollment, device agents, or personal data access. Book a demo to see it in action.