US Recordkeeping
- SEC Rule 17a-4Requires broker-dealers to retain all business communications — including mobile messaging. Here's what a compliant archive actually needs.
- FINRA Rule 4511FINRA's books and records rule requires broker-dealers to create and preserve every required book and record, including all electronic communications.
- SEC Rule 17a-3Requires firms to create records of every business communication. Most firms focus on storage and skip this rule. What compliance means in practice.
- FINRA Rule 3110Requires broker-dealers to establish a supervisory system and written supervisory procedures reasonably designed to achieve compliance — and prove it works.
- FINRA Off-Channel CommunicationsFINRA and the SEC have issued $2B+ in fines since 2021 for off-channel messaging failures. What the enforcement record shows and what a compliant approach requires.
- FINRA Rule 2210FINRA Rule 2210 requires broker-dealers to review, approve, and retain all public communications, including social media. What a compliant program actually needs.
- FINRA Rule 2220FINRA Rule 2220 governs options communications — approval by a Registered Options Principal, FINRA pre-filing requirements, and content standards for retail, institutional, and correspondence.
- Investment Advisers Act Rule 204-2The books and records rule for SEC-registered investment advisers. Rule 204-2 covers mobile messaging — WhatsApp, iMessage, Signal — not just email.
- SEC/FINRA Exam-Ready ChecklistA practical checklist for RIAs and broker-dealers preparing for examination — archive readiness, WSPs, supervision documentation, and what examiners actually check.
Global Financial Frameworks
- BCBS 239Basel Committee principles for effective risk data aggregation and risk reporting. Increasingly applied by global supervisors as a data-governance benchmark for AI activity and communications pipelines at G-SIBs and D-SIBs.
- DORA (Digital Operational Resilience Act)EU regulation applying since 17 January 2025. Covers every EU financial entity and the ICT third parties that serve them, including communications-capture vendors.
- MAR (Market Abuse Regulation)EU regulation requiring firms to retain communications and orders related to financial instruments. Off-channel and AI-assisted messages are routinely requested in MAR investigations.
- MiFID IIEU markets directive requiring recording of electronic communications and phone calls relating to financial instruments. The benchmark for European communications compliance.
AI Governance
- EU AI ActLargest AI-specific law in force globally. Article 12 (logging), Article 14 (human oversight), and Annex III (high-risk use cases including credit, insurance, and access to financial services) govern AI activity at regulated firms.
- NIST AI RMFUS National Institute of Standards and Technology framework for managing AI risk across the lifecycle. Voluntary but widely cited; the de facto US AI risk standard.
- ISO/IEC 42001International AI management systems standard published in 2023. Increasingly cited on enterprise RFPs as the SOC 2 of AI governance.
- Revised Guidance on Model Risk Management (2026)SR 11-7 has been superseded. The OCC, Federal Reserve, and FDIC issued risk-based guidance in April 2026. Generative AI and agentic AI are outside its scope; banks should use existing governance practices for those systems.
Coming soon
- Dedicated deep-dive pages for BCBS 239, MAR, NIST AI RMF, and ISO/IEC 42001
See how Comma keeps you exam-ready.
Book a 20-minute walkthrough — real capture, real-time flagging, and exports built for regulators.
Related reading
