US Recordkeeping
- SEC Rule 17a-4Requires broker-dealers to retain all business communications — including mobile messaging. Here's what a compliant archive actually needs.
- FINRA Rule 4511FINRA's books and records rule requires broker-dealers to create and preserve every required book and record, including all electronic communications.
- SEC Rule 17a-3Requires firms to create records of every business communication. Most firms focus on storage and skip this rule. What compliance means in practice.
- FINRA Rule 3110Requires broker-dealers to establish a supervisory system and written supervisory procedures reasonably designed to achieve compliance — and prove it works.
- FINRA Rule 4530The self-reporting rule. Firms must disclose specified events and certain internal conclusions of violations, generally within 30 calendar days of the applicable triggering point, and file quarterly statistics on written customer complaints.
- FINRA Off-Channel CommunicationsThe SEC, FINRA, and the CFTC have issued $3.2B+ in fines since 2021 for off-channel messaging failures. What the enforcement record shows and what a compliant approach requires.
- FINRA Rule 2210FINRA Rule 2210 requires broker-dealers to review, approve, and retain all public communications, including social media. What a compliant program actually needs.
- FINRA Rule 2220FINRA Rule 2220 governs options communications — approval by a Registered Options Principal, FINRA pre-filing requirements, and content standards for retail, institutional, and correspondence.
- Investment Advisers Act Rule 204-2The books and records rule for SEC-registered investment advisers. Rule 204-2 covers mobile messaging — WhatsApp, iMessage, Signal — not just email.
- SEC/FINRA Exam-Ready ChecklistA practical checklist for RIAs and broker-dealers preparing for examination — archive readiness, WSPs, supervision documentation, and what examiners actually check.
Global Financial Frameworks
- BCBS 239Basel Committee principles for effective risk data aggregation and risk reporting. Increasingly applied by global supervisors as a data-governance benchmark for AI activity and communications pipelines at G-SIBs and D-SIBs.
- DORA (Digital Operational Resilience Act)EU regulation applying since 17 January 2025. Covers every EU financial entity and the ICT third parties that serve them, including communications-capture vendors.
- MAR (Market Abuse Regulation)EU regulation requiring firms to retain communications and orders related to financial instruments. Off-channel and AI-assisted messages are routinely requested in MAR investigations.
- MiFID IIEU markets directive requiring recording of electronic communications and phone calls relating to financial instruments. The benchmark for European communications compliance.
AI Governance
- EU AI ActLargest AI-specific law in force globally. Article 12 (logging), Article 14 (human oversight), and Annex III (high-risk use cases including credit, insurance, and access to financial services) govern AI activity at regulated firms.
- NIST AI RMFUS National Institute of Standards and Technology framework for managing AI risk across the lifecycle. Voluntary but widely cited; the de facto US AI risk standard.
- ISO/IEC 42001International AI management systems standard published in 2023. Increasingly cited on enterprise RFPs as the SOC 2 of AI governance.
- Revised Guidance on Model Risk Management (2026)SR 11-7 has been superseded. The OCC, Federal Reserve, and FDIC issued risk-based guidance in April 2026. Generative AI and agentic AI are outside its scope; banks should use existing governance practices for those systems.
Coming soon
- Dedicated deep-dive pages for BCBS 239, MAR, NIST AI RMF, and ISO/IEC 42001
See how Comma keeps you exam-ready.
Book a 20-minute walkthrough — real capture, real-time flagging, and exports built for regulators.
Related reading
