# Regulations

The communications compliance regulations that matter: FINRA 4511, SEC 17a-4, and more, explained for compliance teams across regulated industries.

Source: https://commacompliance.com/regulations
Last updated: 2026-08-25

---

# Regulatory Compliance

A compliance team's reference for the regulations that govern electronic communications and recordkeeping.

US Recordkeeping

-   [SEC Rule 17a-4](/regulations/sec-17a-4)

    Requires broker-dealers to retain all business communications — including mobile messaging. Here's what a compliant archive actually needs.

-   [FINRA Rule 4511](/regulations/finra-rule-4511)

    FINRA's books and records rule requires broker-dealers to create and preserve every required book and record, including all electronic communications.

-   [SEC Rule 17a-3](/regulations/sec-17a-3)

    Requires firms to create records of every business communication. Most firms focus on storage and skip this rule. What compliance means in practice.

-   [FINRA Rule 3110](/regulations/finra-rule-3110)

    Requires broker-dealers to establish a supervisory system and written supervisory procedures reasonably designed to achieve compliance — and prove it works.

-   [FINRA Rule 4530](/regulations/finra-rule-4530)

    The self-reporting rule. Firms must disclose specified events and certain internal conclusions of violations, generally within 30 calendar days of the applicable triggering point, and file quarterly statistics on written customer complaints.

-   [FINRA Off-Channel Communications](/regulations/finra-off-channel-communications)

    The SEC, FINRA, and the CFTC have issued $3.2B+ in fines since 2021 for off-channel messaging failures. What the enforcement record shows and what a compliant approach requires.

-   [FINRA Rule 2210](/regulations/finra-2210)

    FINRA Rule 2210 requires broker-dealers to review, approve, and retain all public communications, including social media. What a compliant program actually needs.

-   [FINRA Rule 2220](/regulations/finra-rule-2220)

    FINRA Rule 2220 governs options communications — approval by a Registered Options Principal, FINRA pre-filing requirements, and content standards for retail, institutional, and correspondence.

-   [Investment Advisers Act Rule 204-2](/regulations/investment-advisers-act-rule-204-2)

    The books and records rule for SEC-registered investment advisers. Rule 204-2 covers mobile messaging — WhatsApp, iMessage, Signal — not just email.

-   [SEC/FINRA Exam-Ready Checklist](/regulations/exam-ready-checklist)

    A practical checklist for RIAs and broker-dealers preparing for examination — archive readiness, WSPs, supervision documentation, and what examiners actually check.

Global Financial Frameworks

-   [BCBS 239](/key-compliance-terms#gloss-B)

    Basel Committee principles for effective risk data aggregation and risk reporting. Increasingly applied by global supervisors as a data-governance benchmark for AI activity and communications pipelines at G-SIBs and D-SIBs.

-   [DORA (Digital Operational Resilience Act)](/regulations/dora)

    EU regulation applying since 17 January 2025. Covers every EU financial entity and the ICT third parties that serve them, including communications-capture vendors.

-   [MAR (Market Abuse Regulation)](/key-compliance-terms#gloss-M)

    EU regulation requiring firms to retain communications and orders related to financial instruments. Off-channel and AI-assisted messages are routinely requested in MAR investigations.

-   [MiFID II](https://www.esma.europa.eu/policy-rules/mifid-ii-and-mifir)

    EU markets directive requiring recording of electronic communications and phone calls relating to financial instruments. The benchmark for European communications compliance.

AI Governance

-   [EU AI Act](/regulations/eu-ai-act)

    Largest AI-specific law in force globally. Article 12 (logging), Article 14 (human oversight), and Annex III (high-risk use cases including credit, insurance, and access to financial services) govern AI activity at regulated firms.

-   [NIST AI RMF](/key-compliance-terms#gloss-N)

    US National Institute of Standards and Technology framework for managing AI risk across the lifecycle. Voluntary but widely cited; the de facto US AI risk standard.

-   [ISO/IEC 42001](/key-compliance-terms#gloss-I)

    International AI management systems standard published in 2023. Increasingly cited on enterprise RFPs as the SOC 2 of AI governance.

-   [Revised Guidance on Model Risk Management (2026)](/regulations/model-risk-management-2026)

    SR 11-7 has been superseded. The OCC, Federal Reserve, and FDIC issued risk-based guidance in April 2026. Generative AI and agentic AI are outside its scope; banks should use existing governance practices for those systems.

## Coming soon

-   Dedicated deep-dive pages for BCBS 239, MAR, NIST AI RMF, and ISO/IEC 42001

## See how Comma keeps you exam-ready.

Book a 20-minute walkthrough — real capture, real-time flagging, and exports built for regulators.

[Get in Touch](/get-in-touch)[Pricing](/pricing)

Related reading

-   [Resource Guide for Compliance and Regulations](/resources)

    Includes terminology, guides, and compliance explainers.
