Text message archiving for financial advisors is a federal recordkeeping obligation: any text that touches firm business must be captured, stored in tamper-evident form, and retained for years, regardless of whether the message went out on a company phone or a personal one. Broker-dealers work under SEC Rule 17a-4 and FINRA Rule 4511. Registered investment advisers work under SEC Rule 204-2. Dually registered firms answer to both. Since 2021, the SEC and FINRA have imposed roughly $2.7 billion in combined penalties on firms that failed to meet these requirements.
Which Rule Governs Your Firm
Registration status decides the framework. FINRA Rule 4511 requires member firms to create and preserve books and records as required under FINRA rules and the Securities Exchange Act, and preservation must comply with the format standards of SEC Rule 17a-4.1FINRA. FINRA Rule 4511 – General Requirements Registered investment advisers work under a separate rule, 17 CFR 275.204-2, which requires originals of all written communications received and copies of all written communications sent that relate to recommendations, advice, fund transfers, securities orders, or account performance.2eCFR. 17 CFR 275.204-2 – Books and Records to Be Maintained by Investment Advisers
The SEC has confirmed that “written communications” in the adviser rule includes text messages, instant messages, and messages sent through personal email or private messaging platforms.3U.S. Securities and Exchange Commission. OCIE Risk Alert – Electronic Messaging If your firm carries both registrations, both rules apply at the same time and you should default to the stricter requirement on any given point.
The Content Test, Not the Channel
Regulators look at what the message says, not which app carried it or whose phone sent it. A text confirming a client lunch to discuss portfolio allocation is a business record. A text to that same client about weekend plans is not. Substance controls.
That test is what puts Bring Your Own Device policies under pressure. When advisors use personal phones for client conversations, the firm is still on the hook for capturing those messages. Every SEC off-channel sweep since 2021 has centered on firms where personal-device texting went unmonitored. Allowing personal devices without an archiving solution creates a gap regulators have shown no tolerance for.
What a Compliant Archive Entry Contains
Capturing the text of a message by itself does not satisfy the rules. A complete record needs several layers:
- Sender and recipient identity, with verified names tied to phone numbers rather than raw numbers alone.
- Timestamps precise enough to establish the order of messages.
- Attachments and media, including images, PDFs, and voice notes shared in the thread.
- Thread context showing the surrounding exchange, not isolated messages pulled out of sequence.
Compliance officers must be able to search and filter these records by person, date range, or keyword during internal reviews and in response to regulatory requests. A screenshot almost never qualifies, because it lacks verified metadata and can be altered. The archive has to hold records in an immutable format that stays readable for the entire retention window.
How Long You Have to Keep Messages
Retention length depends on your registration, and the timelines are different enough that mixing them up is one of the easier mistakes to make.
Broker-Dealers
Under SEC Rule 17a-4, business-related communications must be preserved for at least three years, with the first two years in an easily accessible location for immediate inspection. Certain records tied to general ledger accounts and bookkeeping carry a longer six-year period.4FINRA. SEA Rule 17a-4 and Related Interpretations
Investment Advisers
Rule 204-2 sets a five-year baseline. Communications relating to recommendations, advice, securities transactions, and account performance must be kept for at least five years from the end of the fiscal year in which the last entry was made, with the first two years in an appropriate office of the adviser.2eCFR. 17 CFR 275.204-2 – Books and Records to Be Maintained by Investment Advisers Dually registered firms should treat the five-year window as the working minimum.
Your system needs to track the age of each message automatically and block deletion before the window closes. Premature deletion, even by accident, is a books-and-records violation.
Storage Format: WORM or Audit Trail
The original version of Rule 17a-4 required electronic records to sit in a non-rewriteable, non-erasable format known as WORM (write once, read many). The SEC amended the rule to offer firms a choice between two approaches.5U.S. Securities and Exchange Commission. Amendments to Electronic Recordkeeping Requirements for Broker-Dealers
- WORM storage. Records are written once and cannot be modified or deleted. Still valid, still widely used.
- Audit-trail alternative. Records can sit on systems that allow modification, but the system must maintain a complete time-stamped audit trail showing every change or deletion, who made it, and when, and must be able to recreate the original record at any point.6U.S. Securities and Exchange Commission. Frequently Asked Questions Regarding Rule Amendments to Broker-Dealer Electronic Recordkeeping Requirements
The audit-trail path gives firms wider vendor choice, since the system no longer has to physically prevent edits. The trade-off is a heavier technical burden: the trail must capture the identity of anyone touching the record, the exact timestamp of each action, and enough data to reconstruct the original with full authenticity.7FINRA. Exchange Act Rule 17a-4 Amendments Chart of Significant Changes Confirm your vendor covers all four elements before going live.
Supervisory Review Is a Separate Obligation
Archiving is half the job. FINRA Rule 3110 requires member firms to establish written supervisory procedures for reviewing incoming and outgoing electronic correspondence related to the firm’s securities business.8FINRA. FINRA Rule 3110 – Supervision Reviews must be conducted by a registered principal, and the review itself must be documented in writing.
The rule sets no fixed review frequency for text messages. Procedures must be “appropriate for the member’s business, size, structure, and customers,” which in practice means a risk-based approach.8FINRA. FINRA Rule 3110 – Supervision A small advisory practice and a large wirehouse will land in very different places, and regulators expect both to justify their choices.
Most firms now use automated keyword-flagging tools that scan archived messages for compliance triggers, then route flagged messages to a principal for manual review. Terms tied to complaints, guarantees, trade instructions, or account transfers typically drive the lexicon. Firms that rely entirely on after-the-fact sampling are out of step with what regulators expect.
Apps and Features You Must Prohibit
The SEC has targeted messaging platforms that undermine archiving by design. Firms are expected to prohibit business use of any platform that allows anonymous messaging, that automatically destroys messages after a set period, or that blocks third-party viewing or backup. Disappearing-message features fall squarely in this category.
The prohibition goes beyond banning apps outright. If a firm permits a platform but fails to disable its auto-delete features, regulators treat that as a supervision failure. And on any approved platform, communications involving recommendations, fund transfers, securities orders, or account performance carry the heaviest oversight expectations.3U.S. Securities and Exchange Commission. OCIE Risk Alert – Electronic Messaging
Consent Before You Text Clients
Before any business text goes out, federal law requires client consent. The Telephone Consumer Protection Act makes it unlawful to send text messages to a cell phone using an autodialer without the prior express consent of the recipient.9Office of the Law Revision Counsel. 47 USC 227 – Restrictions on Use of Telephone Equipment Marketing or promotional texts require written consent with a clear disclosure that the recipient is authorizing the messages.
Service-related texts get more room. When a client provides their phone number in connection with your advisory services, the FCC has treated that as implied consent for messages related to those services. Account alerts, meeting confirmations, and transaction notifications generally fit. A text that shifts into promotional territory, such as pitching a new product or soliciting referrals, triggers the written-consent requirement.
The consent itself is a record. If a client later disputes whether they authorized text communication, your firm has to produce evidence. Collecting consent during onboarding and storing it in the same system that archives the messages keeps everything in one place.
Standing Up an Archiving System
Deployment starts with picking a third-party vendor that fits your firm’s mobile workflow. The technical options fall into three categories.
- App-based archiving. Advisors use a dedicated application for business texting, and the app routes messages through the vendor’s servers, where they are captured before delivery. The firm gets the most control; advisors have to change habits.
- Network-based archiving. Messages are captured at the carrier level, intercepting texts through the service provider without new software on the device. Coverage is broader; setup requires carrier coordination.
- SIM-based or device-level archiving. A software layer on the device captures messages across multiple apps. It handles SMS, iMessage, and third-party platforms but raises more privacy considerations on personal devices.
After the connection is live, run a verification phase confirming that inbound and outbound messages actually reach the archive in real time. Provision administrative access to compliance officers so they can search records, respond to regulatory requests, and conduct the reviews required under FINRA Rule 3110.8FINRA. FINRA Rule 3110 – Supervision Send trial messages with attachments and confirm that media files, timestamps, and sender metadata all record accurately. A system that captures text but drops image attachments has a gap that regulators will find.
When comparing vendors, confirm whether their infrastructure supports WORM, the audit-trail alternative, or both. Ask for documentation of how the system prevents tampering and, on the audit-trail side, how it recreates original records. Vendor certifications matter but do not transfer liability. Your firm remains responsible for every message that should have been captured and was not.
What Getting This Wrong Has Cost
Off-channel communication has been an SEC enforcement priority since 2021. In 2022, sixteen Wall Street firms paid combined penalties exceeding $1.1 billion after admitting to widespread recordkeeping failures involving unarchived text messages and other off-channel communications, with eight firms each paying $125 million.10U.S. Securities and Exchange Commission. SEC Charges 16 Wall Street Firms with Widespread Recordkeeping Failures In January 2025, twelve more firms paid a combined $63 million for the same category of violations, with individual penalties ranging from $4 million to $11 million.11U.S. Securities and Exchange Commission. Twelve Firms to Pay More Than $63 Million Combined to Settle SECs Charges for Recordkeeping Failures Aggregate industry penalties across the sweeps now approach $3 billion.
FINRA has also brought individual actions against registered representatives for using unapproved communication channels, resulting in suspensions and personal fines. Regulators treat this as a core compliance obligation on par with trade reporting and customer protection.