
Between late 2021 and 2024, the U.S. Securities and Exchange Commission and the Commodity Futures Trading Commission ran one of the most consistent enforcement campaigns in recent memory. The target was not a product, a trading strategy, or a market-timing scheme. It was where staff talked. Bankers, advisers, and traders were using personal texts, WhatsApp, and other unmonitored channels to discuss business, and their firms could not produce those records when regulators asked. The combined penalties crossed USD 2 billion (roughly EUR 1.85 billion) across dozens of firms, many of them household names.
The lesson that compliance leaders keep drawing from that wave is usually about surveillance: capture more channels, tighten the policy, sign more attestations. That is correct and incomplete. The deeper finding sitting inside those cases is quieter. Once regulators pulled the messages, the informal ones read worse than anyone expected. The channel got the headline. The words did the damage.
Books-and-records rules (in the U.S., Exchange Act Rule 17a-4 and the CFTC’s Rule 1.31; in the EU and UK, MiFID II Article 16 and the FCA’s SYSC 10A recording requirements) were written to be channel-agnostic on purpose. A business communication is a business communication whether it travels by email, a monitored chat, or a personal phone. Moving a conversation to a faster or friendlier channel changes the format and the tone. It does not change the record-keeping duty, and it does not change discoverability once litigation or an inquiry begins.
That last point is where most teams underestimate their exposure. Staff intuitively write more carefully in email because email feels official. The same person, in a quick text, writes the thing they would never put in a formal letter: a promise the firm cannot keep, a dismissive line about a client, an offhand admission. The off-channel penalties punished the failure to retain. The reputational and legal harm, in case after case, came from what the retained-too-late messages actually said.
The most dangerous message in a regulated firm is rarely the one the writer treats as important. It is the one the writer thinks is trivial: a fast reassurance, a throwaway opinion, a shortcut phrasing under deadline. A crypto-exchange founder’s public “assets are fine” reassurance, sent days before the platform collapsed, became core fraud evidence. A gaming and betting CEO who posted material growth figures from a personal social account drew an SEC Regulation FD settlement of USD 200,000 (about EUR 185,000). Neither writer sat down to commit a violation. Each thought they were sending a quick note.
A pre-send check earns its place precisely on those messages, because the writer is not being careful in that moment. They are being fast.
Two questions decide almost every off-channel situation. First: is this channel in scope for retention? Second: regardless of channel, does this specific message create exposure? The decision guide below answers the first. The self-check answers the second.
| Channel | In scope for business records? | Practical rule |
|---|---|---|
| Corporate email, monitored chat (Teams, Bloomberg, archived Slack) | Yes | Default channel for client and business matters. |
| Personal text / SMS, personal WhatsApp, Signal, WeChat | Yes, if it discusses business | Move the substance to a captured channel. The topic decides, not the app. |
| LinkedIn and other social DMs / posts | Yes, if business or market-moving | A public post can trigger disclosure rules (see the Regulation FD case above). |
| Voice, in-person, ephemeral / disappearing messages | Yes for the obligation, but hard to reconstruct | Follow up in writing on a captured channel; never use auto-delete for business. |
The scope test is simple: if the content is about firm business, the retention duty attaches. The channel only determines how hard it will be to comply, and how bad it looks if you cannot.
Before sending any external or business message, on any channel, run five questions. If the answer to any of them is uncomfortable, slow down.
These five map directly to what regulators and plaintiffs actually pull from the record. In the off-channel wave, the retained messages that hurt most failed the Promise, Tone, and Admission tests. The aircraft manufacturer whose internal lines (“I basically lied to the regulators”) sat at the center of a USD 2.5 billion (about EUR 2.3 billion) deferred prosecution agreement failed the Admission test in a single sentence.
The self-check works as a habit, but habits fail under deadline pressure, which is exactly when the risky quick note gets written. That is the gap a pre-send tool covers. VerbaPulse reads a draft and flags the specific phrase, then offers a short, phrase-level rewrite or says plainly when a line is best removed. Real examples of how it writes:
The suggestions stay short on purpose. The goal is to catch the careless line before send, not to rewrite the message for the author.
A pre-send check is a front-end shield for accidental risk: the well-intentioned employee who does not notice that their quick reassurance reads as a guarantee, or that their venting reads as disparagement. It is not an adversarial control. It will not stop someone who has decided to hide misconduct, and it is not a substitute for the archiving and supervision layer. Tools like Smarsh and Proofpoint capture and review what was sent; that obligation is non-negotiable and a pre-send check does not replace it.
The two layers complement each other. A front-end check means fewer risky messages are written in the first place, so fewer land in the surveillance queue as alerts, investigations, or, later, evidence. It reduces the volume of problems reaching the systems you already run. Firms in scope for these rules can see how this maps to their stack on our financial services page.
Do one thing this quarter: put the five-question self-check in front of client-facing writing, and treat the scope table as the answer to “can I just text them?” The enforcement wave proved that regulators will reconstruct the informal record, and that the informal record is where the careless words live. You cannot control which of your messages a regulator or plaintiff will one day read back. You can control whether the quick note was worth reading back.
This is general information for compliance and risk teams, not legal advice. Confirm your specific retention obligations with counsel.
VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.
Up to 10 seats. EUR 120, credited to your plan if you continue.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →