
Between 2021 and 2023, the SEC and CFTC levied more than USD 2 billion in penalties across firms whose staff conducted business on unmonitored channels. The messages themselves were ordinary: a trade confirmed over a personal phone, a client question answered on a chat app the firm never captured. The penalty was not for the content. It was for the fact that the firm could not see, capture, or govern where its own business communication was happening. The lesson every compliance leader took from it is uncomfortable: you cannot manage what you cannot see, and by the time a message is discoverable evidence, the window to manage it has closed.
Most compliance teams already know their communication risk is real. What they lack is a way to describe it that survives a board meeting. “I have a bad feeling about how sales talks to clients” is an anecdote. It does not get budget, it does not change behavior, and it does not hold up when someone asks for proof. This post is about turning that feeling into something defensible: a written, privacy-respecting view of your own language risk, built from metadata, without anyone reading employee mail.
Risky phrasing does not announce itself. The aircraft manufacturer whose internal messages (“designed by clowns, supervised by monkeys” and “I basically lied to the regulators”) became central to a USD 2.5 billion deferred prosecution agreement did not have a policy gap. It had a visibility gap. Those lines were written by people who did not think of themselves as reckless, in channels no one was watching in real time, and they only became visible when a regulator went looking.
Traditional tooling finds these after the fact. Archiving and supervision platforms (Smarsh, Proofpoint and similar) capture everything and let you search it once you have a reason to. That is essential infrastructure for review, retention, and eDiscovery. It answers “what did we say” after an incident. It does not answer “where is risky phrasing concentrating right now, before it goes out.” Those are different questions, and the second one is where anecdote usually fills the gap.
A useful summary treats risky phrasing as a measurable signal with a location and a trend, derived entirely from metadata: the category of risk a phrase triggers, the department it came from, the date, and whether the sender revised before sending. It never stores or reports the message itself. That distinction is what makes the view shareable with a works council or a data protection officer without a fight.
Three things become legible once you measure at that level:
Kept short and phrase-level, because that is how a pre-send check should read. A sales rep drafts “we guarantee you will pass the audit.” The flag is on the word guarantee, and the suggestion is “we help you prepare for the audit.” One clause, one safer verb. The rep sees it, changes it in two seconds, and the summary records a revised commitment flag instead of a sent one. Multiply that across a department and you have a trend line instead of a lawsuit.
If someone hands you a communication-risk report, or if you are building the internal case for one, this is the outline that separates a defensible summary from a dashboard screenshot. Use it as a checklist.
| Section | What it should contain | How to read it |
|---|---|---|
| Scope and method | What was measured, over what period, and an explicit statement that no message content was stored or read | If it cannot state the privacy method plainly, do not circulate it internally |
| Risk taxonomy | The named categories (e.g. commitment, disparagement, sensitive HR topics, confidentiality) | Categories should map to your actual legal exposure, not generic sentiment |
| Concentration | Flag counts broken down by department or team | Look for the one or two teams carrying most of the risk; that is your intervention target |
| Trend | The 30-day direction, with any spikes tied to a known event | Direction and slope matter more than the absolute number |
| Revision rate | Share of flagged drafts that were changed before sending | High means the control is working; low means the wording or rollout needs attention |
| Recommended action | One or two specific, department-level next steps | A summary that ends in a number and no action is an anecdote with a chart |
The point of the artifact is that it forces the report to be about decisions. Concentration tells you who to talk to. Trend tells you whether to act now or watch. Revision rate tells you whether your existing controls are landing. This is general information, not legal advice, but it is the shape of a document a skeptical reviewer will accept.
A pre-send check is a front-end shield for accidental risk: the careless line a well-intentioned employee does not notice they are writing. It catches the guarantee before it ships. It does not stop a determined bad actor who wants to move to an unmonitored channel, and it is not an adversarial security boundary. Those are real problems, and they belong to policy, culture, and your supervision stack.
So it complements archiving and supervision rather than replacing them. Smarsh and Proofpoint capture and review what was sent. A pre-send check reduces how much risky phrasing reaches those queues in the first place, and the department-level summary gives you a management view those tools were never designed to produce. Fewer flagged lines go out, fewer incidents need review, and you get a defensible picture of the trend. For the team-level version of this, see how it maps to a compliance team’s workflow.
Stop managing communication risk on instinct. Get one written summary that shows where risky phrasing concentrates by department, which way the trend is moving over 30 days, and whether people revise when prompted, all from metadata, with no message content stored. That single document turns “I have a bad feeling about sales” into a decision you can defend and act on.
If you want to see your own numbers, the VerbaPulse 30-day Proof-of-Value Pilot runs up to 10 seats for EUR 120, credited to your plan if you continue, and delivers a written risk summary on day 25 built entirely from metadata.
VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.
Up to 10 seats. EUR 120, credited to your plan if you continue.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →