← All posts
Thought Leadership

From anecdote to evidence: what a language-risk summary shows a compliance team

August 14, 2026 · 7 min read

Between 2021 and 2023, the SEC and CFTC levied more than USD 2 billion in penalties across firms whose staff conducted business on unmonitored channels. The messages themselves were ordinary: a trade confirmed over a personal phone, a client question answered on a chat app the firm never captured. The penalty was not for the content. It was for the fact that the firm could not see, capture, or govern where its own business communication was happening. The lesson every compliance leader took from it is uncomfortable: you cannot manage what you cannot see, and by the time a message is discoverable evidence, the window to manage it has closed.

Most compliance teams already know their communication risk is real. What they lack is a way to describe it that survives a board meeting. “I have a bad feeling about how sales talks to clients” is an anecdote. It does not get budget, it does not change behavior, and it does not hold up when someone asks for proof. This post is about turning that feeling into something defensible: a written, privacy-respecting view of your own language risk, built from metadata, without anyone reading employee mail.

Why anecdote is the default, and why it fails

Risky phrasing does not announce itself. The aircraft manufacturer whose internal messages (“designed by clowns, supervised by monkeys” and “I basically lied to the regulators”) became central to a USD 2.5 billion deferred prosecution agreement did not have a policy gap. It had a visibility gap. Those lines were written by people who did not think of themselves as reckless, in channels no one was watching in real time, and they only became visible when a regulator went looking.

Traditional tooling finds these after the fact. Archiving and supervision platforms (Smarsh, Proofpoint and similar) capture everything and let you search it once you have a reason to. That is essential infrastructure for review, retention, and eDiscovery. It answers “what did we say” after an incident. It does not answer “where is risky phrasing concentrating right now, before it goes out.” Those are different questions, and the second one is where anecdote usually fills the gap.

What a language-risk summary actually measures

A useful summary treats risky phrasing as a measurable signal with a location and a trend, derived entirely from metadata: the category of risk a phrase triggers, the department it came from, the date, and whether the sender revised before sending. It never stores or reports the message itself. That distinction is what makes the view shareable with a works council or a data protection officer without a fight.

Three things become legible once you measure at that level:

  • Concentration by department. Risk is rarely spread evenly. In practice it clusters: sales and client-facing teams generate more commitment and disparagement flags, HR generates more sensitive-topic and bias flags, and a single team can account for a disproportionate share. Concentration tells you where a policy refresher or a targeted conversation will actually move the number.
  • Trend over 30 days. A single week is noise. A 30-day line tells you whether flags are rising, falling, or spiking around a specific event (a product launch, a layoff, a pricing change). Direction matters more than any single day’s count.
  • Revision behavior. When people are shown a flag before they send, do they change the line? A high revise rate is evidence the intervention works. A low one tells you the flag is being ignored and the wording needs work.

What a flag looks like in practice

Kept short and phrase-level, because that is how a pre-send check should read. A sales rep drafts “we guarantee you will pass the audit.” The flag is on the word guarantee, and the suggestion is “we help you prepare for the audit.” One clause, one safer verb. The rep sees it, changes it in two seconds, and the summary records a revised commitment flag instead of a sent one. Multiply that across a department and you have a trend line instead of a lawsuit.

The artifact: what to look for in a language-risk summary

If someone hands you a communication-risk report, or if you are building the internal case for one, this is the outline that separates a defensible summary from a dashboard screenshot. Use it as a checklist.

Section What it should contain How to read it
Scope and method What was measured, over what period, and an explicit statement that no message content was stored or read If it cannot state the privacy method plainly, do not circulate it internally
Risk taxonomy The named categories (e.g. commitment, disparagement, sensitive HR topics, confidentiality) Categories should map to your actual legal exposure, not generic sentiment
Concentration Flag counts broken down by department or team Look for the one or two teams carrying most of the risk; that is your intervention target
Trend The 30-day direction, with any spikes tied to a known event Direction and slope matter more than the absolute number
Revision rate Share of flagged drafts that were changed before sending High means the control is working; low means the wording or rollout needs attention
Recommended action One or two specific, department-level next steps A summary that ends in a number and no action is an anecdote with a chart

The point of the artifact is that it forces the report to be about decisions. Concentration tells you who to talk to. Trend tells you whether to act now or watch. Revision rate tells you whether your existing controls are landing. This is general information, not legal advice, but it is the shape of a document a skeptical reviewer will accept.

Where a pre-send check fits, honestly

A pre-send check is a front-end shield for accidental risk: the careless line a well-intentioned employee does not notice they are writing. It catches the guarantee before it ships. It does not stop a determined bad actor who wants to move to an unmonitored channel, and it is not an adversarial security boundary. Those are real problems, and they belong to policy, culture, and your supervision stack.

So it complements archiving and supervision rather than replacing them. Smarsh and Proofpoint capture and review what was sent. A pre-send check reduces how much risky phrasing reaches those queues in the first place, and the department-level summary gives you a management view those tools were never designed to produce. Fewer flagged lines go out, fewer incidents need review, and you get a defensible picture of the trend. For the team-level version of this, see how it maps to a compliance team’s workflow.

The takeaway

Stop managing communication risk on instinct. Get one written summary that shows where risky phrasing concentrates by department, which way the trend is moving over 30 days, and whether people revise when prompted, all from metadata, with no message content stored. That single document turns “I have a bad feeling about sales” into a decision you can defend and act on.

If you want to see your own numbers, the VerbaPulse 30-day Proof-of-Value Pilot runs up to 10 seats for EUR 120, credited to your plan if you continue, and delivers a written risk summary on day 25 built entirely from metadata.

See it on your own emails

VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.

Start a pilot

Up to 10 seats. EUR 120, credited to your plan if you continue.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← The Rejection Email That Became Evidence Offer Letters and Hiring Promises: When Recruiting Emails Become Binding Commitments →