← All posts
Thought Leadership

What is pre-send compliance? A definition, the rules behind it, and its limits

October 6, 2026 · 8 min read

Take a broker-dealer that sends a product brochure to 26 retail investors in one month. Under FINRA Rule 2210(b)(1)(A), “an appropriately qualified registered principal of the member must approve each retail communication before the earlier of its use or filing”. The principal reads it first. Nothing goes out until they have.

Now take the same firm’s adviser, who emails 25 retail investors in that month and says something just as promotional in the body of a reply. Rule 2210(a)(2) calls that “correspondence”, and Rule 2210(b)(2) gives it one sentence: “All correspondence is subject to the supervision and review requirements of Rules 3110(b) and 3110.06 through .09.” There is no pre-use approval. Review happens through the firm’s supervisory procedures, and Rule 3110.06 lets the firm decide how much of it to do on a risk basis.

The line between those two outcomes is a headcount: more than 25 retail investors in 30 calendar days, or 25 or fewer. The sentence on the page can be identical in both. That gap is where pre-send compliance sits, and this post defines it, shows what the rulebooks require around it, and says what it cannot do.

A working definition

Pre-send compliance is the review of a message’s wording while it is still a draft, with the result shown to the writer so the writer can change it before it leaves. Three things in that sentence carry weight:

  • Timing. The check runs in the compose window, before the send action. A review that happens after send, even a minute after, is a different control.
  • Unit. The check works on language: a phrase, a promise, an admission, a line about a competitor. The output names the sentence and says why it carries exposure.
  • Decision owner. The writer decides. The control advises, explains and, where no compliant wording keeps the meaning, says the line is best removed. A control that holds the message for someone else to release is pre-approval, which is older and does a different job.

How it differs from the controls it gets confused with

Control When it acts What it looks at Who decides What it leaves behind
Pre-send compliance While drafting The wording of the draft The writer A corrected message, and a record of what was flagged
Pre-approval (for example FINRA 2210(b)(1)(A)) Before first use A fixed document A principal or reviewer A signed approval on a file
Data loss prevention At send or on the gateway Patterns: card numbers, labels, file types A rule, then an administrator A block or an alert
Archiving and supervision After send The stored record A reviewer, later A reviewed, retained message

The practical test is simple. Ask what a control can still change. Pre-approval can change a brochure. Archiving can change nothing about the message, only what the firm does about it. Pre-send compliance can change the sentence, because the sentence has not left yet.

What the rulebooks say, and where they stop

The two rulebooks read for this piece ask for three different things, and none of them is a pre-send review of an individual email.

  • Approval before use, for broad communications. FINRA Rule 2210(b)(1)(A), quoted above, applies to retail communications.
  • Review of correspondence, on the firm’s risk judgement. FINRA Rule 3110(b)(4) requires supervisory procedures for “the review of incoming and outgoing written (including electronic) correspondence and internal communications relating to the member’s investment banking or securities business”, appropriate to the member’s “business, size, structure, and customers”. Supplementary Material .06 says the firm must decide, using risk-based principles, how much additional review it needs. The rule text does not say whether that review happens before or after the message is used.
  • A copy, kept. In the UK, SYSC 10A.1.6R requires a firm to “take all reasonable steps to record telephone conversations, and keep a copy of electronic communications” relating to the activities it lists. SYSC 10A.1.14R sets the retention period at five years, and up to seven where the FCA requests it.

Read together, the rules approve broad communications first, require a copy of everything, and leave the review of individual messages to risk-based procedures. The rule text is silent on the moment before send, which is the only moment at which the writer can still change the sentence.

One limit on this reading: it covers two rulebooks. Other regimes (SEC recordkeeping, MiFID II, sector rules outside financial services) ask for their own mixes of these three, and a firm subject to several should check each. Nothing found in the two read here makes pre-send review of correspondence a requirement. It is a voluntary control, which is worth knowing before anyone describes it to a board as “required”.

Why the timing matters: a case

On 7 January 2021 the US Department of Justice announced that a global aircraft manufacturer had entered a deferred prosecution agreement over a conspiracy to defraud the FAA’s Aircraft Evaluation Group. The company agreed to pay a total criminal monetary amount of over USD 2.5 billion: USD 243.6 million as a criminal penalty, USD 1.77 billion in compensation to airline customers, and a USD 500 million fund for the beneficiaries of the 346 people who died in the two crashes. The Department’s own description of the conduct includes “misleading statements, half-truths, and omissions communicated by [the company’s] employees to the FAA”.

The company’s records system did its job. Messages written inside the company were captured, kept and later produced. What the control stack did not do was reach the writer at the moment of writing. A message that admits to misleading a regulator is a sentence a person types in a few seconds. Review after send could only read it.

What a pre-send check returned on real text

VerbaPulse’s Benchmark Report 2026 tests this on documented language. We took 13 lines from real cases that ended in fines, settlements or judgments, each line quoted from the public record, and submitted every one to the live production API on 21 June 2026. Each raw response was stored with a SHA-256 stamp, and the server logs showed zero failed calls in that window, so a “no flag” is a model decision and never a silent error.

Nine of the thirteen lines were flagged with a severity, a category and a recommended action. Four returned no flag. Those four are ambiguous once they are stripped of the thread around them, and we publish them as such.

The output for the line from the aircraft-manufacturer case reads, as the API returned it: High, Legal. “I basically lied to the regulators (unknowingly).” Admission of lying to regulators. Recommended: no compliant version preserves the intent, best removed. That last clause is the behaviour to look for in any tool in this category. Some sentences have a safer version. Some should not be written, and a check that always produces a rewrite is hiding that.

These are famously bad sentences, picked because their words are on the public record, so 9 out of 13 says little about your inbox. Real mail is mostly mundane, context sits three messages up the thread, and an ambiguous sentence stays ambiguous.

Five questions to put to any pre-send tool

  1. Where does it read the text? A check at compose time and a check at the send hook are different products. Ask which one it is, in which clients, and what happens on mobile.
  2. Does it name the sentence and the reason? A risk score for the whole email teaches nobody anything. A phrase-level flag with a stated reason does.
  3. Does it hold the message? If it holds, it is pre-approval and your colleagues will route around it. If it advises, find out whether the writer’s choice is recorded.
  4. Where is the draft processed, and what is kept? Draft text is the most sensitive text a firm has. Ask for the processing location, the retention period and the sub-processors in writing.
  5. What does it miss, and does the vendor say so? Ask for a published result on documented cases, with the misses listed. A vendor that reports no misses has not measured them.

Where pre-send fits next to what you already run

Pre-send compliance targets accidental human risk: the careless line a well-intentioned person does not notice they are writing. It makes no claim to stop a determined insider or a deliberately evasive message, and it does not replace archiving, surveillance or the Rule 3110 review. It sits in front of them, so fewer problem sentences reach the queues that Smarsh, Proofpoint and similar systems feed. For how the two layers divide the work, see our comparison of pre-send and post-send compliance, and for how a compliance team runs it day to day, see VerbaPulse for compliance teams.

What to do on Monday

Take last month’s correspondence review output, whatever your firm calls it: the hits from the sampling, the lexicon alerts, the items an analyst escalated. For each hit, mark whether the problem was a sentence the writer could have changed in the compose window. The count tells you how much of your review effort is spent reading things that were still fixable when they were typed. That number is the case for a pre-send control, or the case against it, and you can have it by lunchtime.

A message to 25 readers and a message to 26 can carry the same sentence. Only one of them needed a principal’s signature before it left.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← The tipping-off prohibition moves earlier in 2027 What does clear, fair and not misleading mean in a customer email? →