Regulators have gone to war with the financial sector over recordkeeping and off-channel communications. What began as a few scattered fines has now become a major, ongoing enforcement trend, with regulatory bodies like the Commodity Futures Trading Commission (CFTC) and the Securities and Exchange Commission (SEC) issuing billions in penalties over the last few years. The crackdown is not slowing down—in fact, it’s intensifying as regulators demand stricter governance of communications across all channels. While improving governance and internal controls is the ultimate goal for financial institutions, oversights inevitably occur. When they do, regulators have made it clear that self-reporting these violations can be the next best option to mitigate fines and legal repercussions.
A recent case that illustrates the importance of self-reporting is Truist Bank’s $3 million fine from the CFTC. The penalty was for recordkeeping violations stemming from the use of unauthorized communication platforms by employees. However, unlike many firms that face harsher consequences, Truist was able to significantly reduce its fine through proactive self-reporting. This blog will explore the details of Truist’s case, the benefits of self-reporting, and what financial firms can learn from this approach.
The Importance of Recordkeeping in Financial Institutions
In recent years, financial regulators such as the CFTC and the SEC have zeroed in on the recordkeeping practices of financial institutions. Their focus is increasingly on ensuring that any communication—whether through official channels or third-party platforms like WhatsApp, iMessage, or personal emails—must be retained and auditable. These off-channel platforms, often used informally by employees, have become a significant area of concern as they represent a blind spot in firms’ compliance frameworks.
The Issue with Off-Channel Communications
What’s particularly problematic for many institutions is the retention of communications on platforms not traditionally seen as formal business tools, like WhatsApp or personal messaging apps. Employees often turn to these channels for the convenience and speed they offer, especially in remote or hybrid work environments. However, regardless of the platform, any communication related to business must be captured, stored, and accessible to regulators.
Firms have increasingly fallen short in this area, leading to billions in fines for recordkeeping violations. Regulatory bodies have underscored that it’s not enough to have compliance measures in place for formal business platforms; every channel used for business communication must be governed by the same retention rules.
Key Requirements from the CFTC and SEC
The obligations imposed by regulatory bodies require firms to meet stringent standards, particularly in the area of communication retention:
- Retention of All Business-Related Communications: This includes emails, phone calls, and increasingly, messages exchanged on third-party apps like WhatsApp or Signal. Any communication that is business-related must be stored and accessible to auditors.
- Monitoring of Employee Communications: Financial institutions must ensure that all business-related communications are conducted on approved platforms that are integrated into the firm’s compliance systems.
- Ensuring Data Accessibility: Communications must not only be stored but also be easily retrievable. This means that firms must invest in secure, scalable solutions that allow for quick access to communications in the event of an audit or investigation.
These requirements are essential for maintaining transparency, protecting investors, and ensuring that markets remain free of manipulation. Yet, they also present significant challenges for firms, especially as employees increasingly use personal devices and unauthorized channels for business communication.
The Truist Bank Case: A $3 Million Lesson in Self-Reporting
In August 2024, Truist Bank was hit with a CFTC fine totaling $3 million for failing to properly maintain and supervise its records as a registered swap dealer. The bank’s employees, including senior executives, used unauthorized communication channels like personal text messages to conduct business, which violated the company’s internal policies. These messages were not captured or archived as required by CFTC regulations, leading to significant recordkeeping breaches.
What sets this case apart, however, is the way Truist responded to these violations. After conducting an internal review, the bank discovered widespread non-compliance with its communication policies. Rather than waiting for the CFTC to uncover the issues, Truist took the proactive step of self-reporting its findings to the regulatory body. Truist’s self-reporting included:
- Disclosing the violation: Truist outlined how its employees had conducted business over personal messaging apps and text messages, which were not properly archived as per CFTC regulations.
- Proactively addressing the issue: The bank quickly implemented internal measures to bring communications back into compliance, such as mandating stricter use of approved messaging platforms and increasing oversight.
- Cooperating fully with regulators: Throughout the investigation, Truist worked closely with the CFTC, providing full access to internal documentation, audit reports, and remedial actions.
This level of transparency and cooperation demonstrated Truist’s commitment to fixing the issue, ultimately resulting in a CFTC fine that was substantially lower than those imposed on other firms for similar violations.
In a statement, Director of Enforcement for the CFTC Ian McGinley said “In responding to an industry-wide and consequential problem, Truist set itself apart from … more than 20 other registrants…Truist’s decision to self-report, cooperate, remediate, and be held accountable allowed it to benefit in the form of a substantially reduced penalty.”
Comparing Truist Bank’s Fine to Other Recent Cases
While Truist Bank’s proactive self-reporting led to a relatively modest penalty, other financial institutions involved in similar violations have faced far more severe repercussions, demonstrating the significant financial and regulatory advantages of early self-disclosure.
Among the institutions fined at the same time as Truist, TD Bank bore the brunt, with penalties amounting to $112 million—the largest total across both the SEC and CFTC. The breakdown of fines included $30 million from the SEC, $75 million from the CFTC for failing to prevent employees from using unauthorized communication methods since 2015, and another $7 million in additional penalties for Cowen (a firm acquired by TD).
In addition to this other penalties for firms who did not self-disclose included:
- Ameriprise, Edward Jones, LPL Financial, Raymond James, and RBC Capital were fined between $45 million to $50 million each.
- BNY Mellon and Pershing paid a $40 million penalty.
- Osaic Services and Wealth paid $18 million.
- Piper Sandler agreed to a $14 million penalty.
The other companies that self-reported paid much smaller fines:
- Cetera paid $4.5 million (also self-reported).
- Hilltop Securities were fined $1.6 million.
Money and Beyond: Why Truist Bank’s Approach Worked
Truist Bank’s proactive stance on self-reporting offers several key lessons for financial institutions navigating similar compliance challenges. Below are the key benefits that the bank reaped by taking swift action and working with the CFTC:
- Reduction in Penalties: Truist’s $3 million CFTC fine was considerably lower than penalties imposed on other banks that committed similar violations but did not self-report. For example, in 2023, JPMorgan Chase was fined $200 million for similar recordkeeping failures, a figure that could have been mitigated had the company self-reported early on. By cooperating with regulators from the outset, Truist positioned itself as a responsible corporate actor, leading to more lenient treatment.
- Demonstrating Corporate Responsibility: Self-reporting signals to regulators that a company takes its compliance obligations seriously. In Truist’s case, the bank not only disclosed the violations but also took immediate steps to address the underlying issues. This willingness to accept responsibility and make meaningful changes reassured the CFTC that Truist was committed to compliance in the long term.
- Improved Cooperation with Regulators: Regulators like the CFTC and SEC often view self-reporting as an indicator of a company’s overall commitment to transparency. By coming forward voluntarily, Truist was able to foster a more collaborative relationship with the CFTC. This level of cooperation can lead to quicker resolutions of investigations and, in some cases, less intrusive oversight in the future.
- Protecting the Bank’s Reputation: While regulatory fines are damaging, the reputational harm that can accompany enforcement actions is often worse. Truist’s decision to self-report allowed the bank to control the narrative around its violations, framing the issue as one of corporate responsibility and transparency rather than negligence. In a highly regulated industry like finance, where trust is paramount, this can be critical in maintaining customer and shareholder confidence.
How to Best Position Your Company Amid Recordkeeping Crackdowns
With the increasing scrutiny and enforcement from regulatory bodies such as the CFTC and SEC, it’s essential for financial institutions to proactively position themselves to manage compliance and avoid hefty penalties. Here’s a bullet-point guide on how to navigate these challenges effectively:
1.Get Governance Right from the Start
- Develop Comprehensive Policies: Ensure that your company has clear, documented policies covering recordkeeping across all communication channels, including off-channel platforms like WhatsApp and personal emails.
- Train Employees Regularly: Make sure all employees are fully trained on the importance of compliance, the specific rules, and what is expected of them when using both approved and unapproved channels.
- Appoint Compliance Officers: Designate officers who are responsible for overseeing recordkeeping practices and ensuring ongoing adherence to policies.
2.Monitor Communications in Real-Time
- Invest in Monitoring Tools: Implement systems that can monitor and capture all business-related communications across multiple channels in real-time. This includes emails, messaging apps, and phone calls.
- Track Off-Channel Communications: Use monitoring tools that can detect when employees are using off-channel communications and either block them or alert compliance teams.
- Establish Alerts: Set up automated alerts that notify compliance teams if any off-channel communications are detected or if there’s a deviation from established practices.
3. Regularly Audit and Assess Compliance
- Conduct Internal Audits: Schedule regular internal audits to assess compliance with recordkeeping regulations. Ensure that all communication records are accessible and stored securely.
- Simulate Regulator Audits: Perform mock regulatory audits to ensure your systems would meet external inspection standards.
- Review Employee Devices: Audit personal devices if employees are using them for business purposes, ensuring that communication is being properly tracked and archived.
4. Self-Report When Necessary
- Identify Failures Early: Proactive monitoring and auditing should help your firm catch recordkeeping failures early. Once identified, act quickly to assess the scale of the issue.
- Take Immediate Corrective Action: Address the failure internally by implementing corrective measures, such as updating policies or improving monitoring systems.
- Prepare a Detailed Report: When self-reporting to regulators, ensure that your report is comprehensive. Include details of the violation, the cause, corrective actions taken, and how you plan to prevent future failures.
- Cooperate Fully with Regulators: Show a willingness to cooperate throughout the process. Regulators have shown leniency toward firms that self-report and demonstrate good faith efforts to address issues.
By following these steps, firms can avoid large penalties, maintain their reputations, and foster better relationships with regulators. As Truist Bank’s case shows, self-reporting, cooperation, and remediation are key to minimizing the negative impact of recordkeeping violations.
Compliance is Still First Prize – Let LeapXpert Show You How
Don’t let “off-channel” communication become a compliance headache. Partner with LeapXpert to turn off-channel communications into authorized channels, creating a seamless, efficient, and compliant communication ecosystem for your organization.
With The LeapXpert Communications Platform, using any app – from WhatsApp, iMessage, and WeChat to Slack and Microsoft Teams – securely and in full compliance – is easy.
The LeapXpert Communications Platform offers full integration of all these digital communication channels and maintains a complete record of all conversations between employees and customers to ensure that data privacy and governance standards are met. The user-friendly dashboard allows for easy auditing and reporting and displays the real-time status of all text messages, conversations, and data sent, as well as flagging when conditions and rules have been breached. Integrated with leading third-party archiving, surveillance, and analytics platforms, all text message records are securely stored and available alongside all the existing business data.
Book a personalized
product demo