What Examiners Actually Ask For When They Request Your Off Channel Records

What Examiners Actually Ask For When They Request Your Off Channel Records

FINRA's June 2025 action against Velox Clearing is the clearest picture available of how off-channel problems surface now. A routine cycle exam turned up more than 10,000 unretained WeChat messages. Compliance had flagged the channel internally. Nobody actioned the flag. Velox paid $1.3 million to FINRA and another $500,000 to the SEC, and the firm's CEO and senior staff had been conducting client business on WeChat all along.

No sweep. No press-release theater. An examiner asked a question during a scheduled exam, and the answer was a paper trail that ended in the middle.

That's the shift compliance officers should be planning around. The SEC's sweep era closed with the January 13, 2025 actions against nine investment advisers and three broker-dealers, which resolved for $63 million combined with the firms admitting facts and violations. What replaced it isn't quieter. It's just less announced. Off-channel findings now come out of cycle exams, and the requests that produce them are more specific than most firms expect.

The request is rarely "give us your text messages"

Examiners generally don't open with a demand for message content. They open with your supervisory framework, then work toward whether the framework produced anything.

FINRA's 2026 Annual Regulatory Oversight Report, published December 2025, references recordkeeping lapses more than 50 times. Electronic communications capture, off-channel use, and inadequate supervision all appear as examination findings. Read the section on supervision and the pattern is consistent: whether written procedures reflect what the firm actually does, whether those procedures get enforced, and whether senior management is accountable for the outcome.

Jamila Mayfield, Comply's Chief Regulatory Services Officer, put the standard about as plainly as it can be put: regulators expect you to write what you do and do what you write, and they expect a timestamped trail showing both.

The timestamped trail is the part firms underestimate. A policy document proves intent. It doesn't prove operation.

Five things they ask you to produce

Based on the 2026 report's findings and recommendations, plus the fact patterns in recent actions, these are the artifacts requests tend to converge on.

1. Your attestation records, with the follow-up

Annual attestations that reps use only approved channels are near universal. Examiners ask what happened next. Which reps attested late, which ones didn't attest at all, and what the firm did about either. An attestation file with 100% completion and no exception handling reads as unverified rather than clean.

2. Evidence you monitored for unapproved channel use

FINRA's 2026 report recommends firms monitor for unapproved channel use, which means examiners are entitled to ask what that monitoring looks like at your firm. Not the policy prohibiting WhatsApp. The detection mechanism. Mobile device management reports, carrier records reviews, app inventory checks, spot reviews of client complaints for references to channels you don't capture.

Velox is instructive here because the detection worked. The firm found the problem. What it couldn't produce was any record of remediation between the internal flag and the examiner's arrival.

3. Your surveillance lexicon and its revision history

FINRA recommends firms regularly refresh communications surveillance keywords. Examiners ask for the current keyword list and when it last changed. A lexicon that hasn't been touched in three years invites the follow-up question about whether it covers the channels and slang your reps actually use. Version history matters more than list length.

4. Mock exam results

The 2026 report recommends firms simulate regulatory examinations. Firms that do this and document it have something valuable when the real request lands: a prior self-identified gap, with a remediation date, closed before an examiner asked. Firms that do it and don't document it get no credit.

5. Proof you validated your capture vendor

This one is newer, and it cuts directly at our own category. The 2026 report calls out vendor reliance without verification as a finding. As more firms depend on capture and archive services, examiners have started asking not whether you bought a solution but whether you tested that it works.

How to test your archiving vendor, including us

We sell iMessage, SMS, and WhatsApp capture into Smarsh, Global Relay, Bloomberg, and Microsoft archives. That gives us an obvious interest in telling you a purchase closes the gap. It doesn't, on its own, and an examiner who asks the vendor-validation question won't accept a contract as evidence.

Run the test yourself, on a quarterly cadence, and keep the output:

  • Send known messages through every covered channel. Group iMessage, SMS with an attachment, MMS, WhatsApp voice note, WhatsApp media. Note timestamps.
  • Search for them in the archive of record, not the vendor's console. The archive is where a production request gets fulfilled.
  • Check what came through degraded. Did the attachment arrive? Is the group thread reconstructable with participants intact? Are edits and deletions reflected?
  • Test a device that shouldn't be enrolled. A rep's newly issued phone, or a personal device added between enrollment cycles. Gaps show up at the edges of onboarding, not in steady state.
  • Log the whole thing, including failures. A validation log with three documented failures and three remediation dates is stronger evidence of a working program than a log with none.

If a vendor discourages you from testing into your archive of record, that's information.

Individual accountability changed the stakes

The SEC's sweep targeted institutions. FINRA is increasingly reaching individuals. By January 2026 FINRA had barred an individual from the industry over off-channel communications, and in October 2025 a former Wells Fargo Advisors broker was fined and suspended for off-channel messaging and deleting the evidence.

The deletion detail is worth sitting with. Spoliation compounds the underlying capture failure, and it converts a recordkeeping finding into a credibility problem that follows the individual. January 2026 also brought a reported $750,000 FINRA fine against Benjamin F. Edwards over texting, and a $65,000 fine against a member firm in November 2025. Check the FINRA disciplinary actions database for the primary releases on all of these before you cite figures in a board deck. The Edwards number in particular traces to secondary reporting.

What counts as a record keeps widening

Three scope expansions in the 2026 report change the inventory question.

AI-enabled communications. FINRA says firms should ensure supervision and governance practices cover capture of AI-enabled communications within books and records. If a rep drafts client outreach with an assistant, the prompt and output are in scope territory.

Chatbots. Customer-facing chatbots are treated as firm communications and must be supervised and archived accordingly. Many firms deployed these through marketing without a recordkeeping review.

Social media influencers. FINRA found that many firms lack supervision and recordkeeping around influencers acting on the firm's behalf, including failure to archive posts. If you've paid someone to post about your firm, those posts are the firm's communications.

Each of these expands what a records request can reach, and none of them are covered by a mobile capture tool. Worth inventorying separately.

Requests don't only come from examiners

Jeff Ziesman, Partner at Norton Rose Fulbright and a former FINRA Deputy Regional Chief Counsel, has made the point that off-channel communications surface in suitability matters, arbitrations, and investigations because their absence undermines a firm's ability to reconstruct what happened.

That reframes the cost. A cycle exam finding is a fine and a remediation plan. A missing message thread in a customer arbitration is an evidentiary hole on the record you needed to defend yourself. FINRA Rule 4511, SEC Exchange Act Rule 17a-4, and FINRA Rule 3110 set the obligation, but the practical value of a complete archive shows up most when you're the one trying to prove what was said.

The gap that actually gets firms cited

Between the internal flag and the examiner's question, there's usually a period where somebody knew. Velox knew. The finding wasn't ignorance of a WeChat problem, it was the absence of anything documented between knowing and being asked.

So when you're preparing for a cycle exam, the useful audit isn't of your policy library. It's of your remediation records. Pick the last three off-channel issues your firm identified, whatever the source: a rep's disclosure, a client complaint referencing a text, a surveillance hit. For each one, find the date it was identified, the date it was closed, and what changed. If any of those three can't be reconstructed from your own files, that's the request you're least prepared for.