Where We Have Been, Where the Signals Point, and What to Do Before Year-End The […]
Spring cleaning for recordkeeping compliance: key SEC rules, retention risks, and do’s and don’ts for advisers and broker-dealers.

There is something deceptively tidy about the word "recordkeeping." It conjures images of organized binders, labeled folders, and the satisfying act of clearing out what is no longer needed. In reality, the recordkeeping obligations facing registered investment advisers, broker-dealers, and financial institutions more broadly are among the most operationally complex compliance requirements in the regulatory landscape, spanning years of retention, dozens of record categories, electronic systems of every description, and jurisdictional considerations that do not stop at the water's edge.
Spring is as good a time as any to take stock. But before firms start deleting old email threads and clearing out shared drives, it is worth understanding exactly what the rules require, and where the traps are.
For registered investment advisers, the primary recordkeeping framework is found in Rule 204-2 under the Investment Advisers Act of 1940. The rule is detailed and demanding, requiring advisers to maintain a wide range of records (including correspondence, trade records, account statements, advisory contracts, financial statements, and the written policies and procedures required under the compliance rule) for periods ranging from two to five years, with records generally required to be kept in an easily accessible place for the first two years of the retention period.
For broker-dealers, the governing framework is principally SEC Rules 17a-3 and 17a-4, which establish what records must be created and how long they must be kept. Rule 17a-4 in particular is exacting, specifying not only retention periods, three years in most cases, six years for certain categories, but also the technical standards to which electronic records must conform. FINRA layered obligations, including those arising under Rules 4511 and 4512, reinforce and in some cases extend these requirements.
These are not static rules. The SEC's 2023 amendments to Rule 17a-4, along with parallel amendments to Rule 18a-6 governing security-based swap dealers, updated the electronic recordkeeping standards that had remained largely unchanged for decades, requiring firms to revisit the technical architecture of their recordkeeping systems and the vendor arrangements that support them.
Recordkeeping obligations under SEC and FINRA rules are not a peripheral compliance concern; they sit at the foundation of regulatory accountability. The rules governing what must be retained, for how long, and in what form are detailed and, in some areas, counterintuitive. The following principles are not a substitute for a thorough review of the applicable rules, but they reflect the issues that arise most frequently in practice and in examination.
Recordkeeping is not just the papers taking up space in your filing cabinet. Modern recordkeeping obligations are broader, more technical, and more consequential than many firms appreciate, and regulators have made clear they are paying attention. This is where many firms find the gap between their understanding of their obligations and the actual state of their programs to be widest.
Electronic records are not a carve-out or a simplified version of the recordkeeping requirements. They are subject to the same obligations, and in some respects, more technical ones. Rule 17a-4 specifies that electronic records must be preserved exclusively in a non-rewritable, non-erasable format, commonly referred to as WORM (write once, read many). The 2023 amendments introduced an alternative audit-trail standard, but that alternative carries its own technical and governance requirements. Either way, a firm must be able to demonstrate that its electronic records cannot be altered or deleted before the applicable retention period has run.
For many firms, this raises immediate practical questions about their current systems. Cloud storage solutions, collaboration platforms, and third-party applications may not, by default, preserve records in a manner that satisfies these standards. The firm's recordkeeping obligations do not bend to accommodate the architecture of a vendor's platform; it is the platform that must be configured to meet the rule, or replaced with one that can.
Email is the most obvious category of electronic record, and it remains a persistent area of regulatory focus. But it is far from the only one. Instant messaging, text messages, and communications sent through collaboration tools- Teams, Slack, and their equivalents- are equally within scope if they relate to the firm's business. The SEC's enforcement actions against major financial institutions in recent years, resulting in billions of dollars in penalties for off-channel communications failures, have made this point emphatically clear. Firms of every size should treat those actions not as cautionary tales about large banks but as a signal about where regulatory attention is focused.
For firms operating across state lines, or with clients, personnel, or counterparties in non-US jurisdictions, the recordkeeping picture becomes considerably more complex.
At the domestic level, state securities regulators may impose their own recordkeeping requirements on state-registered advisers that differ from (and in some cases exceed) SEC requirements. Firms that have grown and transitioned from state to SEC registration, or that operate in multiple states, should confirm that their programs reflect the applicable requirements at each level.
Internationally, the complications multiply. Data privacy regimes in the European Union, the United Kingdom, and a growing number of other jurisdictions impose restrictions on the storage, transfer, and retention of personal data that can create direct tension with US recordkeeping mandates. A firm subject to GDPR's data minimization and storage limitation principles, for example, may find that retaining certain records for the periods required under US rules raises questions under European law, and vice versa, that disposing of records in compliance with European requirements could put the firm in breach of its US obligations.
There is no universal answer to these conflicts, but there is a framework for navigating them: identify the applicable obligations in each jurisdiction, map them against one another, document the analysis, and make defensible decisions with appropriate legal and compliance input. Firms that discover these conflicts for the first time during an examination are in a materially worse position than those that have worked through them proactively.
Firms operating in the digital assets space, whether as advisers to crypto funds, as platforms facilitating digital asset transactions, or as participants in the increasingly regulated tokenized securities market, face a recordkeeping environment that is still taking shape but is already demanding.
The SEC has made clear that its existing recordkeeping rules apply to digital asset securities to the same extent they apply to traditional securities. That means broker-dealers handling digital asset transactions are subject to the same Rules 17a-3 and 17a-4 requirements that govern their traditional securities business, including the WORM storage requirements for electronic records. The practical challenge is that the infrastructure of digital asset markets was not designed with these requirements in mind, and the gap between what the rules demand and what existing systems provide is often significant.
For advisers to digital asset funds, the challenge is compounded by the novelty of the asset class itself. Records of investment decisions, valuations, and trade activity in markets that operate around the clock, across decentralized venues, and without traditional custodial infrastructure require creative but rigorous approaches to recordkeeping program design.
Firms in this space should not assume that their obligations are somehow softer because the regulatory framework is still developing. Regulators have been clear that existing rules apply, and enforcement activity in the digital assets space has demonstrated a willingness to hold firms to those standards even where compliance was operationally difficult.
Private equity advisers often underestimate the duration and complexity of their recordkeeping obligations, in part because the nature of private equity investing (long-dated funds, infrequent transactions, and illiquid positions, etc.) can create a false sense that there is less to track.
In fact, the opposite is often true. The long lifecycle of a private equity fund means that records generated at formation, during capital deployment, and through the management of portfolio companies may need to be retained well beyond the life of the fund itself. Records relating to the basis of investments, valuation decisions, fee calculations, and communications with limited partners carry retention requirements that can, in practice, span decades when fund lifecycles and post-liquidation periods are taken together.
PE advisers are also increasingly subject to scrutiny around their compliance programs and documentation practices following the SEC's expanded focus on private fund advisers in recent years. The expectation that advisers maintain records adequate to demonstrate compliance with their fiduciary obligations, including the basis for investment decisions and the disclosure of conflicts, has only intensified.
Much of the regulatory and enforcement focus in recordkeeping tends to center on retention (e.g., what must be kept, and for how long). Disposal receives less attention, which is precisely why it tends to be where firms encounter problems.
Regulatory-compliant disposal of records is not simply deleting files or shredding paper when someone decides it is time to clear space. It requires a defensible determination that the applicable retention period has run, that no litigation hold or regulatory inquiry is outstanding that would suspend the normal disposition schedule, and that the disposal is documented and consistent with the firm's written retention policy.
Firms that cannot produce records during an examination because they were destroyed, even if destroyed after the retention period had technically expired, face a difficult conversation if that destruction was not systematic and documented. Firms that destroy records in the shadow of a pending inquiry face consequences that go well beyond a recordkeeping violation.
A well-designed records retention schedule, applied consistently and reviewed regularly, is the foundation of a defensible disposal program. It is also, in our experience, one of the most frequently neglected elements of an otherwise reasonable compliance infrastructure.
Recordkeeping compliance is not a one-time project. It is a program, and one that must be designed thoughtfully, implemented consistently, and revisited as the firm's business evolves and regulatory expectations change.
CRC works with registered investment advisers, broker-dealers, and financial institutions across the complexity spectrum to assess, build, and maintain recordkeeping programs that are proportionate to their business and defensible under regulatory scrutiny. Our engagements typically begin with a structured gap assessment, a clear-eyed review of where the firm's current practices stand relative to its applicable obligations, and produce a prioritized remediation roadmap that the firm can act on.
From there, we assist with the development of written policies and procedures, records retention schedules, disposal protocols, and the vendor oversight frameworks necessary to ensure that third-party platforms are configured to meet the firm's regulatory requirements. For firms navigating jurisdictional complexity, whether across state lines or across borders, we bring the analytical framework necessary to identify conflicts, document the firm's analysis, and make defensible decisions.
For firms in the digital assets space or private equity, where the application of existing frameworks to novel business models requires both regulatory expertise and practical judgment, CRC offers dedicated support informed by hands-on experience with the specific challenges those firms face.
Recordkeeping may not be the most glamorous corner of compliance. But it is one of the areas where preparation pays the most visible dividends, and where the cost of neglect tends to surface at the worst possible moments.
If your firm is overdue for a recordkeeping review, or if you are uncertain whether your current program reflects the full scope of your obligations, CRC is ready to help you take stock, and to build something that holds up.
Where We Have Been, Where the Signals Point, and What to Do Before Year-End The […]
There is a comfortable fiction embedded in how most registered investment advisers and broker-dealers think about material nonpublic […]
The recent FinCEN advisory directing financial institutions to detect and report suspicious activity linked to […]
Where We Have Been, Where the Signals Point, and What to Do Before Year-End The […]
There is a comfortable fiction embedded in how most registered investment advisers and broker-dealers think about material nonpublic […]
The recent FinCEN advisory directing financial institutions to detect and report suspicious activity linked to […]