Skip to content

Policy Matching

Turn your archive into an active supervision program.

Monitor business communications in real time with Comma's custom Policy Matching. Flag SEC and FINRA compliance violations before they become exam risks.

Comma runs your compliance policies across captured communications, flags the conversations that carry risk for review, and samples the rest, so supervision is continuous and documented.

Flagged WhatsApp message opened under an Anti-Money Laundering policy with reviewer actions

Storage is table stakes. Supervision is the job.

An archive answers a request after the fact. A supervision program runs every day: it looks at communications as they’re captured and asks whether anything is creating risk now. Comma runs your policies across captured communications continuously, flags what matters for review, and samples the rest. The archive is still there. The supervision layer on top is what makes oversight ongoing instead of episodic.

  • Internal Policy Violations

    "I can get this approved faster if we just backdate the request."
  • Regulatory Red Flags

    "I promise you'll see a bump in Q3."
  • Conflicts Between Policy and Practice

    "If you go with it by Friday, I get a bonus, but honestly, I'd recommend it either way."

How policy matching works

Policy matching runs on every message Comma captures, the moment it’s captured. There’s no batch job to schedule and no separate tool to open. The supervision happens inside the same system that’s already archiving your communications.

  1. Comma captures the message

    Every communication Comma archives is available to policy matching automatically, across email, chat, messaging, social, and collaboration tools. If Comma captures it, your policies run on it.
  2. Your policies evaluate it in real time

    Each message is checked against the SEC and FINRA policies Comma ships with, plus any custom rules you've added. You set how sensitive each policy is, raising the bar so only the strongest matches are flagged, or lowering it to surface more for review. Evaluation happens on capture, not on a nightly sweep, so a flag is available the same day the message is sent.
  3. Risky messages get flagged for review

    Messages that match a policy are surfaced to your review queue with the policy they triggered. Your team reviews flagged items first, not the entire message stream.
  4. The rest gets sampled, not ignored

    Comma spot-checks a share of non-flagged communications, at a rate you set, so you can evidence a review percentage across the whole population, not just the messages that matched a policy.
Comma review queue listing flagged messages across policies like AML, insider information, and off-channel communications

Review and escalation queues

Matched messages don’t just pile up, they route. Flags land in a review queue where your team works them the way supervision actually runs.

  • Dedicated queues

    Separate queues by area so the right reviewer sees the right flags, instead of one undifferentiated pile.
  • Escalation path

    Route high-risk or ambiguous flags to an escalation queue for senior review.
  • Assignment and ownership

    Assign flags to reviewers and filter to what's yours, so nothing sits unowned.
  • From flag to action

    Open a case or place the records on legal hold directly from the queue when a flag needs to go further.
  • Clear dispositions

    Confirm a violation or mark it not a violation, and move the queue forward.

Bring your own policies

Standard coverage is the starting point, not the ceiling. Create your firm’s own policies in the dashboard and they run alongside Comma’s built-in ones, in the same queue and the same workflow, so a custom policy is never a second system to maintain.

  • Build policies yourself in the dashboard, no waiting on a vendor to configure them
  • Describe the risk you want caught in plain language, with the option to narrow it to specific terms
  • Set each policy's sensitivity and spot-check rate on its own, tuned to how much risk it carries

See the compliance policies guide →

Why this isn’t keyword filtering

Keyword filtering flags messages that contain specific words. It doesn’t understand context, so “guarantee” gets flagged whether it’s a prohibited performance promise or an employee guaranteeing they’ll call someone back. The result is a flood of false positives, and the real violations get lost in the noise.

Policy matching evaluates a message against behavioral and regulatory criteria, the intent behind the language, not just the presence of a term. That’s the difference between flagging every message with the word “guarantee” and flagging the one that actually promises a return, and it’s the difference that matters when you have to explain a flagging decision to a regulator.

FAQ about Policy Matching

Does Comma include pre-built SEC/FINRA policies out of the box?
Yes. Comma ships with standard policies covering common SEC and FINRA violations like misleading statements, unauthorized commitments, and conflict-of-interest language. You can run these as-is, adjust thresholds, or add your own rules.
Which regulations require firms to review communications?
FINRA Rule 3110 requires broker-dealers to establish supervisory procedures that include the review of business communications. SEC Rule 17a-4 and FINRA Rule 4511 require those communications to be retained, but Rule 3110 is the one that specifically requires supervisory review and documentation. Policy matching supports the review and documentation side of that obligation.
Does Comma have policy flagging across all channels equally?
Yes. The same policies you set up for email will run across chat and messaging platforms, and for every communication platform that Comma captures for you. If the policy is active, it runs on every message regardless of where it was sent.

See policy matching in action.

We'll walk through a live demo with real messages, real flags, and real supervision workflows.

Related reading