The FCA’s recording regime sits in SYSC 10A of the FCA Handbook, under Recording telephone conversations and electronic communications.
Firms need to capture relevant communications, prevent employees from moving those communications to channels they cannot record, retain the records for the required period, and periodically check that their controls are working. The FCA does not intend to introduce rules for every potential communication scenario. The focus remains on whether firms have effective controls and take reasonable steps to prevent relevant communications from moving outside them.
At a Glance
| FCA recordkeeping | Information |
|---|---|
| Where the rules sit | SYSC 10A (recording of communications) and SYSC 9.1 (general record-keeping), FCA Handbook |
| Issued by | Financial Conduct Authority |
| Origin | UK implementation of the MiFID II recording obligation |
| Who it applies to | Firms carrying out designated investment activities in financial instruments, including MiFID investment firms, certain fund managers, third country firms, and firms active in commodity or energy markets. |
| What must be recorded | Telephone conversations and electronic communications relating to the reception, transmission and execution of orders, and dealing on own account |
| Retention period | Five years, and up to seven years where the FCA requests it |
| Off-channel provision | All reasonable steps to prevent use of privately owned equipment the firm cannot record |
| Monitoring obligation | Periodic monitoring of records of transactions and orders to check compliance |
| Covers messaging apps? | Yes, where the communication relates to an in-scope activity. The rule is channel-neutral by design |
Who SYSC 10A Applies To
SYSC 10A.1.1R establishes the scope. The chapter applies to MiFID investment firms, AIFMs, UCITS management companies, third country investment firms, and firms carrying on commodity futures or energy market activities, in each case where they are carrying out designated investment activities in financial instruments.
SYSC 10A.1.4R excludes a short list of activities. They are narrow and specific, covering particular fund, energy and underwriting business rather than exempting whole categories of firm.
For most firms, the practical question is whether employees are receiving, transmitting or executing client orders in financial instruments, or dealing on the firm’s own account.
What Has to Be Recorded
SYSC 10A.1.6R requires a firm to “take all reasonable steps to record telephone conversations, and keep a copy of electronic communications” relating to those in-scope activities, where they are made with, sent from, or received on equipment the firm provides or permits for business use.
Two aspects matter.
It is channel-neutral. The rule says electronic communications, rather than naming particular applications. A message about a client order is in scope whether it arrives by Bloomberg Chat, Microsoft Teams, WhatsApp or SMS.
It reaches conversations that go nowhere. The obligation covers communications intended to result in an in-scope activity, even where the transaction never happens. A call that ends without an order is still a recordable call.
The Off-Channel Rule: SYSC 10A.1.7R
SYSC 10A.1.7R requires a firm to “take all reasonable steps to prevent an employee or contractor from making, sending, or receiving relevant telephone conversations and electronic communications on privately-owned equipment” which the firm is unable to record or copy.
The standard is reasonable steps, not a guaranteed outcome. A firm is not in breach the moment one message escapes, but a firm that cannot describe the steps it took has nothing to point at when the FCA asks.
Retention: Five Years, Seven on Request
SYSC 10A.1.14R requires relevant records to be kept for five years. The FCA can require them to be kept for up to seven years.
The same rule requires records to be provided to the client involved on request.
That makes retrieval an important part of the recordkeeping process. A record that technically exists but cannot be located, isolated or exported when required is of limited practical use.
Alongside it, SYSC 9.1 carries the general obligation. SYSC 9.1.1R requires firms to “arrange for orderly records to be kept of its business and internal organisation, including all services and transactions undertaken by it,” and SYSC 9.1.1AR extends this for common platform firms, requiring records sufficient for FCA supervision and enforcement. SYSC 9.1.2R sets at least five years for MiFID business records. SYSC 9.1.2-AR adds the qualitative standard: records must be stored accessibly, allow FCA access, permit reconstruction of each transaction, and be protected against manipulation.
For non-MiFID business, SYSC 9.1.5G is deliberately open. Records should be kept “for as long as is relevant for the purposes for which they are made.”
Client notification
Under SYSC 10A.1.11R, a firm must notify new and existing clients, before providing investment services, that telephone conversations and electronic communications will be recorded, and that copies of those records are available for five years to the client and seven years to the FCA.
A firm cannot provide the relevant services by telephone to a client who has not received that notification.
Monitoring your Recording
SYSC 10A.1.15R requires a firm to monitor compliance with the recording and record-keeping requirements of the chapter, by periodically monitoring the records of transactions and orders.
Read that as written. Owning an archive does not discharge SYSC 10A. The firm is required to go back and check that the archive contains what it should: that recording was actually happening, that the coverage matches the population of in-scope activity, and that gaps were found and dealt with. A firm that has never reconciled its order records against its communications records has not performed this rule.
What the FCA Found When It Looked
On August 7, 2025 the FCA published a multi-firm review of off-channel communications covering eleven wholesale banks, large and small. It is the most direct statement available of what the regulator considers good and poor practice here.
The numbers from the sample:
- 178 breaches of firms' own communications policies over the preceding 12 months
- Eight of the eleven firms reported breaches; three reported none
- 131 of the 178 breaches were concentrated in just three firms
- 41% involved staff at director grade or above
The FCA did not open enforcement off the back of the review, and it closed the door on rule-writing: “we do not intend to introduce new rules to cater for every potential scenario related to communication monitoring.”
Good practice the FCA identified. Surveillance lexicons updated to cover emerging channels, including detection of channel hopping. Natural language processing and AI used to filter alerts. Monitoring on-channel behaviour to spot staff whose approved-app usage is unusually low, on the theory that silence on the record is itself a signal. Corporate devices issued to client-facing staff, with some firms using brightly coloured handsets so an unapproved device is obvious in the room. Management information that tracks breach detail, remedial projects, framework effectiveness, vendor KPIs and trend analysis against RAG thresholds.
Poor practice the FCA identified. Third-party vendors delivering service outages, data reconciliation failures and inaccurate transcription. Large firms whose management information focused solely on breach counts with no broader context. Smaller firms whose monitoring was limited to spot-checking outcomes. And no evidence that senior penalties had been administered, despite disciplinary frameworks that allowed for dismissal.
Where Comma Fits
Comma is designed against SEC 17a-4, FINRA 4511, CFTC 1.31, and MiFID II electronic-recordkeeping requirements. Regulators do not approve or certify archiving vendors, and several SYSC 10A obligations, including client notification, monitoring and disciplinary follow-through, belong to the firm and cannot be bought.
The channel list is the point. SYSC 10A is channel-neutral, and the FCA’s review found breaches clustering in senior staff on personal apps. Comma captures across 40+ channels in one archive under one retention policy, including WhatsApp, iMessage, Signal, SMS, MMS and RCS, Telegram, WeChat, email across Gmail, Outlook, Microsoft 365 Exchange and any IMAP provider, Slack and Microsoft Teams, and Zoom meetings, phone and recordings. The full list is on platform integrations.
Retention is configured. Retention runs from capture under your configured policy, which is what lets a five-year window be set deliberately and extended where the FCA asks for seven.
Client-request export. SYSC 10A.1.14R requires records to be handed to the client involved on request. Archived communications are exportable in standard formats, scoped to a custodian, without a support ticket in the path.
Evidence for the monitoring duty. SYSC 10A.1.15R asks you to check your own recording periodically. Detected capture interruptions and known exceptions are durable, reasoned records rather than silent holes, which is the input a periodic reconciliation needs.
Data location transparency. Comma discloses where communications data is processed and stored, and contract schedules identify the specific regions used for capture, storage and processing.
The Practical Requirement
SYSC 10A is not a rule about WhatsApp, Teams or any other individual application. It requires firms to maintain control over relevant business communications as the channels used to conduct that business change.
For compliance teams, that means four things: capture the relevant communications, prevent unrecordable channels, retain the records, and test that the controls are working. For an archive, the question is whether the firm can demonstrate all four.
FAQ about FCA recordkeeping
Does the FCA ban WhatsApp for regulated business?
How long do UK firms have to keep communications records?
Do the rules cover conversations that did not lead to a trade?
Is having an archive enough to satisfy SYSC 10A?
Does SYSC 10A apply to a US firm with UK clients?
What did the FCA's 2025 off-channel review actually change?
Related regulations
Off-Channel Communications Compliance
What off-channel compliance requires, where firms get cited, and what examiners check across jurisdictions.
Read the guide
DORA
EU operational resilience regulation applying since January 17, 2025. UK firms with EU entities face both DORA and the FCA regime at once.
Read the guide
SEC Rule 17a-4
The US broker-dealer recordkeeping standard. For firms operating in both the UK and US, SYSC 10A and 17a-4 apply simultaneously.
Read the guide
