Skip to content

Regulation Guide

The FCA Has Not Written a WhatsApp Rule. It Has Written a Reasonable Steps Rule.

SYSC 10A is often described as the Financial Conduct Authority's (FCA) communications recording rule, yet the harder requirement is broader.

The rules are deliberately not written around a list of apps. The communications channels that employees use continue to change.

SYSC 10A requires UK firms to record telephone conversations and electronic communications tied to orders and own-account dealing, keep them for five years, and take all reasonable steps to stop staff using channels the firm cannot record.

The FCA’s recording regime sits in SYSC 10A of the FCA Handbook, under Recording telephone conversations and electronic communications.

Firms need to capture relevant communications, prevent employees from moving those communications to channels they cannot record, retain the records for the required period, and periodically check that their controls are working. The FCA does not intend to introduce rules for every potential communication scenario. The focus remains on whether firms have effective controls and take reasonable steps to prevent relevant communications from moving outside them.

At a Glance

FCA recordkeepingInformation
Where the rules sitSYSC 10A (recording of communications) and SYSC 9.1 (general record-keeping), FCA Handbook
Issued byFinancial Conduct Authority
OriginUK implementation of the MiFID II recording obligation
Who it applies toFirms carrying out designated investment activities in financial instruments, including MiFID investment firms, certain fund managers, third country firms, and firms active in commodity or energy markets.
What must be recordedTelephone conversations and electronic communications relating to the reception, transmission and execution of orders, and dealing on own account
Retention periodFive years, and up to seven years where the FCA requests it
Off-channel provisionAll reasonable steps to prevent use of privately owned equipment the firm cannot record
Monitoring obligationPeriodic monitoring of records of transactions and orders to check compliance
Covers messaging apps?Yes, where the communication relates to an in-scope activity. The rule is channel-neutral by design

Who SYSC 10A Applies To

SYSC 10A.1.1R establishes the scope. The chapter applies to MiFID investment firms, AIFMs, UCITS management companies, third country investment firms, and firms carrying on commodity futures or energy market activities, in each case where they are carrying out designated investment activities in financial instruments.

SYSC 10A.1.4R excludes a short list of activities. They are narrow and specific, covering particular fund, energy and underwriting business rather than exempting whole categories of firm.

For most firms, the practical question is whether employees are receiving, transmitting or executing client orders in financial instruments, or dealing on the firm’s own account.

What Has to Be Recorded

SYSC 10A.1.6R requires a firm to “take all reasonable steps to record telephone conversations, and keep a copy of electronic communications” relating to those in-scope activities, where they are made with, sent from, or received on equipment the firm provides or permits for business use.

Two aspects matter.

It is channel-neutral. The rule says electronic communications, rather than naming particular applications. A message about a client order is in scope whether it arrives by Bloomberg Chat, Microsoft Teams, WhatsApp or SMS.

It reaches conversations that go nowhere. The obligation covers communications intended to result in an in-scope activity, even where the transaction never happens. A call that ends without an order is still a recordable call.

The Off-Channel Rule: SYSC 10A.1.7R

SYSC 10A.1.7R requires a firm to “take all reasonable steps to prevent an employee or contractor from making, sending, or receiving relevant telephone conversations and electronic communications on privately-owned equipment” which the firm is unable to record or copy.

The standard is reasonable steps, not a guaranteed outcome. A firm is not in breach the moment one message escapes, but a firm that cannot describe the steps it took has nothing to point at when the FCA asks.

Retention: Five Years, Seven on Request

SYSC 10A.1.14R requires relevant records to be kept for five years. The FCA can require them to be kept for up to seven years.

The same rule requires records to be provided to the client involved on request.

That makes retrieval an important part of the recordkeeping process. A record that technically exists but cannot be located, isolated or exported when required is of limited practical use.

Alongside it, SYSC 9.1 carries the general obligation. SYSC 9.1.1R requires firms to “arrange for orderly records to be kept of its business and internal organisation, including all services and transactions undertaken by it,” and SYSC 9.1.1AR extends this for common platform firms, requiring records sufficient for FCA supervision and enforcement. SYSC 9.1.2R sets at least five years for MiFID business records. SYSC 9.1.2-AR adds the qualitative standard: records must be stored accessibly, allow FCA access, permit reconstruction of each transaction, and be protected against manipulation.

For non-MiFID business, SYSC 9.1.5G is deliberately open. Records should be kept “for as long as is relevant for the purposes for which they are made.”

Client notification

Under SYSC 10A.1.11R, a firm must notify new and existing clients, before providing investment services, that telephone conversations and electronic communications will be recorded, and that copies of those records are available for five years to the client and seven years to the FCA.

A firm cannot provide the relevant services by telephone to a client who has not received that notification.

Monitoring your Recording

SYSC 10A.1.15R requires a firm to monitor compliance with the recording and record-keeping requirements of the chapter, by periodically monitoring the records of transactions and orders.

Read that as written. Owning an archive does not discharge SYSC 10A. The firm is required to go back and check that the archive contains what it should: that recording was actually happening, that the coverage matches the population of in-scope activity, and that gaps were found and dealt with. A firm that has never reconciled its order records against its communications records has not performed this rule.

What the FCA Found When It Looked

On August 7, 2025 the FCA published a multi-firm review of off-channel communications covering eleven wholesale banks, large and small. It is the most direct statement available of what the regulator considers good and poor practice here.

The numbers from the sample:

  • 178 breaches of firms' own communications policies over the preceding 12 months
  • Eight of the eleven firms reported breaches; three reported none
  • 131 of the 178 breaches were concentrated in just three firms
  • 41% involved staff at director grade or above

The FCA did not open enforcement off the back of the review, and it closed the door on rule-writing: “we do not intend to introduce new rules to cater for every potential scenario related to communication monitoring.”

Good practice the FCA identified. Surveillance lexicons updated to cover emerging channels, including detection of channel hopping. Natural language processing and AI used to filter alerts. Monitoring on-channel behaviour to spot staff whose approved-app usage is unusually low, on the theory that silence on the record is itself a signal. Corporate devices issued to client-facing staff, with some firms using brightly coloured handsets so an unapproved device is obvious in the room. Management information that tracks breach detail, remedial projects, framework effectiveness, vendor KPIs and trend analysis against RAG thresholds.

Poor practice the FCA identified. Third-party vendors delivering service outages, data reconciliation failures and inaccurate transcription. Large firms whose management information focused solely on breach counts with no broader context. Smaller firms whose monitoring was limited to spot-checking outcomes. And no evidence that senior penalties had been administered, despite disciplinary frameworks that allowed for dismissal.

Where Comma Fits

Comma is designed against SEC 17a-4, FINRA 4511, CFTC 1.31, and MiFID II electronic-recordkeeping requirements. Regulators do not approve or certify archiving vendors, and several SYSC 10A obligations, including client notification, monitoring and disciplinary follow-through, belong to the firm and cannot be bought.

The channel list is the point. SYSC 10A is channel-neutral, and the FCA’s review found breaches clustering in senior staff on personal apps. Comma captures across 40+ channels in one archive under one retention policy, including WhatsApp, iMessage, Signal, SMS, MMS and RCS, Telegram, WeChat, email across Gmail, Outlook, Microsoft 365 Exchange and any IMAP provider, Slack and Microsoft Teams, and Zoom meetings, phone and recordings. The full list is on platform integrations.

Retention is configured. Retention runs from capture under your configured policy, which is what lets a five-year window be set deliberately and extended where the FCA asks for seven.

Client-request export. SYSC 10A.1.14R requires records to be handed to the client involved on request. Archived communications are exportable in standard formats, scoped to a custodian, without a support ticket in the path.

Evidence for the monitoring duty. SYSC 10A.1.15R asks you to check your own recording periodically. Detected capture interruptions and known exceptions are durable, reasoned records rather than silent holes, which is the input a periodic reconciliation needs.

Data location transparency. Comma discloses where communications data is processed and stored, and contract schedules identify the specific regions used for capture, storage and processing.

The Practical Requirement

SYSC 10A is not a rule about WhatsApp, Teams or any other individual application. It requires firms to maintain control over relevant business communications as the channels used to conduct that business change.

For compliance teams, that means four things: capture the relevant communications, prevent unrecordable channels, retain the records, and test that the controls are working. For an archive, the question is whether the firm can demonstrate all four.

FAQ about FCA recordkeeping

Does the FCA ban WhatsApp for regulated business?
No. The FCA has said explicitly that it does not intend to introduce new rules covering every communication-monitoring scenario, and it has not banned specific apps. SYSC 10A.1.7R requires all reasonable steps to prevent staff using privately owned equipment the firm cannot record. A firm that can capture WhatsApp on a permitted device is meeting the rule; a firm that cannot capture it has to prevent its use for in-scope business.
How long do UK firms have to keep communications records?
Five years under SYSC 10A.1.14R, extendable to up to seven years where the FCA requests it. SYSC 9.1.2R separately requires at least five years for MiFID business records. For non-MiFID business, SYSC 9.1.5G says records should be kept for as long as is relevant to the purpose they were made for, which is a judgement the firm has to document.
Do the rules cover conversations that did not lead to a trade?
Yes. SYSC 10A covers communications intended to result in the reception, transmission or execution of an order, or dealing on own account, whether or not the transaction actually concludes. A call that ends without an order is still recordable.
Is having an archive enough to satisfy SYSC 10A?
No. SYSC 10A.1.15R is a separate obligation requiring firms to monitor their own compliance with the recording and record-keeping requirements by periodically monitoring records of transactions and orders. A firm that has never reconciled its order population against its communications records has not performed that rule, however good the archive is.
Does SYSC 10A apply to a US firm with UK clients?
It can. SYSC 10A.1.1R brings third country investment firms within scope where they carry out designated investment activities in financial instruments in the UK. Firms operating on both sides typically run one archive against the stricter combination: the US six-year retention floor for books and records alongside the UK client-access and monitoring duties.
What did the FCA's 2025 off-channel review actually change?
It did not change the rules. The FCA published it on August 7, 2025 after surveying eleven wholesale banks, reported 178 policy breaches over 12 months with 41% involving staff at director grade or above, took no enforcement action, and confirmed it would not write app-specific rules. Its value is as a statement of supervisory expectations: channel-hopping detection, monitoring for unusually low approved-app usage, management information that goes beyond breach counts, and disciplinary follow-through that actually reaches senior staff.

Related regulations

See how Comma supports your recordkeeping obligations

Last updated:

Share this page

More