FINRA and SEC 17a-4 Compliance for Microsoft 365
FINRA and SEC 17a-4 Compliance for Microsoft 365 configures the Microsoft Purview controls a broker-dealer, registered investment adviser, or fund needs to keep required books and records inside Microsoft 365 rather than in a bolt-on archive: retention policies locked with Preservation Lock so no administrator — not even a global admin — can shorten or remove them, retention labels that declare regulatory records where a record type calls for it, capture of email and Teams chats and channel messages under the same policies, a supervisory review workflow in Purview Communication Compliance for the correspondence review your written supervisory procedures require, and an audit evidence pack your compliance officer and counsel can put in front of an examiner. Three weeks, estimated at $4,950 and confirmed as a fixed written quote after scoping. We are Microsoft 365 engineers: we do not give legal advice, we do not decide which of your records fall under SEC Rule 17a-4 or FINRA Rule 4511, and we do not issue attestations. Your compliance counsel owns those questions, and this engagement is built to hand them evidence, not opinions.
What this engagement is
The recordkeeping rules are short to summarize and expensive to get wrong, so here is our engineering reading of the public rule text — your counsel's reading governs. SEC Rule 17a-4 tells broker-dealers which records to preserve and for how long, and paragraph (f) sets the conditions for keeping them electronically. Its 2022 amendments — adopted in October 2022, effective January 2023, with a compliance date in May 2023 for broker-dealers — kept the long-standing non-rewriteable, non-erasable (WORM) standard as one option and added an audit-trail alternative, under which the system must be able to recreate an original record if it is modified or deleted; they also replaced the old third-party access undertaking with a designated third party or designated executive officer arrangement. FINRA Rule 4511 requires members to keep books and records in the format and for the periods set by FINRA rules and the SEC's rules, with a six-year default where none is specified; business communications fall under 17a-4(b)(4) — three years, the first two in an easily accessible place. FINRA Rule 3110 requires a supervisory system including review of incoming and outgoing correspondence and internal communications, and its supplementary material ties retention of those communications to the same 17a-4(b) periods. Investment advisers answer to a different rule — Advisers Act Rule 204-2, with its own electronic-records safeguards — which is why an RIA's scope on this engagement looks different from a broker-dealer's. And since 2022 the SEC's and FINRA's off-channel communications enforcement has made 'where do our people actually talk to clients' the question every firm's board now asks. Microsoft's side of this is well documented and frequently misread. Microsoft has commissioned independent assessments from Cohasset Associates — most recently updated after the 2022 amendments and covering Exchange Online, SharePoint, OneDrive, Teams, and Viva Engage against SEC 17a-4(f), 18a-6(e), FINRA 4511(c), and CFTC 1.31(c)-(d) — which conclude that those services can meet the non-rewriteable, non-erasable requirement when configured with retention policies protected by Preservation Lock, and with retention labels declaring regulatory records where appropriate. The operative word is configured. A default tenant satisfies none of this: retention is off, deletion is a right-click, and an administrator can undo any policy. Purview's Preservation Lock changes that — once applied, the policy cannot be turned off, deleted, or made less restrictive by anyone, including Microsoft-side support; locations can be added and periods extended, never reduced. Regulatory record labels go a step further: labelled items cannot be edited or deleted and the label cannot be removed, which is why Microsoft hides the option behind a PowerShell switch and why we will not enable it without your written go-ahead. The engagement runs in three weeks and starts with your counsel's list, not ours. Week one maps each record category your compliance team identifies — customer correspondence, internal communications relating to the business, order and account records held in Microsoft 365, supervisory review evidence — to the workloads and Purview features that will hold it, and verifies that your licensing actually includes those features. Week two builds everything unlocked: retention policies for Exchange and Teams (chats, channel messages, private and shared channels) and for SharePoint and OneDrive where scoped; retention labels and auto-application where record declaration is warranted; Communication Compliance policies with the scope, conditions, sampling, reviewers, and escalation your supervisory procedures describe; eDiscovery readiness so a prompt-production request is a rehearsed procedure rather than a scramble; and audit-log retention set to what your licensing allows. Week three is the lock: a written go/no-go with compliance and counsel, Preservation Lock applied and verified, regulatory record labels enabled where approved, and the evidence pack assembled — policy exports, lock confirmations, the Microsoft assessment references, screenshots, and a control narrative written for counsel to adapt into your written supervisory procedures. The boundaries are deliberate. We do not advise on which rules apply to you, which records are in scope, or whether WORM or the audit-trail alternative is your firm's basis; we configure to counsel's decision and document it. We do not act as your designated third party or executive officer, and we do not sign attestations — nobody's engagement should. We do not build third-party archivers: if you are keeping Smarsh, Global Relay, or another archive for voice, mobile, or non-Microsoft channels, we design the tenant to sit alongside it honestly; if you are consolidating into Microsoft 365, the archive migration comes first and this engagement follows. For the retention program beyond the regulated record set, see Microsoft Purview Data Lifecycle Management Implementation; for a full litigation-grade discovery build, Microsoft Purview eDiscovery Premium Implementation.
Success criteria
What you receive
How the work unfolds
Kickoff with your compliance officer and counsel; record-category workshop and signed mapping; licensing verification; current-state review of retention, holds, journaling, archivers, and Teams settings; policy and supervision design.
Configure retention policies and labels in an unlocked state; build Communication Compliance policies and assign reviewers; set audit retention; prepare eDiscovery readiness; run coverage, blocked-action, and production tests; validate findings with compliance.
Written go/no-go; Preservation Lock applied and verified; regulatory record labels enabled where approved; first supervisory review cycle completed; evidence pack assembled; readout with compliance officer and counsel; administrator handoff.
Prerequisites
Who does what
IT Partner
- Facilitate the record-category workshop and produce the signed mapping document.
- Verify licensing and document current state, including archivers and journaling.
- Design and configure retention policies, labels, Communication Compliance, audit retention, and eDiscovery readiness to the mapping.
- Run the go/no-go, apply and verify Preservation Lock, and enable regulatory records only on written approval.
- Assemble the evidence pack and the control narrative, and deliver the readout and administrator handoff.
- State plainly what the tenant captures natively and what it does not.
Your team
- Own every legal and regulatory determination: applicability, record categories, retention periods, WORM versus audit-trail basis, and the designated third party or executive officer role.
- Provide access, channel inventory, and stakeholder time on the agreed schedule.
- Sign the mapping and the lock go/no-go, and acknowledge irreversibility in writing.
- Staff the supervisory reviews and maintain written supervisory procedures.
- Adopt the control narrative into your procedures with counsel's review.
- Maintain the configuration and evidence over time, or contract that separately.
What's not included
Limitations & technical notes
Frequently asked questions
Is Microsoft 365 SEC 17a-4 compliant?
The question needs reframing. Microsoft 365 is 17a-4-capable: Microsoft has commissioned independent Cohasset Associates assessments concluding that Exchange Online, SharePoint, OneDrive, Teams, and Viva Engage can meet the rule's non-rewriteable, non-erasable requirement when retention policies with Preservation Lock — and regulatory record labels where appropriate — are configured. A default tenant meets none of it. Whether your tenant does is a configuration question this engagement answers with evidence; whether that satisfies your obligations is a question for your counsel.
What is Preservation Lock, and why do you keep calling it irreversible?
Preservation Lock is a Purview setting that makes a retention policy tamper-proof: once applied, nobody — not your global administrator, not Microsoft support — can turn it off, delete it, shorten its period, or remove locations from it. You can add locations and extend the period, and that is all. That property is precisely what the regulators want and precisely why we build and test everything unlocked first, lock only on a written go/no-go from compliance and counsel, and never apply it beyond the signed mapping.
What changed in the 2022 SEC amendments, and does it matter for a Purview design?
The amendments — adopted in October 2022, effective January 2023, with broker-dealer compliance from May 2023 — kept WORM as one option and added an audit-trail alternative, under which the system must be able to recreate an original record if it is modified or deleted; they also replaced the old third-party access undertaking with a designated third party or designated executive officer arrangement. Microsoft's assessment was updated after the amendments. Which basis your firm relies on is counsel's call; the practical design in Purview is the same locked retention, and we document the basis you choose in the evidence pack.
Do we still need Smarsh, Global Relay, or another archiver?
It depends on what you need captured. For Exchange email and Teams messages, Purview retention with Preservation Lock and Communication Compliance supervision can carry the load natively. For voice, SMS, WhatsApp, and other third-party channels, the tenant needs partner data connectors and device policy — or an archiver that already covers them. Many firms keep an archiver for those channels and let Microsoft 365 hold the rest; we design for that honestly and will not sell against a component you still need.
Does this cover text messages and WhatsApp?
Not natively, and we will not imply otherwise. Purview supports data connectors from partner vendors that import mobile and third-party messaging into the tenant so the same retention, supervision, and discovery apply — those are designed in the position paper and quoted separately with the vendor licensing. Just as important is conduct: the enforcement actions since 2022 were about people using channels that were never captured, and a device policy plus clear rules matter as much as any connector.
We are an RIA, not a broker-dealer. Does this apply to us?
Partly, and differently. Advisers keep books and records under Advisers Act Rule 204-2, which has its own requirements for electronic records rather than 17a-4(f)'s specific standards; dually registered firms carry both. The Purview design — locked retention, supervision workflow, prompt production, evidence — serves both, but the record categories and periods differ, which is exactly why week one starts with your counsel's list rather than a template.
What does FINRA Rule 3110 supervision look like inside Purview?
Communication Compliance policies that scope the supervised persons, apply conditions — lexicons, attachment types, sender and recipient patterns, and machine classifiers — sample a defined percentage of email and Teams messages, route them to named supervisors for review, tag outcomes, and escalate. Reviews and their evidence are exportable, so who reviewed what and when is demonstrable. It is a workflow that supports the review your written supervisory procedures require; the procedures themselves and the judgment applied in each review remain your supervisors' and your counsel's.
Which Microsoft 365 licenses do we need?
Retention policies are broadly available across Microsoft 365 business and enterprise plans; records management with regulatory records, Communication Compliance, eDiscovery Premium, and extended audit retention are tied to specific plans and add-ons such as Microsoft 365 E5, E5 Compliance, or the Purview suite. Week one verifies precisely what your subscriptions include and names any gap; buying a plan is your decision, and we will not recommend one where your current licensing already covers the requirement.
Will you sign an attestation, or act as our designated third party?
No to both. The designated third party or designated executive officer arrangement under amended Rule 17a-4(f) is your firm's to establish, and an attestation of compliance is not something an engineering engagement can honestly issue. What we deliver is the configuration and the evidence pack — exports, lock confirmations, screenshots, Microsoft's assessment references, and a control narrative — so that your compliance officer and counsel can make their statements on solid ground.
What is in the audit evidence pack?
The signed record-category mapping; licensing verification; retention policy and label exports with their locked state confirmed; blocked-action test results for regulatory records; the coverage report of every location under policy; Communication Compliance policy configuration and the first review cycle's evidence export; the eDiscovery production test; audit-retention settings; references to Microsoft's published Cohasset assessments; dated screenshots; and a control narrative mapped to 17a-4(f), 4511, and 3110 written for counsel to adapt. It is assembled so an examiner's request can be answered with documents, not explanations.
What about our existing journaling and legacy archive data?
Current state is reviewed in week one: journaling rules, in-place archives, and any third-party archiver are documented and their retention obligations noted. Consolidating a legacy archive into Microsoft 365 is a separate migration that should run before this engagement so the locked policies cover the imported data; keeping the archiver read-only through its retention period is equally valid. We do not bulk re-label historical content here — a targeted backfill is quoted if you want it.
Can users still delete emails and Teams messages after this?
They can appear to. Under a retain-only or retain-then-delete policy, a user's delete removes the item from their view while the tenant keeps the copy for the retention period — so nothing regulated is lost and the user experience is unchanged. Regulatory record labels are the exception: labelled items cannot be edited or deleted by anyone, which is why they are applied only where the mapping calls for them.
Why is the price an estimate rather than fixed?
Because two variables move it: how many registered entities and workloads the mapping covers, and whether messaging connectors or a full SharePoint and OneDrive records program come into scope. The $4,950 estimate assumes a single tenant with Exchange and Teams at the core and one supervision policy set; the scoping call turns it into a fixed written quote before work begins, and per our standard terms you pay after you approve delivery.
How long do we have to keep records?
That is your counsel's determination, and the mapping records it per category. For orientation only: FINRA Rule 4511 defaults to six years where no other period is specified, and business communications under SEC Rule 17a-4(b)(4) are three years with the first two easily accessible; advisers under Rule 204-2 have their own periods. Purview retention periods are set to whatever counsel specifies — and, once locked, can be extended but never shortened.