First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/FINRA and SEC 17a-4 Compliance for Microsoft 365
ComplianceImplementation

FINRA and SEC 17a-4 Compliance for Microsoft 365

FINRA and SEC 17a-4 Compliance for Microsoft 365 configures the Microsoft Purview controls a broker-dealer, registered investment adviser, or fund needs to keep required books and records inside Microsoft 365 rather than in a bolt-on archive: retention policies locked with Preservation Lock so no administrator — not even a global admin — can shorten or remove them, retention labels that declare regulatory records where a record type calls for it, capture of email and Teams chats and channel messages under the same policies, a supervisory review workflow in Purview Communication Compliance for the correspondence review your written supervisory procedures require, and an audit evidence pack your compliance officer and counsel can put in front of an examiner. Three weeks, estimated at $4,950 and confirmed as a fixed written quote after scoping. We are Microsoft 365 engineers: we do not give legal advice, we do not decide which of your records fall under SEC Rule 17a-4 or FINRA Rule 4511, and we do not issue attestations. Your compliance counsel owns those questions, and this engagement is built to hand them evidence, not opinions.

Timeline 3 weeksService owner Dan ApplebyMicrosoft 365Microsoft PurviewExchange Online

What this engagement is

The recordkeeping rules are short to summarize and expensive to get wrong, so here is our engineering reading of the public rule text — your counsel's reading governs. SEC Rule 17a-4 tells broker-dealers which records to preserve and for how long, and paragraph (f) sets the conditions for keeping them electronically. Its 2022 amendments — adopted in October 2022, effective January 2023, with a compliance date in May 2023 for broker-dealers — kept the long-standing non-rewriteable, non-erasable (WORM) standard as one option and added an audit-trail alternative, under which the system must be able to recreate an original record if it is modified or deleted; they also replaced the old third-party access undertaking with a designated third party or designated executive officer arrangement. FINRA Rule 4511 requires members to keep books and records in the format and for the periods set by FINRA rules and the SEC's rules, with a six-year default where none is specified; business communications fall under 17a-4(b)(4) — three years, the first two in an easily accessible place. FINRA Rule 3110 requires a supervisory system including review of incoming and outgoing correspondence and internal communications, and its supplementary material ties retention of those communications to the same 17a-4(b) periods. Investment advisers answer to a different rule — Advisers Act Rule 204-2, with its own electronic-records safeguards — which is why an RIA's scope on this engagement looks different from a broker-dealer's. And since 2022 the SEC's and FINRA's off-channel communications enforcement has made 'where do our people actually talk to clients' the question every firm's board now asks. Microsoft's side of this is well documented and frequently misread. Microsoft has commissioned independent assessments from Cohasset Associates — most recently updated after the 2022 amendments and covering Exchange Online, SharePoint, OneDrive, Teams, and Viva Engage against SEC 17a-4(f), 18a-6(e), FINRA 4511(c), and CFTC 1.31(c)-(d) — which conclude that those services can meet the non-rewriteable, non-erasable requirement when configured with retention policies protected by Preservation Lock, and with retention labels declaring regulatory records where appropriate. The operative word is configured. A default tenant satisfies none of this: retention is off, deletion is a right-click, and an administrator can undo any policy. Purview's Preservation Lock changes that — once applied, the policy cannot be turned off, deleted, or made less restrictive by anyone, including Microsoft-side support; locations can be added and periods extended, never reduced. Regulatory record labels go a step further: labelled items cannot be edited or deleted and the label cannot be removed, which is why Microsoft hides the option behind a PowerShell switch and why we will not enable it without your written go-ahead. The engagement runs in three weeks and starts with your counsel's list, not ours. Week one maps each record category your compliance team identifies — customer correspondence, internal communications relating to the business, order and account records held in Microsoft 365, supervisory review evidence — to the workloads and Purview features that will hold it, and verifies that your licensing actually includes those features. Week two builds everything unlocked: retention policies for Exchange and Teams (chats, channel messages, private and shared channels) and for SharePoint and OneDrive where scoped; retention labels and auto-application where record declaration is warranted; Communication Compliance policies with the scope, conditions, sampling, reviewers, and escalation your supervisory procedures describe; eDiscovery readiness so a prompt-production request is a rehearsed procedure rather than a scramble; and audit-log retention set to what your licensing allows. Week three is the lock: a written go/no-go with compliance and counsel, Preservation Lock applied and verified, regulatory record labels enabled where approved, and the evidence pack assembled — policy exports, lock confirmations, the Microsoft assessment references, screenshots, and a control narrative written for counsel to adapt into your written supervisory procedures. The boundaries are deliberate. We do not advise on which rules apply to you, which records are in scope, or whether WORM or the audit-trail alternative is your firm's basis; we configure to counsel's decision and document it. We do not act as your designated third party or executive officer, and we do not sign attestations — nobody's engagement should. We do not build third-party archivers: if you are keeping Smarsh, Global Relay, or another archive for voice, mobile, or non-Microsoft channels, we design the tenant to sit alongside it honestly; if you are consolidating into Microsoft 365, the archive migration comes first and this engagement follows. For the retention program beyond the regulated record set, see Microsoft Purview Data Lifecycle Management Implementation; for a full litigation-grade discovery build, Microsoft Purview eDiscovery Premium Implementation.

Success criteria

01A record-category-to-workload map — which records, which rule your counsel cites, which Microsoft 365 location, which Purview feature, which retention period — signed by your compliance officer before any policy is locked.
02Retention policies configured for every mapped location and protected with Preservation Lock, with the lock state verified after application and the irreversibility acknowledged in writing beforehand.
03Regulatory record labels enabled and applied where the map calls for them, with a test proving that edit, delete, and label removal are blocked on a labelled item.
04Coverage report showing every mailbox, Team, channel, site, and account under policy — and any deliberately excluded location named with the reason.
05Communication Compliance policies live with scope, conditions, sampling rate, reviewers, and escalation matching your supervisory procedures; a first review cycle completed and its evidence exported.
06A rehearsed prompt-production procedure: a sample eDiscovery search, hold, and export completed within the window your counsel specifies.
07Audit-log retention set to the maximum your licensing allows and documented, with any licensing gap named.
08The audit evidence pack delivered and walked through with your compliance officer and counsel, with every scope limit stated inside it.

What you receive

Record-category workshop and mapping: your counsel supplies which records and rules apply; we map each category to Microsoft 365 workloads, Purview features, retention periods, and lock decisions in a single signed document.
Licensing verification: which Purview capabilities your subscriptions include — retention policies, records management and regulatory records, Communication Compliance, eDiscovery, extended audit retention — and exactly which gaps would need a plan you do not hold.
Current-state review: existing retention policies and holds, journaling rules, in-place archives, any third-party archiver or connector, and Teams and external-access settings that affect what can be captured.
Retention policy design and configuration for Exchange Online and Microsoft Teams (chats, channel messages, private and shared channels), and for SharePoint and OneDrive where scoped, with retain-only versus retain-then-delete behaviour decided per category.
Preservation Lock application: a written go/no-go with compliance and counsel, the lock applied, and post-lock verification exported for the evidence pack.
Regulatory record labels: PowerShell enablement, label design, manual and auto-apply configuration where approved, and blocked-action testing.
Supervision workflow: Communication Compliance policies for email and Teams with conditions, sampling, reviewer assignment, escalation, and remediation tags; reviewer training; and the procedure for exporting review evidence.
Prompt-production readiness: an eDiscovery case template, hold procedure, export test, audit retention configuration, and a written production runbook.
Off-channel communications position paper: what the tenant captures natively, what mobile and third-party messaging would require through Purview data connectors from partner vendors, and the device and app policy options — configuration of third-party capture is designed here and quoted separately.
Audit evidence pack: policy and label exports, lock confirmations, Microsoft's published assessment references, dated screenshots, and a control narrative mapped to 17a-4(f), 4511, and 3110 — drafted for counsel to adapt into your written supervisory procedures, not as legal advice.
Administrator runbook and handoff: what can and cannot change after the lock, how to add locations and extend periods, and how to keep the evidence current.

How the work unfolds

Week 1 — Map and verify

Kickoff with your compliance officer and counsel; record-category workshop and signed mapping; licensing verification; current-state review of retention, holds, journaling, archivers, and Teams settings; policy and supervision design.

Week 2 — Build unlocked and test

Configure retention policies and labels in an unlocked state; build Communication Compliance policies and assign reviewers; set audit retention; prepare eDiscovery readiness; run coverage, blocked-action, and production tests; validate findings with compliance.

Week 3 — Lock, evidence, readout

Written go/no-go; Preservation Lock applied and verified; regulatory record labels enabled where approved; first supervisory review cycle completed; evidence pack assembled; readout with compliance officer and counsel; administrator handoff.

Prerequisites

A compliance officer and compliance counsel who will decide which record categories, rules, and retention periods apply — and who will sign the mapping before anything is locked. We do not make those determinations.
Microsoft 365 licensing that includes the Purview features the map requires, verified in week one; any purchase to close a gap is your decision and is not part of the project price.
Time-bound, least-privilege administrative access covering Purview compliance roles, Exchange Online, Teams, and — where scoped — SharePoint and OneDrive.
An inventory of the communication channels your registered persons actually use: email, Teams, mobile messaging, third-party apps, and any existing archiver or journaling destination.
Your firm's decision on the designated third party or designated executive officer arrangement under amended Rule 17a-4(f), where it applies — ours to document, not to fill.
Written acknowledgement that Preservation Lock and regulatory record labels are irreversible by design.
Availability of the supervisors who will act as reviewers for Communication Compliance training and the first review cycle.

Who does what

IT Partner

  • Facilitate the record-category workshop and produce the signed mapping document.
  • Verify licensing and document current state, including archivers and journaling.
  • Design and configure retention policies, labels, Communication Compliance, audit retention, and eDiscovery readiness to the mapping.
  • Run the go/no-go, apply and verify Preservation Lock, and enable regulatory records only on written approval.
  • Assemble the evidence pack and the control narrative, and deliver the readout and administrator handoff.
  • State plainly what the tenant captures natively and what it does not.

Your team

  • Own every legal and regulatory determination: applicability, record categories, retention periods, WORM versus audit-trail basis, and the designated third party or executive officer role.
  • Provide access, channel inventory, and stakeholder time on the agreed schedule.
  • Sign the mapping and the lock go/no-go, and acknowledge irreversibility in writing.
  • Staff the supervisory reviews and maintain written supervisory procedures.
  • Adopt the control narrative into your procedures with counsel's review.
  • Maintain the configuration and evidence over time, or contract that separately.

What's not included

Legal advice of any kind: which rules apply to your firm, which records are in scope, retention periods, whether WORM or the audit-trail alternative is your basis, written supervisory procedure authoring, examiner correspondence, or enforcement defence. The control narrative is a technical document for counsel to adapt.
Attestations, certifications, letters of compliance, or any statement that your firm is '17a-4 compliant' — no engagement can honestly issue one, and this one will not.
Serving as your designated third party or designated executive officer under Rule 17a-4(f); the arrangement is yours to make and ours to document.
Third-party archiver builds, renewals, or migrations. Consolidating a legacy archive into Microsoft 365 is Third-Party Email Archive Migration to Microsoft 365; legacy in-place archives are In-Place Archive Migration; keeping an archiver for channels the tenant does not capture is a legitimate design we will accommodate, not sell against.
Implementation of Purview data connectors for SMS, WhatsApp, or other third-party messaging capture, and the partner-vendor licensing they require — designed in the position paper, quoted separately.
Voice recording, trade surveillance, order-management, CRM, or any non-Microsoft system's records — out of scope, and named as such in the mapping so nobody assumes coverage.
A full records-management program across SharePoint and OneDrive beyond the regulated record set — that is Purview Data Lifecycle Management Implementation; a litigation-grade discovery build is eDiscovery Premium Implementation, and searches for a live matter are eDiscovery Search Assistance.
Ongoing supervisory reviews (your supervisors perform them), ongoing administration, and periodic evidence refresh — available as a separately contracted recurring service.
Microsoft licensing purchases, including any plan the licensing verification identifies as genuinely required.
Historical re-labelling or clean-up of years of legacy content beyond what the policies apply automatically; a targeted backfill is quoted if you want it.

Limitations & technical notes

!This page and the engagement contain no legal advice. The regulatory summaries are our engineering reading of public SEC and FINRA rule text and Microsoft's documentation as of September 2026; rules and interpretations change, and your compliance counsel decides what applies.
!Preservation Lock and regulatory record labels are irreversible by design — a locked policy cannot be removed or made less restrictive, and a regulatory record cannot be edited, deleted, or unlabelled. A scoping mistake cannot be undone, which is why everything is built and tested unlocked, locked only on written sign-off, and never applied to locations outside the signed mapping.
!Microsoft's Cohasset assessments are commissioned by Microsoft, apply to the named services in the described configurations, and are not a certification of your tenant; we reference them in the evidence pack and recommend that counsel read them directly.
!WORM versus the audit-trail alternative is your firm's decision. Microsoft positions locked retention as meeting the non-rewriteable, non-erasable standard; we configure to whichever basis counsel selects and document that choice.
!The tenant natively captures Exchange email and Teams chats and channel messages. SMS, WhatsApp, personal devices, and voice require connectors, device policy, and — above all — conduct rules; configuration does not fix off-channel behaviour, and we will say so.
!Available controls depend on licensing. Retention policies are broadly available; records management, Communication Compliance, and extended audit retention are tied to specific plans, and the licensing verification names any gap rather than assuming it away.
!The $4,950 figure is an estimate for a single tenant with Exchange and Teams as the core, one Communication Compliance policy set, and one entity; multiple registered entities, a full SharePoint and OneDrive records program, or messaging connectors are priced in the written quote before work begins, not discovered mid-project.
!The engagement reviews and configures controls; it does not read your firm's communications, and client data stays in the tenant.

Frequently asked questions

Is Microsoft 365 SEC 17a-4 compliant?

The question needs reframing. Microsoft 365 is 17a-4-capable: Microsoft has commissioned independent Cohasset Associates assessments concluding that Exchange Online, SharePoint, OneDrive, Teams, and Viva Engage can meet the rule's non-rewriteable, non-erasable requirement when retention policies with Preservation Lock — and regulatory record labels where appropriate — are configured. A default tenant meets none of it. Whether your tenant does is a configuration question this engagement answers with evidence; whether that satisfies your obligations is a question for your counsel.

What is Preservation Lock, and why do you keep calling it irreversible?

Preservation Lock is a Purview setting that makes a retention policy tamper-proof: once applied, nobody — not your global administrator, not Microsoft support — can turn it off, delete it, shorten its period, or remove locations from it. You can add locations and extend the period, and that is all. That property is precisely what the regulators want and precisely why we build and test everything unlocked first, lock only on a written go/no-go from compliance and counsel, and never apply it beyond the signed mapping.

What changed in the 2022 SEC amendments, and does it matter for a Purview design?

The amendments — adopted in October 2022, effective January 2023, with broker-dealer compliance from May 2023 — kept WORM as one option and added an audit-trail alternative, under which the system must be able to recreate an original record if it is modified or deleted; they also replaced the old third-party access undertaking with a designated third party or designated executive officer arrangement. Microsoft's assessment was updated after the amendments. Which basis your firm relies on is counsel's call; the practical design in Purview is the same locked retention, and we document the basis you choose in the evidence pack.

Do we still need Smarsh, Global Relay, or another archiver?

It depends on what you need captured. For Exchange email and Teams messages, Purview retention with Preservation Lock and Communication Compliance supervision can carry the load natively. For voice, SMS, WhatsApp, and other third-party channels, the tenant needs partner data connectors and device policy — or an archiver that already covers them. Many firms keep an archiver for those channels and let Microsoft 365 hold the rest; we design for that honestly and will not sell against a component you still need.

Does this cover text messages and WhatsApp?

Not natively, and we will not imply otherwise. Purview supports data connectors from partner vendors that import mobile and third-party messaging into the tenant so the same retention, supervision, and discovery apply — those are designed in the position paper and quoted separately with the vendor licensing. Just as important is conduct: the enforcement actions since 2022 were about people using channels that were never captured, and a device policy plus clear rules matter as much as any connector.

We are an RIA, not a broker-dealer. Does this apply to us?

Partly, and differently. Advisers keep books and records under Advisers Act Rule 204-2, which has its own requirements for electronic records rather than 17a-4(f)'s specific standards; dually registered firms carry both. The Purview design — locked retention, supervision workflow, prompt production, evidence — serves both, but the record categories and periods differ, which is exactly why week one starts with your counsel's list rather than a template.

What does FINRA Rule 3110 supervision look like inside Purview?

Communication Compliance policies that scope the supervised persons, apply conditions — lexicons, attachment types, sender and recipient patterns, and machine classifiers — sample a defined percentage of email and Teams messages, route them to named supervisors for review, tag outcomes, and escalate. Reviews and their evidence are exportable, so who reviewed what and when is demonstrable. It is a workflow that supports the review your written supervisory procedures require; the procedures themselves and the judgment applied in each review remain your supervisors' and your counsel's.

Which Microsoft 365 licenses do we need?

Retention policies are broadly available across Microsoft 365 business and enterprise plans; records management with regulatory records, Communication Compliance, eDiscovery Premium, and extended audit retention are tied to specific plans and add-ons such as Microsoft 365 E5, E5 Compliance, or the Purview suite. Week one verifies precisely what your subscriptions include and names any gap; buying a plan is your decision, and we will not recommend one where your current licensing already covers the requirement.

Will you sign an attestation, or act as our designated third party?

No to both. The designated third party or designated executive officer arrangement under amended Rule 17a-4(f) is your firm's to establish, and an attestation of compliance is not something an engineering engagement can honestly issue. What we deliver is the configuration and the evidence pack — exports, lock confirmations, screenshots, Microsoft's assessment references, and a control narrative — so that your compliance officer and counsel can make their statements on solid ground.

What is in the audit evidence pack?

The signed record-category mapping; licensing verification; retention policy and label exports with their locked state confirmed; blocked-action test results for regulatory records; the coverage report of every location under policy; Communication Compliance policy configuration and the first review cycle's evidence export; the eDiscovery production test; audit-retention settings; references to Microsoft's published Cohasset assessments; dated screenshots; and a control narrative mapped to 17a-4(f), 4511, and 3110 written for counsel to adapt. It is assembled so an examiner's request can be answered with documents, not explanations.

What about our existing journaling and legacy archive data?

Current state is reviewed in week one: journaling rules, in-place archives, and any third-party archiver are documented and their retention obligations noted. Consolidating a legacy archive into Microsoft 365 is a separate migration that should run before this engagement so the locked policies cover the imported data; keeping the archiver read-only through its retention period is equally valid. We do not bulk re-label historical content here — a targeted backfill is quoted if you want it.

Can users still delete emails and Teams messages after this?

They can appear to. Under a retain-only or retain-then-delete policy, a user's delete removes the item from their view while the tenant keeps the copy for the retention period — so nothing regulated is lost and the user experience is unchanged. Regulatory record labels are the exception: labelled items cannot be edited or deleted by anyone, which is why they are applied only where the mapping calls for them.

Why is the price an estimate rather than fixed?

Because two variables move it: how many registered entities and workloads the mapping covers, and whether messaging connectors or a full SharePoint and OneDrive records program come into scope. The $4,950 estimate assumes a single tenant with Exchange and Teams at the core and one supervision policy set; the scoping call turns it into a fixed written quote before work begins, and per our standard terms you pay after you approve delivery.

How long do we have to keep records?

That is your counsel's determination, and the mapping records it per category. For orientation only: FINRA Rule 4511 defaults to six years where no other period is specified, and business communications under SEC Rule 17a-4(b)(4) are three years with the first two easily accessible; advisers under Rule 204-2 have their own periods. Purview retention periods are set to whatever counsel specifies — and, once locked, can be extended but never shortened.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,950 per project
3 weeks
Book a compliance scoping call