$2.3B+
FINRA/SEC Records Fines Since 2021
Off-channel and records preservation failures
6 Years
FINRA 17a-4 Core Retention
Customer account records, most business correspondence
$1.9M
Average HIPAA Settlement
For healthcare financial organizations with dual obligations
2025
SEC AI Data Governance Priority
Explicitly cited in FY2026 examination priorities
A broker-dealer that cannot produce a specific client communication from three years ago has a records problem. A registered investment adviser that cannot demonstrate who had access to client portfolio data has a data governance problem. In 2026, those are the same problem — and regulators are treating them that way.
Data governance for financial services firms is not an IT project. It is the operational infrastructure that makes your records defensible, your AI environment auditable, and your firm exam-ready before a regulator schedules a visit.
Most financial organizations have data scattered across dozens of systems — CRM, email, trading platforms, document management, AI tools, collaboration software. Most can retrieve records when asked. Few have continuous visibility into what data they hold, where it lives, who can access it, how long it must be retained, and what happens to it when it flows through AI tools.
That gap is what FINRA examiners, SEC staff, and state regulators are now documenting.
The Records Retention Framework: What FINRA 17a-4 and SEC Rule 17a-4 Actually Require
FINRA Rule 4511 requires member firms to make and preserve books and records in accordance with SEC Rule 17a-4 under the Securities Exchange Act of 1934. Rule 17a-4 is one of the oldest and most technically specific records requirements in financial regulation — and it has become significantly more complex as records now exist across digital platforms, AI systems, and cloud environments.
The core retention requirements most firms know:
What many firms underestimate is how Rule 17a-4 governs the *format* of those records, not just the duration.
⚖️ Rule
The format requirement is where most firms have gaps they do not know about. Communications that exist on collaboration platforms, AI tools, messaging applications, and cloud storage that can be modified or deleted after creation are not in compliant preservation. They exist — but they do not satisfy 17a-4.
Data Classification: The Foundation of Everything Else
Data governance starts with knowing what you have. That is not a philosophical point — it is a practical precondition for every other governance requirement.
A financial firm that cannot classify its data cannot:
Data classification for financial services organizations typically operates across four tiers:
Restricted
Client personally identifiable information, account numbers, Social Security numbers, tax identification numbers, healthcare information for dually regulated firms. Highest protection requirements. Subset of data governed by Reg S-P and applicable state privacy laws.
Confidential
Internal business strategy, M&A information, non-public market data, proprietary models, personnel records. Material non-public information in this tier requires the most rigorous access controls.
Internal Use Only
Internal communications, operational procedures, vendor contracts, non-sensitive employee records. Subject to standard retention requirements but not heightened protection.
Public
Publicly filed documents, marketing materials, regulatory filings, published research. Standard records management without heightened protection requirements.
The classification itself is not the governance. Classification is valuable only when it drives downstream decisions — retention periods applied to each tier, access controls enforced at the system level, and audit logging that tracks who accessed what and when.
Most firms have informal classification practices at best. Records are retained based on system defaults. Access is controlled by folder permissions set years ago. Sensitive data lives in systems that were never evaluated for their data governance posture.
Reg S-P and the Client Data Obligation
Regulation S-P, the SEC's primary rule governing the privacy and security of customer financial information, has been significantly expanded. The 2024 amendments to Reg S-P introduced explicit incident response and notification requirements and strengthened the safeguards rule obligations for both broker-dealers and investment advisers.
The safeguards rule under Reg S-P requires covered firms to adopt written policies and procedures designed to protect customer records and information. In the 2024 amendment, "customer records and information" was clarified to extend to data in electronic form across all systems — including third-party service providers that handle customer data on the firm's behalf.
For financial firms, data governance is the operational mechanism that makes Reg S-P compliance real rather than nominal:
⚠️ Warning
Data Lineage: Why AI Changes Everything
Data lineage — the documented record of where data came from, how it was transformed, and where it went — has historically been a concern for large financial institutions managing complex data pipelines. In 2026, it is a requirement for any firm using AI tools.
The reason is direct: when an AI tool produces an output that influences a business decision — a client communication draft, a research summary, a risk assessment — the firm must be able to demonstrate what data the AI consumed to produce that output. Without data lineage, you cannot answer the question regulators are now asking: *how did your AI arrive at this?*
FINRA's 2026 Annual Regulatory Oversight Report introduced a dedicated Generative AI section specifically addressing supervision of AI-generated communications. The SEC's FY2026 examination priorities explicitly flag AI technologies as a primary focus area. Both regulators expect firms to demonstrate that they understand what data their AI tools are processing.
✅ Action
The practical data lineage requirement for financial firms using AI has three components:
Input tracking — which data was provided to an AI tool, from which system, and by whom. This requires either platform-level logging from the AI vendor or an archive that captures AI interactions at the point of submission.
Output preservation — the AI-generated output must be retained as a record, in a compliant format, for the applicable retention period. An AI-drafted client email is a client communication subject to 17a-4. The fact that AI generated the draft does not change the records obligation.
Decision documentation — for AI-assisted decisions that influence investment recommendations, credit decisions, or other regulated activities, the firm must document that a human reviewed and approved the AI output before it was acted upon. Supervision of AI-assisted decisions is a direct extension of FINRA Rule 3110.
Off-Channel Communications: The Unresolved Gap for Most Firms
The $2.3 billion in FINRA and SEC fines since 2021 was driven primarily by one failure: broker-dealer employees conducting business on personal devices and communication platforms that were not captured, preserved, or reviewable. WhatsApp, personal email, Signal, personal LinkedIn — business communications that existed entirely outside the firm's records program.
That enforcement wave is not over. FINRA examination findings on digital communications supervision remain among the highest-priority areas in the 2026 examination cycle. And the communications gap has expanded.
AI-generated communications create a new category of off-channel risk. An employee who uses an AI tool to draft a client communication, then sends it from a personal device, has created a record in the AI platform's logs — a record the firm cannot access — and sent a communication from a channel the firm cannot supervise. Both failures are independent violations.
A data governance program that addresses off-channel communications requires:
Most firms have an archiver. Fewer have a classification framework that determines which communications belong in it. Almost none have extended that framework to cover AI-generated content.
Access Control Governance: Who Can Touch What, and Why
Regulation S-P's safeguards rule, FINRA Rule 4370 (business continuity), and the general principle of least-privilege access all point to the same requirement: financial firms must control and document who has access to sensitive data.
Access control governance is not a one-time permission-setting exercise. It is an ongoing program that must:
The access control failure pattern FINRA and SEC examiners find most often is not an employee with no authorization who gained access — it is employees with legacy access permissions that were never reviewed, former employees whose access was not terminated, and service accounts with excessive privileges that no one actively monitors.
🔗 Related Service: Data Governance Program
Centience builds and maintains continuous data governance programs for regulated financial organizations — classification, retention aligned to FINRA 17a-4, access control governance, and AI data lineage.
What a Defensible Data Governance Program Looks Like
A financial firm that can demonstrate the following to a FINRA examiner or SEC staff is in a defensible data governance posture:
Data inventory — A documented inventory of data assets across all systems, including what type of data each system holds, which classification tier it belongs to, and who is responsible for it.
Retention schedule — A written retention schedule aligned to applicable regulatory requirements (17a-4, Reg S-P, state requirements) that is actually implemented in the firm's systems — not just documented in a policy binder.
Access control documentation — Evidence that access to sensitive systems is reviewed periodically, that access is revoked when no longer needed, and that access logs are retained.
WORM-compliant preservation — Records subject to Rule 17a-4 stored in non-rewritable, non-erasable formats with accessible backups for the first two years of a retention period.
AI data lineage records — For firms using AI tools, documentation of what data AI systems processed, in what form, and what records were generated as a result.
Off-channel capture — A technical mechanism that captures business communications — including AI-assisted content — into the compliance archive regardless of the originating platform.
The gap between most firms' current state and this posture is real but closeable. The firms that close it before an exam are the firms that spend the examination producing records rather than explaining their absence.
🔗 Related Service: AI Governance Program
AI governance at Centience is built on the data governance foundation — because AI audit trails require data lineage, and data lineage requires classification and retention controls that are already in place.

Frequently Asked Questions




