Records Management for Financial Services: SEC/FINRA Retention, SOC 2 & PCI
Financial-services firms must retain books and records under SEC Rule 17a-4 and FINRA Rule 4511 — most core records for at least six years, with the first two immediately accessible. Electronic records must meet either the WORM standard or, since the 2023 amendments, an audit-trail alternative. GLBA, PCI DSS, and SOC 2 add security and disposal duties.
Broker-dealers and registered investment advisers operate under one of the most prescriptive recordkeeping regimes in American business. The core mandate comes from SEC Rule 17a-4 and FINRA Rule 4511: foundational records such as blotters and ledgers must be preserved for at least six years, with the first two years kept in an easily accessible place, while order tickets, trade confirmations, and business communications must be kept for at least three years. FINRA adds a six-year default for any record with no other specified period.
The most consequential recent change is technical. The SEC's 2023 electronic recordkeeping amendments — adopted October 12, 2022, effective January 3, 2023, with a compliance date of May 3, 2023 — replaced the long-standing WORM-only mandate with a choice. An electronic recordkeeping system must now satisfy either the write once, read many (WORM) standard or a complete, time-stamped audit-trail alternative.
Retention, however, is only half of a compliant program. The Gramm-Leach-Bliley Act and its FTC Safeguards Rule require secure disposal within two years of a customer's last use; PCI DSS and SOC 2 govern how the data is protected and proven; and enforcement is active, with 16 firms paying more than $1.1 billion combined in 2022 for off-channel communications failures. This guide maps the full stack for compliance teams and shows where a regional records partner such as Reynolds Business Systems fits the operational work.
What records management means for financial services
Records management in financial services is the disciplined practice of capturing, retaining, protecting, and ultimately disposing of the books and records a firm is legally required to keep. For a broker-dealer or registered investment adviser, it is not a back-office filing task — it is a regulated control function. The obligations come from a stack of overlapping authorities: the SEC's books-and-records rules (Rules 17a-3 and 17a-4), FINRA Rule 4511, the Gramm-Leach-Bliley Act and its FTC Safeguards Rule, PCI DSS for cardholder data, and SOC 2 attestations that counterparties increasingly demand.
Each authority answers a different question. SEC Rule 17a-4 and FINRA Rule 4511 govern what must be kept and for how long. GLBA governs how customer information is protected and when it must be destroyed. PCI DSS governs the logging around payment-card data, and SOC 2 provides independent assurance that the controls actually operate. A program that satisfies one but ignores the others is not compliant; the frameworks are cumulative, not alternative.
One scope note matters up front. Registered investment advisers are governed primarily by the SEC's Investment Advisers Act books-and-records rule, which sets its own retention periods; broker-dealers and dually registered firms answer to the 17a-4 regime detailed below. The principles — tiered retention, immutability, and demonstrable controls — carry across both.
Records vs. recordkeeping systems
It helps to separate two ideas. The records are the documents themselves — blotters, ledgers, order tickets, account agreements, and the growing volume of electronic communications. The recordkeeping system is the technology and process that preserves them in a compliant state. The 2023 amendments to Rule 17a-4, discussed below, are almost entirely about the second idea: not which records to keep, but how the electronic system must hold them.
SEC Rule 17a-4: the core retention framework
SEC Rule 17a-4 is the spine of broker-dealer recordkeeping. It dictates how long the records required under Rule 17a-3 must be preserved and how accessible they must remain, and it tiers the periods by record type. Under Rule 17a-4(a), core records such as blotters and ledgers must be preserved for not less than six years, with the first two years kept in an easily accessible place. Under Rule 17a-4(b), order tickets, trade confirmations, business communications, and similar records must be kept for not less than three years, again with the first two years easily accessible.
Two categories run on their own clocks. Customer account cards and records relating to the terms and conditions of an account must be preserved for at least six years after the account is closed — a period that begins at closure, not at creation. Records of an associated person under Rule 17a-3(a)(12) must stay in an easily accessible place until at least three years after that person's employment and any other connection with the firm ends. And a handful of foundational documents — partnership articles or articles of incorporation, the charter, minute books, and stock certificate books — must be preserved for the life of the enterprise and of any successor enterprise.
| Record category | Minimum retention | Easily-accessible period | Authority |
|---|---|---|---|
| Blotters, ledgers, and other core books | 6 years | First 2 years | SEC Rule 17a-4(a) |
| Order tickets, trade confirmations, business communications | 3 years | First 2 years | SEC Rule 17a-4(b) |
| Customer account cards / terms and conditions | 6 years after the account is closed | Per applicable rule | SEC Rule 17a-4 |
| Associated-person records (17a-3(a)(12)) | 3 years after employment ends | Entire period | SEC Rule 17a-4 |
| Articles of incorporation, minute books, stock certificate books | Life of the enterprise and any successor | Per applicable rule | SEC Rule 17a-4 |
| Any FINRA record with no other specified period | 6 years (default) | Per applicable rule | FINRA Rule 4511(b) |
The easily-accessible window matters as much as the total period. A record archived to deep cold storage in year one can still violate the rule if a regulator asks for it during the first two years and the firm cannot produce it promptly.
FINRA Rule 4511: the default backstop and the format mandate
FINRA Rule 4511 does two things every member firm should understand. First, Rule 4511(b) establishes a default: members must preserve for at least six years any FINRA books and records for which no other retention period is specified under the FINRA rules or the applicable Exchange Act rules. That backstop closes the gap for record types the more specific rules never name. FINRA's own interpretation of SEA Rule 17a-4(a) reinforces the point, confirming that covered records must be kept for not less than six years, the first two in an easily accessible place.
Second, Rule 4511(c) controls format. It requires all books and records made under the FINRA rules to be preserved in a format and on media that comply with SEA Rule 17a-4. The practical effect is that a FINRA member cannot satisfy its retention duty with an ordinary file server or an editable cloud drive; the storage layer itself must meet the SEC's electronic-preservation standard. That is the bridge from kept the document to kept it in a way the SEC recognizes.
WORM vs. audit trail: the 2023 electronic recordkeeping amendments
For decades, a broker-dealer that chose to preserve records electronically had only one technical path. Before the 2023 amendments, electronic records had to be stored exclusively in a non-rewriteable, non-erasable format — the write once, read many, or WORM, standard. The records were immutable by design, which made them tamper-evident but also rigid and, for modern cloud-native systems, difficult to implement.
The SEC adopted amendments to Rule 17a-4 on October 12, 2022. They took effect on January 3, 2023, with a compliance date of May 3, 2023. The central change was to keep WORM as an option while adding an audit-trail alternative: an electronic recordkeeping system now must meet either the WORM requirement or the audit-trail requirement, letting firms choose the path that fits their architecture.
The audit-trail alternative is not a loophole. It permits records to be modified or deleted only if the system maintains a complete, time-stamped audit trail of every modification and deletion — capturing the date, time, and identity behind each change — sufficient to recreate the original record if it is altered or removed. The amendments also added operational flexibility: a broker-dealer may now designate an executive officer, rather than rely on a third party, to execute the undertakings that provide the SEC access to its electronic records.
| Dimension | WORM (write once, read many) | Audit-trail alternative |
|---|---|---|
| Core principle | Records stored in non-rewriteable, non-erasable media | Records may be modified or deleted if a complete audit trail is kept |
| What it captures | Prevents alteration at the storage layer | Time-stamped log of every modification and deletion: date, time, and identity |
| Recovery requirement | Original is immutable by design | System must be able to recreate the original record if modified or deleted |
| Status after 2023 | Option retained in the amendments | New option added by the amendments |
A defensible recordkeeping program is not a storage decision; it is a controls decision. The rules ask not only what you kept, but whether you can prove it was never altered.
Step-by-step: standing up a compliant recordkeeping program
Translating these rules into an operating program follows a repeatable sequence. The steps below assume a broker-dealer or dually registered firm moving from ad hoc storage to a defensible system.
- Inventory the record types. Map every category the firm creates — blotters, ledgers, order tickets, confirmations, account agreements, associated-person files, and all business communications — against the rule that governs it.
- Assign a retention period to each. Apply the 17a-4 tiers and the FINRA Rule 4511(b) six-year default, recording the longest applicable period for any record that falls under more than one authority.
- Choose an electronic-preservation path. Decide between WORM and the audit-trail alternative based on the firm's systems, and document the choice in written supervisory procedures.
- Capture electronic communications at the source. Off-channel messaging is the single largest enforcement risk; route business communications through monitored, retainable channels before they reach personal devices.
- Verify accessibility. Confirm that records in their first two years can be produced promptly, and that the system can recreate an original if the audit-trail path is used.
- Layer in security and disposal. Apply GLBA Safeguards controls, PCI DSS logging where cardholder data is involved, and a written disposal schedule that destroys records securely once the longest retention period lapses.
- Obtain independent assurance. Use a SOC 2 examination of the recordkeeping vendor to confirm the controls operate as designed.
A worked example: mapping retention for a regional broker-dealer
Consider a hypothetical regional broker-dealer in the Lehigh Valley working through its 2026 retention map. The years below are illustrative, applied to the cited minimum periods to show how the clocks run; they are an example, not a legal opinion.
- Blotters and general ledgers created in 2026 must be preserved through at least 2032 (six years), with 2026 and 2027 records kept easily accessible through the end of 2027.
- Order tickets and trade confirmations from a 2026 transaction must be kept through at least 2029 (three years), with the first two years easily accessible.
- A customer account closed in 2026 starts a six-year-after-closure clock: the account-terms records must be preserved through at least 2032.
- A registered representative who leaves the firm in 2026 triggers a three-year clock on their associated-person record, which must stay easily accessible through at least 2029.
- A customer last served in 2026, with no securities-record obligation or legal hold attached, falls under the GLBA disposal duty: their customer information must be securely destroyed no later than 2028 (two years after last use).
The last two lines show why a single record can be governed by competing clocks. If that departed customer's file also contains securities records under Rule 17a-4, the six-year retention requirement overrides the two-year disposal deadline — the longer regulatory period always governs. A defensible schedule resolves these conflicts explicitly rather than leaving them to a staff member's judgment.
When a retention duty and a disposal duty point in opposite directions, keep the record for the longest period any applicable rule requires, then dispose of it securely. Disposing early to satisfy GLBA can breach 17a-4; keeping indefinitely to satisfy 17a-4 can breach GLBA.
SOC 2 and PCI DSS: proving the controls work
Retention answers whether you kept a record. SOC 2 and PCI DSS answer whether you protected it. SOC 2 is an AICPA attestation evaluated against five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security — the common criteria — is the only category required in every SOC 2 examination; the other four are included based on the services in scope. Across the five categories, the 2017 Trust Services Criteria comprise 61 individual criteria supported by almost 300 points of focus, which is why a SOC 2 report is a substantive document rather than a checkbox.
PCI DSS applies wherever a firm stores, processes, or transmits payment-card data. Requirement 10, which covers logging and monitoring of access, requires audit-trail history to be retained for at least one year, with at least the most recent three months immediately available for analysis. For a financial firm these logs are themselves records, and they intersect with the 17a-4 framework whenever they document access to regulated books and records.
| Framework | Primary concern | Key quantified requirement |
|---|---|---|
| SEC 17a-4 / FINRA 4511 | Record retention and immutability | 6-year core retention; WORM or audit trail |
| GLBA / FTC Safeguards Rule | Protecting and disposing of customer information | Secure disposal within 2 years of last use; MFA using 2 of 3 factor types |
| PCI DSS Requirement 10 | Logging and monitoring access to cardholder data | Retain audit logs at least 1 year; 3 months immediately available |
| SOC 2 (AICPA TSC) | Independent attestation of controls | 5 Trust Services Criteria; Security always required |
GLBA and the FTC Safeguards Rule: the duty to dispose
The Gramm-Leach-Bliley Act, implemented for many firms through the FTC Safeguards Rule, reframes records management around a duty most retention discussions overlook: the duty to dispose. The rule requires financial institutions to securely dispose of customer information no later than two years after the most recent use to serve the customer, unless a legitimate business need or legal requirement justifies keeping it longer. Retention, in other words, is not a default; it must be justified.
The Safeguards Rule also imposes concrete security controls. It requires multi-factor authentication for anyone accessing customer information, using at least two of the three recognized factor types — knowledge, possession, and inherence. And it sets a breach-notification trigger: a financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, of a breach involving the unencrypted information of at least 500 consumers. Together these provisions make clear that protecting and timely-destroying records is as much a part of compliance as retaining them.
What non-compliance costs: the off-channel enforcement wave
The financial consequences of recordkeeping failures are not theoretical. In September 2022 the SEC charged 16 Wall Street firms with widespread recordkeeping failures tied to off-channel communications; the firms agreed to pay combined penalties of more than $1.1 billion. Eight of those firms, together with five affiliates, each agreed to a $125 million penalty. The conduct ran from January 2018 through September 2021 and reached employees up to senior-executive level who used personal-device text messaging for business matters that was never captured or preserved.
The pattern was established a year earlier. In December 2021, J.P. Morgan Securities agreed to pay a $125 million SEC penalty for failing to preserve business communications sent over WhatsApp, text message, and personal email — a direct violation of Rule 17a-4(b)(4) and 17a-4(j). The throughline is consistent: the records that triggered the largest penalties were not ledgers or trade tickets but ordinary messages employees sent through unmonitored channels. A technical retention system is only as strong as the firm's ability to capture communications before they escape it.
Off-channel communication — business conversations conducted on personal phones and messaging apps — is the dominant recordkeeping enforcement theme of recent years. A compliant archive cannot preserve a message it never received.
The seven-year myth and the IRS tax overlap
Ask most professionals how long to keep financial records and the answer is seven years. That figure is real but narrow. The IRS instructs taxpayers to keep records for seven years specifically when they file a claim for a loss from worthless securities or a bad-debt deduction. For most other purposes the IRS general period is three years — the standard period of limitations on income-tax returns — and employment-tax records should be kept for at least four years after the tax becomes due or is paid.
For a securities firm, none of these IRS periods displaces the SEC and FINRA rules. The seven-year tax figure governs the firm's own tax exposure; the six-year and three-year 17a-4 periods govern its regulated books and records. The two regimes coexist, and a complete schedule accounts for both rather than collapsing everything into a single seven-years assumption.
Common mistakes and when not to keep a record
Several recurring errors separate a defensible program from a vulnerable one.
- Treating retention as the only goal. Over-retention conflicts with the GLBA two-year disposal duty and enlarges the data a breach can expose. Keeping everything forever is a liability, not a safeguard.
- Storing records on editable media. An ordinary file server fails FINRA Rule 4511(c), which requires media compliant with SEA Rule 17a-4 — either WORM or a qualifying audit trail.
- Ignoring the easily-accessible window. Meeting the total retention period while burying recent records in slow archives still violates the first-two-years accessibility requirement.
- Leaving communications uncaptured. The enforcement record shows that off-channel messages, not core ledgers, drive the largest penalties.
- Letting clocks run from the wrong date. Account-terms records run six years from account closure, and associated-person records run three years from the end of employment — not from creation.
The corollary is knowing when not to keep a record. Once the longest applicable retention period has lapsed and no legal hold is in place, continued retention of customer information runs against the GLBA disposal duty. Secure, documented destruction is the compliant end state — not indefinite storage.
The Lehigh Valley angle: turning rules into operations
For financial firms across the Lehigh Valley — the broker-dealers, advisory practices, and community banks serving Allentown, Bethlehem, and Easton — the practical challenge is converting this regulatory stack into day-to-day operations. That means digitizing paper account files into a system that can enforce retention schedules, meeting the first-two-years accessibility requirement, and being able to prove the WORM or audit-trail standard to an examiner.
Reynolds Business Systems has worked in document management for more than five decades from its base in Emmaus, Pennsylvania, and is a Laserfiche Certified Partner — relevant here because the compliant electronic recordkeeping platforms financial firms rely on must meet the SEC Rule 17a-4 standard. The benefit of a regional partner is proximity: scanning, indexing, and records-program support delivered locally, with the controls documentation compliance teams need when they answer to the SEC, FINRA, and the FTC. The goal is a records program that is defensible on its worst day — the day a regulator asks to see it.
Frequently asked questions
What financial records should be kept for 7 years?
The seven-year figure usually traces to IRS guidance: the IRS instructs taxpayers to keep records for seven years when they claim a loss from worthless securities or a bad-debt deduction. For securities-industry books and records, the governing periods come from SEC Rule 17a-4 and FINRA Rule 4511 — generally six or three years — not a blanket seven.
How long do broker-dealers have to keep records?
Under SEC Rule 17a-4, core records such as blotters and ledgers must be preserved at least six years, with the first two years easily accessible, while order tickets, confirmations, and business communications must be kept at least three years. FINRA Rule 4511(b) adds a six-year default for any record with no other specified period.
What is SEC Rule 17a-4?
It is the SEC regulation governing how broker-dealers preserve the books and records required under Rule 17a-3. It sets minimum retention periods, requires the first two years of many records to be easily accessible, and — since the 2023 amendments — lets firms store electronic records in either WORM form or with a qualifying audit trail.
What changed in the 2023 electronic recordkeeping amendments?
The SEC adopted them on October 12, 2022 (effective January 3, 2023; compliance May 3, 2023). The headline change replaced the WORM-only mandate with a choice: firms may use WORM or maintain a complete, time-stamped audit trail of modifications and deletions. Firms may also designate an executive officer, instead of a third party, for SEC access undertakings.
What is the difference between WORM and an audit trail?
WORM stores records in non-rewriteable, non-erasable media so they cannot be altered. The audit-trail alternative allows modification or deletion provided the system keeps a time-stamped record of every change — date, time, and identity — sufficient to recreate the original record. Since the 2023 amendments, both satisfy Rule 17a-4.
Does FINRA require a specific recordkeeping format?
Yes. FINRA Rule 4511(c) requires all books and records made under the FINRA rules to be preserved in a format and on media that comply with SEA Rule 17a-4. In practice that ties FINRA member firms to the same WORM-or-audit-trail electronic-preservation standard the SEC enforces.
How long must customer account records be kept after an account closes?
SEC Rule 17a-4 requires account cards and records of the terms and conditions of a customer account to be preserved for at least six years after the account is closed. That clock starts at closure and runs separately from the six-year period that applies to the firm's general books and records.
What does the GLBA Safeguards Rule require for disposal?
It requires financial institutions to securely dispose of customer information no later than two years after the last time it was used to serve the customer, unless there is a legitimate business need or legal requirement to keep it. The rule also mandates multi-factor authentication and breach notification to the FTC within 30 days for breaches affecting at least 500 consumers.
What is SOC 2 and is it required?
SOC 2 is an AICPA attestation evaluated against five Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security, the common criteria, is required in every SOC 2; the others depend on scope. It is not legally mandated, but it is widely expected of vendors that handle financial data and recordkeeping.
How long must PCI DSS audit logs be kept?
PCI DSS Requirement 10 requires retaining audit-trail (log) history for at least one year, with at least the most recent three months immediately available for analysis. This applies to firms that store, process, or transmit cardholder data, and the logs themselves become records the firm must manage.
What are the penalties for recordkeeping failures?
They are substantial. In September 2022 the SEC charged 16 firms over off-channel communications, with combined penalties exceeding $1.1 billion; eight firms each paid $125 million. A year earlier, in December 2021, J.P. Morgan Securities paid a $125 million penalty for failing to preserve WhatsApp, text, and personal-email business communications.
Can a firm keep records longer than the rules require?
It can, but over-retention carries its own risk. Holding customer information past its useful life conflicts with the GLBA two-year disposal duty and expands the data a breach can expose. The disciplined approach is a written schedule that retains each record exactly as long as the longest applicable rule requires, then disposes of it securely.
Sources Cited
20 REFS- Legal Information Institute, Cornell Law School (mirror of eCFR)
- U.S. Securities and Exchange Commission
- U.S. Securities and Exchange Commission
- Financial Industry Regulatory Authority (FINRA)
- Financial Industry Regulatory Authority (FINRA)
- Financial Industry Regulatory Authority (FINRA)
- U.S. Securities and Exchange Commission
- U.S. Securities and Exchange Commission
- U.S. Federal Trade Commission (Gramm-Leach-Bliley Act)
- U.S. Internal Revenue Service
- Linford & Company LLP
- Secureframe
- Mimecast
- Global Relay
- Laserfiche



