
If you're an SEC-registered investment adviser, you have to keep your firm's written client communications for five years, and the first two of those years the records have to sit in an appropriate office of the adviser. That's the whole rule in one sentence.
The hard part isn't the retention period. It's proving you captured everything, including the texts.
Small RIAs get this wrong in a specific way: they assume that because email lives in Microsoft 365 forever, they're compliant. They aren't. Mailbox retention is not an archive.
What does SEC Rule 204-2 actually require?
Rule 204-2 is the books-and-records rule for investment advisers. On communications, paragraph (a)(7) requires you to keep "Originals of all written communications received and copies of all written communications sent by such investment adviser" relating to recommendations or advice, any receipt or disbursement of funds or securities, and the placing or execution of orders.
The retention clock is in paragraph (e)(1): records must be "maintained and preserved in an easily accessible place for a period of not less than five years from the end of the fiscal year during which the last entry was made on such record, the first two years in an appropriate office of the investment adviser."
Read that carefully. Five years runs from the end of the fiscal year of the last entry, not from the date of the email. A December message and the following January message can sit a year apart on the retention calendar.
How broker-dealers differ
Broker-dealers live under Rule 17a-4, and the numbers are different. Communications get three years under paragraph (b)(4), the first two in an easily accessible place.
Paragraph (f) gives two ways to hold electronic records. One is the traditional WORM format, non-rewriteable and non-erasable. The other is an audit-trail system that time-stamps every modification and deletion and can recreate an altered record.
If your firm is dually registered, you follow both, which in practice means the longer period and the stricter format.
Why isn't Microsoft 365 retention enough?
Because retention and archiving answer different questions. Retention keeps a copy. An archive proves the copy wasn't changed, captures mail the mailbox never held, and produces it on demand in a format an examiner accepts.
Three gaps show up in nearly every small RIA we look at:
- An administrator can turn it off. If a global admin can alter a retention policy, your "immutable" record isn't. Litigation hold and Purview retention lock help, but only if they're configured and documented.
- Nothing outside the mailbox is captured. Texts, WhatsApp, Teams chat, LinkedIn messages. If advice went through it, it's a record.
- Search is not production. Being able to find a message is not the same as exporting a defensible set with metadata intact and a chain of custody.
The off-channel problem is where the fines are
On January 13, 2025, the SEC announced that 12 firms, nine investment advisers and three broker-dealers, agreed to pay more than $63.1 million combined to settle charges that their personnel "sent and received off-channel communications that were records required to be maintained under the securities laws."
That was one announcement in a long run of them. On August 14, 2024, the SEC charged 26 firms with $392.75 million in combined penalties for the same failure.
None of those firms lacked email archiving. They lacked control over the channels their people actually used. An adviser who texts a client "I'd move out of that fund before earnings" has created a required record on a device your archive never sees.
What should a small RIA do about it?
Start with the policy, because the technology follows from it.
- Name your approved channels and ban the rest in writing. Email and one messaging platform is a defensible answer. Six channels with no capture is not.
- Capture what you approved. Put a compliant archive in front of email and your messaging platform. Archiving only email while allowing business texting is the exact gap the SEC has been fining.
- Handle mobile deliberately. Either issue firm phones with captured messaging, or use a mobile archiving product on personal devices. "We tell people not to text clients" is not a control.
- Test a production. Once a year, pick a client and a date range and actually export the full set. Firms discover their gaps during an exam otherwise.
- Document the supervision. Rule 206(4)-7 requires you to review "no less frequently than annually" whether your policies are adequate and whether they're actually being followed. Keep evidence of that review, not just the archive.
Retention and archiving are one piece of a broader compliance picture for advisory firms. Our guide to SEC Reg S-P for RIAs covers the incident-response and customer-notification side, and our data retention guide works through the same questions for firms outside financial services.
Frequently asked questions
How long do RIAs have to keep emails?
Five years from the end of the fiscal year in which the last entry was made, with the first two years in an appropriate office of the adviser, under Rule 204-2(e)(1). Broker-dealers keep communications three years under Rule 17a-4(b)(4), the first two in an easily accessible place. Dually registered firms should plan to the longer period.
Do text messages have to be archived?
If they relate to advice, recommendations, orders, or the movement of client funds, yes. The rule is about the content of the communication, not the app it traveled through. The SEC's off-channel enforcement actions have turned on exactly this point.
Is Microsoft 365 retention enough on its own?
Usually not. Native retention can satisfy the preservation period if it's configured, locked, and documented, but it doesn't capture channels outside the tenant and it doesn't give you the supervision and production workflow an exam expects. Most firms pair Microsoft 365 with a dedicated archive.
Does WORM storage still get required?
Not exclusively. Rule 17a-4(f) now lets broker-dealers choose between WORM format and an audit-trail system that time-stamps and recreates any modified or deleted record. Advisers under 204-2 have never been held to a WORM mandate, but they still need records that can be shown to be complete and unaltered.
What does an SEC exam actually ask for?
Typically a date-bounded set of communications for named clients or employees, produced in a usable electronic format with metadata. The failure mode isn't missing the deadline. It's producing a set that's visibly incomplete because a channel was never captured.
If you're not certain your archive would survive a document request, reach out for a complimentary review. We work with advisory firms across New York, New Jersey, Connecticut, and Southwest Florida on exactly this, alongside broader cybersecurity and compliance work.
Related reading
CybersecuritySEC Reg S-P for RIAs: The Deadline Passed, Now What?
Read Article
CybersecurityNYDFS 23 NYCRR 500 Compliance: A Guide for Small Firms
Read Article
CybersecurityData Retention for Small Business: What to Keep, How Long
Read ArticleAlso on this topic: SEC Reg S-P Deadline Passed: What Small RIAs Do Now
Discuss cyber security for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
