Why comms compliance rules are converging worldwide

compliance

Regulated organisations no longer answer to a single communications compliance rule. Instead, they sit beneath a web of overlapping regimes, each drafted for a different market, all converging on the same demand: capture, retain and produce communications evidence on request.

According to Wordwatch, a UK investment desk can fall under MiFID II, MAR and the FCA conduct rules simultaneously, while a US broker-dealer juggles SEC, FINRA and CFTC obligations, and an EU entity layers DORA on top of everything else.

Across the UK and EU, the underlying recording duty has stayed largely static while supervisory scrutiny has intensified. MiFID II’s Article 16(7) still requires five-year retention, extendable to seven, but ESMA’s 2024 sanctions report shows enforcement value more than doubling year-on-year.

MAR does not mandate recording itself, but it relies on the evidence base MiFID II creates, meaning gaps in mobile capture can leave reconstruction requests unanswered. DORA, in force since January 2025, has pulled archiving infrastructure into third-party concentration and exit-plan testing, while the FCA’s own multi-firm review uncovered 178 breaches of internal communications policy across eleven wholesale banks, with 41% involving director-grade staff.

In the US, SEC Rules 17a-4 and 18a-6 remain the anchor, though the article stresses a widely repeated misconception: neither rule specifies retaining records in their “original format,” nor sets a five-year period.

What they actually demand is a record that is complete, unaltered and quickly retrievable, with preservation of the original file simply the most reliable way to prove it. FINRA’s Rule 3110 adds a supervisory layer that depends entirely on the completeness of underlying data, while CFTC Rule 1.31 sets a frequently misquoted one-year floor for oral communications, one that longer-running obligations elsewhere will usually override.

APAC regulators are converging on the same standard from different angles. Hong Kong’s SFC treats data location as an explicit compliance question, Singapore’s MAS is pushing reconciliation between trade and communications records, and Australia’s ASIC has named voice notes and encrypted messaging as channels most capture estates fail to reach.

For firms operating across several of these regimes, the article’s practical guidance is straightforward: default to the longest applicable retention clock, preserve original files rather than transcoded versions, and unify capture across every channel rather than splitting it across multiple systems.

The full Wordwatch post can be read here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.