Accountability usually sits with the organisation’s compliance, legal, and security leadership, because those functions own governance policy, retention controls, and evidentiary readiness. Executives should ensure capture covers the relevant channels, archive settings are defensible, and search and export can support litigation hold or regulatory requests without delay. Governance failure is an organisational risk, not just an IT issue.
Who owns the accountability gap when regulated communications cannot be produced?
Accountability is not confined to the team that runs the archive or messaging platform. When regulated communications are not captured, retained, or searchable during an investigation, the failure usually reflects a governance breakdown across compliance, legal, security, and the business owners of the communication channels. The key issue is whether the organisation can prove coverage, retention, and retrieval under scrutiny, not whether the missing content was technically “someone else’s system.”
That matters because evidentiary readiness is part of regulatory control, not an after-the-fact forensic luxury. If a channel is used for business decisions, client commitments, approvals, or supervision obligations, it must be brought into the organisation’s control boundary and validated as searchable and exportable. NIST Cybersecurity Framework 2.0 is useful here because it frames governance, protection, detection, and recovery as coordinated duties rather than isolated technical tasks. In practice, many organisations discover the accountability failure only after an investigation request exposes that no one had validated end-to-end capture for the channels people actually used.
What has to work for capture, retention, and search to be defensible?
Defensible capture depends on three linked conditions: the right sources, the right retention rules, and the ability to retrieve data in time. A system can be “enabled” and still fail if a channel is excluded, an archive connector breaks, retention is too short, or search cannot reconstruct the relevant conversation. That is why accountability sits with governance leadership first and operations second. The business, compliance, and legal functions decide what must be preserved; technology implements and verifies it.
In practice, regulated communications include more than email. They may include chat, collaboration tools, shared workspaces, recorded calls, and any workflow where regulated decisions or commitments are made. If those channels are in scope, the organisation should be able to show:
- which channels are covered and which are explicitly excluded;
- how retention periods are set and approved;
- how legal hold overrides normal deletion;
- how search and export are tested before an investigation occurs;
- who can attest that captured records are complete enough for regulatory review.
NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant because it maps the underlying control problem: retention, auditability, access control, and system integrity must all hold together. Where this guidance breaks down is when the organisation treats retention as a storage setting instead of an evidence lifecycle with ownership, testing, and escalation.
Where accountability usually fails first in regulated-communication investigations
Tighter communication control often increases operational overhead, requiring organisations to balance evidential completeness against user convenience and channel sprawl. The most common failure is not malicious deletion but unmanaged drift: people adopt a new platform, a mobile app, or an informal collaboration method faster than governance updates the approved capture scope.
There are several common edge cases. Sometimes the organisation has retention, but not searchable retrieval, so the archive exists yet cannot support an investigation efficiently. In other cases, retention meets a minimum period but fails the legal or regulatory horizon for a specific matter. Another recurring issue is responsibility fragmentation: IT may operate the tooling, compliance may define the rule, legal may issue holds, and security may own monitoring, but none of them own end-to-end proof that the evidence chain works.
The practical rule is that if a communication channel is used to conduct regulated activity, the organisation must treat capture failure as a governance defect, not a mere configuration nuisance. Guidance is still evolving on newer collaboration and AI-mediated channels, so teams should label any coverage assumption that is based on consensus rather than a settled regulatory interpretation. When in doubt, the safer position is to prove capture and retrieval before allowing the channel to become business-critical.
Risk and Threat Considerations
The material risk is evidentiary loss: if regulated communications cannot be captured or searched, the organisation may be unable to respond to an investigation, substantiate decisions, or prove that supervision and retention obligations were met. That creates compliance exposure even when no malicious actor is involved.
Failure mechanism: The risk materialises when capture scope, retention rules, and searchability are managed as separate operational tasks. Gaps appear through excluded channels, broken connectors, short retention settings, weak legal-hold handling, or archives that cannot be queried fast enough for an inquiry.
Impact: The organisation may face incomplete disclosure, adverse regulatory findings, loss of defensible evidence, and avoidable legal or supervisory escalation. It can also lose confidence in its recordkeeping controls across other business units because one failed retrieval undermines trust in the whole governance model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Regulated communications need clear business and compliance ownership. |
| PR.DS-11 — Data Resilience | Retention and recoverability determine whether records remain usable for investigations. | |
| DE.CM-08 — Monitoring for Anomalies and Events | Searchability and retrieval depend on monitoring archive and collection failures. | |
| Recommendation — Define who owns capture coverage and evidentiary readiness for each regulated channel. Ensure retained communications stay retrievable and intact for the required period. Monitor capture and archive pipelines so missed records are detected quickly. | ||
| CIS Controls v8 | 3.4 — Automated Backup Verification | Recordkeeping requires verified recoverability, not assumed storage success. |
| 5.3 — Data Recovery Process | Investigations need a dependable recovery path for retained communications. | |
| 8.2 — Untrusted Data Handling | External or informal channels can bypass governed capture and retention. | |
| Recommendation — Verify that archived communications can actually be restored and searched. Test the recovery path that produces records for legal or regulatory requests. Restrict regulated communications to channels that can be governed and retained. | ||
| DORA | ICT-4 — Digital Operational Resilience Testing | Evidence retrieval failure is an operational resilience issue for regulated firms. |
| Recommendation — Test evidence retrieval under investigation-like conditions before you need it. | ||
| NIS2 | Article 21 — Cybersecurity Risk-Management Measures | Governed retention and retrieval are part of resilient security management. |
| Recommendation — Assign accountability for record retention and retrieval as part of risk controls. | ||
Practitioner Guidance
What to prioritise: Establish which communication channels are in scope for regulated activity before debating tooling. The first control question is not “can we archive it?” but “can we prove this channel is covered, searchable, and subject to hold when required?”
What to verify: Validate the full evidence chain, not just the archive status. Teams should test a real retrieval path, confirm the output is complete enough for review, and check that retention and hold settings behave as intended when a matter is opened.
Practitioner takeaway: Accountability belongs to the organisation that permits the channel to be used for regulated activity, and the real test is whether it can produce evidence on demand without improvisation.
Related resources from NHI Mgmt Group
- Who is accountable when sovereign recovery fails during a regulated incident?
- Who is accountable when AI agent access to SaaS data exposes regulated information during audit scope?
- Who is accountable when privileged access fails during a communications blackout in a distributed environment?
- Who is accountable when Article 32 controls fail during a GDPR investigation?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org