The duty to preserve business communications and related records for the period required by law or regulation. For broker-dealers and similar firms, this includes keeping originals, copies, and accessible archives in a secure format so regulators can review them and the firm can reconstruct activity when needed.
What Recordkeeping Obligation Covers
A recordkeeping obligation is a legal or regulatory duty to preserve required communications and records for a defined period, in a format that remains accurate, searchable, and available for supervisory review or later reconstruction.
At its core, the term is about evidentiary continuity. The organisation must be able to show what happened, when it happened, and who approved it, which is why retention, integrity, and retrieval matter as much as storage.
Why Recordkeeping Is a Control, Not Just Storage
Recordkeeping is a governance control because the record only helps if it is complete, tamper-resistant, and retrievable when needed. A mailbox archive, ticketing system, collaboration platform, or data lake may all hold records, but none satisfy the obligation unless retention rules, indexing, and preservation are applied consistently.
This is especially important in regulated environments such as broker-dealers, where firms may need originals, copies, and accessible archives that can support reconstruction of business activity. The obligation therefore blends compliance, auditability, and operational resilience.
What Records Usually Fall Within Scope
Scope depends on the rule set, but the most common records include customer communications, trade-related messages, approvals, supervised activity, policy exceptions, and other business correspondence that regulators may request. The key question is not whether the record is convenient to keep, but whether law, regulation, or supervisory policy requires its preservation.
Scope also tends to include metadata and context that make a record meaningful, such as timestamps, sender and recipient information, version history, and attachments. If those elements are stripped away, the retained item may no longer function as a compliant record.
How Recordkeeping Supports Supervision and Reconstruction
Proper recordkeeping lets a firm answer two practical questions: what was communicated or decided, and can that evidence still be trusted later. That is why preservation controls must support retention, search, export, and supervisory review without altering the underlying content.
For a useful external baseline on the surrounding control environment, NIST frames related record preservation, auditability, and access discipline through NIST SP 800-53 Rev 5 Security and Privacy Controls. Where records are stored in cloud services or collaboration platforms, firms often also map the obligation to retention, logging, and protection controls in NIST Cybersecurity Framework 2.0.
Risk and Threat Considerations
Recordkeeping failures create both compliance exposure and security exposure. If records are incomplete, altered, deleted too early, or stored in a way that cannot be searched or reconstructed, the organisation may be unable to demonstrate proper conduct, respond to regulators, or investigate internal events.
Failure mechanism: Records are dispersed across tools, retention settings are inconsistent, or deletion and format conversion break the chain of evidence, making later retrieval unreliable.
Impact: The firm can face enforcement risk, adverse audit findings, failed supervision, and weakened incident reconstruction when it most needs a trustworthy historical record.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Recordkeeping supports reviewable, reconstructable audit evidence for regulated activity. |
| AU-11 — Audit Record Retention | The term is fundamentally about preserving required records for a mandated retention period. | |
| MP-6 — Media Sanitization | Preservation requires controlled disposal so records are not lost before lawful retention ends. | |
| Recommendation — Configure audit and preservation controls so retained records remain reviewable and reconstructable. Apply AU-11 retention periods to preserve required communications and business records. Prevent premature disposal and ensure records are sanitized only after retention expires. | ||
| ISO/IEC 27001:2022 | A.5.33 — Protection of Records | Annex A specifically addresses protecting records to preserve integrity and availability. |
| A.5.34 — Privacy and Protection of PII | Recordkeeping often retains personal data and must preserve it lawfully and securely. | |
| Recommendation — Protect records so they remain intact, accessible, and evidentially useful throughout retention. Apply lawful retention and protection controls to records containing personal data. | ||
| NIST CSF 2.0 | PR.DS-11 — Data is Retained, Archived, and Disposed of According to Policy and Legal Requirements | This directly matches legal retention and archive obligations for business records. |
| Recommendation — Define and enforce retention, archive, and disposal rules for required records. | ||
Practitioner Guidance
Governance implication: Treat recordkeeping as an owned control with explicit retention rules, system coverage, and evidence quality requirements. The practical question is not only whether records are stored, but whether the firm can prove the record is complete, preserved for the required period, and retrievable in a usable form.
What to watch for: Gaps usually appear where business activity moves into new channels, such as chat, collaboration suites, or third-party platforms, before retention and supervision controls have been extended to those systems.
Related resources from NHI Mgmt Group
- What breaks when contemporaneous recordkeeping is replaced by later reconstruction?
- Who is accountable when identity controls fail a SOCI reporting obligation?
- Who is accountable when a portfolio company fails a compliance obligation?
- What do security and compliance teams get wrong about eKYC recordkeeping?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org