Record keeping sounds like storage and is actually retrieval. Every regime that supervises trading firms requires records to be kept in a form that permits reconstruction of each step of a transaction and prompt production to the regulator. The second half of that sentence is the demanding one.
What counts as a record
Wider than the trade blotter. In practice a supervised firm is expected to hold, at minimum, client agreements and every accepted version, identity and due diligence documents with the assessments made on them, order and execution records including timestamps and the venue or counterparty, client money reconciliations, statements issued, marketing material published with the approval that cleared it, complaints files, incident and breach records, board and committee minutes, and the communications that relate to any of the above.
Communications is where most firms are short. Several regimes require recording of telephone conversations and electronic communications that relate or are intended to relate to the conclusion of a transaction, together with a copy of the record being available to the client on request. That obligation reaches messaging apps as well as email when staff use them for business, which is why firms either supply a channel that records or prohibit the ones that do not, and enforce the prohibition. A policy nobody enforces is treated as no policy at all.
The periods are set by regime, not by convenience
Retention lengths differ, and there is no single number that covers a group operating in several places. The safe method is to build a schedule per entity: for each record type, the rule that creates the obligation, the period, when the clock starts, and where the record lives. Clocks commonly start at the end of the client relationship rather than at creation, which for a client of eight years means the record survives long past the trade it documents.
Three complications recur. Overlapping obligations, where AML rules and market conduct rules impose different periods on the same file and the longer one governs. Litigation and regulatory holds, which suspend deletion entirely for anything in scope of a dispute or an investigation, and which must be capable of being applied quickly. And group operations, where the same record supports two entities in two regimes and is kept to the stricter standard. The reporting side of the same discipline is covered in the regulatory reporting calendar and in transaction reporting.
Retention periods are rules, and they change. Build the schedule from the current rulebook for each entity with local advice, review it when rules change, and treat any figure you read in an article, including this one, as a prompt to check rather than an answer.
The form the record has to be in
Regimes generally require records to be kept in a durable medium that allows them to be retained in a form the regulator can access, prevents alteration and permits any correction to be identified, and allows the sequence of events to be reconstructed. That rules out a store where a record can be quietly edited with no history, and it makes ordinary database backups insufficient on their own, since a backup preserves the data without preserving the fact that a field changed.
What satisfies it is an append only history: who changed what, when, and what the previous value was. Firms usually get this from the platform and CRM rather than building it, and it is worth asking a vendor directly whether the change history is queryable and exportable, because that is where the requirement bites. The mechanics are described in compliance audit trails.
Retrieval is the other half. A supervisor's request arrives as a client name and a date range, not as a table name. If producing that means pulling from the platform, the CRM, a ticketing tool, a mail archive and a payments dashboard by hand, the deadline will hurt. Firms that keep the client identifier consistent across systems answer these requests in hours.
Retention and the right to erasure
Clients ask to be deleted. In the EU and in the growing number of regimes modelled on it, the right to erasure does not override a legal obligation to retain, so a firm holding trade and AML records under a statutory period refuses the deletion for those records and says why. What it must still do is delete what is not covered by the obligation, marketing data being the obvious case, and stop processing the retained data for anything other than the purpose that justified keeping it.
Doing that requires the firm to know which fields sit under which obligation, which is another argument for the schedule. A blanket refusal is as much a compliance failure as a blanket deletion. The overlap is set out in data protection for trading firms, and where the data physically sits raises its own questions covered in data residency rules.
Who holds the records when a vendor leaves
The obligation stays with the firm even when the data sits in a supplier's system. That makes the exit terms of every platform, CRM and KYC contract a compliance matter: what happens to the records on termination, in what format they are returned, how long the vendor retains a copy, and whether the firm can export at any time without asking. A firm that switches platforms and loses five years of order history has breached its own obligation, and the vendor's terms will usually not be the reason a regulator accepts.
Ask the question during procurement, not during the migration. It is a short clause, and it is the difference between a change of supplier and an unrecoverable gap.
"Nobody has ever been fined for keeping too much. Plenty have been fined for keeping the right thing in a system they could not search."
— Alex Onta, Executive Director, SINGUARD
Key Takeaways
- Records cover far more than trades: agreements, due diligence, communications, marketing approvals, complaints, reconciliations and minutes all sit in scope.
- Build a retention schedule per entity naming the rule, the period and when the clock starts, and apply the stricter period where obligations overlap.
- Records must be tamper evident and reconstructible, which needs an append only change history rather than backups alone.
- A client's erasure request does not defeat a statutory retention obligation, but it does require deleting everything outside it.
Frequently Asked Questions
Do messaging apps need to be recorded?
If staff use them for conversations relating to transactions, the recording obligation applies to that channel in the regimes that impose it. Firms respond either by providing a recorded channel and blocking the rest, or by permitting a channel that can be captured and archived. An unenforced ban gives no protection.
When does the retention clock start?
Depends on the record and the rule. Many obligations run from the end of the client relationship rather than from the date the record was created, which makes long standing clients the ones with the oldest surviving files. Set the start point per record type in your schedule instead of assuming a single rule.
What happens to records if we change platform or CRM vendor?
The obligation stays with the firm, so the exit provisions in the vendor contract decide whether you can meet it. Agree before signing what is exported, in what format, on what notice, and how long the vendor keeps its own copy. Discovering the answer during a migration is too late.
About the Author
Alex Onta is an Executive Director at SINGUARD. He built eTrader, the terminal, the mobile apps, eTrader Broker, Copytrading, Business and Community, along with the worldwide clustered-server infrastructure it all runs on, with his brother Roman Onta helping on the design, and he leads that division today. Together with Roman he builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals, and the two of them carry worldwide compliance, payment processing and international business structuring side by side. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.