Compliance recording field guide
Compliance Recording and Message Retention: Internal Communications, Monitoring, and Chain of Custody
A jurisdiction-aware blueprint for deciding what to capture across calls, meetings, chats, and channels; how long to retain it; how to preserve evidence; and how one governed dashboard supports Cisco, Webex, and Microsoft Teams workflows.
Signal path
Where call-recording.com intervenes
From technical requirement to working recording
call-recording.com brings supported Cisco voice recordings, Webex call recordings and message history, and Beta Microsoft Teams meeting recordings, transcripts, chats, posts, and replies into one organization dashboard with source context, search, retention, and scoped access.
What does compliance recording actually require?
Compliance recording is the controlled capture, preservation, supervision, retrieval, and disposal of business communications that a law, regulator, contract, investigation, or documented company policy puts in scope. It can include customer calls, internal calls, meeting recordings, transcripts, chat messages, channel posts, replies, business SMS, attachments, and the metadata needed to understand who communicated, when, and through which system.
There is no single global law requiring every organization to record every interaction. Some financial-services rules require particular communications to be recorded and retained. Privacy, employment, interception, and labor laws can limit monitoring. Litigation can suspend ordinary deletion. Healthcare and payment rules change how captured content must be protected or whether sensitive data may be stored at all.
This guide is a practical framework, not legal advice or a complete statement of every jurisdiction. Your compliance, privacy, employment, records, and litigation counsel should approve the actual scope and schedule.
Start with a communications inventory, not a recording switch
The Teramind compliance-monitoring overview makes a useful operational point: compliance monitoring is an ongoing process of assessing laws, internal controls, records, and corrective action. The important word is process. A recording platform cannot decide which rule applies to which person or conversation.
Build an inventory before selecting capture settings:
| Question | Evidence to document |
|---|---|
| Who is regulated? | Legal entity, business unit, role, registration, desk, geography, and supervisor |
| What activity is regulated? | Order, advice, trade, complaint, customer instruction, clinical interaction, payment, or ordinary collaboration |
| Which channels are used? | Cisco voice, Webex Calling, Webex spaces, Microsoft Teams meetings, Teams chats/channels, SMS, email, social messaging, or personal devices |
| What must be captured? | Audio, video, transcript, message content, attachment, edits/deletions, call metadata, approvals, or surveillance results |
| How long is it retained? | Rule-specific period, business period, legal hold, deletion trigger, and review owner |
| How is it produced? | Search fields, export format, access authority, audit evidence, regulator deadline, and chain-of-custody procedure |
The result should be a channel-and-obligation matrix. “Record everything forever” is not a defensible substitute for one.
UK FCA and MiFID rules can reach internal electronic communications
For in-scope UK investment activity, FCA SYSC 10A requires affected firms to take reasonable steps to record specified telephone conversations and keep copies of specified electronic communications. The rule is tied to activities such as receiving, transmitting, arranging, or executing relevant orders and transactions; it is not a general rule for every conversation in every FCA-regulated firm.
The FCA recordkeeping schedule states five years from the communication, extended to seven years when the FCA requests it. Firms must identify relevant internal and external communications, maintain a written policy, restrict business on channels that cannot meet the policy, periodically monitor records on a risk-based and proportionate basis, and demonstrate management oversight.
The corresponding MiFID II delegated regulation expressly refers to relevant internal telephone conversations and electronic communications. It also requires notice to clients and access to copies for five years, or up to seven years at the competent authority's request.
The operational obligation is therefore wider than storing call audio. A firm needs channel coverage, policy enforcement, capture testing, search, supervision, retrieval, and evidence that gaps or exceptional circumstances were handled.
FCA COCON 2026 makes reliable work-channel evidence important, but does not order blanket surveillance
From September 1, 2026, the FCA's new COCON 1.1.7FR extends conduct-rule scope in non-banking firms to certain serious bullying, harassment, or violence involving colleagues where there is a sufficient work-related link. The FCA's official non-financial misconduct guidance tells firms to review policies, conduct-breach reporting, fitness-and-propriety assessments, regulatory references, and staff understanding.
The FCA also says firms do not need to monitor employees' private lives or social-media accounts, investigate trivial or irrelevant private-life allegations, or act contrary to privacy, employment, or other law. COCON does not prescribe a universal message-retention period.
The supplied Luware analysis explains why contemporaneous company-channel records can matter when a firm must decide what happened, whether conduct was serious, whether a notification follows, and what a regulatory reference should say. That is a useful investigation perspective, but it should not be converted into an unsupported claim that COCON requires all calls, meetings, and chats to be recorded.
A balanced policy retains defined business communications where there is a lawful and proportionate reason, protects complainants and accused employees, and leaves private life outside routine collection.
SEC and FINRA duties focus on business content, including internal and off-channel messages
For U.S. broker-dealers, FINRA's books-and-records guidance explains that Exchange Act Rule 17a-4(b)(4) covers communications sent and received relating to the broker-dealer's business. That can include email, instant messages, texts, chat, social-media content, and internal communications, whether carried on the firm's system or a third-party platform.
The normal communications period described by FINRA is at least three years, with the first two years readily accessible. FINRA Rule 4511 supplies a six-year default for FINRA records that have no other specified period. The correct period therefore depends on the record category; “FINRA means six years for everything” is inaccurate.
The SEC's off-channel enforcement actions show the practical risk. Required business records were lost when personnel, including supervisors and senior managers, used unapproved communication methods. A policy that names approved tools but cannot detect, capture, preserve, and supervise actual business communications is incomplete.
Rule 17a-4 electronic recordkeeping adds a second question: can the system preserve the record in compliant WORM form or maintain a complete time-stamped audit trail, verify completeness and accuracy, and promptly produce records? Ordinary searchable cloud storage should not be represented as Rule 17a-4 compliance without that specific assessment.
CFTC and Dodd-Frank rules cover specified pre-execution oral and written communications
Swap dealers and major swap participants have separate obligations under 17 CFR 23.202 and 17 CFR 23.203. In-scope daily trading records include pre-execution oral and written communications concerning quotes, solicitations, bids, offers, instructions, trading, and prices that lead to a swap or related transaction.
Those communications may occur by telephone, email, instant message, chat room, or mobile device. Voice-recording retention can differ from the longer period for other swap records, so the schedule must be mapped to the current rule and the firm's exact registration and activity.
Our separate Dodd-Frank call-recording guide covers the swap-specific detail. The broader lesson is that omnichannel capture must follow the regulated activity across platforms rather than assume the desk phone is the entire record.
GDPR and UK worker-monitoring rules can limit collection and retention
The GDPR requires a lawful basis, purpose limitation, data minimization, transparency, security, accountability, and storage limitation. It does not provide one universal retention period for calls or messages. The controller must justify the period against the purpose and any specific legal obligation.
The UK ICO's worker-monitoring guidance says employers considering email or message monitoring must identify a clear purpose, assess necessity and proportionality, inform workers, and complete a data-protection impact assessment for content monitoring. It warns that personal communications, union communications, special-category data, household members in remote-work settings, and covert collection create heightened risks.
That means the technically possible scope is not automatically the lawful scope. Organizations should separate metadata monitoring from content review, restrict content access to defined circumstances, exclude personal channels where appropriate, and maintain a documented retention and deletion policy.
Read the GDPR call-recording guide and workplace messaging guide for the privacy and employee-rights detail.
U.S. monitoring must also account for interception, state notice, and labor rights
U.S. federal and state interception and recording laws vary by channel, party location, consent, confidentiality, and purpose. A company should not assume that ownership of a device or account creates permission to record every conversation. The call-recording law guide explains the federal baseline, stricter state consent rules, interstate calls, and notice design.
Employment monitoring also sits beside labor law. The National Labor Relations Board explains that employees can have protected rights to discuss pay, benefits, and working conditions with coworkers, including through social media. Monitoring policy and disciplinary use should be reviewed so they do not unlawfully interfere with protected concerted activity or create prohibited surveillance of protected communications.
State laws may add advance notice for electronic monitoring, restrictions on access to personal social accounts, biometric rules, privacy torts, and limits on off-duty conduct. Remote workers make location part of the legal analysis.
Healthcare and payment data are overlays, not generic recording mandates
HIPAA does not generally require covered entities to record oral communications. HHS confirms that the Privacy Rule does not require oral interactions to be taped or retained after transcription. But if a recording or transcript is maintained and used to make decisions about an individual, it may become part of a designated record set; electronically stored protected health information also brings Privacy and Security Rule safeguards into scope.
PCI DSS creates a different constraint. The PCI Security Standards Council states that card verification codes may not be stored after authorization, even in encrypted audio. Payment flows should prevent sensitive authentication data from entering the recording, use pause/redaction where appropriate, or securely delete prohibited data under an approved design.
These examples show why “capture every channel” can conflict with “collect only what is permitted.” Queue, user, call type, meeting type, and message-source exclusions belong in the design.
Retention is a schedule with triggers, not one global number
A defensible retention schedule should name the record category, legal basis, start event, normal period, accessibility requirement, deletion method, hold behavior, and owner. Examples include:
- five years, with possible extension to seven, for specified FCA/MiFID communications;
- three years, first two readily accessible, for specified broker-dealer business communications under Rule 17a-4(b)(4);
- a different period for CFTC oral communications and related swap records;
- a purpose-based period for quality, complaints, or employee investigations where no fixed statutory period applies;
- immediate suppression or deletion for payment authentication data that must not be stored;
- suspension of deletion when a valid legal hold, regulator request, complaint, or investigation applies.
Avoid silently resetting retention when records are migrated between platforms. Preserve the original event time, source identity, applicable schedule, and hold status. Review the schedule when a new channel, jurisdiction, analytics feature, or business purpose is introduced.
Legal holds override routine deletion when preservation duties arise
Regulatory retention and litigation preservation are related but different. A record may have reached the end of its normal schedule yet still need to be preserved for a complaint, subpoena, investigation, or reasonably anticipated litigation.
Federal Rule of Civil Procedure 37(e) addresses electronically stored information that should have been preserved in anticipation or conduct of litigation but was lost because reasonable steps were not taken. A practical legal-hold workflow should:
- identify people, platforms, channels, dates, and issues in scope;
- stop scheduled deletion without changing unrelated records;
- preserve source metadata, message edits/deletions, attachments, and recording files;
- document collection and access;
- test that records remain searchable and exportable;
- release the hold through an authorized, recorded decision;
- resume the correct retention schedule after release.
The platform can enforce a hold only after the organization defines when and how one is issued.
Chain of custody is about authenticity and handling, not a marketing label
“Chain of custody” is often used broadly for digital records. In U.S. federal evidence practice, Federal Rule of Evidence 901 asks for evidence sufficient to support a finding that an item is what its proponent claims. Rule 902 provides self-authentication routes for certain certified electronic records and data copied from electronic devices, media, or files.
For calls and messages, preserve enough context to explain the record from source to production:
- source platform, tenant or organization, and provider record ID;
- conversation, room, meeting, call, or thread ID;
- sender, organizer, owner, participants, and role information where available;
- source-created, sent, edited, deleted, imported, and exported timestamps;
- original media or content format and any later transcription, conversion, or redaction;
- retention class, hold status, access history, and export authorization;
- integrity checks or hashes where the evidence procedure requires them;
- the person and process responsible for collection and production.
call-recording.com can preserve source identifiers, timestamps, recording and message context, and organization-scoped records where the provider API exposes them. That supports an evidence process. It is not by itself a representation that every export is court-admissible, cryptographically immutable, WORM-compliant, or accompanied by a complete legal chain of custody.
Compliance monitoring is more than collecting an archive
Collection answers “Do we have a record?” Monitoring asks “Are controls working, and are we finding the risks the policy was designed to address?” A mature program tests both coverage and use.
Useful controls include:
- reconcile expected calls, meetings, users, chats, and channels against imported records;
- alert on capture outages, expired authorizations, permission changes, stalled imports, or unapproved channels;
- sample records using a documented, risk-based method;
- separate reviewers from subjects and restrict sensitive investigations;
- record review outcomes, escalation, remediation, and closure;
- test regulator, discovery, and subject-access retrieval;
- review false positives, bias, language coverage, and proportionality before adding automated analysis;
- verify deletion and hold behavior instead of assuming policy settings worked.
The archive, supervision workflow, and conduct decision should remain distinguishable. Keeping every message is not the same as monitoring compliance effectively.
How call-recording.com unifies voice and collaboration evidence
call-recording.com provides one organization-scoped dashboard environment for recording and collaboration records from supported systems. It can combine Cisco CUCM, UCCX/Finesse, and CUBE SIPREC capture with supported Webex Calling records, Webex messaging history, and a Microsoft Teams integration currently labeled Beta.
The unified value is governance: authorized teams work from one service for search, review, retention, and platform administration instead of maintaining disconnected local audio folders and ad hoc exports. Source-specific screens and permissions still matter; “unified” does not mean every provider record is flattened into one indistinguishable object.
The security architecture limits network exposure for customer-hosted Cisco capture. The recording-integrity design uses local persistence, journaling, retry, and receipt confirmation for Cisco media delivery. The Trust Center documents the boundary between implemented controls and customer-specific governance.
Microsoft Teams coverage: recordings and scoped business messages
The Microsoft Teams integration can import meeting recordings and transcripts plus authorized chat messages, channel posts, and channel replies through Microsoft Graph. Existing history can be imported, and supported Graph change notifications can feed new records. The integration remains Beta and depends on tenant administration, Graph permissions, application access policy, subscription health, and the resources Microsoft makes available.
Microsoft's Teams Export API documentation describes programmatic access to meeting recordings and Teams content. Coverage must be validated against the actual authorization model: private or encrypted content, unsupported workloads, deleted data, personal accounts, federated tenants, and off-channel apps may sit outside the accessible record set.
call-recording.com lets the compliance team retain Teams-source identity and timing with the imported content and review it within the same organization environment used for other supported platforms. It does not turn an unapproved WhatsApp or personal-text conversation into a captured Teams record.
Webex coverage: separate recording and compliance-message authorizations
Webex call recordings and Webex messaging history are connected separately so an organization can approve the minimum scope needed for each purpose. The Webex Converged Recordings APIs expose recording identifiers, metadata, and media for authorized administrators or compliance officers. The Webex compliance APIs provide organization-level event and message access through designated compliance scopes.
call-recording.com can import Webex recording history, process supported live recording events, and import organization messaging history with the compliance authorization. Provider permissions, source ownership, API history windows, license level, deletion state, and recording configuration determine what is available.
This separation matters for proportionality. A firm that needs Webex Calling recordings does not automatically need every Webex space message. A firm investigating regulated chat may need the message-history connection and a carefully bounded reviewer group.
A unified dashboard still needs channel-specific policy
Use one dashboard as the control plane, but keep policy attributes on each source and record class:
| Control | Cisco voice | Microsoft Teams | Webex |
|---|---|---|---|
| Scope | CUCM users, contact-center paths, CUBE sessions, supported call flows | Authorized meetings, recordings, chats, channels, and replies | Separately authorized call recordings and organization message history |
| Primary evidence | Audio, call metadata, recorder and delivery state | Recording, transcript, message content, thread and meeting context | Recording, message/event content, source IDs, owner and room context |
| Coverage risk | Cisco configuration, endpoint/gateway path, recorder health | Graph permission, app policy, subscription, unsupported or off-channel content | Compliance role, OAuth scope, event/history window, provider recording policy |
| Governance | Recording notice, retention, access, hold, review | Approved-channel policy, employee notice, retention, supervision, hold | Recording and message scopes, privacy boundary, retention, supervision, hold |
The dashboard reduces operational fragmentation. The customer remains responsible for deciding which rows in this matrix are legally required, proportionate, and tested.
Implementation checklist for compliance recording and internal communications
- Identify every legal entity, regulated role, jurisdiction, and business activity.
- Inventory voice, meeting, chat, channel, SMS, email, social, and personal-device workflows.
- Map each obligation to content, metadata, retention, access, supervision, and production requirements.
- Define approved channels and a practical escalation path when a channel is unavailable.
- Complete privacy, employment, labor, consent, DPIA, and works-council review where applicable.
- Configure the minimum necessary Cisco, Teams, and Webex capture scope.
- Give callers, customers, and workers the required notice before monitoring begins.
- Establish role-based access for playback, message review, export, deletion, and administration.
- Set category-specific retention, defensible deletion, and legal-hold rules.
- Preserve source identifiers, timestamps, edit/delete state, and transformation history.
- Test expected-versus-captured completeness for each platform and call/message scenario.
- Simulate a regulator request, investigation, legal hold, export, and access request.
- Document gaps, unsupported channels, expired permissions, and compensating controls.
- Review vendors and recordkeeping formats against rule-specific requirements such as Rule 17a-4.
- Reassess the program whenever platforms, APIs, laws, purposes, or employee populations change.
What call-recording.com does not decide for you
call-recording.com provides technical capture, import, search, retention, access, delivery, and platform-management capabilities for supported sources. It does not decide whether your organization is a broker-dealer, swap dealer, investment firm, HIPAA covered entity, employer subject to a particular state notice law, or controller with a valid lawful basis.
It also does not eliminate the need for Microsoft, Cisco, and Webex licensing and permissions; written supervisory procedures; employee and caller notices; a records schedule; legal-hold authority; reviewer training; regulator-specific electronic-recordkeeping validation; or counsel's advice.
Treat the platform as part of the control environment. Compliance is the tested combination of law, policy, people, source coverage, technical controls, and evidence.
Bottom line
The central compliance-recording problem is no longer just how to record a telephone. Regulated and sensitive interactions move among Cisco calls, Webex Calling, meetings, spaces, Microsoft Teams recordings, transcripts, chats, channels, and replies. The obligation follows the activity and content, while privacy and employment boundaries follow the people whose communications are captured.
A defensible program knows what must be recorded, what may be monitored, what must not be stored, how long each record lives, when deletion stops, and how authenticity is demonstrated. call-recording.com gives organizations a unified place to operate supported Cisco, Webex, and Microsoft Teams records while keeping source identity and platform-specific authorization visible. The organization supplies the legal decisions, policies, reviewers, and proof that the configured controls actually work.
Where call-recording.com intervenes
From technical requirement to working recording
call-recording.com brings supported Cisco voice recordings, Webex call recordings and message history, and Beta Microsoft Teams meeting recordings, transcripts, chats, posts, and replies into one organization dashboard with source context, search, retention, and scoped access.
Source ledger
Primary references and technical evidence
Validate version-specific commands, legal scope, and policy decisions against the current source applicable to your environment.
Legal and compliance content is general information, not legal advice. Cisco behavior and commands vary by product release, platform, firmware, and call flow.
Continue the research