How to Achieve BYOD Compliance for Financial Services

Financial advisors who use personal phone numbers for client communication can create compliance challenges for their firms. Appointment requests, account instructions, and investment discussions can enter personal inboxes outside the firm's archiving and supervision processes.

As a result, compliance officers could struggle to retrieve required records when an advisor deletes messages, loses a device, or leaves the firm.

A Bring Your Own Device (BYOD) policy can help establish how advisors conduct business on personal phones and how your firm retains and supervises those communications.

Below, we explain how to put those requirements into practice.

Table of Contents

1. BYOD compliance for financial services: the fundamentals

2. How to establish a compliant BYOD process

3. What happens when a phone is lost, replaced, or an advisor leaves?

4. Put your BYOD calling and texting policy into practice with iPlum

5. BYOD compliance for financial services: FAQs

6. Give advisors a business number your firm can supervise

BYOD compliance for financial services: the fundamentals

Bring Your Own Device allows employees to use personal devices for business activities, such as client calls, text messaging, and access to company applications.

For financial services firms, BYOD compliance means ensuring those activities meet applicable regulatory requirements. An advisor's ownership of the device does not change your firm's obligations concerning customer information, business records, or supervision.

Your firm must address three responsibilities:

  • Protect customer information: Establish safeguards against unauthorized access to sensitive data.
  • Preserve required records: Retain business communications according to applicable retention and storage requirements.
  • Supervise business communication: Establish review procedures, investigate potential violations, and document corrective action.

That said, FINRA permits the use of personal devices when firms can retain, retrieve, and supervise business communications. A message's content determines its record retention obligations, regardless of who owns the device.

Therefore, your BYOD policy should distinguish device approval from permission to use specific applications. 

In addition, it should identify the channels advisors can use for business and establish how your firm will archive and review those communications.

How to establish a compliant BYOD process

Your BYOD policy should define how your firm authorizes personal devices, preserves business communications, and supervises their use. 

Here's a breakdown of how to establish one:

Identify where advisors already conduct business

Begin with an inventory of the devices, phone numbers, and communication accounts employees use for business. Ask advisors how clients currently contact them, including through channels your firm has not approved.

Your review should account for:

  • Personal SMS and iMessage conversations.
  • WhatsApp and other messaging accounts.
  • Personal email and social messaging.
  • Business calls through personal numbers.
  • Client communication managed by assistants or contractors.

Also, examine communication outside business hours. An advisor could use an approved application during the day but respond to client messages through a personal account in the evening.

For each channel, document the employee, the business purpose, the approval status, and the archive destination. Investigate any channel whose business records your firm cannot locate or retrieve before authorizing further use.

In addition, assess historical communications. 

Adopting a new business application does not preserve messages held in existing personal accounts. Assign compliance officers the responsibility for identifying required records and arranging an appropriate collection process.

Define what the firm can access on a personal phone

Before enrolling a personal device, explain your firm's access and monitoring terms. 

Employees should know which business records administrators can review and which personal information remains outside routine monitoring.

Distinguish device management from application management. Device management applies settings to the phone according to its enrollment configuration. Application management governs designated business applications and their data.

Your security requirements should address:

  • Operating system updates and security patches.
  • Screen locks and authentication.
  • Restrictions on compromised or modified devices.
  • Transfers of business data into personal storage.
  • Lost-device reporting and access revocation.

Also, document any remote deletion capabilities. Specify which data administrators can erase, under what circumstances, permitting deletion, and who must authorize the action. Verify how the chosen configuration treats personal content.

If an employee declines the enrollment terms, establish an alternative, such as a company-issued phone. Document that arrangement before granting access to business applications.

Move client conversations to an approved business number

Assign advisors a dedicated business number and update their client-facing contact details. 

Email signatures, business cards, websites, appointment messages, and client records should display the approved number.

However, updating published details will not reach every existing client. Therefore, advisors should notify clients who use their personal number and explain where to send future business calls and texts.

Your policy must also address business messages received through personal channels.

For example, a client could send investment instructions to an advisor's personal inbox. 

The advisor should follow your reporting and preservation procedure, then move the subsequent discussion to the approved channel. Redirecting the conversation does not resolve the obligation to preserve the original message.

The SEC's electronic messaging observations discuss procedures for transferring business messages received through prohibited channels into an appropriate system.

Specify whom employees should notify and which collection method they must use. Explain that a screenshot alone does not establish adequate preservation and that employees must not delete records requiring retention.

Also, document an approved communication alternative for application outages. Employees should know how to continue client service under your policy when the primary channel is unavailable.

Test archiving before authorizing client use

Verify the proposed service against your firm's requirements before approving it for client communication. Send sample messages, then retrieve them through the process your compliance officers will use.

Test incoming and outgoing communication. Where your policy permits them, also test images, attachments, and group conversations.

Confirm that the archive preserves message content, participants, timestamps, and relevant attachments. Authorized reviewers should be able to retrieve and export those records in usable formats.

For recorded calls, test the calling configurations advisors will use. Verify recording behavior and required announcements under each applicable configuration.

Your vendor assessment should also address:

  • Retention settings and protection against premature deletion.
  • Administrator access after an employee account closes.
  • Export formats and associated charges.
  • Record availability after subscription cancellation.
  • Record transfers when changing providers.

Make successful retrieval testing a condition of approval. Document the results, any limitations, and the individual responsible for accepting the configuration.

FINRA recommends testing vendors' capabilities through simulated examination requests in its regulatory oversight report.

Assign reviewers and investigate personal-channel use

Establish how your firm will review archived communications.

Here you'll need to assign responsibility for reviews, determine their frequency, and document procedures for escalation and corrective action.

Select a review method appropriate to your business activities and communication volume. Investigate unexplained changes, such as a substantial decline in an advisor's business texting despite continued client activity.

Also, examine references to conversations conducted elsewhere. A message mentioning instructions sent through a personal account warrants further review, although it does not establish misconduct on its own.

FINRA identifies deficiencies involving missing business texts, inadequate procedures, and insufficient reviews. It also discusses monitoring reductions in activity within approved channels.

Employee training should address specific situations, such as clients requesting WhatsApp replies or colleagues sending business questions to personal numbers. Apply the same requirements to supervisors and document how your firm addresses violations.

While at it, reassess approved channels after material application or configuration changes. Verify that archiving and supervisory access continue to function as required before authorizing any new communication features.


What happens when a phone is lost, replaced, or an advisor leaves?

Your BYOD process should anticipate events that interrupt access to the original device.

If a phone is lost or stolen, the employee should report it promptly through a defined contact route. 

Revoke business access where possible, assess potential exposure of customer information, and activate your incident-response process. Applicable Regulation S-P requirements address unauthorized access to or use of customer information.

If an advisor replaces a phone, approve the replacement before restoring business access. Revoke old sessions and verify that communication reaches the archive from the new device. A successful app login alone does not verify preservation.

If an advisor leaves, restrict their access and, where your service permits, arrange reassignment of the business number. Confirm that account closure does not delete records your firm must retain. Assign responsibility for incoming client communication and preserve access for authorized reviewers.

Before approving your departure process, test one question: can your firm retrieve historical messages after disabling the advisor's account?

The answer should come from a completed test, rather than an assumption that the former employee will provide their phone number later.


Put your BYOD calling and texting policy into practice with iPlum

Once your firm has established its requirements, choose a business communication service that employees can use on their personal smartphones.

iPlum's Mobile Compliance Solution for Financial Professionals provides a dedicated business line through an app. 

Your firm can use that line as the approved destination for client calls and texts, then apply its own supervision procedures to the resulting records.

With iPlum, you can:

Give advisors a separate business line

Advisors can use an iPlum business number on an existing smartphone to separate professional communication from their personal line.

During rollout, assign the number before asking advisors to redirect clients. Update their published contact details and confirm that they know how to place business calls and respond to messages through iPlum.

Before launch, ask an advisor to demonstrate an incoming client call, an outgoing text, and a record request. Correct any mistakes during onboarding, then document completion of the exercise.

For advisors with established client relationships, plan the transition deliberately. A new number only changes communication habits when clients receive it, and advisors consistently use it.

Archive business texts and record calls through iPlum

The Enterprise plan offers automatic inbound and outbound call recording, recording announcements, WORM archiving, and up to 10 years of retention.

Configure these capabilities according to your firm's requirements. Confirm the retention arrangement, recording settings, and consent process before authorizing client use.

Also, test sample exchanges during setup. Your compliance officer should retrieve the resulting records and verify that the service behaves as expected under the intended configuration.

Give administrators access to communication records

iPlum provides user administration, password policies, audit logs, and recording, playback, and downloads. These capabilities give your firm an administrative process for accessing business records.

Assign access based on responsibilities, then document who reviews communications and responds to record requests.

That said, be sure to distinguish communication through iPlum from activity elsewhere on the phone. 

Installing the app does not archive unrelated personal texts or WhatsApp conversations. Your firm must still enforce its approved-channel policy and address device security separately.


BYOD compliance for financial services: FAQs

Does FINRA allow financial advisors to use personal phones?

Yes. Firms can permit personal phones when they can retain, retrieve, and supervise business communications. Device ownership does not exempt business messages from applicable record retention requirements or supervisory obligations.

Does a second SIM make business texting compliant?

No. A second SIM provides another number, but it does not establish compliant archiving or supervision. Your firm must verify how it preserves, retrieves, and reviews business messages sent through it.

Can my firm review business messages on my personal phone?

Your firm should define access through its BYOD agreement and applicable law. Separate business applications can distinguish professional records from personal conversations, giving employees specific expectations about monitoring and privacy.

Must all financial advisors record mobile calls?

No. FINRA Rule 3170 applies to designated taping firms. Other obligations depend on business activities and applicable rules. Your firm should assess recording requirements and consent obligations before enabling recording.

Does installing a business phone app archive older personal texts?

Installing an app does not automatically preserve historical messages in unrelated accounts. Your compliance officer should assess those records, arrange appropriate collection, and then direct future conversations through approved channels.


Give advisors a business number your firm can supervise

Your firm's oversight of client communication should extend to the personal devices advisors use for business. 

A dedicated business number establishes an approved channel for those conversations, with records available for retention and supervisory review.

iPlum enables your firm to introduce that channel on advisors' existing smartphones. 

Alongside your BYOD procedures, it provides the calling, texting, recording, and archiving capabilities needed to manage mobile business communication.

Take the next step toward a supervised mobile communication process. 

Sign up for iPlum's Mobile Compliance Solution for Financial Professionals.

Tags
No items found.
Download Our APP Now!