Mobile Communications | Connector for SMS
What Is the Shield Connector for SMS?
SMS — Short Message Service — is the universal mobile text messaging standard used across every mobile network globally. For regulated financial services firms, SMS represents one of the most persistent and most scrutinised off-channel compliance risks: a communication channel that is universally available to every employee on every mobile device, that generates brief, informal, and frequently substantive business communications, and that has historically been difficult to capture, archive, and surveil to the standard required by financial services regulators.
Shield’s SMS connector provides platform-agnostic, carrier-level capture of business SMS communications for regulated employees — ingesting text messages and associated metadata directly into Shield’s compliance platform, regardless of the carrier or device through which they are sent. From the moment data enters Shield, it is available for AI-powered surveillance, investigation, regulatory archiving, and eDiscovery, all within a single unified platform alongside every other channel the firm uses.
SMS compliance does not require a single solution. The right capture approach depends on how regulated employees are using mobile — whether through corporate devices managed by the firm’s own carrier infrastructure, through enterprise mobile communications platforms such as Movius, 1Global, or similar solutions that provide a dedicated business number, through carrier-level capture arrangements with operators such as Singtel, Telia, or Movistar, or through a combination of these. Shield’s SMS connector is designed to work across all of these deployment models, providing a unified SMS compliance record regardless of the capture mechanism.
SMS is not a legacy channel. Despite the proliferation of enterprise messaging platforms, SMS remains the most universally available communication channel for mobile-to-mobile and mobile-to-external communication — and it remains the channel regulators most frequently encounter in enforcement actions involving off-channel communications. Firms that have addressed WhatsApp, WeChat, and enterprise messaging compliance without addressing SMS may have the most consequential gap remaining in their mobile compliance programme.
Why SMS Compliance Is Complex
SMS presents compliance challenges that are specific to the mobile text messaging environment and distinct from those of enterprise messaging platforms or email. Several issues arise consistently across regulated firms:
- Universal availability and the off-channel enforcement context. Every employee with a mobile device has SMS capability, regardless of whether they have been issued a corporate device or enrolled in a compliant mobile communications programme. Regulators globally — including the SEC, FCA, and MAS — have made clear through significant enforcement actions that uncontrolled SMS communications are a primary supervisory focus. Firms with front-office staff using personal mobile SMS for business communications — even occasionally — carry material compliance exposure that enterprise messaging policies alone do not address.
- Fragmented capture across devices, carriers, and platforms. SMS compliance capture is inherently fragmented because SMS does not flow through a single enterprise platform. Messages may be sent from corporate devices managed by the firm’s carrier infrastructure, from personal devices used for business through a Movius or 1Global business number, or from personal devices used without any capture mechanism in place. A complete SMS compliance programme requires capture at both the enterprise platform and carrier levels, with visibility across all device and carrier configurations in use across the regulated workforce.
- Mobile-specific language and informality. SMS communications are characteristically brief, informal, and dense with abbreviations — a combination that generic keyword-based surveillance tools are poorly equipped to handle accurately. Context that would be explicit in an email is frequently implied in SMS, and genuine misconduct may be expressed in language that looks entirely ordinary without financial services NLP context.
- Metadata completeness. SMS generates metadata alongside message content — including sender and recipient identifiers, timestamps, delivery status records, and network identifiers — that is essential for audit trail integrity and regulatory examination responses. Archiving solutions that capture message text while discarding or misformatting this metadata produce records that are incomplete for investigation and eDiscovery purposes.
- Cross-channel continuity. SMS conversations rarely represent the complete picture of a business interaction. A conversation that begins over SMS may continue on a voice call, and conclude via Bloomberg IB or email. Compliance architectures that hold SMS data separately from other channels make cross-channel reconstruction slow, error-prone, and structurally incomplete.
Key Features of the Shield SMS Connector
Platform-Agnostic SMS Capture. Shield’s SMS connector ingests business SMS communications regardless of the carrier or capture mechanism through which they are delivered — including corporate device carrier capture, enterprise mobile platform capture via Movius, 1Global, or similar solutions, and carrier-level capture via Singtel, Telia, Movistar, or other operators. All SMS data is ingested into the same unified compliance archive regardless of its source.
Full Metadata Preservation. Shield retains and enriches the complete SMS metadata layer, including sender and recipient identifiers, timestamps, delivery status records, network identifiers, and message IDs. This metadata is preserved in its original form, made fully searchable, and stored as part of the immutable compliance record — ensuring that investigations, regulatory examination responses, and eDiscovery productions are accurate and legally defensible.
Immutable, Audit-Ready Archive. All SMS data captured by Shield is stored in a tamper-evident, WORM-compliant archive with a complete audit trail of every access and action taken on the record. Data is indexed for rapid search and retrieval, supporting regulatory examination responses, eDiscovery requests, and internal investigations. Retention periods are fully configurable to meet jurisdiction-specific requirements — including the six-year standard under SEC Rules 17a-3 and 17a-4, the five-to-seven-year requirements under MiFID II and MAR, and the five-year requirements under CFTC Regulation 1.35.
Out-of-the-Box AI Surveillance Models. Shield ships with pre-configured AI surveillance models for SMS, targeting behaviours including market manipulation, information leakage, MNPI sharing, front-running, and personal misconduct — all calibrated to the specific language patterns of mobile SMS communications in financial services contexts. Models can be customised to reflect a firm’s specific risk appetite, restricted lists, and internal policy requirements.
Unified Cross-Channel Surveillance. SMS does not exist in isolation. The same employees communicating over SMS are also using Bloomberg IB, email, Microsoft Teams, and other channels — often about the same trades, clients, and positions. Shield ingests SMS into the same unified compliance platform as every other channel, enabling compliance teams to correlate text messages with voice interactions and electronic communications from all other sources. This cross-channel context is essential for accurate misconduct detection and complete trade reconstruction.
Data Governance and Chain of Custody. Shield’s SMS connector preserves a complete, verifiable chain of custody from ingestion through archiving and retrieval. Every stage of data handling is logged, auditable, and reportable — giving compliance officers and legal teams the confidence that SMS records are admissible, complete, and unaltered throughout their lifecycle.
Regulatory Coverage
SMS communications are classified as business records subject to capture, retention, and surveillance requirements across multiple regulatory frameworks. The Shield SMS connector supports compliance with:
- SEC Rules 17a-3 and 17a-4 — requiring broker-dealers to capture, preserve, and produce records of all communications related to their business, stored in WORM-compliant, non-rewriteable format with an audit trail, for a minimum of six years — applicable to SMS communications conducted in connection with regulated activity, regardless of the device or carrier through which they are sent.
- FINRA Rules 4511 and 3110 — requiring member firms to archive all communications relating to their business as such — including mobile text message communications — with written supervisory procedures, supervision requirements, and full audit trail capability in place.
- MiFID II Article 16(7) and Market Abuse Regulation (MAR) — requiring investment firms to record and retain electronic communications related to orders and transactions for a minimum of five years, with trade reconstruction capability within three days, and to monitor communications for indicators of insider trading, front-running, and market manipulation across all channels including mobile SMS.
- CFTC Regulation 1.35 and 17 CFR § 23.202 — requiring swap dealers, major swap participants, and futures commission merchants to retain records of all communications relating to commodity interests and swap transactions as part of a complete audit trail for trade reconstruction, including mobile SMS communications.
- FCA Rules (SYSC 10A and MAR) — requiring FCA-regulated firms to record and retain relevant electronic communications for a minimum of five years, and to implement effective surveillance arrangements to detect and prevent market abuse — including communications conducted via personal or corporate mobile devices.
- MAS, ASIC, and equivalent APAC regulations — requiring MAS-regulated and ASIC-regulated firms to retain records of communications related to regulated activity, including mobile SMS, with applicable retention and retrieval standards.
- GDPR and applicable data privacy regulations — Shield’s architecture supports data residency requirements and privacy-compliant data handling across jurisdictions, enabling firms to meet GDPR and equivalent national privacy obligations for SMS data alongside their financial services recordkeeping requirements.
Other Related Connectors
Shield’s connector portfolio spans the full range of eComms channels and trading platforms used across regulated financial institutions. All connectors feed into a single unified compliance platform — so SMS data is always reviewed in the context of every other channel your workforce uses.
- Movius SMS
- Movius Mobile Audio
- 1Global
- Singtel SMS
- Singtel Voice
- Telia
- Bloomberg IB and Bloomberg Mail
- Microsoft Teams
- Microsoft Exchange
- WhatsApp Business
- Voice and Turret
- Zoom
- Gmail
Frequently Asked Questions
What is the difference between the SMS connector and carrier-specific SMS connectors such as Singtel SMS, Movius SMS, or Telia?
The SMS connector provides platform-agnostic SMS capture — ingesting business SMS communications regardless of the carrier or enterprise mobile platform through which they are delivered. Carrier-specific connectors such as Singtel SMS, Movius SMS, and Telia are optimised for the specific infrastructure, metadata structures, and data delivery mechanisms of those platforms, and are appropriate for firms where all or most regulated SMS activity flows through a single carrier or enterprise mobile platform. Firms with regulated employees using multiple carriers or devices, or with a combination of corporate device and enterprise platform deployments, may use the SMS connector as a unified ingestion mechanism alongside or instead of individual carrier-specific connectors. Shield’s onboarding team can advise on the appropriate configuration for a firm’s specific mobile infrastructure.
Does the SMS connector cover MMS as well as SMS?
Yes. Shield’s SMS connector captures both SMS (text-only messages) and MMS (multimedia messages including images, audio, and video attachments) within the same unified ingestion stream, preserving all attachment content and metadata alongside the text record.
Which regulations does the Shield SMS connector help firms comply with?
The Shield SMS connector supports compliance with SEC Rules 17a-3 and 17a-4, FINRA Rules 4511 and 3110, MiFID II, Market Abuse Regulation (MAR), CFTC Regulation 1.35 and 17 CFR § 23.202, FCA SYSC 10A, MAS and ASIC requirements, and applicable data privacy regulations including GDPR.
How does Shield handle the informal and abbreviated language typical of SMS communications?
Shield’s surveillance engine applies NLP models specifically trained on financial services language — including the brief, informal, and abbreviation-heavy communications typical of mobile SMS. This contextual understanding reduces false positive alerts and ensures that genuine risk signals are identified accurately, even when expressed in casual or abbreviated language that generic keyword-based systems routinely misread or miss entirely.
Can SMS data be reviewed alongside voice calls and other channels during an investigation?
Yes. Shield ingests SMS into the same unified compliance archive as every other channel — voice calls, Bloomberg IB, email, Teams, and mobile. A business interaction may begin with an SMS exchange, continue on a voice call, and conclude over Bloomberg IB or email. Shield combines all of these into a single searchable record, enabling compliance teams to reconstruct the complete sequence of a business interaction across all platforms in a single workflow.
How should firms approach SMS compliance for employees using personal devices?
Personal device SMS is the most significant unaddressed mobile compliance gap for most regulated firms. The most effective approaches involve deploying an enterprise mobile communications platform — such as Movius or 1Global — that provides employees with a dedicated business number on their personal device, separating business SMS from personal traffic and making business communications capturable. Shield’s SMS connector ingests data from these enterprise platforms alongside corporate device carrier capture, providing a unified SMS compliance record regardless of the device configuration in use across the regulated workforce.
How should firms handle GDPR and privacy obligations for SMS communications?
SMS communications captured for compliance purposes are subject to GDPR obligations — including requirements around lawful basis for capture, data subject access rights, and retention limitation — that apply regardless of whether the messages are captured at the carrier level or via an enterprise mobile platform. Shield’s architecture supports privacy-compliant handling of SMS data, including configurable retention periods and data residency controls, enabling firms to meet their GDPR and equivalent privacy obligations across the full SMS compliance programme.