Speakers
Manuj Paradker
VP of Customer Success, LeapXpert
Rieko Moody
Product Manager, Shield (former VP of eComms Surveillance & Governance, JPMorgan Chase)
David Aaronson
Senior Product Marketing Manager, Shield
Mobile digital communications compliance has never been more complex. From WhatsApp to iMessage, Slack to Teams, the channels people communicate on keep expanding and so do the regulations about monitoring them.
We surveyed financial services organizations to find out the challenges they’re facing capturing and surveilling unmonitored communication channels, which channels are the most concerning, and their plans to regulate employees’ communications in the future.
Manuj Paradker
VP of Customer Success, LeapXpert
Rieko Moody
Product Manager, Shield (former VP of eComms Surveillance & Governance, JPMorgan Chase)
David Aaronson
Senior Product Marketing Manager, Shield
Shield Insiders In-Focus | Presented by Shield and LeapXpert
Speakers
David:Okay, I think we can start. Hello, everyone, and welcome to our webinar, 2023 State of Mobile Communications Compliance: Survey Results, presented by Shield and LeapXpert. I’m David Aaronson, Product Marketing at Shield, and I’m fortunate to be joined today by Manuj Prabhakar, VP of Customer Success at LeapXpert, as well as my colleague Rieko Moody, Product Manager at Shield and former VP of eComms surveillance and governance at JPMorgan Chase. With Manuj calling in today from Singapore, me sitting here in Israel, and Rieko welcoming the new day in California, I can confidently say we’ve got some excellent global coverage here. So welcome, both of you, and thank you for joining. At the half-hour mark, we’ll open up Q&A, so shoot over any questions you have in the Q&A feature.
Now, I remember fondly as a teenager being on the corded phone lines with friends all day and night — but landlines have become a thing of the past, and the cords are shockingly all gone. Now everything we do is on our mobile phones, and business is no different. Along with our new shiny phones have popped up a new set of opportunities for market manipulation and bad actors in the financial services industry — meaning even more challenges for regulatory bodies. The SEC, FINRA, FCA, and ASIC have all, over the last few years, come to the table and said in no uncertain terms: all communications must be monitored, no matter the device. And we’ve seen what happens when an organization tries to rely on simply banning these new communication channels. What would once have been an earth-shattering dollar amount of fines has become commonplace — millions and millions of dollars for unmonitored channels and communications.
So after all these years, we wanted to understand how much has actually changed. How are people reacting? What actions are being taken? How is the new avalanche of data being processed and surveilled? That’s why Shield and LeapXpert started this survey of 200 compliance leaders in financial services. We’ll send that over to all the attendees at the end of the call. So now that we’ve set the stage, let’s dig into the facts. Manuj, what’s the most interesting result you’ve seen here?
Manuj:Well, David, hello, everyone. There are many, many findings, but the top one that stands out for me goes to the point you touched on — banning and putting a policy in place. Organizations lack confidence: about 73% of the people surveyed said they lack confidence in banning as a way to add value. This is no surprise. Changing human behavior by policy is not an easy thing, and especially when it comes to social messaging, banning is even harder, because today social messaging is part of everybody’s life. Just like how we communicate in our personal lives, it’s the same in business — the majority of people use social messaging as a way to communicate.
Just as we operate in a customer-centric way, our customers operate in a client-centric way. So, for example, if an investment adviser is contacted by a client on their personal phone — WhatsApp or another channel — it’s extremely difficult for that banker to decline or reject that channel. Thinking about compliance at that point is the last thing on their mind; they just want to reply, because it’s an important client. We also demand faster responses in the current world — it’s more convenient, and people want faster answers. So as soon as you have contact on a social messaging app that people are using, it’s a natural human way for people to engage. So it’s not very surprising. We’ve seen this even in the last year — compliance officers’ responses about lacking progress, around 72%, is absolutely the top concern.
David:Thanks, Manuj. Rieko, what did you find interesting in this report?
Rieko:Thank you. To me, the one that stands out is that almost half said they’re not happy with user adoption. That tells me we have a lot of work to do there. It takes time to adapt to any change — and as you get older, like me, everything takes time. When you go to foreign countries, even something like driving on the left versus the right — small things — it’s human nature. But we also have to acknowledge that there really is no option here but to embrace it. New policies are in place, and you just have to adapt.
In terms of the survey’s nuance between manager versus C-suite, what it really shows is that more senior folks understand the time required for any policy change. It’s one thing to implement a policy and hope people follow it; it’s another to make sure people are actually following the new policies. So they’re a little more realistic about it. Another thing it points out is that people may be feeling concerned about privacy or data security — it’s possible employees aren’t aware that the company has fully vetted the privacy and data-security process. So it could be a matter of education, but hopefully people get acclimated and used to this new way of doing things. We also saw in the survey that, more than half the time, it’s actually the client — especially on the manager side — where the messages are coming in from the clients, and you’re not the one initiating. So there really isn’t much option for inhibition. Banning is really not the answer, so we just have to look at how to embrace it and put policies around this new way of doing business.
David:That’s a great point, Rieko, referring back to that two-thirds — the survey found two-thirds of initiated conversations are actually clients. So these communication tools are no longer just a convenience; they’re core sales tools. This is how we do business. Both statistics you and Manuj pointed to — the 73% lack of confidence in banning, and the poor adoption and reliability of some of these tools — really speak to whether we feel confident in our ability to interact with customers in a way that’s regulated and lets us monitor and understand what’s going on in these conversations. And the reality is, if you don’t know what’s going on in these conversations, that’s a big issue — a $2.1 billion issue, which is kind of the whole purpose of the report to begin with.
David:Looking at both of these stats, we see a lot of trends that aren’t always the same across North American and European compliance teams. So one of the things that was really important to us in the report was to get that perspective and understand how different regions are looking at this issue. Manuj, what’s your take on the survey results between North America and Europe, in terms of approaches and feelings?
Manuj:Well, the US market is obviously trending fast, and this is not surprising to us — we’ve seen this trend start maybe eighteen months ago or even earlier. It’s mainly because US regulators have been much more focused on fines and guidance, and we’ve seen how the SEC has acted in the last year and the year before. On the other hand, Europe is catching up on the US trend, but the results show it moving even faster than we anticipated, which is really good. But it’s also important to see how this plays out between different geographies and countries. On one side, it’s the trend of compliance; on the other, you have to look at how people are using the channels. When it comes to the US, it’s WhatsApp and iMessage, quite prominently. When it comes to Europe, it’s much wider — multichannel: WhatsApp, Signal, Telegram, and more.
Just to expand on that, what I see is that the globalization of business is driving a multichannel approach. So the same applies to the US and Europe. When you talk about social messaging, as much as the business wants to adopt it, it’s more driven by the end clients — and end clients are connected to the culture and the country. That’s probably why you see the US is majority iMessage by default, and we’re seeing a huge trend on using iMessage, whereas Europe is much more multichannel. Our report also shows that multichannel is increasing quite fast — from around 20 to 26% up to 45%. So regulators have to find a way to capture all of it; it’s not just about one or two messaging apps. That’s the key nuance I see across different geographies and regions, and it applies to much wider geographies as you expand.
David:Manuj, I think that goes back to what we said previously — it comes down to culture and to what people are doing. How are people communicating? I started off talking about being on the phone as a teenager with all the cords. That was then; how are we talking now? Different places in the world communicate differently. So whatever they’re going to be talking on is going to be what’s regulated and looked at. That’s a great call-out. Rieko, can you respond to that?
Rieko:Yeah. What we also want to look at is capturing for the regional nuances we talked about — but also the monitoring side. We’ve talked about all these regional nuances and all the different capturing we need to do, but one thing we need to really look at is what we’re actually doing for monitoring. What type of solutions does the company actually have, and how confident do you feel about them?
It’s really about addressing the different nuances. A couple of examples: people talk differently on WhatsApp versus company chats versus email. On email, I tend to write the whole story of my life, with all the context and background and bullet points — that’s the nature of email. Company chats can be much shorter, though on Teams at work I still give a bit more background. Whereas on WhatsApp with my friends — smaller screens, smaller bubbles — I use a lot of acronyms, like “LMK” or “GSD.” So when you’re capturing and monitoring, are you catching those nuances in the way people talk differently?
Another one is venue-hopping. We talked about all these different channels. It’s possible that I’m on the phone with David at one point, then I start to send something on the company chat, then I have a related item on email, and then on the side I’m on WhatsApp. Do you have a way to track and look at all of that, say, in a timeline? Because you want to do some of the analytics in your tool — whether internal or external — you want a view where you can analyze the venue-hopping.
And another one — it’s not new, but with recent news, emojis. You definitely want to capture them, but you also want to monitor them. There was a lawsuit in Canada where the use of a thumbs-up emoji was considered legally binding as part of a contract. So it used to be more of a “nice to have, let’s capture emojis.” But if it can carry the meaning of a legally binding contract, you have to monitor it — how were people using those emojis, what did they mean?
The last thing I wanted to touch on: we talked about all these new channels and regional ones, but there are a lot of channels and platforms, and the firm can only do so much to anticipate what they are. What about new channels compliance wasn’t aware of, or when people try to use prohibited channels — even ones your company couldn’t capture? The really important thing is to have a process to monitor those instances. You don’t know what you don’t know, but you can’t just say “I don’t know.” Having a robust process in place to catch and capture those instances makes a strong case with regulators.
David:Thank you, Rieko. Just a reminder to everyone: anyone with questions, please ask them in the Q&A. And — what does GSD stand for? No, I’m just kidding. But it’s very funny: I remember my father a few years ago asking, “Wait, how does WhatsApp work? When do you send a voice message and when do you type?” And I’m thinking, “I don’t know, we just do.” So the way people behave and choose to behave across different channels is different, and there are subtleties to it. Like you said, there are risks hiding in the different ways we communicate — emojis being one of them. And I really appreciate you bringing up that Canadian court decision, because it speaks to how archiving and monitoring have come a long way from just saving documents in a storage hall somewhere, or email down in the on-prem archive. It’s so much more than that. The way we communicate with each other has evolved so much, and some of the older approaches to surveillance just aren’t sophisticated enough to capture what’s going on in these conversations.
David:At the end of the day, we know regulators are now scrutinizing how firms are monitoring these conversations and what they’re doing to gain insight into risks potentially hiding there. In our report, 64% of respondents said their biggest concern was regulatory audits. Rieko, what about internal systems — aren’t they there to protect firms from these kinds of fines and worries about audits?
Rieko:Sure. Just to touch on the 64% for regulatory audits — I think the second was fines, at 34%. When you hear about over two billion in fines, it’s impossible not to worry about regulatory audits and fines, so we should acknowledge that. But ideally, you want an internal strategy to avoid those regulatory fines. There are a lot of classic internal controls — training is definitely important; you have to remind people, run the training, and show that you did it. You do attestations that people aren’t using any prohibited channels. But as we talked about, that’s really no longer good enough. You have to make sure you have a capturing process and a monitoring process. Hopefully those things help dodge the bullet of regulatory audits.
But the critical practice all firms need to perform here is what we’d call a mobile assessment. You want to look at the possible channels — geographically and by business — and identify which ones are actually used, which ones you need to capture, what data you need to capture, and how you ingest and provision it. Device is also something that comes up a lot: are you using a corporate device, or are people still using bring-your-own-device? There are different associated risks depending on the device. And if you’re still on BYOD, how are you mitigating those risks? So definitely do those assessments internally. Hopefully everyone has been on top of it by now, but if not, those are steps you want to take before a regulator knocks on the door. It’s always better to be proactive than to wait for someone else to visit — or to find the issue internally, which is great, whether it’s internal control or a risk you find yourself.
David:Thank you, Rieko. That point of becoming proactive is very much the story here. We’re talking about 2.1 billion reasons to become proactive, and not just wait for someone to knock on the door and tell you what you’re doing wrong. Manuj, would you like to respond to Rieko’s answer?
Manuj:Yeah, it’s an important area — regulators and how that impacts things. Some of the key points Rieko touched on in the previous question — about multichannel, and how you make sure people use the approved channel, because there’s always another channel they can bypass to. How do you control that? And that ties back to corporate device versus bring-your-own-device. There are platforms available today, like LeapXpert and Shield, that can help customers bring those channels in as official communication without leaving a back door for people to use.
And when you talk about corporate device versus BYOD, from the regulator’s point of view, having a corporate device solves a lot of challenges. But we also see that regulators are now getting to the individual level, not just the organization level. A good example: I think in May or June, a couple of months ago, they fined two individuals — ten thousand, fifteen thousand dollars, and suspended them for many months — for not complying with some of these regulations. So regulators are getting stricter and more stringent, and it’s very important that organizations start to look at this much more deeply. It’s not that you don’t have a solution — you do. Now is a good place to really look at how to bring these channels into the proper compliance fold.
David:Thank you. That actually speaks to one of the questions that came through in the Q&A: when it comes to all these regulations and what’s coming up next, the regulators aren’t going to tell you what’s coming up next — that’s kind of the purpose of principles-based regulation. So the question becomes: what is the next WhatsApp? What are the next points of focus you think regulators will be pointing to? Rieko, you can answer first.
Rieko:I think we’re actually starting to hear a lot about voice surveillance recently. The concept of voice surveillance isn’t that new, but what we hear about now is the concern with sampling. There are still a lot of firms doing sample reviews, because compared to, say, written communications, voice can be trickier to capture and to identify suspicious conversations in. So some firms are doing sample reviews as opposed to a full 100% review. But there are concerns being raised recently because of recent fines with the interdealer brokers, where they were doing a sample review — picking and looking at conversations — that didn’t catch any of the market-conduct or employee-conduct issues. So we’re starting to hear quite a bit about that. In the same conversation, we also hear about transcript accuracy — it still seems to be quite a challenge for some of the solutions and firms already monitoring voice, so they’re looking for solutions with better transcription accuracy. Another one we hear is Zoom — video calls, like the one we’re doing now. The question is always: do we need to capture it? Is there a requirement, and is there a solution that can capture all these video calls? So I think that’s going to be one of the next ones to come up. I don’t know what your thoughts are.
Manuj:I agree with Rieko. Language barriers and transcription are definitely one of the top asks — we’re seeing that with many customers, and especially since social messaging is bringing people together and removing the barriers of boundaries and languages. It’ll play a key role. The second area, from my point of view, is multichannel, and it’s more at the cultural level — clients have a choice of which channel they want to use to communicate with the business. Consolidation of all these channels into one is probably the next step we see. Rieko mentioned voice as well, and we’re starting to see that single identity is going to be a key driver in the market. What does single identity mean? Say I’m an investment adviser — I’ll have one number, and I can tell clients, “You choose how you want to contact me: call me, WhatsApp me, iMessage me, LINE me, any channel you choose.” That’s how we see this space evolving. Solutions like LeapXpert already deploy those kinds of capabilities, and with Shield coming in as a way to meet the compliance requirement end to end, in a single platform, that’s where I see the trend going. It’ll make compliance much easier — instead of finding many platforms to stay compliant, it all gets consolidated to a single platform where you can look at all the channels. From the compliance and employee points of view, it brings a lot of ease. So I think it’ll bring a lot more value to the business.
David:Those are really good points, both of you — especially the whole end-to-end part, which is becoming a much bigger issue. It’s capture, it’s archiving, it’s retention policies, it’s data sovereignty. And I’ll segue directly into the Q&A.
David:One of the questions that came in: how do you actually monitor all this stuff? We’re not just talking about more — we’re talking about mountains and mountains more, and it’s even harder to analyze this new data coming in. The actual question was: do you think generative AI may help to identify suspicious messages more accurately? Rieko, do you want to speak to that? You’re on mute.
Rieko:Thank you. The first time I’ve gotten the “you’re on mute” — well, we all get it all the time. The answer is definitely yes. There’s a lot of research being done right now on whether it’s going to be accurate. You have to think about what we talked about with the capturing tools — a lot of the data privacy and security considerations that people need to think through. But in general, from a lot of the resources we’ve all seen, it’s quite remarkable, and a lot of technology should adapt it to answer some of the questions and concerns you have — obviously not taking it at face value and saying, “Yep, this is the answer.” You never want to take whatever is produced as “here is the answer” or “here is our finding.” But it is quite powerful, even in the risk and compliance space. It’s a shame if people aren’t thinking about it yet — that’s definitely something that will come, both in the vendor space and within firms themselves, and a lot of them are looking at it.
David:Thank you, Rieko. Manuj, I think you can take this one: what are some of the key factors people look for when selecting a mobile messaging compliance solution? I’m sure you get that question a lot.
Manuj:Yeah, it’s a good question. As I was replying to the earlier point, multichannel support is top of mind, because if you’re a business supporting your clients beyond one location — which most businesses are today — you have to have multichannel support. There’s no way you can say “I’m just going to deal with one,” because that means you’ll lose the clients who aren’t using the channel you support, and then people find a way to start using it in a non-compliant way. So multichannel support will continue to be a key factor, and we’ve seen this in many financial institutions.
On top of that, one of the survey questions was about how to deal with the data, and a lot of the findings were about people wanting to integrate the data with their CRM and other workflows. We’re starting to see those requirements play a role in deciding on these platforms, because social messaging has a lot of capabilities you can integrate within your business. And when you integrate with your internal systems, you have to make sure the platform complies with your internal guidelines, security, GDPR, and your data-leakage prevention. There are so many aspects to look at when you use this platform as a client-facing tool. So those are the very common use cases and key factors firms look at when they select the tools.
David:Thank you, Manuj. This next question, I think, is also for Rieko: how do financial institutions address the challenges of data overload and actually analyze the data? I’m guessing “data overload” is what I referenced before — the mountains of data, the avalanche of data, because it keeps going. It’s not going to stop. So what’s the best way of doing it? Maybe this speaks to becoming proactive — you just can’t stay in the defensive stance anymore.
Rieko:Manuj, call me through one by one, is what I was going to say — but no. I do want to use the word AI; I think it’s just the word of the day. You can’t have a conversation without hearing it. Any data-analytics techniques — whether that’s artificial intelligence as the larger pool, machine learning, or generative AI — it’s a big item where you also want to collaborate. Whether internally, if you have a brilliant data scientist dedicated to looking at all the different parts of the data, you have to leverage them. And if your organization isn’t investing in that, or size-wise you don’t have a data scientist dedicated to risk and compliance — maybe they’re looking more at front-desk stuff — then you might want to collaborate with a technology provider. But the key is to address these challenges in a smarter way, rather than looking at it one by one, because that’s just not possible anymore. The data is becoming larger and larger as we speak — these Zoom calls, the volume is massive, and what we’re speaking across all these different forms is massive. We can’t just sit back and relax and hope whatever we happen to find is good enough. Going back to the regulator’s point: they also know there are different mechanisms and solutions out there now, so they’re not going to be happy if you say, “Oh, we’re doing random sampling, we’re trying our best because we don’t know the unknown risk.” But if you have a much smarter way to look at those things and be more proactive, that’s really the key.
David:Thank you. That’s where strategy comes in. To do what we’ve been doing was one strategy; you need a different strategy now. You raised all the points of what’s being used in the industry at scale, and it really is incredible what people are accomplishing. Here’s another question that just came in: are you able to analyze the video itself, or are you just analyzing the audio transcript? Manuj, do you want to take it?
Manuj:Yeah. There are many tools available to do audio and video transcription — absolutely possible. On top of that, just to touch on a couple of points Rieko was making about the data: audio and video data also goes into that. These are datasets that are GDPR-relevant for some data, but on the other hand, there’s a lot of good, valuable information to look at and learn from to increase client engagement. We’re seeing clients start to use this data to look back at how best to engage with clients, what challenges they’re having, and where they can improve. So having the right tool — whether it’s generative AI or other tools — to analyze that data and stay on top of it in a timely fashion, before it’s too late and it just becomes data sitting in the back yard, is super important.
David:Yeah, thank you, Manuj. And I think Gartner just put out a Hype Cycle report that introduced a new category called Digital Communications Governance, which was previously Enterprise Information Archiving. Part of the story is exactly what we’ve been talking about: archiving is just where you put the data — it’s just storage. That’s not really the real challenge today. The challenge today is how do we access data to be able to put it in an archive, and how do you analyze that data?
David:I’ll take one more question before we wrap up. This one: what is the challenge banks may encounter when they want to adopt messaging compliance platforms on top of their existing DLP policy? Anyone want to take that?
Manuj:I can. DLP policy has existed for a very long time. Any provider coming into this space should be able to appreciate the DLP policies the banks already have in place, and find a way to inherit that into the new channels. That’s the common trend, because no bank wants to rebuild a new DLP just because they went with a new channel. Most products or solutions support this, so I don’t personally see any major challenges in the way we’re dealing with it. Given the context of the question — if the concern is that banks want to adopt on top of the existing DLP — my answer would be no, it’s not a major concern. There are a lot of tools available where the new platform can just integrate with existing DLP systems and start using it.
David:And I think there’s also another side to DLP, which is more the MNPI-leakage side — someone who’s not supposed to talk to someone else, people in different restricted groups, and that data being shared, whether intentionally or not — and being able to get insights from the data we’re already collecting and analyzing. Rieko?
Rieko:On the insider-trading and data-leakage side, especially MNPI, it’s true that we’re starting to see more data integration and collaboration. We were talking about different data types — e-communications, voice, iMessage, WhatsApp — but because we’re talking about data, there are also different ways to look at and integrate it. There’s a deal list, say, in the control room, and there are ways to look at that and look at communications, so you can flag if certain deals are talked about outside of the people who should know about them. So now that many data points exist, and because we can integrate and combine them, it’s really a matter of — I should say imagination, but really thought leadership — to think about what we want to capture and what we want to cover in terms of risk. If you share that, someone nowadays can come up with the solution. So it’s an exciting time; we don’t just have to sit back and worry. There are different means, methods, and solutions that can be proactive. It’s a matter of putting the ideas together and thinking about the outcomes you want to see.
David:Thank you. Just wrapping up: one of the perspectives I took after going through the survey answers and digging through the data is that we’ve known about the complexity of electronic communications data for some time. The data types are all over the place — it’s unstructured data by definition — so being able to even look at it and get some answer out of it is super challenging. But we’ve come a long way from just storing papers, documents, and emails in archives. Regulators and internal risk teams have kind of taken this defensive approach over the years — after 2008, and after the last couple of years — trying to say, “Okay, what do we do? How do we react? Let’s start requiring all electronic communications to be surveilled, let’s add Dodd-Frank, let’s do supervision.” There have been all kinds of movements to try to rein in what’s going on. And we’ve reached a tipping point. That’s what all these fines were about: you can no longer just ban things that people are using. It’s not working. Maybe in the past you could get away with it, but now you can’t. People are using it; people are communicating this way.
Just pointing to the survey results: the top three channels respondents said they are currently capturing or going to be capturing very soon — I think nearly 100% said WhatsApp was one of them. It was WhatsApp, iMessage, and SMS. And what do they all have in common? A phone number — they’re all tied to your phones. So the way we communicate isn’t just picking up the phone; it’s using our phones’ core functionality, which is so different from what it used to be.
So today, it’s much more about how you take a proactive stance and get ahead of risk. That’s why it was really important that Shield and LeapXpert — we were naturally in touch with each other about this subject the whole time — decided it was time to get these answers and understand directly from compliance professionals what’s challenging them, and whether they’re still going to try to ban this or not. And we see the confidence just isn’t there anymore. So change is coming, if it hasn’t already. Change happens slowly, as Rieko pointed out — things take time, education is a strong piece, getting used to new technology, new realities, new challenges, and new user experiences all comes with the territory. We’re going to get there, and a lot of people already have.
Just to wrap up, a couple of words about LeapXpert and Shield. The LeapXpert communications platform captures and manages business communications conducted over consumer messaging applications and voice channels. It enables enterprises to achieve regulatory compliance and meet strict governance policies through comprehensive record-keeping and unrivaled data security and control capabilities. Users benefit from choosing the right communication channel for efficiency and client satisfaction, while meeting enterprise compliance, governance, and security needs. And from the field’s perspective, that is definitely a broad range of challenges that are very difficult to get ahead of, so LeapXpert is one of the leaders in this and definitely worth talking to.
And a quick word about Shield: the Shield platform is built with modern architecture, designed to deliver actionable insights about risk to stakeholders throughout your organization. It’s engineered to adapt to the fast pace of technology, ensuring you’re always ahead of the curve. We invite you to learn more by visiting our website or reaching out to our team of experts.
Thank you, Rieko and Manuj, for this really great conversation today — it was awesome. And thank you, everyone, for joining us. Have a great day.
Manuj:Thank you, everyone.
Rieko:Thank you, and bye, everyone.
No. In the survey, 73% of compliance leaders said they lack confidence in banning as a way to add value, and about two-thirds of messaging conversations are initiated by clients, not staff. When a client reaches an adviser on WhatsApp, declining isn’t realistic. Banning only pushes communication into unmonitored channels — which is exactly what drove the roughly $2.1 billion in off-channel fines.
Why are employees slow to adopt approved compliant channels?
It takes time, and the survey showed it: nearly half of respondents said they’re unhappy with user adoption. Senior leaders tend to be more realistic than managers about the time a policy change requires. Part of the gap is education — employees may not realize the company has already vetted privacy and data-security concerns. Reinforcement and training matter, because banning simply isn’t a viable alternative.
Yes. The US is trending fastest, driven by aggressive SEC fines and guidance, and leans heavily on iMessage and WhatsApp. Europe is catching up faster than expected but is far more multichannel. Either way, multichannel use is climbing quickly — from roughly 20–26% toward 45% — so a single-channel capture strategy leaves real gaps.
It’s mapping reality before a regulator does. Look at which channels are actually used across your geographies and business lines, decide what data must be captured and how you’ll ingest it, and assess devices — corporate-issued versus bring-your-own — since each carries different risks. If you’re on BYOD, document how you’re mitigating them. Do this proactively, before a regulator knocks on the door.
No — capture is just storage; the real work is monitoring. People communicate differently on WhatsApp, Teams, and email, so monitoring has to catch those nuances, including acronyms and shorthand. It also needs to follow “venue-hopping,” where a single conversation moves across phone, chat, email, and WhatsApp, and reconstruct it on one timeline so nothing falls through the cracks.
Yes. A Canadian court ruled that a thumbs-up emoji was legally binding as part of a contract, which turns emojis from “nice to capture” into something you must actively monitor. Modern surveillance has to interpret how people actually use symbols, images, and shorthand — not just scan plain text — because meaning increasingly lives outside the words themselves.
Yes, and increasingly so. Beyond the roughly $2.1 billion in firm-level off-channel fines, regulators have moved to the individual level — the panel cited two people fined around $10,000 and $15,000 and suspended for months. Regulator expectations are getting stricter and more stringent, so personal accountability is now part of the risk picture, not just corporate exposure.
Yes — reviewing it manually, “one by one,” is no longer possible. Generative AI and machine learning can help identify suspicious messages and analyze unstructured data at scale, whether through internal data scientists or a technology partner. The caveat: never take AI output at face value as a finding. Regulators now expect smarter, proactive methods rather than random sampling.
Gain access to exclusive insights, industry influencers, and thought leaders in
Digital Communications Governance and Archiving (DCGA).