Electronic Messaging Exams: Looking Beyond Emails

The SEC is conducting “electronic messaging” examinations, which include all forms of written communications related to an Adviser’s business which are conveyed electronically by methods other than email messages sent or received using the Adviser’s email system.

The types of electronic messaging in the examination include those of the Adviser and the Adviser’s personnel (including independent contractors) used for the Adviser’s business and subject to the Books and Records rule (Rule 204-2(a)(7) or (11)).

The types of electronic messaging include:

  • Instant messaging
  • Text/SMS messaging
  • Email and personal or private messaging, whether on the Adviser’s systems or third party apps or platforms
  • The Adviser’s mobile devices
  • Personally owned computers or mobile devices used by Adviser personnel, including independent contractors

The exam document request asks the Adviser to provide copies of written policies and procedures relating to electronic messaging, including informal or unwritten policies or procedures, and those addressing transmittal of sensitive information and related security and privacy concerns.  The exam requests identification of all persons overseeing the policies and procedures and their roles and responsibilities, monitoring and review processes, exception reports, whether any violations have been detected, a summary of any internal audits or compliance reviews associated with electronic messaging, and copies of any risk assessments or risks, and how the Adviser mitigates or addresses these risks.  Information regarding recordkeeping is requested, including if maintained by a third party vendor.

Takeaways: 

  • Review your policies and procedures related to electronic messaging. Ascendant’s Cybersecurity Practice can partner with you to craft more robust policies related to Electronic Communications, Acceptable Use and Information Security that are tailored to your business and cover policies and controls for email, text messaging, apps and cloud-based services. You can also use our proprietary technology tool, Ascendant Compliance Manager, to manage and distribute those policies, capture employee attestations, document your control activities and log any material findings. Contact us to learn more.
  • We’ve also previously weighed in on some of your options relating to policies regarding personal e-mails at work in a previous blog we did on cybersecurity, linked here.
  • We believe this is a sweep exam in the NY region, which may be designed for information gathering and result in a soon-to-be SEC Guidance Alert. We will continue to keep you posted if/when we learn anything new.

Related Content

Latest Content

Insurance Considerations for Investment Advisers

How much coverage is enough? What types of insurance policies do you need? Whether you are starting an investment advisory practice, launching a new line of business, or reevaluating your existing risks, there are critical questions to ask to make sure you understand the various ways to protect your firm. Join us for a practical … Continued

Fifth Circuit Weighs In on DOL Fiduciary Rule

A panel of the U.S. Court of Appeals for the Fifth Circuit has vacated the Department of Labor’s Fiduciary Rule. In a 2-1 split, the Fifth Circuit’s decision overrules a Dallas District Court’s decision, which had previously upheld the rule. Unfortunately, the decision does little to settle the fate of the beleaguered rule. Although it … Continued

SEC Proposes Amending Investment Company Liquidity Disclosures in Forms N-PORT and N-1A

On March 14, 2018, the Securities and Exchange Commission (“SEC”) proposed amendments to the mutual fund liquidity-related disclosure requirements. Specifically, the proposal: Adds a new requirement to “briefly discuss the operation and effectiveness of the Fund’s liquidity risk management program during the most recently completed fiscal year” in the Fund’s Management Discussion of Fund Performance … Continued

Paradigm Shift in SEC Exams, Benefits of a Mock Exam

For investment advisers currently going through an SEC exam, the process likely bears little resemblance to exams of old. Call it the new normal, a paradigm shift, or simply the effects of the SEC having to do more with less, but anecdotal evidence among those now experiencing the exam process suggests some interesting new trends. … Continued

Why Should a Big Hedge Fund Use a Compliance Consultant?

If your firm isn’t already using an outside consultant, you may want to ask yourself “why not?” Oftentimes at hedge funds, compliance officers struggle to successfully fulfill the requirements of the job without an essential tool in their toolbox: the outside compliance consultant. Why? The primary reason is simple: resources. When your head is down … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.