SEC 17a-4FinancialUnited StatesSecurities / Broker-Dealers

SEC Rule 17a-4 - Records to be Preserved

SEC regulation requiring broker-dealers to preserve records in non-rewritable, non-erasable format (WORM). Critical for trading firms, investment advisors, and financial institutions.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

SEC 17a-417a-4(b)(4)Retention and availability

Trade Records

Records of every trade and trade-related database modification MUST be preserved for at least 6 years.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

SEC 17a-417a-4(f)Integrity of the recordRetention and availability

Electronic Storage

Electronic records MUST be preserved in WORM (Write Once Read Many) format with audit trail.

A requirement like this is about the record surviving the person who would rather it did not, which means the audit trail has to be protected as carefully as the data. File activity monitoring hashes the datafiles, the transaction logs, the backups, and the audit trail itself with XXH3, then baselines them — so an alteration or a deletion is evident rather than inferred, and it is attributed to the session and OS user behind it. Because the same platform holds the query trail, a destructive statement and the file-level change it produced are two views of one event rather than two investigations.

SEC 17a-417a-4(f)(2)(ii)The files under the database

Verification

Broker-dealers MUST verify automatically the quality and accuracy of electronic storage.

Datafiles, redo and WAL logs, backups and exports, configuration files, binaries, keystores, and scheduled jobs are hashed and baselined, so a change to any of them is detected with the permission and ownership context around it. The differentiator is attribution: because the same platform holds the query trail, a modified datafile is correlated with the session and statements running at that moment — who and why, not only what and when.

SEC 17a-417a-4(f)(3)Retention and availability

Audit System

MUST maintain a separate audit system that accounts for input and preserves entries with timestamps.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

What SEC 17a-4 covers

17 CFR 240.17a-3 and 240.17a-4

Defined by record TYPE rather than by data class — the books and records a broker-dealer must make and then preserve.

In scope

  • Blotters of daily purchases and sales, receipts and disbursements
  • General ledgers and customer account records
  • Order tickets and confirmations
  • Communications received and sent relating to the business

The communications limb is the one that produced the off-channel enforcement sweep: business conducted on a personal device is a record the firm was required to preserve, wherever it happened to occur.

17 CFR 240.17a-4 · as at 2026-08

How SEC 17a-4 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The SEC and FINRA civilly; the Department of Justice for wilful violations.

Published maximumChargedAs at
USD 2.7 billionNo ceilingassessed across roughly 60 firms since 2021 for off-channel recordkeeping. An enforcement pattern, not a ceiling: the rules carry no statutory cap at all2026-08

The recordkeeping rules carry no ceiling, and the off-channel communications sweep shows what that means in practice: business conducted on personal devices and unapproved messaging apps was not captured, and the penalties were sized to the firm rather than to a schedule. This is an enforcement pattern, not a published maximum.

The USD 2.7 billion figure describes what has been assessed to date. It is not a ceiling and should not be read as one.

Who is personally on the hook

Who can be charged
Any person who wilfully violates the Exchange Act or a rule made under it, including supervisors and compliance officers charged individually
For what
wilfully failing to preserve required records, including business conducted on channels the firm does not capture
Maximum
Up to USD 5 million and 20 years imprisonment for a wilful violation
Brought by
The US Department of Justice, alongside SEC civil proceedings
PrisonPersonal fineNot indemnifiable

Uncapped exposure that sits outside this instrument

These come from company law rather than from SEC 17a-4, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Who the instrument makes accountable

Rule 17a-4(f) requires a designated officer or the compliance officer of the firm to attest to the recordkeeping arrangements, and FINRA supervisory rules put the failure on named supervisors.

The insurance position

Regulatory investigation costs are commonly covered under a professional or D&O wording; disgorgement and penalties are frequently excluded, and settlements in the recordkeeping sweep were generally characterised as penalties.

How this class of policy is commonly written. Only your own policy answers what it covers.

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for SEC 17a-4,
not configured for it afterwards

Policy Template

Trade Data Immutability

Monitor all modifications to trade and order databases

Report

SEC 17a-4 WORM Compliance

7-year immutable audit trail for regulatory examination

Classification

Trade Record Patterns

Identify orders, executions, and trade-related data

Alert

Record Modification Attempt

Alert on any attempt to modify preserved records

Other Financial frameworks

Walk into the SEC 17a-4 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment