Showing posts with label electronic storage. Show all posts
Showing posts with label electronic storage. Show all posts

Thursday, August 5, 2010

ESM: Another Provider

Just wanted to let you know about another provider of electronic storage--for emails and other files: OneSecure Technology. From what I hear, they provide good service at a good price--especially for you small firms out there struggling to keep up the expensive cost of compliance.

Here is an overview of some of the support and compliance help the firm provides: The firm also offers other services aimed at the financial services industry: web site design and hosting, email hosting, email encryption service, social media archiving / controls, data protection and back-up, web filtering (control web access to Facebook, other websites), and network security.
Required attestation lettes: format and access Supervisory Lexicon - monitoring tools for flagging electronic communication containing potential compliance violations; assigns them for further review
Contacts for support, training and system URL’s
Email Set up Documentation
Email Admin Interface Training
New Client Communications
Email Archive Admin Training
Archive End User Training Documentation
Product Documentation for Companies written Policies and Procedures
Mock Audit run through


Don't forget to keep your CRD notifications current: if you switch providers, you have to file a new notification in Forms and Filings/Financial Notifications/Electronic Storage Media and you have to upload new attestation letters.

Wow, this subject has a way of spoiling a good mood. Yikes.

Thursday, January 28, 2010

Social Networking Sites: Word to the Wise

FINRA has put out guidance on the topic of social networking sites (SNS). The explosion of electronic communications in many forms has made it difficult for BD’s to know how to follow SEC books & records rules. It used to be straightforward, but with tools like Facebook & Twitter, it’s tough to decide what constitutes categories like advertising, public appearance, correspondence and recommendations. I suggest you read Notice 10-06 (it’s not long!) so you are aware of FINRA’s concerns.

What FINRA wants is this: if your Reps or the Firm itself use SNS’s for business purposes, then you have to be able to supervise all postings, whether they are ‘static’ (like profiles or wall posts) or ‘interactive’ (like chats or interactive posts with third parties), and you have to be able to store all that content under SEC books and records rules (17a-3/a-4). Pre-approval of anything considered an ‘advertisement’ (the static content) is required; pre-approval is not required for interactive content, but all other requirements apply to that material.

Sound like a big job? It is! Word has it the bigger e-mail storage vendors are working on products that firms can use to meet these requirements (automatically saving the online content and providing an automated review tool for monitoring it), but I can imagine those products will not be cheap. And it’s harder to imagine small firms being able to adequately meet the supervision/r-k requirements on their own.

So, if you are going to allow Reps to participate in SNS’s, you HAVE to implement procedures to meet FINRA’s guidance. And you HAVE to follow those procedures.

If you would rather avoid this administrative challenge & expense (and the related liability of allowing the activity), you will have to be clear about your expectations of firm personnel. Make sure your procedures include a prohibition of this activity; it would also be smart to send an e-mail reminder to everyone at your firm. I suggest:

Our firm strictly prohibits you from engaging in business communications in a social media site (such as Twitter, Facebook and Linked-In, among others). Your participation in such sites must be for purely personal reasons. You may not present yourself on such sites as a representative or agent of the firm: to do so is considered “advertising” and requires pre-approval by our compliance staff. Likewise, on such sites you may not recommend securities or engage in discussions about securities or the firm’s business. Lastly, you may not: link to third party material relating to securities; assist third party site participants in preparing such material; or comment on/endorse third party posts on such material. Our firm may from time to time request access to your social networking sites in order to spot check them for compliance with this prohibition. Perceived violations will be met with disciplinary action.
No matter how you word it, the message should be clear--personnel may not use these sites for business purposes: to do so immediately puts your firm at risk.

Thursday, June 26, 2008

I won't call it a reversal

...but it seems like one.

Oh, I'm talking about electronic storage rules again. When I die, will someone please make sure my tombstone says something about my dedication to this cause? ...says something...not necessarily flattering.

Okay, so in the last two days I've run into situations where it appeared that 3rd party electronic storage vendors would not provide the representation letters generally expected under 17a-4(f)(2)(i)--you know the letter--the one that says the media will do the things listed under (f)(2)(ii), as follows:

(A) Preserve the records exclusively in a non-rewriteable, non-erasable format;

(B) Verify automatically the quality and accuracy of the storage media recording process;

(C) Serialize the original and, if applicable, duplicate units of storage media, and time-date for the required period of retention the information placed on such electronic storage media; and

(D) Have the capacity to readily download indexes and records preserved on the electronic storage media to any medium acceptable under this paragraph (f) as required by the Commission or the self-regulatory organizations of which the member, broker, or dealer is a member.

Since way back, when this subject was just a shadow across compliance officers' desks, the expectation--and instructions from then-NASD, I might add--was that, if the firm used a 3rd party vendor to store its electronic records, it was the 3rd party vendor who was required to make those representations in writing, on their letterhead, to the regulators. The firm would engage the vendor to store information (such as e-mails), would request the letter, would get the letter, and would mail it to Susan DeMando's office. Later, firms had to submit it to FINRA online.

Firms storing their own records electronically would make the representations themselves, in writing to FINRA.

What I just learned from a helpful and trusted FINRA staff member is this: the format representations letter does NOT have to come from the 3rd party vendor. Quoting (f)(2)(i) of the Rule: "...the member, broker, or dealer must provide its own representation or one from the storage medium vendor or other third party with appropriate expertise that the selected storage media meets the conditions set forth in this paragraph (f)(2)." The staff member said that the BD would make the representations 'unless they don't have the knowledge' to make them.

My opinion is this: most firms are hiring out because they don't have that knowledge or anything close to it. But hey, I've been wrong--or at least misled--before.

Most 3rd party vendors, in my experience, give those letters to their clients for delivery to FINRA. I would expect it if I were you. If the vendor wants to charge you for the letter, save your money and write the letter yourself.

Here's the thing , though: make sure you, the BD, get solid, written clarity from your 3rd party vendor before writing and submitting your letter to FINRA. You have to be sure the media meets the criteria. You're hiring the vendor because you can't or don't want to store the records yourself... you'll need to rest assured that the records meet the regulator's expectations, right? Otherwise, why pay their prices??

Oh, and remember: you always have to submit an 'access letter' to FINRA-complying with 17a-4(f)(3)(vii)--and that letter has to come from an independent third party (any old third party will do--as long as they know what they're talking about and they're not an affiliate or relative). Your third party storage vendor will write that letter for you--if they don't, fire them.

Thanks to Davis for his inspiration... he knows that nothing gets me going like ESM.

>

Friday, June 20, 2008

Little more input on audit function under electronic r/k rule

Quick--I promise--update on the 'audit function' under 17a-4(f)(3)(v). This week a FINRA examiner provided verbal guidance in response to a firm's written request for such. The guidance was not specific; it was based only common sense, not formal guidance from SEC or FINRA higher-ups. It consisted of recommending a periodic review of stored records to confirm that they are intact.

Okay then.

Obviously more on this subject is necessary for firms to fully understand their responsibilities.

AND...I came across another outside vendor for e-mail archiving: Global Relay Communications. I haven't gotten permission to link to them--please google them and check out their broker-dealer services. They seem quite thorough in their comprehension of FINRA members' regulatory burdens. Their materials plainly address all requirements and describe how their systems meet them... nice to see. Here's an excerpt from their presentation on the audit function (okay, I didn't get permission to copy this--but I'm hopeful the G.R. folks will appreciate the plug):

"All messages stored in the Message Archiver are forwarded directly from the Member firm’s email server, with no User intervention. During the lifecycle of a message, all actions (viewing, replying, forwarding, downloading, flagging, notation, review) by any User, Reviewer, Super Reviewer, Administrator or the system itself associated with the message are logged. The Message Archiver’s detailed logs provide a full audit trail verifying the integrity of the message. These logs automatically appended to the messages and are viewable and made available to authorized administrative Users.

As detailed directly above, Message Archiver immediately provides a full audit trail accessible to any authorized administrative User. A side benefit of the system, is that a firm also builds an audit trail for the auditors actions in the archive during an online audit.

Global Relay’s Message Archiver employs retention schedules for all audit results. Audit results are retained for the lifecycle of the message. The SEC three and six year retention requirement for records set out in paragraph (a) and (b) of this Rule 17a-4 can be applied to the audits within Message Archiver."

Happy Summer!


Wednesday, February 20, 2008

Link to Sources for Going Paperless

Investment News delivers stories and information useful to investment advisors. They started a newsletter about technologoy developments called IN: Tech and Davis Janowski posted an article on February 19 about going paperless. The article references vendors providing applications and other solutions that may be of interest to you, the broker-dealer struggling to keep up with record keeping demands.

I got pemission to provide the link to the article... go to: A Paperless Office Can Boost Your ROI and see what you think.

Remember to read my other entries on electronic record keeping if you want to test your ability to see cross-eyed. :)

Tuesday, February 12, 2008

See Jan. 22 Post on ESM: Audit System

Hi. I'm still new at this blogging thing. I posted a new entry today--February 12, 2008--but it showed up as posted on Jan. 22. That's when I started writing it and saved it as a 'draft.' Please see that entry, below, for a tedious but possibly interesting discussion of a requirement under the SEC electronic storage rules you may not know about.

Thanks.

Monday, January 28, 2008

ESM: Outsourced or In-House?

If you keep any primary records exclusively in electronic format you know you have to meet all those tedious requirements under SEC 17a-4(f) (see other blog entries, below). ESM=Electronic Storage Media.

You have a choice to make: do you attempt to meet the requirements using an in-house system or by hiring a third-party vendor? Or both? Some firms use third parties to archive and monitor their e-mails, IM’s and external message systems like Bloomberg; and they use an internal system to store and backup their other—non-communications—records. The goal in either case is to ensure proper archiving, back-up and recovery, and content management.

Quick apology: I have no expertise in this area—the tech side, that is. The vocabulary is foreign to me and therefore I use layman terms when speaking to the issues. But consider this: I’m not very different from small B-D business owners who are struggling to understand the rules and implement a compliant system. Regulators should—and I’ve seen evidence that they do—cut firms some slack in this area.

Your choices of third parties are many: Seccas, Smarsh, Iron Mountain Digital, Amicus and AdvisorMail, to name a few. As time goes by these services become more conversant in SEC-speak and more able to meet your regulatory compliance needs without resistance or ignorance. They meet the storage, serializing, indexing and backup requirements, they provide back-up copies on disk when requested, they issue representation letters as required, and they provide nice software tools for searching data and completing lexicon-based compliance reviews. And their pricing is pretty good: a one-time set up fee plus a small fee per month, per user/mailbox. This is a nice way for very small firms to meet ESM rules because you are leaving the technical stuff and the hardware expense to folks in the know. [That said, remember that member firms have been cited with violating the rules because their vendors didn’t meet the rules…that is, compliance is ultimately your responsibility, not the vendor’s.]

In-house systems for very small firms tend to be, well, non-compliant. Many firms keep records on their hard drives, then periodically download them to disk or tape. Their records are rewritable and erasable for a period of time prior to being stored in WORM (write once, read many) format. That gap of time is technically not okay under the rule. Also, they generally do not have indexing or auditing capabilities. Lastly, they may not make back-up copies of the archives that, too, are serialized, indexable and subject to an audit system. And, while these firms may have notified FINRA/SEC of their use of electronic storage, a) their representations may not be true; and b) they may not understand or meet the obligation under 17a-4(f)(3)(vii) to have a non-affiliated third party issue an ‘access letter’—a statement that the third party can get to and provide records requested by regulatory authorities. Firms that meet every letter of the ESM rules most likely have an expensive system or full IT staff in place. One such system is put out by EMC. Their software and hardware products are, as far as I can tell, state of the art and—important for you—completely compliant. And at least one third party vendor I know uses the EMC system in providing services to firms like yours. The problem here, depending on the firm’s size, is cost. EMC’s policy engines, ‘E-Mail Xtender’ and “Disk Xtender,” may be affordable choices for establishing records storage, indexing and destruction parameters, but in both cases you’ll still need a hardware storage system to hold those records and enforce the established policies (such as EMC’s “Centera” product). That’s where it gets expensive. Then again, if you’re spending a lot of time and money storing your records and updating your servers, breakeven may be just a few years away.

How far to go in attempting to meet every aspect of the ESM rules?—that is the question. Is a good faith, less-than-absolutely-compliant approach acceptable? It is if you say it is, but you may be forced to defend your choices. The more resolute and sincere your defense, the more apt you are to win your own principle-based vs. rule-based battle. Not the war, though: that rages on.


Footnote: Another consideration… the cost of discovery. If your system feels good enough, but doesn’t meet every requirement, and if your firm is subject to a regulatory investigation, you will spend huge bucks to recover and produce requested records. This possibility should be built into any cost benefit analysis.


Links (without permission but with luck, permitted):
EMC: http://www.emc.com/solutions/business-need/compliance-ediscovery/index.htm
Smarsh: http://www.smarsh.com/prinsite/my/default.asp
Seccas: http://www.seccas.com/
Amicus: https://www.amicus.com/solutions/EMM/
Iron Mountain Digital: http://www.ironmountain.com/digital/
AdvisorMail: http://www.advisormail.net/emailcompliance/index.asp



Stay tuned; another--maybe my last?--entry on the audit aspect of ESM rules is forthcoming.

Tuesday, January 22, 2008

Electronic Storage Media: Audit System?

Warning: you will need energy to get through this... if there's a power source nearby, plug in and read on.

This blog entry addresses a specific instance of what many have experienced: differing expectations from FINRA on meeting SEC rules. With regard to electronic storage, this is typical. On the one hand, we are informed that there are no interpretations: the rule is the rule and must be followed. On the other hand, we're expected to accept different degrees of testing during exams and differing exam findings--some tolerant and seemingly 'principle-based' and some strictly by the book. FINRA staff do not apologize for this. Exam methodologies are 'risk-based' and therefore can vary greatly--even for firms with identical business niches. While that seems reasonable, it also seems unfair.

17a-4(f) rules relating to electronic storage are hard to live by. Most small firms do not meet those standards. But then again, most small firms are forgiven by FINRA examiners (not officially, of course) who witness the firms making good faith efforts towards compliance. A firm that backs up its server daily and takes the tapes home is generally not penalized for not having WORM compliant media and not evidencing instantaneous compliance with the rules (that is, there is a gap between record creation and compliant-format storage). And that's good.

But how to plan for this sort of non-uniform enforcement? I mean, a compliance consultant like moi can't just say, "Awe, don't worry about it--your system is close enough!" Our job--I should say my job--is to help firms understand what is expected of them (i.e., rules) and help them put in place procedures that meet those expectations (i.e., compliance). It's not up to me to exempt firms from certain aspects of certain rules, where there is no official regulatory exemption. I have to promote compliance to the highest degree. But in cases like electronic storage, my job is hard.

Here is an example: SEC 240.17a-4(f)(3)(v) says, "The member, broker, or dealer, must have in place an audit system providing for accountability regarding inputting of records required to be maintained and preserved pursuant to Rules 17a-3 and 17a-4 to electronic storage media and inputting of any changes made to every original and duplicate record maintained and preserved thereby."

This little (v) is down deep in the electronic storage rules and not typically seen in exam findings. In fact, many compliance personnel and FINRA staff don't even know about this rule. Lately some firms were written up in exit conferences for lack of compliance. I did some research and had some conversations in an attempt to understand what, exactly, is expected under this rule. Here's what I can report:

  • There is no published guidance on this specific paragraph under 17a-4(f)--the audit system; that is, there is no Notice or other such wonderful distillation of FINRA or SEC expectations for compliance.
  • There is no conspiracy, in my judgment, by FINRA examiners to suddenly pick on small firms in examinations; no master plan to increase awareness of this subject by including it in every LOC henceforth. There is however--dare I say the word--inconsistency among Districts and examiners, so that you may or may not be tested for compliance with this little paragraph (v).
  • 'Audit system' appears to imply a system that keeps records of every record saved on the firm's ESM (electronic storage media). The records show the creation time and date of each record created, as well as every change made to those records. The system also must keep information on every duplicate record created/changed. This might be easy for some IT folks to understand and implement; it may be insanely impossible for non-IT minded small firms attempting to understand and implement.
  • The only thing close to an explanation of SEC's expectations for an audit system are included in their release of the final rule from 1997 (SEC Release No. 34-38245--http://sec.gov/rules/final/34-38245.txt ). Here's the paragraph:

'The Proposing Release would have required a broker-dealer to "have in place an audit system providing for accountability regarding all access to records maintained and preserved using optical storage technology and any changes made to every original and duplicate optical disk." Commenters sought clarification as to whether this provision requires maintenance of a log of all persons who have the capability or authority to access optical disks, or maintenance of a log indicating each instance where data is added to a disk. The rule adopted by the Commission today requires an audit system to be utilized only when records required to be maintained under Rule 17a-4 are being entered or when any additions to existing records are made. Therefore, an audit record is not required when a record is accessed but cannot be altered by the reader.'

So this can be interpreted--or can it?--to mean firms that have their records in truly WORM compliant format do not have to have an audit system for tracking changes to the records--duh, they can't be changed. But they do have to have a system that tracks inputting of records; some way to track at what date and time a record was created in the WORM format. And of course, the duplicate records also have to have such a tracking system.

But here's a possible contradiction... in FINRA's release of amendments to the SEC Rule, they state this: "Audit Systems: Requires the implementation and use of an audit system where required records pursuant to Rule 17a-4 are being entered or when any additions to existing records are made. No audit records will be required for records that can be accessed but not altered by the reader." That would imply that firms do not have to have audit records at all if their data is non-rewriteable. Perhaps firms should think about quoting this in their next exam, if tested. Here's the link to this text: http://www.finra.org/RulesRegulation/NoticestoMembers/1997NoticestoMembers/P004673

  • Explanations from two District staff members treat the subject this way: audit system means firms have to periodically check to see that their electronically stored records are indeed still there; that is, they should access their records once in a while to see if the records are intact. That seems simplistic to me and not in-line with the SEC's language, above. But then again, if the District staff will examine for compliance under this interpretation, it's not a difficult standard to meet.
  • On the subject of third-party ESM providers... who knows? The rule itself speaks to the member having an audit system in place: does that mean the third party provided can't run the audit system? My helpful FINRA contacts did not have an answer for this. The question must be directed to the SEC.
  • In talking to EMC squared, their systems are most likely to include such a tool, but it's not necessarily called that, which makes the subject hard to sort out.
  • On the broader topic of ESM, here's some good news (old news, but still good): SIFMA has requested that SEC amend 17a-4(f) to create a reasonableness standard for ESM compliance. Ahhhh, wouldn't that be nice? It is also pursuing changes to 17a-4(b)(4)--retention of communications. See http://www.sifma.org/regulatory/erecords/index.html for reading on the subject.
All that may not sound helpful in the way I like to be. This is not black and white: it's a lovely shade of grey. If you are unsure about whether your firm meets this 'audit system' requirement, may want to ask your IT people or third party vendor, then decide if it's worth worrying about. You may want to also call your liaison to ask what your District expects to see. To meet the rule may mean you're exceeding the expectations of your District. Or not--you may be charged with non-compliance in your next exam. The good news is, you'll be prepared to discuss the topic. Knowledge is power.


More power to you.


Thursday, January 3, 2008

Expectations Under 17a-4 for Electronic Records

Here's a summary of the Books and Records rules, as they relate to electronic storage. This is technical, so it's okay if you get sleepy reading it... but it's a nice reference for when you need it.

SEC Rule 17a-3 and 17a-4

SEC Rule 17a-3 requires broker-dealers to make certain records, including trade blotters, asset and liability ledgers, income ledgers, customer account ledgers, securities records, order tickets, trade confirmations, trial balances and various employment related documents. Rule 17a-4 specifies the manner and length of time that the records maintained by broker-dealers must be preserved. In combination, Rules 17a-3 and 17a-4 require broker-dealers to create and preserve a comprehensive record of all securities transactions the broker-dealer effects and of the securities business in general. The SEC views these requirements as the primary means of monitoring compliance with the securities laws, including anti-fraud provisions and financial responsibility standards.

Email is one of the most significant communications applications of the modern era and is no doubt a book and record under Exchange Act Rules 17a-3 and 17a-4 if it is a communication related to a broker-dealer's "business as such." The key requirements with regards to email archiving gleaned from SEC Rule 17a-4 are as follows:

SEC 240.17a-4(f)(2)(ii)(A)
"Preserve the records exclusively in a non-rewritable, non-erasable format."

SEC 240.17a-4(f)(2)(ii)(B)
"Verify automatically the quality and accuracy of the storage media recording process."

SEC 240.17a-4(f)(2)(ii)(C)
"Serialize the original and, if applicable, duplicate units of storage media, and time-date for the required period of retention the information placed on such electronic storage media."

SEC 240.17a-4(f)(2)(ii)(D)
"Have the capacity to readily download indexes and records preserved on the electronic storage media to any medium acceptable under this paragraph (f) as required by the Commission or the self-regulatory organizations of which the member, broker, or dealer is a member."

SEC 240.17a-4(f)(3)(i)
"At all times have available, for examination by the staffs of the Commission and self-regulatory organizations of which it is a member, facilities for immediate, easily readable projection or production of micrographic media or electronic storage media images and for producing easily readable images."

SEC 240.17a-4(f)(3)(ii)
"Be ready at all times to provide, and immediately provide, any facsimile enlargement which the Commission or its representatives may request."

SEC 240.17a-4(f)(3)(iii)
"Store separately from the original, a duplicate copy of the record stored on any medium acceptable under Rule 17a-4 for the time required."

SEC 240.17a-4(f)(3)(iv)
"Organize and index accurately all information maintained on both original and any duplicate storage media."

SEC 240.17a-4(f)(3)(iv)(A)
"At all times, a member, broker, or dealer must be able to have such indexes available for examination by the staffs of the Commission and the self-regulatory organizations of which the broker or dealer is a member."

SEC 240.17a-4(f)(3)(iv)(B)
"Each index must be duplicated and the duplicate copies must be stored separately from the original copy of the index."


SEC 240.17a-4(f)(3)(iv)(C)
"Original and duplicate indexes must be preserved for the time required for the indexed records."


SEC 240.17a-4(f)(3)(v)
"The member, broker, or dealer, must have in place an audit system providing for accountability regarding inputting of records required to be maintained and preserved pursuant to Rules 17a-3 and 17a-4 to electronic storage media and inputting of any changes made to every original and duplicate record maintained and preserved thereby."

SEC 240.17a-4(f)(3)(v)(A)
"At all times, a member, broker, or dealer must be able to have the results of such audit system available for examination by the staffs of the Commission and the self-regulatory organizations of which the broker or dealer is a member."

SEC 240.17a-4(f)(3)(v)(B)
"The audit results must be preserved for the time required for the audited records."

SEC 240.17a-4(f)(3)(vi)
"The member, broker, or dealer must maintain, keep current, and provide promptly upon request by the staffs of the Commission or the self-regulatory organization of which the member, broker, or broker-dealer is a member all information necessary to access records and indexes stored on the electronic storage media; or place in escrow and keep current a copy of the physical and logical file format of the electronic storage media, the field format of all different information types written on the electronic storage media and the source code, together with the appropriate documentation and information necessary to access records and indexes."

SEC 240.17a-4(f)(3)(vii)
"For every member, broker, or dealer exclusively using electronic storage media for some or all of its record preservation under this section, at least one third party (the undersigned), who has access to and the ability to download information from the member's, broker's, or dealer's electronic storage media to any acceptable medium under this section, shall file with the designated examining authority for the member, broker, or dealer the following undertakings with respect to such records."

Electronic Storage

In my ever diligent attempt to clarify FINRA’s expectations regarding electronic storage of records, I learned the new spin yesterday. A contact of mine at FINRA is the e-storage guru. He’s a nice man who shares insights with me from time to time. Yesterday we discussed, again, notification requirements—remember those? Firms have to make representations, or have their 3rd party vendors represent, that their e-storage conforms to SEC Rule 17a-4(f)(2)—that is, WORM format, quality/accuracy of media is verifiable, serialized/time-stamped, and indexed/downloadable. Also, a third party has to represent, under 17a-4(f)(3)(vii), that it can access the records and provide to regulatory authorities when requested. This is not news to you and me, although to many BD firms it’s still a mystery.

What is new is this: in the past, for instance, at FINRA conferences, panelists have discussed the issue of how long data sits on a server (in non-compliant format—i.e., it is rewritable/erasable) before it is downloaded to a compliant format for storage. There was an expectation out there that—of course—information would necessarily have to be in non-compliant format for a little while (a day for some firms, a week for others, etc.). Yesterday, my contact stated emphatically that the SEC allows for no such ‘gap.’ The information, from the moment of its creation, should conform to the standards in 17a-4(f)(2).

FINRA understands the difficulty of enforcing SEC Rules and admits that flexibility is required. But they also don’t stray from preaching the letter of the law. I can’t say whether this hard-line stance will be adopted universally by FINRA examiners—we can never really predict their preferences for findings—but it is worth noting.

One more thing: Third party storage vendors charge a lot of money, and there is the perception among some regulators that they’re ripping off BD’s—basically, they’re riding on firm paranoia and overcharging for the SEC representation letters. Some of these vendors use storage software provided by a company called EMC. It may be worth cutting out the middle man—that is, a BD may want to maintain, backup and protect its own records using EMC products, rather than relying on a third party to do it. This may be more cost effective in the end. And the good news is, the EMC product ensures instantaneous compliance--from the moment of record creation (i.e., no gap). In this case, the firm itself makes the required (f)(2) representations and gets any old 3rd party to make the (f)(3) –access—representation (an easy rep to make). We may see a movement towards this self-storage model.




Update: Talked to Iron Mountain just now. They do not consider the (f)(3)(vii) representation easy to make. They will NOT make the (f)(3)(vii) reps for their storage clients. That is, for clients who use them only to store their records--not their 'digital clients' for whom they create and maintain the records in compliant format--they will not issue a letter stating that they will provide access to those records when requested by authorities. Reason? They don't want the responsibility of producing records over which they have no control...legal cya. Their representative told me that they have some 1/2 million of those customers...when I noted that there are only little over 5,000 BD's, and that making such representations wouldn't expose them too heavily, she had no comment. Also, she admits that they never have requests from FINRA and the only federal requests are subpoenas in large-scale investigations of wrongdoing...in other words, (f)(3)(vii) is never really invoked. Which is exactly what my FINRA contact said: 99.9% of the time, these 3rd party vendors will never have to do what they're jacking their prices for.

Link to EMC, fyi:
http://www.emc.com/solutions/index.jsp?tab4