Banks, brokerages dogged by e-mail regulations
The securities industry faces a growing number of mandates
June 29, 2004 12:00 PM ETComputerworld -
NEW YORK -- IT managers in the financial services industry are finding it increasingly difficult to comply with a swath of regulations that force banks and brokerages to store and be able to easily access e-mail and instant messaging (IM) exchanges with customers.
The Securities and Exchange Commission, the New York Stock Exchange and the National Association of Securities Dealers have all recently imposed regulations about the type of information broker/dealers can share with clients via e-mail or IM -- as well as how long those messages must be stored so they can be retrieved for regulatory audits. Those regulations have created "a poisonous atmosphere" in the securities industry, said Stephen J. Shine, senior vice president and senior counsel at Prudential Equity Group LLC in Newark, N.J.
It's also a potentially costly problem for firms that don't comply. The most notable enforcement actions were taken in December 2002, when the SEC fined five broker/dealers a total of $8.25 million for failing to preserve e-mail correspondence with clients for the requisite three years and/or failing to keep the e-mails in an accessible place for at least two years (see story).
Shine was one of the speakers at a financial services e-mail, IM and collaboration conference held here today by the Information Management Network, a New York-based organizer of finance and investment conferences.
Brokerages frequently automate and test backup and recovery of e-mail and IM, but those efforts are probably not done "consistently enough to meet regulatory requirements," said Andy W. Welch, a senior manager in KPMG LLP's risk advisory practice in Short Hills, N.J.
One of the key challenges securities firms face is being able to retrieve and present customer e-mail correspondence to regulators within 24 hours, as required under some regulations. "Regardless of how sophisticated your e-mail retrieval system is, you won't be able to comply by tomorrow," said Shine.
He recommended several steps securities firms should take to "intervene" with regulators, such as asking for adequate time to review e-mail correspondence using word searches, to determine whether any of the requested correspondence might impinge upon attorney/client privilege.
Regulators at the Federal Deposit Insurance Co. in Washington, which insures deposits at 9,116 U.S. banks, are also concerned about the potential network vulnerabilities created when bank employees use IM and how hackers might be able to infiltrate a bank's network to steal customer identities. Attempts by banks to secure IM exchanges using a firewall so far have proved to be "very difficult," said Kathryn M. Weatherby, an examination specialist in the
Networking
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
CIO Viewpoints: Exchange 2007 Risks and Mitigation Strategies
Download This Whitepaper Today!
Key Strategies for Managing Data Growth
What are you storage challenges?
Applying Remote Support Technology for Maximum Impact
Download Now!
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
IBM Migration Factory: A smooth transition to new technology
Find out how to migrate your applications smoothly over to IBM.
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Natural User Interface for Enterprise Applications
Download this Complimentary White Paper! Provided by Workday.
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
Download this Complimentary White Paper! Provided by Workday.
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
