JPMorgan hit with $200M in fines for letting employees use WhatsApp
cnbc.com
cnbc.com
The messaging software used within banks (e.g. Symphony) is really awful and it is particularly bad when you're no longer able to speak to clients in person.
They should improve the messaging software they use, on top of getting everybody to do the training for the 100th time, etc.
And, frankly, it's hard to assume positive intent. These are bankers, they should know this. If they knew it and did it anyway, then yeah, I'm glad they got hit by the fine and I don't really have any sympathy for the blight of bad chat software.
Could this have the effect of actually increasing incidents of bad behavior?
Never did it make me think I could just as well front run clients with a secret account since forgetting to disclose an old account I never used was bad too. I declared late that old account and apologized instead, for instance.
I think these rules are, like all rules, also mostly to draw responsibilities in case of trouble: they do nothing to prevent a criminal to crime, but once the crime is done, he cant claim he did everything by the book if the book was so clear.
My point is that the existence of fines and non-stop training courses drilling in the correct messaging software to use to all employees doesn't end this behaviour. Do we increase the punishments or require more training courses to be taken? Will that have any effect?
I'm suggesting that if we really care about reducing impropriety we should also improve the software in use.
If this was done for malice, I agree that the fine would have minimal effect.
This also means that since financial crime most arises out of opportunity rather than genetic predisposition, this would eventually have let to it if it had not already. The fact the SEC discovered it during investigations doesn't sound very good in that regard.
And a lot of non finance people always dismiss fines because they sound small vs the whole group profit, but damn 200 mil it s a team entire year of profit and it would fuck me to hear the bank had to give it back because assholes couldnt get bothered to transcribe whatsapp into emails at the very least.
Please point me towards some examples where these types of fines actually changed how companies do business, because as far as I can tell they keep getting fined for the same things over and over again and they keep making record profits!
I can dig up examples where banks are fined hundreds of millions when they made billions. Why should I believe this is any different?
I think it can be reduced, and good software can help, but stamping it out is impossible.
Please note that this comment only refers to this rule in general, not to the specific JPM instance.
It's not like everyone is doing illegal stuff just because they can set up WhatsApp either, it's just it's been drilled in so many times, there's no excuse.
Laws don't stop people who don't know, don't understand, don't care, or some combination.
The line between personal and business isn't black and white, and broker dealers are required to neatly separate them into "things you can talk about here and nowhere else" and "things you can only talk about elsewhere and never here." Oh, and to boot, WhatsApp is encrypted, so you never know what people are talking about anyway. So, even if they are talking about personal stuff as friends, the fact that they could have been talking about business can make it a fineable offense, even though they wouldn't have been allowed to talk about it in work channels.
So, please tell me exactly why this is such an easy thing to follow.
My personal view is that the SEC just wants to ban all finance employees from ever being allowed to use encrypted messaging (9mm people in the US), which would then put pressure on Facebook to decrypt its messenger (the government's actual goal). And they know that going after places like JPM will get all the finance-hating public riled up, and ignore the fact that this is just one more example of the government trying to get more power to spy on people. Just my take.
If your friend texts you about AAPL, then you email him back or call him. The rule is pretty clear.
That being said, the rule is way behind the technology. Most people use texting in place of talking, which has different requirements (sometimes very different requirements).
Refraining from texting clients is not sufficient. You also cannot send an undocumented message to your coworker talking about how you’re going to approach a meeting with a client. But you can talk about how you think the client’s toupee is funny, unless the SEC is mad at you, then they will interpret this as a business communication and fine you. And I think it’s terrible that HN is on the side of making these terrible, vague, ‘regularly capture’ laws simply because the SEC put out a memo detailing allegations that were unlitigated in court and because big banks bad.
For the first one, the lawyers summarize it as this: “another only should you not cross the line, you should stay as far away from it possible to give the most clarity to your actions for the regulators”.
I’m afraid your completely off base on the purpose of these regulations and the interests of the SEC. Don’t feel bad or take this personally, such misunderstanding are common outside the industry, until I worked for an investment bank I didn’t know any of this either.
The purpose of the regulations is auditability and accountability. Financial institutions must record all communications pertaining to trading so that it can be scrutinised by the SEC and provided to courts in case of a dispute.
The SEC is absolutely fine with these communications being encrypted, as long as they are logged by the employer.
The SEC has no problem whatever with people in finance using Facebook for private communication that’s nothing to do with trading, where then it’s encrypted or not, because that’s entirely beyond their remit. However persons covered by the regulations may be required to provide copies of their private communications, in order to show that they were not using those channels to discuss regulated activity. They have to sign contracts affirming that they will do this if requested to.
My fine happened to be that we logged every single piece of email communication, but we used a vendor who wasn't Finra approved to do the logging. The idea that the SEC cares about logging communications is most certainly the pitch that they give for why they're doing what they're doing. But it's not reality.
These fines exist for exactly two purposes: (1) so the government can put out PR that they're totally doing their job and regulating the banks, when we all know they are just a revolving door to the banks. And (2) to create 'regulatory capture' for the banks, who will gladly fork over a few hundred million per year so long as it makes it too difficult for their competitors to navigate the regulatory landscape. As we were told, there's mostly nothing you can do to avoid the fines. They invent a new reason to fine you ever year. View it as a tax, and hope they don't raise the taxes next year.
> The SEC is absolutely fine with these communications being encrypted, as long as they are logged by the employer.
From a factual standpoint, this is just wrong. Unless you mean they log the decrypted messages. The SEC has rules about the format you must log in, and encrypted is not one of them.
So what? That doesn't take away from the credibility of the insinuation.
There is litterally zero opportunity to not know or understand. The only reason to flout the rules is if you are either stupid, hate getting paid your bonus or straight up want to be fired.
Annecdoteally, I have personally been involved with multiple firings of people for breaking these rules. Not a single one is emplyable within the finance industry as a result.
Here it feels like it became completely normal to take decision completely out of record, and with no way to trace who said what when, no way to defend themselves out of suspicion, which is why we keep records in banks in the first place.
Working in finance, in general, isn't "good user experience". Compliance manuals (reread yearly!), compliance training (e.g. anti-money laundering even for employees that have no contact with any cash, bank accounts or clients), trading oversight/restrictions, ... But people do it because it is (might be) worth the money.
"All communication must be recorded" is the least of these nuisances. People who avoid it are doing so willingly, for a reason.
Edit: Also, judging by the title, this is next level bad: JPMorgan "letting" means they knew and didn't do anything against it (e.g. fire employees or report them to the authorities). Normally the punishment for these kinds of things is severe, you can easily get "cannot ever work in finance again" by the regulator.
(1) all of your evidence comes from the prosecution side of a legal argument. None of their claims were litigated in court. And you should know better than to think lawyers defending their clients make honest accusations.
(2) there are tons of good reasons to use WhatsApp. It’s the most used digital messaging platform in the world. Are all JPM employees supposed to just cut off communication with their European friends? Never talk to anyone from a country worried about spying and thus using encrypted messaging?
It’s shocking to me how quickly smart people on HN can forget about the virtues of encrypted messaging the moment Big Brother sticks a bank with a fine and makes insinuations that they maybe could have maybe been using it to make money in an unsavory manner.
> Even the managers and senior personnel responsible for compliance used their personal devices to communicate sensitive business matters, the SEC said.
What has "don't use Whatsapp for business communication, ever!" to do with "cut off communication with their friends"?!
If you don’t want to follow this law, then don’t text your clients. It’s that simple.
Also, every client has email, which is compliant. Use that. [0]
I’ve worked in finance for years - this is a simple rule (although hard for firms to police).
https://violationtracker.goodjobsfirst.org/parent/jpmorgan-c...
"Oh, $200M? Yeah just stack it over there with the others. 'k thx bye."
my response was, paraphrased: "no, you want to know where the actually dangerous criminals are? down near wall street/broad street/beaver street".
I also wanted to give them an intentionally nonsensical answer , as the origin of their query and conversation seemed to be trending towards a racist dog whistle that I should be extremely concerned for my personal safety in the center of Harlem based on my appearance.
No matter how much we threaten disciplinary action in our handbook, people still use it, they just hide it more. Obviously we have no way of proving it, but we can see people doing it when the office is open. The financial regulator says we should use technology to reduce WhatsApp use - but given it's happening on personal phones, I'm not sure what we're supposed to do. Obviously nobody would accept company spyware on their personal phone.
Is there some solution to this issue that I'm missing?
It just makes no sense to me on the face of it. What do you do if they have a chat in the pub after work, bug the table?
Yes, it’s dumb, and your point stands.
After further reading I'm torn. This feels like regulatory overreach. The only measure I can think of is supplying a company phone and doing everything possible to encourage people to only use their personal phone for non-business work.
This is up to and including being tolerant of personal use of company phones within reason.
Otherwise, you're hosed. There's really no way to comply. Strangely enough, I'm both in favor of, but abhor this type of regulation.
Yes. White collar insider trading needs this type of draconian control to chart info flow...
Yet yeeech! It makes me want to puke. I do not envy you. Godspeed.
This also assumes life can be neatly separated into business and non-business.
Now you're looking at 3 phones. Which is why this entire drive to have records of every comm is smelling of overreach; but again, with financial crime, the only way to stamp it out is following this type of draconian paper trail practice.
I don't see a non-paimful solution here except potentially those who work in the financial sector agreeing to be bugged, and even then, if they're just going to get fined anyway...
I don't know. It just doesn't seem that hard to keep client related comms to official channels.
I worked for a BD where we had zero clients. Your rule would have gotten us fined. Trust me, it's not as easy as you think. We've spend tens of thousands on lawyers who have in-turn spend thousands of hours thinking about this topic. You nor I nor the smartest person you know could stamp this out over an HN discussion.
Obviously people use messaging software with their colleagues.
The correct solution is to design systems in which that isn't an issue. If you need to monitor what people are saying at all times then you have far bigger problems.
It's a wholly different situation if colleagues were just informally chatting with one and another but they were circumventing regulations that require talk about customers to be documented.
But I 100% agree with you, such lowly use-cases like the SEC chasing some bankers don't register on NSA's (and similar agencies') radar, it's only money, after all, I think they're more interested in dealings involving power itself.
On a related note, the major issue with the SEC as highlighted by every knowledgeable commenter is that they have a revolving door shared with the same banks and organizations they are supposed to monitor. People leave SEC and join Goldman Sachs or JPM and then when new administrators come in they rejoin the SEC. It’s corruption at an unprecedented level.
Publicly challenging them is not illegal or even bad so that seems reasonable.
This will eventually be the starting point of a very slow reform at Tesla, so not a bad deal.
It's a large organization, sure, but at this point one has to ask just how much they "wouldn't encourage it" or how much do they actually institutionally discourage it.
And that's just revenue. If the profit margin on your deals was 20% (pretty whopping for banking services) you'd need to bring in 10bn in revenue. That would mean doing maybe $1tn worth of deals.
Its really clear that he is coordinating this and making it more likely to stick by splitting each cattle prod between the agencies.
That market participants don't know how far an agency can go is equivalent to Israel's nuclear policy, little bit of ambiguity and uncertainty has a deterrent effect. And if anything given how routinely market participants still abuse every little trick they can regulators aren't scary scary enough.
And no offense but you've got "fintech, commodities and digital assets" in your bio, are you by any chance making money off some underregulated crypto scheme and have been at the receiving end of regulatory action?
I’ve felt similarly about these agencies long before I brushed against their purview