SEC Charges 16 Wall Street Firms with Widespread Recordkeeping Failures
sec.gov
sec.gov
> As technology changes, lots of forms of written electronic communication become substitutes not for memoranda, but for face-to-face conversation. So the SEC’s requirements constantly become broader. If you just talk to your colleagues in person, the SEC does not expect you to preserve that. Once you move that chat to WhatsApp, it does.
If Microsoft develops a building-wide speech to text device will it be required to be installed?
Emails & chats are easier to NLP/search/flag. Drop an f-bomb, or use a word like "scam" in chat casually ("that f-bomb dinner last night was a rip-off, what a scam!") is 100% going to get auto-flagged and reviewed by compliance and/or your boss. Saying that verbally on the phone is not, because the tech isn't there to transcribe and auto-flag calls.
Recorded calls are more kept in evidence to produce in the event of an investigation triggered by something else. So a lot of senior people end up nudging conversations to the phone. They don't plan to do any crimes, and they certainly don't plan to get caught.
The next level is that for a lot of senior people, they operate almost entirely in the in-person verbal realm. There are no rules requiring any recording or record keeping of verbal discussions/meetings/etc, and implementing them would be hard if there were.
This is why in big cases, its always some low level guy or middle manager who goes down for the "crime", because they are the most senior person involved in the activity to actually commit any of it to writing. 1000% his boss, and his bosses boss were aware / in on it / even ordering the activity to happen.. they just never put that down anywhere..
Examples of this are the LIBOR "London Whale" scandal, some of the "rogue traders" like at SocGen, "Fabulous Fab", and many more.
I bet at most banks once you hit the MD level, the vast majority of outgoing emails you would see going out are simple one-word "yes/no/approved" or variations of "lets discuss offline / call me / lets meet about this". And 0.0% of them use any chat apps at work.
WhatsApp is a thorny issue because most places stopped giving out work devices but make you download all the work apps. You develop personal friendships with coworkers and feel that out-of-hours non-work chat should happen in places like WhatsApp. Sometimes innocently out of laziness, some people end up commingling a bit. A minority of cases you'll have guys actually using private apps to evade monitoring. No one wants their personal messaging off their personal devices being recorded by their workplace. Maybe the right outcome here is mandatory personal & work device segregation, companies issue "work phones" and thats the end of it.
"Congratulations" on typed chat, phone call to boss within 3 minutes, and required a written report to senior senior management. There was unironic suggestions of doctors notes when the reason for the congratulations was their wife had just had their first kid.
> places stopped giving out work devices but make you download all the work apps
Havent come across this before, work issued device only, all calls and messages were recorded and preserved for 7 years. Installing any chat apps on the phone; sackable offence. Giving your personal phone number in any business context; sackable offence. Making a work related call from anything other than your mobile phone / recorded office line; sackable offence.
> they operate almost entirely in the in-person verbal realm
Inevitable really - and if you wanted any actual response from management, stick your head in their office and ask. If it goes tits up, you are on your own though as inevitably they "dont recall" that conversation.
I can highly reccomend - The Lowball Tapes - The secret tapes the authorities, on both sides of the Atlantic, wouldn’t want you to hear, that could upend the official version of the biggest scandal since the financial crash. https://www.bbc.co.uk/programmes/m0014x77
In US it's become the norm to not issue work device hardware anymore sadly. Some people didn't like carrying 2 devices, and firms like saving $$ so win-win. Nonetheless, I got a few compliance pings when WFH and giving my phone # over work chat to someone to call me.
> Inevitable really - and if you wanted any actual response from management, stick your head in their office and ask. If it goes tits up, you are on your own though as inevitably they "dont recall" that conversation.
Precisely. I worked for a guy who had a particularly egregiously offensive boss. The big boss would claim to not have read emails, saying "you have to talk to me, you can't just send me an email, how do you know I've read it?" but then when they did things verbally, the guy would be like "I don't recall that conversation, you need to email me". Basically lol nothing matters. Dude got himself a C-suite gig at a competitor, but made sure to fire my boss on his way out because he was a small spiteful man.
Story old as time. Probably sold them on all those deals they made happen by being all over everything.
Just to balance it out - I have seen some people write some utterly stupid shit and get away with it (as well as contact list with plenty of people who have been fired for these sorts of things). "We need to keep compliance from finding out about this as it is against the rules" being top of my list of how did they keep their jobs.
I might be dense, what's the issue with congratulating someone? It can of course be for something untoward, but there are surely a lot more valid reasons for giving coworkers props ("congratulations on the promotion", "congratulations on your good work on project X", etc).
Champagne was a banned word as well. "I'll get the Champagne" in particular would see you sent to the Break Room for re-education. Shampoo and eventually derivatives of liquid with bubbles was also added to the list as creative traders mocked the system.
One phrase the Goldman software searched for: “How could this happen again?” https://www.cnbc.com/2016/06/15/you-wont-believe-what-gets-a... The general lists are pretty tame - mid 2010's were pretty wild as all this stuff was coming in.
Savvy Goldman types have long favoured the nifty acronym LDL – let’s discuss live – as a way of avoiding writing the wrong things down. https://archive.nytimes.com/opinionator.blogs.nytimes.com/20...
You have things like false alarms when acronyms start to overlap, like PA being "personal assistant" and "personal account".
And then stuff like Egol using "LDL" to take his conversations with his subordinate, Fabulous Fab off electronic form.
Fab ends up guilty of fraud, paying fines, and kicked out of industry to go work in academia.
Egol, who was his senior, and nearly a decade older so been through a few economic cycles.. stayed on with the firm 6 more years and then moved on up in the industry.
(although I wouldn’t be surprised if msft keeps a copy still because of this reason)
Having said that, there's no allegation or evidence given that these side channels were used particularly or mainly to hide illegal activity. Using official communications systems can be clunky and inconvenient, and it's also possible this was done more to hide activity from potential rivals within the organisation than from regulators, although I'm sure that happened too. We don't really know.
I think people on "the outside" completely underestimate how true this is. If you've never worked at a 100K employee firm, and especially a bank.. its unimaginable. It sets up a lot of weird incentives, particularly for some rules/processes to seem very arbitrary and rigid. This is because the sample size is so big, they end up worrying about the worst thing the worst person could do.
Inevitably this leads to backdoors and side channels to work around the standard processes because these processes make doing your job insufferably more difficult.
For years we had chat apps which were horribly slow on desktop and had no mobile app, while we all had iPhones/Androids in our pockets.
An anecdote would be that at one bank I worked, releasing a new version of our application required filling out a change request form. This form was a desktop app which was multi-page, multi-tab, with pop-up modals. There were radio buttons, checkboxes, drop down selectors, and free form text fields. Once certain parts were completed, you couldn't go back and correct them if wrong and had to start again. We had 1-2 out of 20 devs good at filling out the form, and it took 45 minutes. We then had to chase 5+ MD-level (don't read email / chat / etc) to click the approve button between then & when we wanted to release. We budgeted a week to chase these guys. Again if we failed to get approvals it went back to square 0 and start over on the form again.
I've spent 20+ years with various banks and it is obvious when i read comments about "banks" those writing have near-zero experience.
Expanding on the change control for just a second.
Imagine that one arm of the bank (Say ATM's) only releases updates once per year and so they can spend days filling out the CR's, chasing approvals, etc.
Their change is also very visible outside the bank and needs to be carefully vetted. They then create "processes and controls" around this.
Now, imagine working for "Capital Markets" where you need to update your system constantly to stay competitive, but also have the banks change process enforced on you?
You need change management, but the banks processes are overwhelming and inflexible...
This "one size does not fit all" pattern is very common in Banks (i would imagine in any large org?).
We live in a pretend society.
These types of fines are so the SEC can pretend that they're not a worthless sack of shit.
I've been on the receiving end of compliance rules around various communications (for example being forbidden from ever writing "ISO" because it's a heavily regulated but also exceptionally important order type) that did nothing to protect markets, other participants, or the firm I was working at.
My experience with various financial regulators was that they were far more interested in finding ways to slap someone with some random rule violation as opposed to meaningfully trying to protect consumers/markets, so if the most the SEC can come up is that there were record keeping violations I wouldn't read too much into it.
This is mostly an outdated and now probably overreaching law, written in 1948 when most conversations happened face to face and written memos were more significant/official. An employee using Whatsapp to ask if someone wants to get a drink after work or talk about last night's basketball game isn't exactly sinister, but the interpretation is that all of that needs to be done on the recorded, audited channels.
They could still just talk face to face if they wanted to coordinate crimes, the SEC isn't making every bank employee wear a microphone yet.
There wouldn't be. That's the entire point of using chat.
> They could still just talk face to face if they wanted to coordinate crimes, the SEC isn't making every bank employee wear a microphone yet.
Of course they could. We can at least keep corruption moderately inconvenient.
Given what we know about insider trading on Wall Street (and LIBOR etc), most likely there was a lof of incriminating discussions. And there does seem to be some evidence in the case of Nomura.
https://dealbreaker.com/2022/09/make-sure-to-delete-that-inc...
"The head of a trading desk routinely directed traders to delete messages on personal devices and to use Signal, including during the CFTC's probe."
1000% this was done in-person, not in any electronic medium Probably by telling his right-hand-man or sub-heads who then distributed the message in-person, non-electronically as well
I once worked on a phone app which would give internal users the ability to make certain transactions while away from the desk. It was the mobile version of something they had on their work PC.
Compliance's concern was it could be used while overseas where subject to other regulators. It was pointed out to compliance that these same users were using these same phones to make voice calls to execute the same transactions, for decades.
Having to enter the information in electronically rather than over a phone call is demonstrably better from a record keeping & being compliant perspective. It turned into a case of bringing existing practices more "into the light" was actually considered worse than the status quo.
1)In a way I don't blame them - I have trouble myself keep records lol. Though it's a giant company they should have systems in place
2)I never understood this "fine" stuff - so did they solve the problem or what?