The rise of disappearing messages is creating a compliance headache that financial services firms can no longer afford to ignore, according to new research from MCO (MyComplianceOffice).
Apps such as WhatsApp, Signal, Telegram and WeChat, which let messages auto-delete after being viewed, are now used by more than three billion people worldwide, with WhatsApp alone accounting for two billion active users. MCO warns that this widespread adoption means regulated firms must assume employees are already using these channels for business purposes, whether sanctioned or not.
The risk lies in the gap between how these apps are built and what regulators demand. Financial firms are required to retain and produce all business-related communications on request, yet ephemeral messaging is designed to leave no lasting record. MCO notes that even ostensibly permanent platforms such as Microsoft Teams and Slack carry configurable retention settings that, left unmanaged, can quietly delete messages too early.
Regulators have been blunt about where responsibility sits. Assistant attorney general Kenneth A. Polite Jr. said in a keynote address to the ABA’s 38th Annual National Institute on White Collar Crime, “If a firm has not produced communications from these third-party messaging applications, our prosecutors will not accept that at face value. They’ll ask about the firm’s ability to access such communications, whether they are stored on corporate devices or servers, as well as applicable privacy and local laws, among other things. A firm’s answers – or lack of answers – may very well affect the offer it receives to resolve criminal liability. So when crisis hits, let this be top of mind.”
MCO points out that while sweeping SEC enforcement actions on books and records violations may be less frequent under the current administration, this does not remove the underlying obligation. Regulators still expect defensible retention processes, and employee communications remain central evidence in investigations and litigation.
To manage the risk, MCO recommends firms adopt clear, risk-based policies covering bring-your-own-device use, train staff and document their understanding, deploy surveillance technology to capture off-channel activity, disable auto-delete features on licensed platforms and, where appropriate, prohibit unauthorised apps outright.
MCO’s own tools, including eComms Keep and eComms Review, are designed to help firms capture and archive ephemeral communications in tamper-evident formats while giving compliance teams the ability to search and monitor activity across channels, supporting audit readiness and reducing exposure to regulatory and legal risk.
For more insights, read the full story here.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





