Yes, financial advisors can text clients. No regulator has ever said otherwise. What the SEC and FINRA have said - loudly, with more than $3.5 billion in fines since 2021 - is that a business text is a business record, and a business record that disappears into an advisor's personal iMessage thread is a violation no matter how harmless the message was.
That distinction should reframe the entire question. The firms that got fined were not fined for texting. They were fined for pretending they did not text while their people texted anyway, on channels nobody captured. The fix is not to ban the channel your clients clearly prefer. It is to run that channel like every other one you already supervise.
The fines were never about texting
Since 2021, regulators have collected over $3.5 billion in penalties for off-channel communications - business conversations happening on personal phones, personal messaging apps, and anywhere else the compliance archive could not reach. One 2024 sweep charged 26 firms and extracted nearly $393 million in a single action.
Read the enforcement orders and the actual messages are strikingly mundane: scheduling meetings, confirming a wire went through, market small talk. Regulators did not object to the content. They objected to the fact that when they asked for the records, the records did not exist. The channel was the violation, not the conversation.
Enforcement has moved downstream
The first wave hit the largest wirehouses, with headline penalties of $125 million or more per firm. It would have been easy to file the whole thing under problems for firms with skyscrapers. That window has closed. Later sweeps named mid-size broker-dealers, independent RIAs, and municipal advisors, and regulators have charged individuals personally - fines and suspensions attached to a specific person, not just a corporate settlement the firm absorbs.
The other pattern worth noticing: firms that self-reported their gaps and fixed them received visibly smaller penalties than peers who waited to be caught. Regulators are rewarding firms that treat this as an operational problem to solve, and punishing the ones still hoping the exam skips them. For a five-person RIA, "we are too small to be on the radar" is no longer a strategy.
The rules in plain English
Strip out the rule citations and the framework is short. This is operational guidance, not legal or compliance advice - confirm the specifics for your registration with your attorney or chief compliance officer - but the working translation goes like this:
- Business texts are books and records. If a message relates to your advisory or brokerage business - even "running 10 minutes late" for a client meeting - it must be captured the same way an email would be.
- Retention runs 3-5 years depending on registration. Broker-dealer records generally carry a three-year requirement with the first two years easily accessible; RIA books and records generally run five. Your compliance manual says which clock applies to you.
- Messages must be supervisable. Someone designated has to be able to review them - through sampling, keyword surveillance, or both. An archive nobody can search does not count.
- Personal channels are the whole problem. A client texting an advisor's personal iMessage or WhatsApp creates a record the firm cannot capture, retain, or review. That is the exact fact pattern behind the fines.
The four-part compliant setup
Every defensible texting program reduces to the same four pieces. None of them requires an enterprise budget.
- An approved business number per advisor. Each advisor texts from a texting-enabled business line the firm controls, not a personal cell. Clients save one number, every message flows through a channel you own, and when an advisor leaves, the number and the relationship history stay with the firm.
- Automatic archiving of every message. Capture happens at the platform level, both directions, timestamped, exportable - with no human step involved. Any workflow that depends on forwarding messages or screenshotting threads will fail precisely when it matters, and an examiner will not accept "we usually remembered."
- A one-page written policy. State what texting is for, which channels are approved, and the move when a client texts a personal phone anyway: reply once from the approved number, ask them to use it going forward, and capture the stray inbound message. Have everyone attest annually. One page that people follow beats forty pages nobody reads.
- Client consent. Collect opt-in during onboarding or with a first text the client confirms, and honor opt-outs immediately. Consent is both good manners and a carrier registration requirement for business texting - unregistered traffic increasingly gets filtered before it ever reaches the client.
A paper ban is the worst position available
Plenty of firms responded to the enforcement wave by prohibiting texting in the compliance manual and considering the matter closed. Then a client texts anyway, because texting is how they communicate with everyone else in their life, and the advisor replies once because ignoring a client feels worse than bending a policy. Now the firm has business records that exist but were never captured - plus a written policy proving it identified the risk and chose a ban it does not enforce.
That is the exact posture the enforcement orders describe. Most of the fined firms had prohibitions on paper; the messages flowed anyway, often including the executives who signed the policy. A good-faith program with real capture beats a strict ban with none, every time it is tested.
What still belongs in email or on a call
Compliant texting is not a license to move the whole relationship into a message thread. Text is a logistics channel: appointment confirmations, scheduling, "your documents are ready to sign", a reminder that a form is still outstanding. Short, factual, operational. Keep the substance on channels built for it:
- Recommendations and advice - anything a client could act on belongs in a documented email or a conversation, not a text bubble.
- Performance discussions - context, comparisons, and numbers need more room than 160 characters and often trigger disclosure requirements.
- Anything requiring disclosures or disclaimers - if the message needs fine print, it is not a text.
- Complaints - acknowledge briefly, then route to your compliance process immediately rather than resolving by thread.
Run that split and texting becomes the easiest compliance win available: a channel clients love, doing the low-stakes work it is best at, with every message already sitting in the archive. The firms writing nine-figure checks were not undone by scheduling texts. They were undone by scheduling texts nobody could produce.
Frequently asked questions
No. FINRA has said for years that texting is a permitted business communication as long as the firm retains and supervises the messages like any other written channel. Every major enforcement action in this area punished unarchived channels, not the act of texting itself.
Generally three years for broker-dealer books and records, with the first two easily accessible, and five years for RIA records - which is why "3-5 years depending on registration" is the common shorthand. Many firms simply keep everything for six or more years to avoid managing two clocks. Confirm your exact obligation with your compliance officer.
Only if the firm can automatically capture and retain those messages, which is rarely true for personal accounts - and personal-app conversations are precisely what drove the multibillion-dollar off-channel fines. The safer pattern is a texting-enabled business number per advisor with archiving built in.
In practice, yes. Carrier rules require registered, consent-based business texting, and documented opt-in with an easy opt-out is a core piece of a defensible program. The simplest approach is folding consent into onboarding paperwork or confirming it in the first message.