Popular on TelAve
- WADA AWARDS - where Diamonds melt into glamour
- Rep. Gina H. Curry and Dr. Conan Tu Inspire at Kopp Foundation for Diabetes Hybrid Fundraising Gala and National Leadership Forum
- "Super Leftist", the new poetry book by Pierre Gervois
- Cracking the Code of AGI: Phinge to Solve AGI With Netverse Patented, App-less Integrated Verified Platform & Technologies Through its Hardware
- Frost Locker: New Research Reveals Mild Cold—Not Extreme Cold—Delivers Real Health Benefits of Cold Therapy
- Mullins McLeod Surges Into SC Governor's Race with $1.4 Million Raised in First Quarter; Most from His Own Commitment, Not Political Pockets
- New Article Reveals Common Pricing Pitfalls in Flooring Projects — And How to Avoid Them
- Milwaukee Job Corps Center: Essential Workforce Training—Admissions Now Open
- Phinge Effect: How Billions in VC Funding Could Shift From Current Tech, AI & App-Store Developers to Fund Third-Party Platform Developers on Netverse
- $73.6 Million Multi-Year Backlog and Florida State Term Contract Drive Momentum for AI-Cybersecurity Pioneer: Cycurion, Inc. (N A S D A Q: CYCU) $CYCU
Similar on TelAve
- Arnica Unveils "Arnie AI" to Secure the Future of AI-Driven Software Development
- How to Optimize Your Website for AI Search with DeepRank AI
- DeployHub Joins Catalyst Campus SDA TAP Lab
- Wzzph Deploys 5-Million-TPS Trading Engine with Hot-Cold Wallet Architecture Serving 500,000 Active Users Across Latin America
- Offline Asset Protection: NJTRX Implements 98 Percent Cold Storage as Industry Faces 2 Billion USD Losses
- PatientNow Acquires Recura, the AI Growth Engine Powering Practice Growth
- Engaged at Any Age: 73-Year-Old Client Finds True Love Through Elite Asian Matchmaker
- He Started a New Career at 77; Maybe Not His Last
- Wzzph Provides Stablecoin Trading Solutions for Latin American Traders Amid Digital Currency Policy Adjustments
- Bitcoin at $115K: AZETHIO Launches Exchange Targeting Institutional Compliance Requirements
Six Features a D3P Needs to Make the Cloud 17a-4 Compliant
TelAve News/10665293
FINRA now allows member firms to use the cloud but cloud providers will not act as your designated third party (D3P). So firms need to outsource to a D3P with six key features built into their software before moving to the cloud.
NEW YORK - TelAve -- FINRA now allows member firms to use the cloud to store electronic records and emails, however if you are a compliance officer and have done your homework, you have noticed that cloud providers will not act as your designated third party (D3P). Reason being, they can't guarantee data stored with them will be retained for 7 years. In other words, they can't prevent anyone from deleting anything from their cloud account at anytime – a big no-no for regulators. Especially when they show up for the electronic records request during the audit and see huge gaps in your data archive. Therefore, if you are a FINRA firm, such as a broker-dealer, RIA or any other registered firm and want to use the cloud you need to find a D3P that will connect into it and make it 17a-4 compliant.
Here are six things you should look for in a D3P to help you make the cloud 17a-4 compliant.
1. Direct Cloud Connector:
The first thing firms need in a cloud D3P provider is a connector built into their software that logs directly into all popular cloud services and archives data. Furthermore, this connector will copy data seamlessly to their system, automatically each night as opposed to using a sync tool to access the cloud. The sync tool is a problem because it adds an extra step to the cloud archiving process which may end up causing gaps.
Similarly, when choosing a cloud provider avoid the less popular ones such as ShareFile, SugarSync or iCloud because they are proprietary and don't allow direct connections with cloud archiving services. Instead use Office 365, Dropbox, Google Suite or OneDrive. However, for small firms I don't recommend SharePoint for file storage because its too complex. The best cloud storage combinations are Office 365 hosted email with OneDrive or the G Suite email including electronic records stored in google personal drives or team drives.
2. Automatic Detection of New Cloud Data:
Also, the D3P's software must automatically detect new cloud data sets as they are created. For example, as the firm adds new users in Office 365, SharePoint, or OneDrive sites, its automatically added to the 17a-4 archive. This applies to G Suite as well where user accounts are frequently added including their personal or team drives. If the D3P has automatic detection, they don't need to be notified every time new employees are added to the cloud.
More on TelAve News
3. Electronic Records Retention:
Once the provider has the cloud data transferred to their system, it must be retained properly as per 17a-4. Now, here is where it gets dicey because if you've actually read the rule, you'll find an overly complicated laundry list of retention stipulations. For example, the rule states that exception reports must be kept at least 18 months, order tickets 3 years, records relating to customer accounts (first two years in an easily accessible place); for 6 years or default 6-year retention period for those FINRA books and records that don't otherwise have a specified retention period.
My advice: Ignore the rule here and simply ensure the D3P applies a 7-year blanket retention rule to ALL data relating to the business. With this policy you're done separating different data types then trying to apply a unique retention policy to each set, which is impossible to maintain, especially for a small firm without an IT dept.
4. Downloading Data:
At the end of the day, the reason you hire a D3P at all is to access archived electronic records or emails when needed. Aside from disaster recovery, the main reason you need a D3P is during the electronic records request when FINRA asks for a sample data set that can go back seven years.
First, its important the D3P has a secure Web portal to access the 17a-4 data archive. What's key here is data must be downloadable in a format regulators can read, especially when they are breathing down your neck during the audit. Here are the guidelines: emails must be downloadable in pst format, office docs in their native format, and customer data bases should be exported in file formats that can be accessed such a csv or text. Finally, these electronic record downloads from the 17a-4 archive must be copied instantly to a DVD so the regulator can take it back to their office for review.
Secondly, the D3P must retain cloud data for users that have been removed and keep them in an archive state so they can be retrieved. This includes Office 365 mailboxes or G suite users that have been removed and OneDrive sites or Dropbox accounts that get deleted. Keeping electronic records from users that have been removed from the cloud will also help with compliance since old employee data is often requested during audits.
5. Security:
Of course, security is something firms need to worry about every time they make a change in their technology, and the compliance officer will surely get called in if data is compromised. But, security breaches rarely occur on the D3P's end. This is because they host their systems in secure data centers that are locked down, protected by firewalls, and monitored closely. Instead, most hackers launch their attacks from the end user's PC. What this means is compliance officers that are concerned with protecting electronic records to meet 17a-4 need to understand that hackers will try to exploit systems from inside the office. Therefore, the best defence against security threats is strong passwords, understanding how to limit administrator rights to cloud systems, locking or logging off computers that have access to the cloud and keeping virus programs up to date to prevent people from downloading malicious malware that will hack into cloud systems.
More on TelAve News
6. Pricing:
Finally, when choosing a D3P to archive your cloud data, its important their price structure is based on raw data, not per user license. You want to find one that uses raw data only pricing because it will be cheaper to archive cloud data backup sets since products like Dropbox, G Suite and Office 365 are based on individual user accounts that can increase exponentially as the firm grows but contain little data. Having pricing based on raw data amounts will average out the cost across all cloud users no matter how many you add, therefore the price will only increase as more data is added. Thus, giving your firm more flexibility to control data archiving costs as you grow.
Summary:
Since cloud providers are not 17a-4 compliant as a compliance officer for a FINRA firm you need to outsource to a designated third party (D3P) that can make the cloud compliant before you begin storing electronic records and emails there. There are six things you need to look for in a D3P that will ensure no gaps appear in the data archiving process, that electronic records can be accessed during an audit, and costs are kept low as possible.
About AdvisorVault:
AdvisorVault is the only D3P that has designed their software to help small FINRA firms archive cloud data to meet 17a-4 - focusing on solving this unique problem, our consolidated solution gives firms one vendor to help them satisfy today's demands surrounding data archiving and supervision. We have created a centralized archiving option that captures data and emails no matter where they are stored - in-house or in the cloud: total peace of mind - out of the box.
AdvisorVault Contact:
Allan Lonz, President
alonz@advisorvault.org
www.advisorvault.org
Direct: 416-985-0310
Toll-free: 1-866-732-1407 ex 1
Here are six things you should look for in a D3P to help you make the cloud 17a-4 compliant.
1. Direct Cloud Connector:
The first thing firms need in a cloud D3P provider is a connector built into their software that logs directly into all popular cloud services and archives data. Furthermore, this connector will copy data seamlessly to their system, automatically each night as opposed to using a sync tool to access the cloud. The sync tool is a problem because it adds an extra step to the cloud archiving process which may end up causing gaps.
Similarly, when choosing a cloud provider avoid the less popular ones such as ShareFile, SugarSync or iCloud because they are proprietary and don't allow direct connections with cloud archiving services. Instead use Office 365, Dropbox, Google Suite or OneDrive. However, for small firms I don't recommend SharePoint for file storage because its too complex. The best cloud storage combinations are Office 365 hosted email with OneDrive or the G Suite email including electronic records stored in google personal drives or team drives.
2. Automatic Detection of New Cloud Data:
Also, the D3P's software must automatically detect new cloud data sets as they are created. For example, as the firm adds new users in Office 365, SharePoint, or OneDrive sites, its automatically added to the 17a-4 archive. This applies to G Suite as well where user accounts are frequently added including their personal or team drives. If the D3P has automatic detection, they don't need to be notified every time new employees are added to the cloud.
More on TelAve News
- POWER SOLUTIONS N.V. Partners with ENERGY33 LLC to Deliver a 40.5 MW Temporary Power Project for ECUACORRIENTE S.A. in Ecuador
- Indiana and Starlink Local Installers working in tandem
- Pioneering the Future of Human-Computer Interaction Through AI-Powered Neural Input Technology: Wearable Devices Ltd. (N A S D A Q: WLDS)
- Epic Pictures Group Sets North American Release Date for the Action Thriller LOST HORIZON
- HR Soul Consulting Recognized as a 2025 Inc. Power Partner Award Winner for the Fourth Consecutive Year
3. Electronic Records Retention:
Once the provider has the cloud data transferred to their system, it must be retained properly as per 17a-4. Now, here is where it gets dicey because if you've actually read the rule, you'll find an overly complicated laundry list of retention stipulations. For example, the rule states that exception reports must be kept at least 18 months, order tickets 3 years, records relating to customer accounts (first two years in an easily accessible place); for 6 years or default 6-year retention period for those FINRA books and records that don't otherwise have a specified retention period.
My advice: Ignore the rule here and simply ensure the D3P applies a 7-year blanket retention rule to ALL data relating to the business. With this policy you're done separating different data types then trying to apply a unique retention policy to each set, which is impossible to maintain, especially for a small firm without an IT dept.
4. Downloading Data:
At the end of the day, the reason you hire a D3P at all is to access archived electronic records or emails when needed. Aside from disaster recovery, the main reason you need a D3P is during the electronic records request when FINRA asks for a sample data set that can go back seven years.
First, its important the D3P has a secure Web portal to access the 17a-4 data archive. What's key here is data must be downloadable in a format regulators can read, especially when they are breathing down your neck during the audit. Here are the guidelines: emails must be downloadable in pst format, office docs in their native format, and customer data bases should be exported in file formats that can be accessed such a csv or text. Finally, these electronic record downloads from the 17a-4 archive must be copied instantly to a DVD so the regulator can take it back to their office for review.
Secondly, the D3P must retain cloud data for users that have been removed and keep them in an archive state so they can be retrieved. This includes Office 365 mailboxes or G suite users that have been removed and OneDrive sites or Dropbox accounts that get deleted. Keeping electronic records from users that have been removed from the cloud will also help with compliance since old employee data is often requested during audits.
5. Security:
Of course, security is something firms need to worry about every time they make a change in their technology, and the compliance officer will surely get called in if data is compromised. But, security breaches rarely occur on the D3P's end. This is because they host their systems in secure data centers that are locked down, protected by firewalls, and monitored closely. Instead, most hackers launch their attacks from the end user's PC. What this means is compliance officers that are concerned with protecting electronic records to meet 17a-4 need to understand that hackers will try to exploit systems from inside the office. Therefore, the best defence against security threats is strong passwords, understanding how to limit administrator rights to cloud systems, locking or logging off computers that have access to the cloud and keeping virus programs up to date to prevent people from downloading malicious malware that will hack into cloud systems.
More on TelAve News
- Brazil 021 Chicago Launches New Website and Expands with No-Gi Classes for All Levels
- American Star Guard Unveils a Powerful Rebrand and Expanded Security Services Throughout Nevada
- PlaceBased Media Expands Point-of-Care Advertising Inventory Across U.S. Clinic Network
- Flexible Plan Investments launches FlexDirex, a first-to-market suite of single-stock ETF strategies in the U.S
- How AI is Exposing Major Flaws in the Foundation & Structure of Technology, Hardware & the Internet & Phinge's Patented Netverse, App-less Solution
6. Pricing:
Finally, when choosing a D3P to archive your cloud data, its important their price structure is based on raw data, not per user license. You want to find one that uses raw data only pricing because it will be cheaper to archive cloud data backup sets since products like Dropbox, G Suite and Office 365 are based on individual user accounts that can increase exponentially as the firm grows but contain little data. Having pricing based on raw data amounts will average out the cost across all cloud users no matter how many you add, therefore the price will only increase as more data is added. Thus, giving your firm more flexibility to control data archiving costs as you grow.
Summary:
Since cloud providers are not 17a-4 compliant as a compliance officer for a FINRA firm you need to outsource to a designated third party (D3P) that can make the cloud compliant before you begin storing electronic records and emails there. There are six things you need to look for in a D3P that will ensure no gaps appear in the data archiving process, that electronic records can be accessed during an audit, and costs are kept low as possible.
About AdvisorVault:
AdvisorVault is the only D3P that has designed their software to help small FINRA firms archive cloud data to meet 17a-4 - focusing on solving this unique problem, our consolidated solution gives firms one vendor to help them satisfy today's demands surrounding data archiving and supervision. We have created a centralized archiving option that captures data and emails no matter where they are stored - in-house or in the cloud: total peace of mind - out of the box.
AdvisorVault Contact:
Allan Lonz, President
alonz@advisorvault.org
www.advisorvault.org
Direct: 416-985-0310
Toll-free: 1-866-732-1407 ex 1
Source: AdvisorVault
0 Comments
Latest on TelAve News
- $430 Million 2026 Revenue Forecast; 26% Organic Growth; $500,000 Stock Dividend Highlight a Powerful AI & Digital Transformation Story: IQSTEL $IQST
- Wzzph Deploys 5-Million-TPS Trading Engine with Hot-Cold Wallet Architecture Serving 500,000 Active Users Across Latin America
- Preston Dermatology & Skin Surgery Center and Dr. Sheel Desai Solomon Dominate Raleigh's Best Awards from The News & Observer
- $73.6 Million Multi-Year Backlog and Florida State Term Contract Drive Momentum for AI-Cybersecurity Pioneer: Cycurion, Inc. (N A S D A Q: CYCU) $CYCU
- Year-Round Deals for Customers With Square Signs
- SecurePII Raises US$3.5M (A$5M) to Unlock AI and Compliance for Voice Data and Expands Global Presence
- Peter Coe Verbica Stands with Rural Families and Horse Owners: "Keep Horses Classified as Livestock"
- The Mobile-First Company Raises $12M to Build Simple, Powerful Software for Small Teams
- Lick Pineapple Flavored Massage Oil Outperforming and Enticing
- Cerberus ODC in Collaboration with NVIDIA Launches All-American AI-RAN Stack, Enabling AI-Native 5G Today and Accelerating the Path to 6G
- National Compliance Firm issues Artificial Intelligence Policy Program for Mortgage Banking
- Pastor Darrell Armstrong Suspends Gubernatorial Campaign And Endorses Mikie Sherrill
- Dr. Johnny Shanks Attends Full Arch Growth Conference 2025
- Offline Asset Protection: NJTRX Implements 98 Percent Cold Storage as Industry Faces 2 Billion USD Losses
- Thousands of Smiles, Millions of Logo Views: RoarFun Brings Emotions Into Premium Retail Spaces with Formula Simulator for Immersive Brand Activation
- Qvarz LLC Expands Global Reach with High-Precision Quartz Cuvettes and Optical Components
- $300 Million Web3 Initiative and ZIGChain Partnership Power $20 Target in Noble Capital Markets Report for SEGG Media (N A S D A Q: SEGG)
- Assent Recognizes Manufacturers for Leading Supply Chain Sustainability Programs
- Arc Longevity Sells Out Debut Women's Creatine Gummy
- Frost Locker: New Research Reveals Mild Cold—Not Extreme Cold—Delivers Real Health Benefits of Cold Therapy