8 Financial services archive storage carries obligations that most enterprise storage never faces. Banks, broker-dealers, asset managers and insurers must keep communications, trade records, customer documents and audit evidence for years, sometimes decades, in forms regulators accept as tamper-proof. They must find specific records quickly when supervisors or courts ask, place holds that override deletion and prove that nothing was altered. The volumes are large and growing, from email and chat to voice recordings and trade data, and the rules differ across the US, Europe, the UK and Asia. This article explains what regulatory archives contain, the regulatory requirements that shape storage in major regions, the storage capabilities banks look for and how to design an archive platform that scales. It is general information, not legal advice; institutions should confirm requirements with their compliance and legal teams. What a bank’s regulatory archive contains Electronic communications: email, instant messaging, collaboration platforms and, increasingly, mobile messaging. Voice recordings: trader turrets, mobile calls and contact center calls. Trade and transaction records: orders, executions, confirmations and reports. Customer records: account opening, know-your-customer files and correspondence. Financial and audit records: ledgers, reports, audit workpapers and evidence. Application archives: data from retired systems retained for regulatory reasons. Many of these sit in separate archiving applications, each with its own storage, which is one reason institutions look to consolidate onto a shared archive platform. Regulatory requirements by region United States SEC Rule 17a-4 requires broker-dealers to preserve specified records for defined periods, many for three or six years, with the first two years easily accessible. Electronic records must be kept either in a non-rewriteable, non-erasable format, commonly called WORM, or, since amendments adopted in 2022, in a system that maintains a complete time-stamped audit trail of modifications and deletions. FINRA rules and CFTC recordkeeping rules for futures and swaps add further requirements, including retention for swap records through the life of the swap and beyond. European Union MiFID II requires investment firms to record telephone conversations and electronic communications relating to transactions and to keep them for five years, extendable to seven at the request of the competent authority. GDPR applies to personal data in archives, requiring retention to be justified and data to be protected. DORA adds ICT risk management and resilience obligations for financial entities, including backup and recovery. United Kingdom The FCA’s recording requirements broadly mirror MiFID II, generally requiring records to be kept for five years and up to seven if the FCA requests. UK GDPR governs personal data. Asia-Pacific and Middle East Regulators in Japan, Singapore, Hong Kong, the UAE and elsewhere set their own record-keeping and outsourcing rules, often including expectations about data location, access by supervisors and resilience. Many institutions keep regulated archives in-country to simplify compliance. Storage capabilities banks look for Immutability or audit trail Regulated records must be protected from alteration and early deletion. Object lock in compliance mode provides WORM retention that even administrators cannot override. Independent assessments of a storage platform’s WORM capabilities against SEC 17a-4 and related rules are commonly requested by compliance teams. Retention management Different record types have different retention periods, and periods can vary by jurisdiction. Storage and archiving applications must apply retention per record or per category and expire records when retention ends. Legal holds Litigation, investigations and regulatory inquiries require holds that suspend deletion for specific records until released, regardless of retention dates. Search and retrieval Regulators and courts expect timely production. The archiving application provides search and eDiscovery; storage must deliver records quickly, including for large productions. Durability and resilience Archives must survive hardware failure and site loss. That means erasure coding within a site and copies at a second site, with tested recovery. Security and access control Archives hold highly sensitive data. Encryption, strict access control, separation of duties and audit logging are essential. Data residency Many institutions must keep certain records within specific countries, or must be able to show regulators exactly where data resides. Scale and cost Communications archives grow quickly, especially with voice, video and collaboration data. Storage must scale to petabytes at a sustainable cost per terabyte, for retention periods that outlast hardware generations. Architecture: consolidating archives Many banks run multiple archiving applications for email, voice, trade data and documents, each with dedicated storage. Consolidating the storage layer onto a single S3-compatible object storage platform, while keeping specialized applications on top, reduces cost, simplifies retention and immutability and makes resilience consistent. Each application uses its own buckets and policies, with object lock where required. New communication channels keep arriving Regulators have made clear that record-keeping obligations follow the business, not the channel. Enforcement actions in recent years over the use of unapproved messaging apps by staff have pushed firms to capture more channels, including mobile messaging, collaboration platform chats, meeting recordings and transcripts. Each new channel adds volume and new formats to the archive. Video meeting recordings in particular can be far larger than email. Storage plans should assume that the set of captured channels will keep expanding, and that archive growth will accelerate rather than level off. Supervision and surveillance workloads Archives are not only for retention. Compliance teams run surveillance over communications and trades to detect market abuse, misconduct and conduct risk, increasingly using analytics and language models over large volumes of text and voice. These workloads read archived data repeatedly, so the archive tier must deliver reasonable throughput as well as capacity. Keeping archived data on online object storage, rather than offline media, makes surveillance and analytics practical without restoring data first. Cost over the retention period Archive cost should be modeled over the full retention period, not the first contract term. A record captured today may need to be kept for five to seven years or more, through at least one hardware refresh. Storage that refreshes in place, without migrating records and re-proving their integrity, avoids one of the largest hidden costs in regulated archiving. Migrating legacy archives Banks often carry archives on aging storage or in legacy archiving products. Migrations must preserve record integrity, metadata, retention dates and legal holds, and produce an audit trail showing that nothing was lost or altered. Working with compliance and audit teams Storage teams rarely own archive requirements, but they own the platform that must meet them. Involve compliance, records management, legal and internal audit early. Agree which records go where, which retention and hold rules apply, how evidence of immutability is produced and how often controls are tested. Provide reports showing object lock settings, retention dates and access logs so that audits can be supported without manual investigation. Checklist: financial services archive storage Inventory archive content types, applications and storage. Map retention and format requirements by jurisdiction. Use WORM or audit-trail capable storage, with independent assessments. Apply retention per record type and support legal holds. Ensure fast retrieval for regulatory and legal production. Protect archives with encryption, access control and audit logs. Keep data within required locations. Design multi-site resilience and test recovery. Consolidate archive storage onto a scalable platform. Plan migrations with integrity and audit evidence. Putting it together Financial services archive storage must keep records unaltered, retained correctly and retrievable on demand across multiple regulatory regimes. US rules such as SEC 17a-4, EU and UK rules derived from MiFID II and local rules across Asia and the Middle East set different periods and formats, but they converge on the same storage capabilities: immutability or audit trails, retention and holds, resilience, security and data location control. A consolidated, scalable object storage platform with compliance-grade object lock provides that foundation for every archiving application on top. Frequently asked questions What storage do banks use for regulatory archives? Banks commonly use archiving applications on top of WORM-capable storage, increasingly S3-compatible object storage with object lock, kept across multiple sites. Does SEC 17a-4 still require WORM storage? Since amendments adopted in 2022, broker-dealers can use WORM storage or a system that maintains a complete time-stamped audit trail. How long must MiFID II communications be kept? Five years, and up to seven if requested by the competent authority. What is a legal hold? An instruction that suspends deletion of specific records because of litigation, investigation or regulatory inquiry, regardless of normal retention. Can banks keep archives in the cloud? Some do, subject to outsourcing, residency and supervisory requirements. Many keep regulated archives on premises or in national facilities. Further reading MiFID II and Dodd-Frank records storage Trade-voice recording storage Insurance document retention storage SEC 17a-4 compliance