Poor Communications Governance: The Major Risk Hiding in Plain Sight

Communications governance

The scope of regulatory attention is expanding and moving well beyond incident response. Auditors, regulators, and investigators are increasingly focused on how organizations govern day-to-day business communication, not just what happened when something went wrong. It is a move that has real implications for legal and compliance teams, and for the organizations they serve.

The enforcement record makes the point, particularly at financial organizations. Since late 2021, the U.S. Securities and Exchange Commission has charged more than 100 firms and levied over $2 billion in penalties for failures to preserve business communications conducted over text, WhatsApp, and similar channels — including a further $63 million against twelve firms in January 2025. Notably, many of those firms had policies in place. What they could not do was demonstrate that the policies were enforced.

The communications challenge and resulting risks are no longer confined to email, it is assessed across all business communication channels. But what does that really mean? What was once a question about email governance is now a question about Teams, Zoom, Slack, mobile messaging, and whatever platform employees happen to be using that week. And as those channels multiply, so does the complexity of demonstrating that policies are consistently applied across all of them.

Inconsistency Is Where Exposure Starts

Inconsistencies between systems can increase exposure during audits and investigations. That might sound like a technical problem, but it is fundamentally a legal one. When an organization cannot show that its policies are applied consistently across communication channels, it becomes very difficult to defend its position when those communications are reviewed.

Part of the problem is awareness. The sheer breadth and availability of communication options and technologies mean that employees have more ways than ever to communicate outside approved or governed systems. When that happens, it creates real gaps in oversight and control that can affect an organization’s ability to retrieve communications when needed, demonstrate how policies were applied, and meet its obligations under data laws and other regulations.

Under data protection laws, organizations are expected to be able to describe and show how personal data is handled within everyday communications, not just within core systems. That expectation applies regardless of which platform the communication took place on.

The Legal Landscape Is Broader than Most Teams Realize

Requirements regarding company identification, legal disclosures, and disclaimers apply broadly to organizational communications. That naturally includes email, but organizations need to be alert to how those requirements extend to other channels and whether they are being applied consistently across them.

Accessibility obligations are another area that often goes unexamined. Requirements under the Equality Act and the Americans with Disabilities Act can apply to digital communication and how information is presented. These are not edge cases, they are baseline legal requirements that apply to the way organizations communicate, and they must be factored into how communication governance is designed.

The common thread across all of these areas is consistency. It is not enough to have baseline policies in place. Regulators expect organizations to demonstrate how communication is governed across platforms, and how those governance standards are maintained over time.

What Regulators and Internal Auditors Are Looking For

When regulators or internal auditors review communication governance, they are looking for several things: clear policies that define how communication should be handled across channels; evidence that those policies are applied consistently in practice, not just documented; a record of how policies are updated and maintained over time; and confidence that controls are built into systems rather than relying on individual behavior.

That last point is worth dwelling on. Relying on individual behavior to enforce communication standards is one of the most common ways organizations get this wrong. Policies exist, but there is no mechanism to ensure they are applied in the same way across different teams, systems, or regions. Over time, that creates variation and when that variation is exposed during an internal audit or investigation, it becomes very hard to explain.

This is not a U.S.-only phenomenon. When the U.K.’s Financial Conduct Authority reviewed how eleven wholesale banks were managing off-channel communications in August 2025, it identified 178 breaches of internal messaging policies in a single year, with 41 percent involving directors or senior staff. The FCA has taken a supervisory rather than enforcement-led approach, and has said it will not write new rules for every communication scenario. But its findings now set the baseline expectations firms are assessed against.

The Risk of Communication Outside Approved Systems

The focus on information sharing via AI services over the last couple of years illustrates what is at stake when organizations lose control over where business communication occurs. The lack of control over business information can be very real. When employees communicate outside approved systems, it creates gaps in record-keeping, makes it difficult to retrieve communications when it is needed for review, and undermines the organization’s ability to demonstrate that policies are applied consistently.

In the SEC’s most recent enforcement orders, the failures involved personnel at multiple levels of authority, including supervisors and senior managers. The very people responsible for enforcing the policies being breached.

That creates exposure during internal audits and investigations. Organizations need to decide how those channels are governed or restricted within their own businesses. That is not a technology decision alone. It requires a clear legal and policy framework, and it requires enforcement.

Start with Ownership, Education, and Consistency

From a legal standpoint, building effective communication governance comes down to a few core requirements. There needs to be clear ownership of how communication standards are defined and maintained. Without that, accountability becomes diffuse, and policies drift.

Educate your staff, so that every employee understands what the policies are, how they are applied, and their own role in abiding by them. There must also be consistency in how policies are applied across communication channels, with the ability to demonstrate how controls are applied across systems.

Evidence that updates are implemented consistently and in a timely manner matters too. When requirements change, those changes need to be reflected across all relevant systems. Manual processes make that harder. When an update depends on individual teams making changes in separate platforms, things fall out of sync. That creates exactly the kind of inconsistency that becomes difficult to defend when communication is reviewed.

Make Governance Provable, not Just Defined

The most important starting point is understanding where your communication governance is not aligned. Look across systems, identify where policies are applied differently, and understand where visibility is limited. Once that picture is clear, organizations can prioritize what needs to change. Educating staff on what the policies are, how they are applied, and their role in applying them is crucial to making those controls meaningful.

The goal is to demonstrate controls through technical enforcement and appropriate record-keeping, and to show consistency in how policies are applied and maintained. That is what regulators expect. And as communication continues to expand across platforms, it is what effective governance requires.  Internal audit end slug


Ed Bodey is General Counsel at  Exclaimer. With nearly two decades in legal practice focused on technology companies, he advises firms across industries and growth stages on complex commercial, regulatory, and governance matters, helping them navigate the decisions that shape how they scale.

Leave a Reply

Your email address will not be published. Required fields are marked *