Glossary
SEC Rule 17a-4
Also called: 17a-4, Rule 17a-4
SEC Rule 17a-4 governs how broker-dealers preserve their records. It prescribes retention periods by record type, requires the first two years to be easily accessible, and permits either non-rewriteable storage or an audit-trail arrangement evidencing that records have not been altered or erased.
SEC Rule 17a-4 explained
Two routes, not one
The rule is commonly described as requiring WORM media. It does not. It permits either a non-rewriteable, non-erasable medium, or an audit-trail arrangement that evidences records have not been altered or erased. The second route is what makes compliant cloud storage possible, and it is why an immutable audit trail matters more in this sector than in any other.
Easily accessible
Records must be kept for three or six years depending on type, with the first two years in an easily accessible place. That creates two retention tiers rather than one, and a system that treats retention as a single period cannot express the requirement.
Prompt production
The rule expects records to be produced promptly on request. That is a retrieval requirement, and it is where organisations with documents spread across network shares fail an examination regardless of how well they store things.
The related rules
FINRA Rule 4511 sets a six-year default for books and records where no other period applies, which makes an "unclassified records" report an operational necessity: a document type with no retention rule attached defaults to a gap.
Attestation
Examiners frequently expect a third-party attestation that the storage arrangement meets the rule. That is a question to ask a vendor early, because obtaining one late in a procurement is slow.
FAQ
SEC Rule 17a-4: common questions
Does cloud storage satisfy 17a-4?
It can, by either route — object lock in compliance mode for the media route, or an immutable audit trail for the arrangement route. Which one your compliance function accepts is worth settling before you build.
Which records are actually in scope?
Specified categories rather than everything the firm holds. Establishing the scope before designing retention prevents applying the strictest rule to your entire estate.
Related terms
- 21 CFR Part 1121 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
- Business associate agreementA business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- eIDASeIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- GDPRThe General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
آخر مراجعة: 28 أغسطس 2026. Browse the full glossary.