What Does a Regulator Expect to See in Supporting Documentation?

Six years for broker-dealers, five for advisers, and two different ways to satisfy the SEC's electronic recordkeeping rule. What examiners actually test in supporting records, and where firms get it wrong.

What Does a Regulator Expect to See in Supporting Documentation?
In short
Regulator-ready documentation means supporting records that an examiner can locate, read and test without help from the people who produced them. It covers the record itself, its history of changes, and the link between the record and a responsible person; without all three, the examiner is left relying on the firm's own account.

Examiners rarely grade filing cabinets. They ask whether a record can be found, read and checked against what a firm said it did. A compliance lead who cannot answer that without a colleague's memory hands the examiner a gap. The SEC's recordkeeping rule for broker-dealers puts it plainly: the firm has to furnish copies that are legible, true, complete and current, promptly, on request. Regulator-ready documentation is the supervisory end of audit-ready records: the same files, judged by whether an outsider can work with them.

What is regulator-ready documentation?

Regulator-ready is industry shorthand rather than a term defined in the rules cited here. It is the supervisory end of audit-ready records: the same files, judged by whether an outsider can work with them. The substance behind it is written down, though, and in the United States it is unusually concrete: when an examiner asks, the firm produces the record, in a form the examiner can read, without a negotiation about formats.

Three properties carry most of the weight: retrieval, readable content and a reconstructable history. The third is the one firms notice last, because it only fails when someone asks what the file looked like before the last edit.

The SEC's electronic recordkeeping rule addresses that directly. A firm storing records electronically has two ways to satisfy it. Either it keeps the records in a format that cannot be rewritten or erased, or it keeps a complete time-stamped audit trail that captures every modification and deletion, the date and time of each action, where applicable the identity of the person behind it, and enough information to permit re-creation of the original record if it is modified or deleted.

A supporting record means the document a firm relies on when it explains a decision: the instruction, the approval, the valuation input, the exception memo. Communications count too. The same rule treats correspondence sent and received, including internal memoranda, as records to be preserved. In audit language the same material has a name.

Under the standards of the PCAOB, the board that sets and inspects audit standards for US public-company audits, "audit evidence is all the information, whether obtained from audit procedures or other sources, that is used by the auditor in arriving at the conclusions on which the auditor's opinion is based." What a firm keeps is what a reviewer works from.

Retention duties are specific rather than universal. Broker-dealers preserve their core books, such as blotters and ledgers, for six years under the SEC's preservation rule, and many other records, including communications and internal memoranda, for at least three years. In both cases the first two years must be easily accessible. Registered investment advisers work to a different clock: five years from the end of the fiscal year in which the last entry was made, again with the first two years close at hand. Two registrations, several periods, one firm. A single house retention rule tends to be wrong somewhere.

Why does regulator-ready documentation matter for compliance and risk teams?

The reader of your records is a stranger with a mandate. An examiner, an auditor or a fund's independent public accountant arrives with none of the context that made the file obvious to your team. Whatever works because someone recalls the background stops working there.

Two points follow, and both are written into the rules rather than inferred from them. The first is locatability: the firm has to keep current the information needed to access and locate a record, and hand that over promptly when asked. Findability is a regulated property of the system, not a convenience for staff.

The second is that outsourcing storage does not outsource the duty. When a third party holds the records, that provider has to undertake in writing that the records remain the firm's property, that they will be surrendered promptly on request, and that the SEC's representatives may examine them. A vendor contract that is silent on examination access leaves a gap the firm owns.

A compliance or risk lead has to evidence controls that otherwise leave no trace. Whatever trace does exist has to outlast staff turnover and system migrations. Chain of custody for digital records is usually where that trail breaks, and broken custody is a recurring reason why records fail review in regulated finance.

How do you make supporting records regulator-ready?

Step 1: Name the record and the responsible party

Decide which artifact is the record of the decision, and who owns it. If two systems hold candidate versions, a reviewer cannot tell which one the decision rested on.

Step 2: Fix the content at a point in time

Compute a cryptographic digest of the file. A hash digest is used to detect whether a message has been changed since the digest was generated. The check only works if the digest is stored somewhere other than the file it describes. Proving that a document has not been altered rests on that arithmetic.

Step 3: Bind identity and time to the content

A signature attaches a named party to that digest. A time-stamping service supports assertions that a datum existed before a particular time. Identity and timing are not decoration here: the audit-trail option in the SEC's electronic recordkeeping rule asks for the date and time of each action and the identity of the person who took it.

Step 4: Keep the history, not just the latest version

Corrections are normal; losing the earlier content is the problem. The rule's own standard is the ability to re-create the original record if it was modified or deleted. An append-only history keeps superseded versions readable next to the current one.

Step 5: Rehearse retrieval by an outsider

Ask someone with no project context to find a record and check it. Keep an audit preparation checklist for regulated finance, note where the search stalls, and rehearse against it before the next exam.

The values below are illustrative.

A fund accounting lead at an administrator approves a pricing-source override for an unlisted holding on 4 June, at 08:20 UTC. The override memo is stored with digest prefix b71c, signed under the lead's own credential, and timestamped.

Two months later a reviewer asks whether the memo predates the NAV it supports. The reviewer recomputes the digest of the file handed over, compares it with b71c in the history, and reads the signing time. Three questions are answered without asking the fund accounting lead anything: the file is the one that was signed, the signer is the named lead, and the signature predates the NAV. What the reviewer still cannot see is whether the override was the right call. That judgment stays with the auditor and the valuation committee.

How is a regulator-ready record different from a well-organized file?

What separates the two is whether the file still makes sense once the person who built it has left the room.

Question a reviewer asks Internally tidy file Regulator-ready record
Can it be found without the owner? Retrieval depends on team knowledge Locating information is kept current and produced on request
Is this the version that was relied on? Latest save, earlier content overwritten Either non-rewriteable storage or an audit trail that re-creates the original
Who fixed the content, and when? File metadata, editable in place Digest plus signature and a bound time stamp
Has anything changed since? Compared by eye or by date Digest recomputed and compared
What does the answer establish? Content looks plausible Integrity and sequence, not correctness

Tamper-evident means that a change becomes detectable, not that a change becomes impossible. That distinction comes from NIST, the National Institute of Standards and Technology, the US federal agency whose publications define the SHA-256 hashing standard. NIST describes blockchains as tamper-evident and tamper-resistant distributed ledgers. The wording comes from the body that defines the underlying cryptography, which makes it the ceiling a vendor claim should respect.

What are the common mistakes with regulator-ready documentation?

A document management system is often mistaken for the evidence itself. It holds files and controls access, which is necessary and not sufficient. If the integrity check lives in the same system that could alter the file, an outside reviewer has to trust the operator rather than test the record.

Teams read a hash as a verdict on content. A digest does not say what changed, only that something did. It also does not prove that the content was correct when it was fixed, which is why the valuation, the approval and the review still have to happen.

A retention period from one registration turns into a house rule for everything. A firm that is both a broker-dealer and a registered adviser is working to two different clocks at once. Mapping duties per rule takes longer than writing a single house rule, and it is the version an examiner can follow.

The chain breaks when systems change. Chain of custody means the documented history of who held a record and when. Migration, re-export and re-signing can break that history without an obvious signal, and the break may only surface at the next exam.

Where does Filedgr fit?

The useful outcome is narrow: a reviewer outside your firm can check a record without asking your team to vouch for it. Filedgr is verification infrastructure for that step. It supports compliance evidence, review and reporting workflows rather than replacing the systems that produce the numbers.

The mechanics are plain. A record is hashed with SHA-256, then signed by the party who owns it. The hash, the signature and the time stamp are anchored to a blockchain transaction and kept in an append-only history, and access to the content itself is permissioned per recipient in a Filedgr Vault. Proof Packages bundle files with their hashes, signatures and time stamps, so the same check works outside Filedgr.

A recipient can then confirm three things: that the file matches the recorded hash, that the signature belongs to the party named, and that the history shows no gap. Teams that hand records to counterparties can see how Filedgr approaches secure data sharing.

Filedgr does not calculate a NAV, validate a valuation, judge whether a record satisfies a rule, or file anything with a regulator. Those decisions stay with the firm, its auditor and its counsel. Record integrity is one property of audit-ready records; retention, retrieval and access control are the others a firm has to evidence separately.

Frequently asked questions

Is regulator-ready a formal regulatory term?

No, and a firm that treats it as a defined status ends up auditing itself against a phrase instead of against the duties that bind it. The SEC's recordkeeping rules carry the substance: records produced promptly in legible, true, complete and current form, stored either in a non-rewriteable format or with an audit trail that can re-create the original.

How long do supporting records have to be kept?

It depends on the registration and the record type, so a single house period is a planning tool rather than a legal answer. Broker-dealers preserve core books such as blotters and ledgers for six years and many other records, including communications, for three, with the first two years in an easily accessible place. Registered investment advisers generally work to five years from the end of the fiscal year of the last entry. Each duty is mapped from its own rule by the team that owns the records.

Does a hash or a time stamp make a document legally binding?

No, and treating it that way creates risk. A digest detects change to the content, and a time stamp supports the assertion that the content existed before a given moment. Whether a record carries weight in a given proceeding is a legal question for counsel, decided under the applicable law and rules of procedure.

Can a third party verify a Filedgr record without an account?

Yes. Since June 2026, a third party can check a record's signature and blockchain transaction in the public Filedgr Explorer, without a Filedgr account and without seeing the content. Proof Packages carry the same hashes, signatures and time stamps with a file, so the check also works outside Filedgr. Access to the content itself stays a separate, permissioned decision.

Sources

  1. SEC, 17 CFR 240.17a-4(j), Records to be preserved by certain exchange members, brokers and dealers — prompt production of legible, true, complete and current copies. https://www.ecfr.gov/current/title-17/chapter-II/part-240/subject-group-ECFR17722751b422db3/section-240.17a-4, accessed 2026-09-22.
  2. SEC, 17 CFR 240.17a-4(f)(2)(i) — electronic recordkeeping: non-rewriteable, non-erasable format or complete time-stamped audit trail permitting re-creation of the original record. https://www.ecfr.gov/current/title-17/chapter-II/part-240/subject-group-ECFR17722751b422db3/section-240.17a-4, accessed 2026-09-22.
  3. SEC, 17 CFR 240.17a-4(f)(3)(iv) — organize, maintain, keep current and provide promptly the information necessary to access and locate records. https://www.ecfr.gov/current/title-17/chapter-II/part-240/subject-group-ECFR17722751b422db3/section-240.17a-4, accessed 2026-09-22.
  4. SEC, 17 CFR 240.17a-4(a) and (b) — preservation periods of not less than six years and not less than three years, the first two years in an easily accessible place. https://www.ecfr.gov/current/title-17/chapter-II/part-240/subject-group-ECFR17722751b422db3/section-240.17a-4, accessed 2026-09-22.
  5. SEC, 17 CFR 240.17a-4(b)(4) — originals of communications received and copies of communications sent, including inter-office memoranda. https://www.ecfr.gov/current/title-17/chapter-II/part-240/subject-group-ECFR17722751b422db3/section-240.17a-4, accessed 2026-09-22.
  6. SEC, 17 CFR 240.17a-4(i)(1) — records held by an outside recordkeeping service remain the firm's property, surrendered promptly on request, with examination permitted by Commission representatives. https://www.ecfr.gov/current/title-17/chapter-II/part-240/subject-group-ECFR17722751b422db3/section-240.17a-4, accessed 2026-09-22.
  7. SEC, 17 CFR 275.204-2(e)(1), Books and records to be maintained by investment advisers — not less than five years from the end of the fiscal year during which the last entry was made, the first two years in an appropriate office. https://www.ecfr.gov/current/title-17/chapter-II/part-275/section-275.204-2, accessed 2026-09-22.
  8. SEC, Electronic Recordkeeping Requirements for Broker-Dealers, Security-Based Swap Dealers, and Major Security-Based Swap Participants, Release No. 34-96034, 2022-11-03 — WORM retained as an option, audit-trail alternative added. https://www.federalregister.gov/documents/2022/11/03/2022-22670/electronic-recordkeeping-requirements-for-broker-dealers-security-based-swap-dealers-and-major, accessed 2026-09-22.
  9. PCAOB, AS 1105: Audit Evidence, paragraph .02, 2010. https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105, accessed 2026-09-03.
  10. NIST, FIPS 180-4 Secure Hash Standard, 2015-08. https://csrc.nist.gov/pubs/fips/180-4/upd1/final, accessed 2026-09-03.
  11. IETF, RFC 3161 Internet X.509 PKI Time-Stamp Protocol, 2001-08. https://www.rfc-editor.org/rfc/rfc3161, accessed 2026-09-03.
  12. NIST, NISTIR 8202 Blockchain Technology Overview, 2018-10. https://csrc.nist.gov/pubs/ir/8202/final, accessed 2026-09-03.

Get started today

Stay ahead of audits and evolving regulations with verified integrity.
Get in touch to learn more.