Our bank has an internal messaging platform that is used for internal communications only. We currently archive these messages, but the platform is predominantly used for non-business-related communications. We would like to turn off the archiving feature so that the messages are automatically deleted. We also would train our employees not to use the messaging platform for any business-related communications. Is there any guidance on the deletion of employee instant messages?


Yes, guidance issued by the OCC in 2016 discourages the permanent deletion of messages transmitted over internal chat and messaging platforms.

The guidance reminds OCC-supervised banks that the use of chat and messaging platforms that allow for the permanent deletion of transmitted messages “conflicts with OCC expectations of sound governance, compliance, and risk management practices as well as safety and soundness principles,” particularly if the deletion occurs “within a relatively short time frame.” The OCC also noted that “[[b][/b]b]ank management must ensure that its adoption of any communications technology continues to allow for examiner access to appropriate bank records.”

While your bank’s primary federal regulator is the FDIC, we believe that FDIC examiners also may find that enabling an auto-delete function on an internal messaging platform impedes their ability to thoroughly examine your bank’s records. Although you may advise your examiners that your bank’s policy forbids the use of the messaging platform for any business-related communications, your examiners would not be able to verify adherence to this policy if all such messages are automatically deleted.

