Regulators are no longer just reviewing incidents they are reviewing how you communicate

By: Ed Bodey, General Counsel, Exclaimer

The scope of regulatory attention is expanding and moving well beyond incident response. Auditors, regulators, and investigators are increasingly focused on how organizations govern day-to-day business communication, not just what happened when something went wrong. It is a move that has real implications for legal and compliance teams, and for the organizations they serve.

The communications challenge and risk is no longer confined to email, it is assessed across all business communication channels. But what does that really mean? What was once a question about email governance is now a question about Teams, Zoom, Slack, mobile messaging, and whatever platform employees happen to be using that week. And as those channels multiply, so does the complexity of demonstrating that policies are consistently applied across all of them.

Inconsistency is where exposure starts

Inconsistencies between systems can increase exposure during audits and investigations. That might sound like a technical problem, but it is fundamentally a legal one. When an organization cannot show that its policies are applied consistently across communication channels, it becomes very difficult to defend its position when those communications are reviewed.

Part of the problem is awareness. The sheer breadth and availability of communication options and technologies mean that employees have more ways than ever to communicate outside approved or governed systems. When that happens, it creates real gaps in oversight and control that can affect an organization’s ability to retrieve communications when needed, demonstrate how policies were applied, and meet its obligations under data laws and other regulations.


Communication Governance Is Becoming a Regulatory Priority

Under the data protection law, organizations are expected to be able to describe and show how personal data is handled within everyday communications, not just within core systems. That expectation applies regardless of which platform the communication took place on.

The legal landscape is broader than most teams realize

Requirements regarding company identification, legal disclosures, and disclaimers apply broadly to organizational communications. That naturally includes email, but organizations need to be alert to how those requirements extend to other channels and whether they are being applied consistently across them.

Accessibility obligations are another area that often goes unexamined. Requirements under the Equality Act and the Americans with Disabilities Act can apply to digital communication and how information is presented. These are not edge cases, they are baseline legal requirements that apply to the way organizations communicate, and they must be factored into how communication governance is designed.

The common thread across all of these areas is consistency. It is not enough to have baseline policies in place. Organizations rightly continue to be expected to demonstrate how communication is governed across platforms, and how those governance standards are maintained over time.


What regulators and auditors are looking for

When regulators or auditors review communication governance, they are looking for several things: clear policies that define how communication should be handled across channels; evidence that those policies are applied consistently in practice, not just documented; a record of how policies are updated and maintained over time; and confidence that controls are built into systems rather than relying on individual behavior.

That last point is worth dwelling on. Relying on individual behavior to enforce communication standards is one of the most common ways organizations get this wrong. Policies exist, but there is no mechanism to ensure they are applied in the same way across different teams, systems, or regions. Over time, that creates variation and when that variation is exposed during an audit or investigation, it becomes very hard to explain.


The risk of communication outside approved systems

The focus on information sharing via AI services over the last couple of years illustrates what is at stake when organizations lose control over where business communication occurs. The lack of control over business information can be very real. When employees communicate outside approved systems, it creates gaps in record-keeping, makes it difficult to retrieve communications when it is needed for review, and undermines the organization’s ability to demonstrate that policies are applied consistently.

That creates exposure during audits and investigations. Organizations need to decide how those channels are governed or restricted within their own businesses. That is not a technology decision alone. It requires a clear legal and policy framework, and it requires enforcement.


Start with ownership, education, and consistency

From a legal standpoint, building effective communication governance comes down to a few core requirements. There needs to be clear ownership of how communication standards are defined and maintained. Without that, accountability becomes diffuse, and policies drift. 

Educate your staff, so that every employee understands what the policies are, how they are applied, and their own role in abiding by them. There must also be consistency in how policies are applied across communication channels, with the ability to demonstrate how controls are applied across systems.

Evidence that updates are implemented consistently and in a timely manner matters too. When requirements change, those changes need to be reflected across all relevant systems. Manual processes make that harder. When an update depends on individual teams making changes in separate platforms, things fall out of sync. That creates exactly the kind of inconsistency that becomes difficult to defend when communication is reviewed.


Make governance provable, not just defined

The most important starting point is understanding where your communication governance is not aligned. Look across systems, identify where policies are applied differently, and understand where visibility is limited. Once that picture is clear, organizations can prioritize what needs to change. Educating staff on what the policies are, how they are applied, and their role in applying them is crucial to making those controls meaningful.

The goal is to demonstrate controls through technical enforcement and appropriate record-keeping, and to show consistency in how policies are applied and maintained. That is what regulators expect. And as communication continues to expand across platforms, it is what effective governance requires.


About the Author

Ed Bodey is General Counsel at Exclaimer, where he advises on legal, compliance, regulatory, and governance matters affecting enterprise communication and digital collaboration technologies.