Most SYSC 10A capture estates were designed around a desk phone and, later, a corporate mobile line running through the same recording platform. That design assumption is increasingly out of date. A relationship manager fields a quick question over WhatsApp because the client sent it that way first. A trader confirms a detail on a personal handset between meetings because it's faster than logging back into the desk system. Neither of those exchanges was planned as an evasion of the recording obligation — they were just the path of least resistance in the moment — but the record still has a hole in it where a relevant communication should be.

The obligation itself — for firms within SYSC 10A's scope — doesn't stop at the edge of the corporate phone system. Under SYSC 10A.1.7R, firms must take all reasonable steps to prevent staff from making, sending, or receiving relevant communications on privately-owned equipment the firm is unable to record or copy — which puts the burden on the firm to control the channel, not merely to record the ones it happened to provision. An app a firm never issued, sanctioned, or built a capture path for isn't a grey area sitting outside the rule — it's a channel the firm has, in practice, failed to take those reasonable steps against.

Provisioned and permitted aren't the same control

A written policy that says "no business communications on personal devices" is necessary and almost never sufficient on its own. Policy sets the expectation; it doesn't detect the exception. The gap tends to open in the space between what a firm has told staff not to do and what a firm can actually observe — a workforce under time pressure will reliably find the fastest route to answer a client, and if that route is a personal messaging app, the firm typically doesn't find out from a compliance system. It finds out from a data subject access request, a client complaint, or a regulator's sample request landing on a conversation that was never centrally recorded in the first place.

Closing that gap is less about banning apps — which mostly pushes the behaviour further out of sight — and more about narrowing the distance between the sanctioned channel and the fast one. That can mean provisioning an approved messaging channel with the same immediacy as the app staff would otherwise reach for, mobile device management that can attest to which apps are actually installed on a work-carrying device, and a genuinely quick escalation path for the "the client only has my mobile number" situation, rather than leaving that as an unaddressed edge case that quietly becomes routine.

What good practice actually looks like day to day

The firms that manage this well tend to treat off-channel risk as an ongoing detection problem rather than a one-off policy exercise. New joiners get the sanctioned channel set up before their first client contact, not weeks into the role once habits have already formed. Periodic attestations ask a specific, checkable question — which apps are installed, which numbers are client-facing — rather than a generic sign-off nobody reads closely. And when a gap does surface, it gets logged and remediated the same way a missed call recording would be, rather than treated as a one-off exception to quietly forget.

Regulatory attention on this has been building rather than settled, which is itself a reason not to wait for a definitive enforcement precedent before tightening the control. The FCA's August 2025 multi-firm review of off-channel communications — which covered eleven wholesale banks and found that 41% of internal policy breaches involved individuals at director grade or above — asked firms almost exactly what this piece has been arguing for: whether leadership sets a genuine tone from the top, whether accountable executives get the management information to oversee compliance, and whether senior managers act promptly once a pattern of non-compliance emerges. The review's sample was wholesale banks rather than the full range of firms SYSC 10A covers, but the direction it signals is one every firm in scope should read as a preview, not a large-bank-only problem.

That's the same posture the compliance tooling built under this roof is designed around: not a single control that captures everything perfectly, but a system built to notice where a gap has opened and say so before someone else has to ask.