Go back to blog

Off-channel communications: The risk hiding in bank email

There are many ways to contact a bank today: Live Chat, Secure Messenger, in branch, or on the phone – the list goes on. Every other channel sits behind authentication. Client correspondence does not. And three banks have decided to do something about it.

Most banks are confident this gap doesn't exist. If you ask them where client conversations live after the fact, they'll point to the portal, the app, or perhaps the contact center. These are all governed and logged.

Or so the banks think.

Push a little further and it opens up. Ask where the mortgage file, the corrected statement, or the signed mandate actually traveled, and the answer is almost always email.

That's not a gap anyone chose. It's what's left over after fifteen years of digitizing everything around it.

Why email outlasted every project sent to replace it

Most banks have already tried. Asynchronous chat gets launched, adoption looks promising, and then it plateaus. The reason is rarely the channel itself. It is that the conversations worth moving are the ones that carry a document.

A client reports a problem and attaches a screenshot. An advisor sends a report. A corporate treasurer needs a form countersigned. The moment chat cannot carry the file, the conversation falls back to email and takes the rest of the relationship with it. In corporate and institutional teams especially, the document is the business communication.

So attachments become the obvious fix. They are also not enough. Banks that have worked through this properly arrive at the same list of requirements:

  • Secure file exchange inside the authenticated domain, not a link out to a portal
  • Case linking, so the conversation is attached to the record and its audit trail, rather than to a person
  • Transfer between colleagues and teams, with the full history intact
  • Multi-party participation, with access controls that let specialists advise without being visible to the client
  • Proactive outbound, so the bank can start the conversation
  • Persistent, searchable history that survives handovers, absences, and staff turnover

That is not an attachment feature. That is a channel.

What email actually costs

The case for moving is usually made on efficiency. The stronger case is on risk.

Attachments travel outside the bank's perimeter without end-to-end encryption, which makes email the preferred vector for social-engineering fraud. Context lives in one person's inbox, so handing a case to another team means starting it again. Threads fork, subject lines drift, versions multiply, and no single record of the case exists. There's no PII redaction, no audit logs, and no way to place a thread on legal hold. Archiving depends on individual discipline rather than on retention schedules built into the channel. And the client waits, with no visibility of what happens next.

Every one of those is a control problem, not a productivity problem. Which is why the banks moving fastest are not the ones with the biggest efficiency targets. They are the ones whose compliance and fraud functions got involved, and for them this reads as a regulatory compliance gap.

Off-channel communications already has a price tag

The regulators have already put a number on this, and it isn't a data protection question. Since December 2021, the SEC has fined more than 100 firms a combined $2.2 billion for recordkeeping failures tied to exactly this pattern: business correspondence that never made it into an archived, audit-ready system of record. Most of those cases involved WhatsApp and personal text messages rather than email, but the record keeping obligations are the same ones email quietly fails.

FINRA's books and records rules and SEC 17a-4 require firms to capture business communications in a searchable format with clear audit trails, not leave them as unstructured data scattered across inboxes. Bolting on an email archiving solution after the fact, whether that's Bloomberg Chat, Microsoft Teams, or Office 365 and Google Workspace's native retention tools, treats the symptom. A channel that's authenticated, logged, and audit-ready from the first message treats the cause. Treating archiving as an afterthought is not a compliance strategy across the financial industry or anywhere else. The fine is one cost, the reputational damage that follows is another.

Three ways banks are actually retiring the mailbox

Division by division. One of Europe's largest universal banks is retiring its in-portal mailbox in sequence, starting with personal banking – the highest-volume, most standardized correspondence in the group. Corporate, institutional, and wealth divisions follow, each with its own transition program as part of a wider digital transformation. The framing matters more than the mechanics: messaging is positioned as the destination channel, not as a support add-on running alongside email.

One document, made mandatory. A European private bank took the opposite route, a pattern also playing out across investment firms and other wealth managers. Rather than a bank-wide switch, it picked a single artifact: the monthly portfolio report. Advisors are required to send it through secure messaging, inside a conversation pre-configured to contain the client, the advisor, and the assistant. Customers receive a push notification, but the document itself only opens after authentication. The driver was fraud as customers were being targeted directly by increasingly convincing social engineering. The side effect was that customers learned a rule that protects them everywhere: this bank does not send documents by email.

Merge everything inbound into one thread. A national retail bank replaced traditional email with a single ongoing secure conversation per client, enriched with collaboration tools and written back automatically to the CRM. Agents work in one place instead of switching between an inbox, a chat console, and a case system. Written channels now carry a quarter of all client inquiries, with agents handling around 240,000 conversations a year alongside roughly a million virtual-agent interactions, and the automation program across channels has produced efficiency gains equivalent to about 40 full-time roles.

Three different entry points. The same destination.

What replaces it, in practice

The pattern that works looks less like a chat window and more like a case file that the client can write into.

Inbound communication

The client writes from the portal or the app, already authenticated – no secure-mail portal, no password-protected PDF. The request routes by topic, segment, or relationship. It is worked over hours or days, with files, screenshots, and internal notes accumulating in the thread, and the client notified when there is news. When it closes, the record is complete, exportable, and ready for search and retrieval.

Outbound messages

Proactive contact stops depending on whether the client answers a voice call. The advisor writes into the secure thread; the client reads it in the app and replies on their own time. Each relationship has one persistent thread, opened at onboarding. Wealth managers running this model report around 50% more client-advisor interactions and 25% less advisor time spent on administration.

Files sharing

The attachment never leaves the bank. Documents stay behind authentication and end-to-end encryption, scanned and retained under the bank's own data retention policy, and both sides can find them again months later. When writing stops working, the same conversation opens into co-browsing, a shared document, or a digital signature request.

Seamless communication

Transfers move the whole thread: history, files, and participants, so the receiving team opens the case fully briefed and the client keeps the same reference and never repeats themselves. Specialists, back office, or compliance can be pulled in mid-case as hidden participants, governed by the same access controls throughout. Assistants sit permanently in the relationship thread, which makes cover during absence automatic rather than improvised.

Contextual messaging integration

Embedding Unblu Messaging directly into internal advisor software unifies client communications with core operational context. Rather than operating as an isolated channel, the messaging framework functions natively within the advisor's primary interface, displaying real-time conversation threads alongside account data, historical interactions, and relational records. This structural integration eliminates context switching, reduces cognitive load, and ensures that advisors evaluate and respond to client inquiries with immediate access to complete situational data.

The question worth asking internally

Not "should we add a messaging channel?" The question is narrower and more useful: which conversations are still falling back to email, and what is missing that forces them there?

Answer that honestly and the migration plan tends to write itself. It usually starts with one document, one segment, or one division – not with a program.

Want to find out more?
Reach out to us today for more information or to schedule a demo
Book a demo

Frequently asked questions

How should a bank start replacing email with a compliant messaging channel?

Most banks that succeed start with a single, narrow use case rather than a company-wide mandate: one document type, one client segment, or one division. A common starting point is making a single high-risk document, such as a monthly portfolio report or a signed mandate, mandatory to send only through secure messaging rather than email. From there, banks typically expand division by division, starting with the highest-volume correspondence such as personal banking, before extending to corporate, institutional, and wealth management teams. Compliance and fraud teams are usually the ones who initiate this shift, since the gap shows up first in regulatory audits and fraud investigations rather than in customer satisfaction scores. Any deployment should support flexible data storage options, including cloud, Swiss sovereign cloud, or on-premise hosting, so data-sovereignty requirements determine where records live, not the vendor's default setup.

How does secure messaging address the compliance gap that email and WhatsApp leave open?

Secure messaging platforms address this gap by keeping every conversation inside an authenticated channel from the first message, so there is no separate archiving solution to bolt on afterward. Messages, files, and case notes are captured automatically with full-fidelity metadata, stored under the bank's own data retention policy, and made searchable for compliance audits and legal hold requests. Because access is tied to the bank's existing login rather than a phone number or social account, user roles and access controls determine who can see a conversation, and every action is logged for an audit trail. Unblu's Secure Messenger, for example, is built to meet GDPR, FINMA, FINRA, and MiFID II requirements while giving banks full ownership of the data, unlike consumer apps such as WhatsApp or Signal, which offer no native archiving or compliance controls.

What do SEC and FINRA recordkeeping rules require of financial services providers?

SEC Rule 17a-4 and FINRA Rule 4511 require broker-dealers and investment advisers to capture, preserve, and retrieve business communications for a set retention period, in a format regulators can access during an audit. These rules were written for structured recordkeeping solutions such as email archiving software and instant messaging archiving tools, and cover communications made through company-approved channels including Bloomberg Chat, Microsoft Teams, and enterprise email. Since December 2021, the SEC has fined more than 100 financial services providers a combined $2.2 billion for failing to meet these obligations, mostly for allowing employees to conduct business over personal devices using WhatsApp or text messages that were never captured by an approved archiving service. The rules apply regardless of which platform a conversation happens on.

Why is email considered an off-channel communication risk for banks?

Email is an off-channel communication risk because it typically sits outside a bank's authenticated, archived environment even though it carries the most sensitive client documents: mortgage files, corrected statements, signed mandates, and portfolio reports. A 2023 UK consumer survey by Mailock found that 30% of people who had shared personal data by email had sent bank details this way, while 73% of the same respondents said they knew email was not secure. Email also lacks native access control, PII redaction, and a shared retention policy, so a forwarded thread carries everything the original message did, with no audit log recording who saw it or when. For a bank, that turns every email attachment into an ungoverned copy of client data sitting on a server the bank does not control.

What is off-channel communication in banking?

Off-channel communication is any business conversation that happens outside a financial institution's approved, archived, and audited systems, most commonly WhatsApp, personal text messages, or standard email. Regulators including the SEC and FINRA require broker-dealers and investment advisers to capture and retain records of business communications under rules like SEC 17a-4 and FINRA Rule 4511. When a client or advisor exchanges account details, a signed mandate, or a portfolio report through personal email or messaging apps rather than an authenticated system of record, that exchange is off-channel: it has no audit trail, no enforced retention schedule, and no place in the bank's compliance workflows. The term became widely used after 2021, when the SEC began fining financial services organizations for exactly this gap.