FCA-regulated firms··7 min read

How FCA-regulated firms can manage WhatsApp without losing the communication trail

A practical operating model for FCA-regulated firms using WhatsApp, covering ownership, context, escalation, retention and review without treating chat as the system of record.

Customers and commercial partners may prefer WhatsApp because it is immediate and familiar. The operational risk begins when conversations depend on personal phones, nobody owns the next reply, earlier context is missing or a communication trail cannot be reviewed when needed.

The goal is not to make chat the system of record. It is to govern the channel and connect material activity to the firm's approved processes. Operations, compliance, customer-service and commercial leaders should shape those boundaries together, in line with the firm's own regulatory, legal, retention and supervision requirements.

Why WhatsApp creates an operational control gap

Personal-number dependency

If a client relationship runs through one employee's phone, the business may lose continuity when that person is absent or leaves. It also blurs the boundary between staff private contact details and firm-controlled communication.

Unclear ownership of the next reply

A team may see a message without knowing who should answer or when. A quick acknowledgement is not the same as accepting responsibility for the next action.

Missing history across shifts and teams

A responder may see the latest question but not the earlier quotation, outbound template or promised follow-up that prompted it. Without that context, the firm risks repeating questions or responding inconsistently.

Outbound activity without guardrails

Templates, reminders and internal automations can save effort, but a misrouted message or an unintended bot reply can reach a customer before anyone notices. Teams need to know who approved the content, who may send it and how a send is stopped when something looks wrong.

A trail that is difficult to retrieve

When messages are spread across devices and groups, producing a usable view for a particular customer and date range becomes laborious. The practical question is whether authorised reviewers can retrieve what the firm has chosen to retain, in context, under its own policy.

A practical operating model

1. Use firm-controlled access and business identities

Define which business identity and number a customer is contacting. Use a firm-controlled setup with authorised access rather than unmanaged personal accounts. Make account ownership, device access and the process for joiners, movers and leavers explicit.

2. Give each conversation an owner and status

Route a new conversation to a named person or team, with a visible state such as new, in progress, waiting, escalated or resolved. Record the next action and its owner before a handover. Access for several colleagues is useful, but it does not itself assign responsibility.

3. Keep the context that explains a reply

A responder should be able to see relevant earlier customer messages, approved outbound templates, reminders and follow-ups. If the customer replies to an automated prompt, show what was sent and why rather than treating the reply as a fresh, unrelated enquiry. Limit copied information to what the receiving team needs.

4. Define escalation routes before they are needed

Set clear routes for complaints, vulnerable customers, suspected fraud, urgent matters and anything that belongs in another approved system. Staff need to know whom to contact, what to acknowledge, when not to continue in chat and where the next step is recorded. Out-of-hours messages also need a stated owner or fallback, not an implied promise of continuous monitoring.

5. Separate chat from the authoritative record

WhatsApp can carry an operational exchange, but material decisions, advice, approvals and required records must be transferred to the firm's designated systems according to its policies. Name the person responsible for that transfer and make the completion visible. Do not assume a searchable chat or an internal workspace is itself the formal record.

6. Plan retention and retrieval deliberately

Agree what the firm must retain, for how long, who can retrieve it and how access is controlled. Test whether date-range exports or periodic archives preserve the necessary chronology and context, and how reviewers check that retrieval works. The retention schedule and any deletion or correction process must follow the firm's own requirements, not a default set by the chat channel.

7. Put automation behind controls

Use approved templates, authenticated access and limited permissions for any tool that can send or trigger customer-facing messages. Define when a human reviews a proposed send, how opt-outs are handled and how a team stops a faulty sequence. Test safeguards against bots or internal tools sending an unintended reply or message to the wrong recipient.

How WhatsApp and Slack can work together

WhatsApp can remain the external conversation channel while Slack or another approved team workspace helps colleagues coordinate internally. Route each conversation to a meaningful team or thread, name channels so people can distinguish customers or workflows, and show the earlier messages and owner alongside the next action. This can reduce screenshot forwarding and context lost between handovers without asking every internal colleague to work in the customer's chat.

The boundary matters: Slack should not silently become the regulatory record unless the firm's policy explicitly makes it so. Decisions and required records still need their designated destination. Keep access and retention rules for internal collaboration as deliberate as those for the external channel.

A simple message lifecycle

  1. Receive: bring the message into an approved, firm-controlled channel and establish its arrival time.
  2. Identify: establish the customer and purpose using the firm's approved process before sharing account-specific information.
  3. Assign: give a named person or team ownership, status and a next action.
  4. Respond: reply from an approved business identity with relevant prior context.
  5. Escalate or transfer: move complaints, vulnerability concerns, suspected fraud or other exceptions to the appropriate route.
  6. Record: place any material outcome, decision or required record in the designated system.
  7. Retain and review: apply the firm's retention, retrieval and supervision process to the communication trail.

This sequence is a workflow prompt, not a universal regulatory checklist. A firm should adapt it to the products, customers and obligations involved.

Questions to answer before launch

Document the answers with the people responsible for operations, compliance, technology and customer service:

  • Which use cases are approved, and which messages or content are prohibited in WhatsApp?
  • Who owns the account and number, and who grants, reviews and revokes access when staff join, move roles or leave?
  • What are the complaint, vulnerable-customer, suspected-fraud and urgent-issue escalation paths?
  • Who owns messages outside staffed hours, and what expectations are communicated to customers?
  • Who approves outbound templates, handles opt-outs and reviews permissions for automations and internal sending tools?
  • Can an authorised person retrieve a usable customer and date-range trail? Have retention, exports or archives been tested?
  • How are deletion and correction requests handled under the firm's applicable policy?
  • What monitoring, incident response and periodic review will identify missed replies, unintended sends and broken handovers?

These are operational design questions, not legal conclusions. Obtain the firm's own regulatory and legal review before launch, and revisit the answers when a workflow, system or obligation changes.

Start with a controlled pilot

Choose one bounded team or approved use case and a small number of trained users. Work through real examples with sensitive details handled according to firm policy: an ordinary enquiry, a reply to a template, a complaint, an after-hours message and a change of owner. Write down what success looks like before expanding: clear ownership, useful context, accurate escalation, retrievable records and access that matches current roles.

Also define failure criteria: an unowned conversation, a customer-facing automation firing unexpectedly, a missing material record, a failed date-range retrieval or access remaining after a role change. Review actual handovers, escalations, retrieval and user permissions with the firm's responsible teams. Tighten the process before adding another team or message type.

Keep the conversation familiar and the trail deliberate

Familiar customer communication and operational control need not be opposites. Keep WhatsApp familiar for the customer while giving the firm shared ownership, relevant context, sending safeguards and a deliberate path into its approved records.

Jely helps service teams bring WhatsApp conversations into shared operational workflows with routing, visibility, handovers and automation. Firms remain responsible for their own policies, supervision and record-keeping requirements; using Jely or any messaging workflow does not automatically make a process FCA-compliant. Book a demo to discuss whether this approach could fit your approved communication process.