02 / Compliance
A communications audit is not lost for lack of recordings. It is lost by failing to find the right recording, in time, with proof that it is the original. This page is about that, and about turning a request that takes days into one that takes minutes.
The regulator asks for one specific interaction: a client, an approximate date, a product. From here, without a unified archive, the day usually goes like this.
One specific interaction: a client, an approximate date, a product.
Someone has to guess where to start. The knowledge lives in people's heads, not in an index.
By phone number. It does not match: the contact actually began on chat.
One more system, one more search, more time draining away.
You assemble the interaction piece by piece, from three places that do not talk to each other.
When it finally turns up, the most important part is missing: proving that nobody has touched it since.
The three failure points are always the same: the interaction is split across channels, the index does not allow searching by case, and there is no reliable record of access. Any one of these, on its own, turns a minutes-long request into a days-long one. Together, they turn a routine audit into an internal emergency, with people idle, deadlines tight and the never-comfortable feeling that the answer depends on whoever happens to still remember how that old system works.
In a unified archive, you search by client number, by date, by agent or by case reference, and the voice, chat and email of that interaction appear together. Retrieval takes seconds, and comes with the record of who accessed it attached. What was a hunt for a file becomes a search.
The difference is not one of speed, but of nature. In a hunt for a file, the result depends on tacit knowledge: knowing where to look, which system to open, who to call. In a search, the result is always the same, no matter who runs it. That is what an auditor values, not the speed of one particular person, but the guarantee that the answer exists and is reproducible.
An audit trail is the record of who accessed what, when and why. For an auditor, acceptable means three things: that it cannot be erased or edited by whoever consults it, that it logs every access and every export, and that it allows you to demonstrate that the recording handed over is identical to the original.
Without an audit trail, finding the recording solves half the problem. The other half, proving it is trustworthy, is the half that decides the audit. Showing that something exists is not the same as showing that this something is what happened. In a regulatory process, that distinction is everything.
A recording without a chain of custody is a claim, not evidence.
And in an audit, it is the evidence that decidesLegal requirements
Directive 2014/65/EU (MiFID II) requires communications connected to transactions to be kept for five years, on any channel. A competent authority may extend the period to seven years.
Regulation (EU) 2022/2554 (DORA), in force since 17 January 2025, asks what MiFID II does not: what if the archive stops? Resilience with documented RTO and RPO.
Keeping data for five years and erasing it at the end of the retention period are the same obligation. Article 5(1)(e) imposes storage limitation: keeping it longer is, in itself, a breach.
A tamper-proof record of every access and every export. Proving who listened matters as much as the recording itself. Without it, finding the file solves only half the audit.
Retention is not a single number. An operation in Portugal, another in Spain and a chat channel may all have different periods. The archive has to apply the right rule to each interaction: keep it for the legal period, erase it automatically when that ends, and keep the trail of that erasure. Configured this way, retention stops depending on someone remembering to delete.
This is the point that fails most quietly. Organisations concentrate on keeping and forget that the law also requires erasing. An archive that keeps everything «just in case» is not prudent, it is non-compliant. Erasure by rule, automatic and logged, settles both sides of the obligation at once.
Self-assessment
A short test, taken from the full assessment. Answer honestly; nobody is watching.
Your level of exposure: ,
Low risk
On all three fronts, your archive answers without relying on anyone's memory. The full assessment confirms the strengths and points out what is worth reviewing to keep them.
Medium risk
The essentials work, but they rest on manual effort and a few blind spots. In an audit you would get there, spending time and depending on the right people being available. The assessment shows where to automate.
High risk
Your archive depends on people, on separate systems and on luck, and there is probably data kept past its retention period, which is in itself a breach of the GDPR. These are known gaps with a clear solution. The report sets out what to address first.
In practice
uPlayback brings the voice, chat and email of the same interaction into a single archive, searchable by case, with a tamper-proof audit trail on every access and every export. Retention rules apply by country and by channel, with automatic erasure at the end of the retention period. When the regulator asks, the answer is one search, with the evidence included.

Continue reading
Compliance, integrations and deployment answered live, with your questions on the table and no generic pitch.