Social media is a growing source of compliance headaches for enterprises, as workers communicating via social channels increasingly opens organisations up to greater risks. Effects extend from recordkeeping failures to market manipulation, and bad actors are increasingly able to hack social media accounts with malicious intent. For some, especially businesses in regulated industries such as financial services, compliance risks – and the impact of social media – are coming to the fore.
The collapse of Silicon Valley Bank in 2022, for example, was accelerated by panic on social media that saw backers remove their funding, hastening the bank’s failure. It’s not just social ‘hype’ that’s dangerous, the US Securities and Exchange Commission’s (the Commission) X account was hacked in a SIM swapping attack in January 2024, resulting in significant market impact. The attackers published false information that the Commission had approved spot bitcoin exchange-traded funds being published, triggering a US$40bn market swing.
Tighter Regulation Raises the Stakes
Non-compliance across social channels is now a big deal. M1 Finance, a firm offering a robo-advisory investment platform, has been fined US$850,000 by the US Financial Industry Regulatory Authority (FINRA) to settle claims that about 1,700 social media influencers paid by the firm made misleading or exaggerated claims to attract investors.
Undue volatility caused by social media interactions is unacceptable to regulators and enterprises. With that in mind, tighter regulation is being introduced, alongside improved approaches and policies for compliant social media usage.
The UK’s Financial Conduct Authority (FCA) has warned firms and influencers to keep their social media advertising lawful. The organisation has set out guidance for memes, reels and gaming streams that promote financial services, and reported that it removed more than 10,000 misleading advertisements in 2023, up from 8,500 in 2022. Meanwhile, the SEC’s new Marketing Rule in the US requires firms to capture all social media channels if they are used for commercial purposes.
Capture is the Core of Compliance
Misuse of social media channels is not only confined to external bad actors and over-zealous influencers. Employees themselves can pose social media risks, even when using approved work channels such as LinkedIn. This is especially true where employees use LinkedIn to communicate for business purposes, falling outside of compliance policies or recordkeeping requirements. LinkedIn is increasingly a source of non-compliant communications, and firms are becoming cognisant of this risk - according to recent research from Global Relay, 33% of firms are capturing LinkedIn data.




