The Cost of Email Non-Compliance: What the Fines Don’t Show

Cost of non-compliance

TL;DR We write every word in our blog posts, but asked AI to summarize it

Sixteen firms agreed to pay $1.1 billion in one day, and nobody was accused of fraud. What email non-compliance really costs, in fines, lawsuits, and search bills, and what every case has in common.

On September 27, 2022, sixteen Wall Street firms agreed to pay more than $1.1 billion in penalties. On a single day.

The charges were not about fraud. What the firms admitted was simpler: their people had discussed business by text message on personal phones, the firms had not kept those messages, and so the records were likely missing when the regulator went looking. As the SEC’s enforcement director put it, recordkeeping requirements are “sacrosanct”.

It is tempting to file that under “Wall Street problems”. Most organizations will never see an SEC order. But the fine is only the most visible cost of non-compliance, and it is rarely the largest.

The cost of non-compliance is everything an organization pays for failing to meet a legal, regulatory, or contractual obligation: fines, legal judgments and settlements, the bill for finding and reviewing records, and lost trust. Only the first is specific to regulated industries. The others reach every organization that runs on email.

Cost 1: Fines and Penalties for Non-Compliance

Start with the number everyone looks for.

  • 2006: Morgan Stanley agreed to pay $15 million after the SEC said it had failed to produce tens of thousands of emails during two investigations, and had overwritten backup tapes after the subpoenas arrived. The firm settled without admitting or denying the allegations.
  • 2022: the sixteen firms above, $1.1 billion combined, with eight banking groups paying $125 million each.
  • 2024: another 26 firms, $392.75 million combined, for the same failure.

To be exact about it: the 2022 and 2024 cases were about messages sent outside the firms’ approved systems, in 2022 text messages on personal phones, and not about email. The principle is the same one that applies to email. Business communication that lives outside the system you govern is a record you cannot produce.

Fines like these are specific to regulated industries. The next three costs are not.

Cost 2: The Lawsuit You Lose Over a Missing Email

Laura Zubulake worked on the Asian equities desk at UBS Warburg. When she was passed over for a promotion, she sued her employer for discrimination. It was an ordinary employment dispute, the kind any company of any size can face.

It became one of the most cited cases in American litigation because of email. UBS first produced about 100 pages of email, while Zubulake herself had kept about 450. More turned up later, and it emerged that others had been deleted or not preserved after the company knew a lawsuit was coming. The judge told the jury it could assume the missing emails would have hurt UBS. In 2005 the jury awarded Zubulake $29.2 million.

No regulator was involved. No compliance rule specific to banking was broken. The cost came from one thing: when it mattered, the company could not show what its own email said.

This is the cost that applies to everyone. You do not need to be regulated to be sued, and in a dispute, a missing email is read against you.

Cost 3: The Search

Even when nothing is missing, finding it is expensive.

When an organization is sued or investigated, it has to find and hand over every relevant email and document. A RAND Corporation study measured what that costs, across 57 such cases at very large companies. Review, meaning lawyers reading the documents to decide what to hand over, typically took about 73% of the total bill. Collecting the documents took about 8%, and processing them about 19%. The study is from 2012 and review technology has improved since, but the shape of the bill has not changed: you pay for every message a person has to look at.

That makes two kinds of email expensive:

  • Email that was never filed. It is scattered across personal mailboxes, including those of people who have left, with nothing tying it to a project, client, or case. A search returns everything that might be relevant, and someone has to read it.
  • Email that should have been deleted. Every message kept without a reason is a message someone may have to review later. Keeping everything forever is not the safe option. It is the expensive one. That is why legal often wants email deleted, on a schedule, under a retention policy.

Cost 4: The Trust

Bainbridge Island is a small city in Washington State. Two residents asked for emails that city council members had sent and received about city business on their personal email accounts, and in 2013 they sued to get them. The city’s own governance manual required council members to use their city accounts and to forward any city email to the city for retention.

The emails were not produced. A judge ruled against the city and criticized two council members for deleting public records. The city settled for $487,790, and one of the council members agreed to resign as part of the settlement. The city had also spent more than $245,000 on its own lawyers.

For a small city that is a painful sum. The larger cost is the one that doesn’t appear in the settlement: residents learned that their city could not account for its own records. In government, and in any organization that answers to the public, to clients, or to an auditor, that is the cost that lasts.

What Every One of These Has in Common

Every one of these organizations knew what it had to keep.

The Wall Street firms had policies on business communication, and employees at every level, senior executives included, did not follow them. Bainbridge Island had a governance manual that said exactly what to do with city email. UBS staff had been instructed to preserve the emails. Morgan Stanley already had the subpoenas.

In every case the obligation was clear. The record was in the wrong place: on a phone, in a personal account, on a backup tape, in one employee’s mailbox. A policy describes where records should be. It does nothing to move them there.

That is the real lesson of the cost of non-compliance. Organizations rarely fail because they decided to break a rule. They fail because doing the right thing with an email took effort, at a moment when someone was busy, and so it did not happen.

How to Lower the Cost of Non-Compliance

  1. Decide which emails are records. Not all of them are. What makes an email a record is its content, not its format.
  2. Keep those where the organization can reach them. In Microsoft 365 that means a SharePoint or Teams location with the rest of the project, case, or client file, not a personal mailbox.
  3. Make saving them take seconds. Anything slower will be skipped, and a skipped email is the one you will be asked for.
  4. Delete the rest on a schedule. Once the emails that matter are safely kept, the others can go, and your future search bill shrinks with them.

Steps 2 and 3 are what harmon.ie is built for. It puts SharePoint, Teams, and OneDrive in a sidebar inside Outlook, so saving an email to the right location is a drag and drop. The sender, recipients, subject, and date are written into SharePoint columns on every save, so the email can be found later by search or filter. With email automation, you set rules and harmon.ie keeps saving the right emails for you: every new message in a conversation, emails from a sender you save regularly, or every new email that lands in an Outlook folder. Capturing a record no longer depends on someone remembering to save it. Once an email is in SharePoint, it is covered by the Microsoft 365 retention settings of that location, which is what makes step 4 possible. And because harmon.ie is a client-side application, the email goes from Outlook to your own Microsoft 365 tenant and nowhere else.

Two customers show both halves of the result. A US federal government agency became 100% compliant with government directives, with uptake of almost 100% and no training required. A global hospitality chain deleted over 35 million redundant emails and preserved 40,000 valuable records in two months, during the initial rollout. Keeping the right emails is what made it safe to delete the rest.

This article is for general information and is not legal advice. Retention and recordkeeping obligations vary by industry and jurisdiction.

Email automation is now in beta.

See how harmon.ie keeps the right emails where you can find them. Explore the email compliance solution →

Start a free 21-day trial – no credit card required →

Did you find this content interesting? Subscribe to stay updated.

Email Automation

First look: email automation in New harmon.ie

See how New harmon.ie saves the right emails to Microsoft 365 for you.