Email Migration for Financial Services and Accounting Firms: A Compliance-First Guide to Microsoft 365 and Google Workspace
Email migration for a financial advisory practice, CPA firm, or bookkeeping business is not the same project as migrating email for a retail shop or a marketing agency. Every mailbox in a financial services or accounting environment doubles as a regulatory record. Get the migration wrong and a firm doesn’t just lose emails; it creates a books-and-records gap that surfaces during an SEC exam, a FINRA audit, or an IRS inquiry, sometimes years after the fact. This mirrors the same records-first approach we take with other guides, including our Email Migration for Law Firms and Email Migration for Schools.
This guide walks IT decision-makers, compliance officers, and firm administrators through what makes email migration different for registered investment advisers (RIAs), broker-dealers, CPA firms, tax preparers, and bookkeeping practices, and how to plan a migration that keeps every record intact and defensible. For a breakdown of what a compliance-grade migration typically costs, see our Email Migration Costs Guide.
Why Financial and Accounting Firms Can’t Migrate Like Everyone Else
A standard SMB migration guide will tell you to move mailboxes, verify mail flow, and retrain users on the new interface. For a financial services or accounting firm, that’s the easy 80%. The hard 20% is everything tied to recordkeeping law:
- Retention obligations that outlast the migration project by years. A dropped folder, a broken legal hold, or a silently failed journal rule doesn’t show up as an error message. It shows up eighteen months later as a missing record during an examination.
- Multiple overlapping regulators. A hybrid firm (say, a CPA practice that also offers investment advisory services) can be answering to the SEC, FINRA, the IRS, and the FTC simultaneously, each with a different retention clock.
- Litigation holds and supervisory reviews that must survive the platform switch. If a hold was placed in the old system, it has to carry over cleanly, not just to the new mailbox, but to the new platform’s hold mechanism.
- A narrow window for the actual cutover. Tax season (roughly January through April, plus extension deadlines in September and October) and quarter-end reporting periods are effectively off-limits for anything that risks mailbox downtime.
The Regulatory Landscape, Mailbox by Mailbox
Before touching a migration tool, map which rules apply to which mailboxes. The requirements differ meaningfully depending on whether a firm is a broker-dealer, an RIA, a tax preparer, or some combination.
Broker-dealers: SEC Rule 17a-4 and FINRA Rule 4511
Broker-dealers must preserve business-related email communications, and FINRA Rule 4511 and SEC Rule 17a-4 require preservation for at least three years in a secure, auditable, and retrievable manner. Under the rule’s content-based standard, the communication channel is irrelevant: if a message relates to the firm’s business, it must be captured and retained regardless of which medium carried it. The first two years of records must remain in an easily accessible format, per Rule 17a-4(b)(4)’s requirement that the first two years of business-related communications stay in an easily accessible place.
Critically, records must be stored in a non-rewriteable, non-erasable format, commonly referred to as WORM (Write Once, Read Many). This is where migrations go wrong most often: moving a WORM-archived mailbox from one platform to another can break the very immutability that made it compliant in the first place, unless the receiving platform’s retention lock is configured before a single message lands.
Registered investment advisers: Investment Advisers Act Rule 204-2
RIAs operate under a longer clock. Most records must be kept for at least five years from the end of the fiscal year in which they were created, with the most recent two years immediately accessible at the firm’s principal office. The rule’s scope is broad by design: advisers must keep originals of all written communications received and sent related to advisory activities, along with copies of advertisements and newsletters. Regulators have made clear this isn’t limited to email in the narrow sense; business-related communication on platforms like Teams, Slack, or WhatsApp needs to be captured and archived just as rigorously as email. Firms migrating a mixed Teams-and-email environment need to confirm both channels are captured under the new platform’s retention policy before decommissioning the old one.
CPA firms and tax preparers: IRS retention rules and the WISP requirement
Tax return preparer retention obligations run through Internal Revenue Code Section 6107(b), which sets a baseline three-year retention period tied to the return’s filing, though many practitioners retain records for six to seven years as a defensive practice given the IRS’s extended lookback windows for substantial underreporting. Separately, and often overlooked in migration planning, tax preparers are legally classified as financial institutions under the Gramm-Leach-Bliley Act. Accounting firms that qualify as financial institutions under the Act are subject to the FTC Safeguards Rule, which independently requires a formal written information security program. The FTC’s updated Safeguards Rule requires designating a qualified security program coordinator, conducting formal risk assessments, and implementing encryption and multi-factor authentication for systems containing customer financial data. That Written Information Security Plan (WISP) has to name the specific platform, MFA configuration, and encryption standards in use, which means it needs a documented update the moment a firm changes email providers. Tax preparers must certify they have a WISP in place as part of their annual PTIN renewal, and falsely certifying constitutes perjury that can result in PTIN revocation and license suspension.
Platform Compliance Comparison: Microsoft 365 vs. Google Workspace for Regulated Firms
Both platforms can meet SEC and FINRA recordkeeping standards, but they get there differently, and the gap matters for firms choosing a destination platform during migration. If you’ve already settled on a direction, our Google Workspace to Microsoft 365 migration guide and Microsoft 365 to Google Workspace migration guide cover the technical migration steps in detail; for firms still deciding between the two, see our Microsoft 365 vs. Google Workspace comparison.
Microsoft 365 ties its compliance case to Microsoft Purview’s Preservation Lock. Once Preservation Lock is enabled on a retention policy, it can’t be disabled, and no data collected under that policy can be overwritten, modified, or deleted during the preservation period, not even by an administrator. Microsoft has commissioned independent Cohasset Associates assessments confirming this satisfies SEC Rule 17a-4(f), and Microsoft 365 supports the rule’s Audit Trail Alternative through Purview Data Lifecycle Management, eDiscovery (Premium), and Audit (Premium).
Google Workspace meets the same requirements through a different path. Google’s native Vault does not independently satisfy WORM requirements out of the box; instead, Cohasset’s assessment found that Google’s functionality with AODocs Compliance Archive meets the SEC requirement to retain records in non-rewriteable, non-erasable format for applied retention periods and legal holds, when properly configured. Google also offers a contractual path for the SEC’s third-party undertaking requirement: firms can request a SEC 17a-4(i) Addendum or SEC 18a-6(f) Addendum for Google Cloud and Google Workspace, after which Google can sign the required Alternative Undertaking and share it with the customer to submit to regulators.
The practical takeaway for a migration project: neither platform is compliant by default. One compliance consultant who has audited both put it plainly: Microsoft 365, Google Workspace, and every other major platform can be part of a compliant architecture, but only if configured, retained, supervised, archived, and tested correctly, because the product name doesn’t make the system compliant. A migration plan for a regulated firm needs a retention and immutability configuration step before go-live, not after.
The Security Case for Getting This Migration Right
Financial and accounting firms are disproportionately targeted by email-based fraud, which raises the stakes on migration security specifically (temporary relaxed spam filtering, forwarding rules left over from a transition period, or delayed MFA rollout are exactly the kind of gaps attackers look for). For the broader SMB threat picture, see our Phishing and Email Security stats article.
The scale of the threat: business email compromise in 2025 resulted in $3.04 billion in reported US losses across 21,442 FBI IC3 complaints, with an average loss per complaint of $141,000, marking a new record after a brief dip in 2024. Wire-fraud attempts are also accelerating in frequency, with wire-transfer BEC attempts surging 136% quarter-over-quarter in Q4 2025 alone, at an average requested wire amount just over $50,000. Finance and accounting functions are named targets, since attackers specifically go after finance, procurement, and executive-support teams because those roles can authorize changed bank details, payroll updates, and invoice approvals. Sector-specific data confirms accountants and advisers aren’t a hypothetical target: 35.9% of IT and security professionals at financial services firms report experiencing a business email compromise incident resulting in financial or data loss within the past 12 months.
A migration is a natural point to close gaps rather than reopen old ones: enforce MFA on day one of the new platform rather than “soon after,” retire legacy authentication protocols that don’t support modern MFA, and audit inherited mail-forwarding rules before flipping DNS, since dormant forwarding rules are a documented technique attackers use in compromised mailboxes to maintain persistent access.
A Compliance-Safe Migration Framework
1. Inventory before you touch anything. Catalog every mailbox by regulatory classification (broker-dealer records, RIA advisory communications, tax preparer files, general business mail) before scoping the migration. Mixed-purpose mailboxes need the strictest applicable retention rule.
2. Confirm and document all active legal holds and supervisory reviews. Any open litigation hold or FINRA/SEC supervisory review must be mapped to its equivalent mechanism on the destination platform (Purview eDiscovery holds on Microsoft 365, or Vault holds paired with a compliant archive layer on Google Workspace) before the source mailbox is decommissioned.
3. Configure retention and immutability on the destination platform first, migrate second. Enable Preservation Lock (Microsoft 365) or configure the compliant archive layer (Google Workspace) and validate it against a test mailbox before migrating a single regulated record. Migrating into an unconfigured destination, even briefly, can create a gap in the chain of custody.
4. Preserve chain of custody metadata. Original sent/received timestamps, message headers, and journal records need to survive the migration intact. Confirm the migration tool preserves this metadata rather than resetting it to the migration date, which is a common default behavior worth explicitly checking.
5. Schedule around the regulatory calendar, not just the IT calendar. Avoid cutover during the two weeks before quarterly FINRA filing deadlines, the run-up to April and October tax deadlines, and SEC exam response windows if a firm is currently under review.
6. Update the WISP and compliance manual the same week as go-live. The written security plan and any FINRA/SEC compliance manual references to “our email system” need to reflect the new platform, MFA configuration, and archive vendor immediately, not at the next annual review cycle.
7. Re-verify with a Rich Results or archive audit test post-migration. Before declaring the migration complete, run a sample eDiscovery search across the full retention window to confirm historical mail migrated correctly and remains searchable and immutable.
Choosing a Migration Partner for a Regulated Firm
Not every managed service provider has handled a books-and-records-sensitive migration before. When vetting a partner, ask directly:
- Have they migrated mailboxes under active FINRA or SEC supervisory hold, and can they describe how continuity was preserved?
- Do they configure Purview retention policies or Google Vault/compliant-archive settings as a standard part of the migration, or is that scoped separately (and often forgotten)?
- Can they provide a written chain-of-custody summary for the migration itself, something a compliance officer can hand to an examiner if asked how records were preserved during the platform change?
- Do they schedule cutover around a firm’s specific regulatory calendar rather than a generic “off-hours weekend” default?
Frequently Asked Questions
Does migrating to a new email platform reset our SEC or FINRA retention clock?
No. The retention period is tied to when the record was originally created, not when it was migrated. However, the firm remains responsible for proving an unbroken chain of custody across the migration, which is why documenting the process matters as much as the technical steps.
Is Google Workspace SEC 17a-4 compliant out of the box?
Not by default. Google Workspace can meet the requirement, but typically requires a compliant archive layer configured alongside Vault, plus a signed SEC addendum from Google covering the third-party undertaking requirement. Firms should confirm this configuration during migration planning rather than assuming native settings are sufficient.
Is Microsoft 365 SEC 17a-4 compliant out of the box?
Microsoft 365’s native retention tools can meet the requirement once Preservation Lock is properly enabled on a retention policy, but this configuration is not automatic. It must be set up deliberately as part of (or immediately after) migration, not left as a default setting.
How long do accounting firms need to keep client emails after a migration?
It depends on the record type and applicable rule. Tax return-related records generally need a minimum of three years per IRC Section 6107(b), though many firms retain records for six to seven years given the IRS’s extended audit lookback for substantial underreporting. Firms also offering advisory services may face the longer five-year RIA retention standard under Investment Advisers Act Rule 204-2 for advice-related communications.
Does our firm need a new WISP after switching email providers?
Yes. The FTC Safeguards Rule and IRS Publication 4557 both require the written information security plan to reflect the firm’s actual current systems, including the specific email platform, MFA implementation, and encryption in use. An outdated WISP that still names the old platform is a documented compliance gap.
Need expert help? EMNMS is here to help with all your email management needs!
Recent Comments