WORM Compliance and What SEC 17a-4 Actually Requires
WORM is one of two ways to satisfy the SEC's electronic records rule, and since 2022 it is no longer the only one. Knowing which route your vendor takes matters more than the acronym.
Sealed, hash-verified records · Built for SEC 17a-4, FINRA, HIPAA & CJIS programmes · Email, Teams chats, Drive, AI assistants & more
What is WORM compliance?
WORM stands for write once, read many: storage that accepts a record once and then physically prevents it being rewritten or erased for a set period. In recordkeeping, WORM compliance is shorthand for meeting SEC Rule 17a-4(f) by keeping records in non-rewriteable, non-erasable form. In October 2022 the SEC amended the rule, and since then a firm may instead meet it with an audit-trail alternative: a system that maintains a complete record of every change, so an original record can be recreated and any alteration is evident. Both routes are valid; they make different promises, and they fail in different ways.
Key capabilities
Choosing between the two routes
- Ask any vendor which route they take, and ask them to show it — a claim of WORM is a claim about storage, not a feature flag
- The audit-trail route answers a broader question: not only was this record preserved, but who looked at it, when, and what they did next
- If your written procedures specify storage-level locking, it can be enabled for your archive without a migration
- An auditor role can verify the chain of custody without being able to read a document, so verification does not require handing over access
Frequently asked questions
Does SEC 17a-4 still require WORM storage?
Not exclusively. Since the amendments adopted in October 2022, Rule 17a-4(f) permits an electronic recordkeeping system to meet the requirement either by preserving records in a non-rewriteable, non-erasable format or by maintaining an audit trail that allows the original record to be recreated if it is altered or deleted. Firms should confirm which route their system takes and reflect it in their written procedures.
Is Grotabyte WORM storage?
No, and it does not describe itself that way. Grotabyte takes the audit-trail route: sealed, hash-verified records on a tamper-evident, hash-chained ledger, with every access and export recorded. Storage-level retention locking is available on request as an additional control.
What is the difference between a retention lock and WORM?
A retention lock prevents deletion and overwriting for a defined term, including by accident and by automated lifecycle rules — which was confirmed by measurement. It differs from non-rewriteability because whoever holds the storage account can lift the rule, after which the object can be deleted. That distinction is why the two terms should not be used interchangeably.
How do I know a record has not been altered?
Every record is sealed with a SHA-256 hash that is chained to the previous entry. Altering or removing a record breaks the chain at that point, and chain verification reports it. The verification can be run by an auditor who has no ability to read the documents themselves.
See worm compliance in action
Book a personalized demo and see how Grotabyte fits your data sources and compliance requirements.