Work in financial services, healthcare or any other regulated sector and there is a fair chance you carry a regulatory duty to record particular employee communications, voice calls placed through Teams included. Compliance recording in Teams is a fundamentally different animal from the "Record" button participants see during a meeting, and treating the two as one produces compliance gaps that are hard to account for to regulators.
This article sets out that difference, the technical workings of compliance recording, and the considerations to weigh before rolling it out.
Compliance Recording Distinguished from Convenience Recording
Convenience recording, occasionally called "ad-hoc recording", is what a meeting participant starts by pressing the "Record" button. The result lands in the organiser's the personal file store or in a the file service channel library. Meeting policies govern it, with the admin deciding whether users may start it at all, but at bottom it is voluntary and user-initiated.
Compliance recording diverges on every point that matters. It is:
- Policy-based rather than user-initiated: Designated users are recorded automatically because of the policy assigned to them, and they have no ability to opt out.
- Stored somewhere compliance-specific: Not the personal file store and not the file service, but a compliance recording store run by the recording solution, which is usually a third-party recording platform.
- Captured at media stream level: Rather than screen-recording the meeting, compliance recording taps the audio and video stream directly through the vendor's Teams Policy-Based Recording architecture.
- Not interruptible: A participant attempting to end the recording or leave the call does not stop the compliance capture, which runs for as long as the policy applies.
- Announced in the client: The presence of a recording bot is visible to participants. Whether such a banner meets a given statute is a legal question rather than a Teams setting.
- Held outside the cloud suite: The file belongs to the recording platform, not to the personal file store, so a retention label applied to the personal file store has no authority over it.
How Teams Policy-Based Recording Is Architectured
Compliance recording in Teams runs on a policy-based recording architecture first introduced several years ago. The mechanism proceeds like this:
- An administrator defines a compliance recording policy in the Teams Admin Center.
- That policy points at a recording application, being a certified third-party recording bot registered in the cloud platform.
- The policy gets assigned to particular users, namely the custodians who must be recorded.
- A user covered by the policy joins a call or meeting, and the recording bot is invited automatically as a participant and starts capturing the media stream.
- Whatever was recorded is transmitted to the recording platform, whether third-party or the vendor's own compliance recording infrastructure.
The practical consequence is that policy-based recording demands a third-party compliance recording solution, or the vendor's own compliance recording product. Teams does not include it free of charge: extra licensing and a compatible recording platform are required. The vendor's list of certified compliance recording partners appears in the Teams documentation.
Configuring the Compliance Recording Policy
Compliance recording policies live in the Teams Admin Center under Voice > Compliance recording policies. In more recent Admin Center layouts they sit in the left-hand navigation beneath the "Enhanced encryption policies" section, so verify the current placement, as it shifts from time to time.
Every policy names a recording application, identified by its the cloud platform app ID, and sets a recording mode: required, which blocks calls when the recording bot is unavailable; optional, which lets calls proceed regardless; or disabled, which switches recording off for that policy.
"Required" is the mode for environments where regulation insists that every covered communication gets recorded. Should the recording system be unavailable when a covered user places a call, the call is blocked instead of going ahead unrecorded. For regulated industries, that is the cautious, compliance-safe choice.
What Sorts of Calls Fall Under It?
Teams compliance recording policies are able to cover:
- One-to-one Teams audio and video calls
- Teams PSTN calls, where Teams Phone has been deployed
- Teams meetings, ad-hoc, scheduled and channel meetings alike
Any call with at least one policy-assigned participant falls under the policy. Whether the recording takes in every participant or only the audio of the covered one depends on which recording platform you run and how it is configured. Get to know your platform's data capture model before you tell regulators what is and is not being recorded.
Consent and Disclosure Obligations
Wherever call recording is mandated for financial or healthcare communications, disclosure duties usually come with it: the other parties have to be told the call is being recorded. Teams Policy-Based Recording can be set to play a disclosure announcement at the beginning of a recorded call. Precise requirements differ across jurisdictions and regulations, MiFID II, Dodd-Frank, HIPAA and the rest, so talk to your compliance team before treating Teams compliance recording as your only disclosure mechanism.
A "Recording in progress" banner in the meeting UI should not be assumed adequate for your particular regulatory requirements. Verbal disclosure is demanded by some regulations, consent by others. Establish which applies before you deploy.
How Compliance Recordings Are Stored and Searched
The recording platform's compliance store holds compliance recordings, not Teams and not the personal file store. Reaching them for regulatory review or eDiscovery means going through the recording platform's own interface rather than the compliance portal, which is a material difference from convenience recordings, since those sit in the cloud suite and are searchable through compliance portal eDiscovery.
Check that the compliance recording platform you pick plugs into your eDiscovery workflow and that recordings fall under suitable retention policies. Retention settings on the recording platform and in your the compliance portal have to line up, so that recordings are kept for the full regulatory period required.
The Call That Connects While the Recorder Bot Is at Capacity
How strict Teams compliance recording is comes down to the policy mode. Under required mode, a call or meeting that cannot attach the recording bot should not go ahead for a user covered by the policy. Under optional mode, that identical failure yields a connected call with no recording behind it. Regulated teams frequently believe that buying a recorder means they have required mode; the mode is its own setting, and optional is the usual default in the vendor's starter template.
A brokerage with 200 covered staff migrated to Teams Phone and switched on a certified recorder. While the vendor completed capacity planning, the policy sat in optional mode for two weeks and calls carried on succeeding. Sampling the recorder's catalogue revealed gaps in the busiest hour, when the bot pool ran dry and the calls proceeded without it. No one had been asked to reconcile the phone log against the recording catalogue. Doing so was what prompted the move to required mode and resized the bot pool to the peak instead of the average.
If the recorder fails, required mode blocks the business. That is deliberate, and it demands an operational owner: who gets paged, how staff are instructed to place the call some other way where regulation permits a fallback, and how the blocked-call tally gets reviewed. Hand over a required policy with nobody watching the failure counter, and it will be relaxed to optional during the first outage and left there.
Coverage attaches to the user, not to a phone number and not to a team. A trader with the policy is recorded; a colleague without the policy who joins that same meeting may still be captured because the bot is present, depending on the platform. Get that behaviour confirmed in writing by the vendor before you describe it to compliance. "We record the desk" holds true only when every person on the desk has the policy assigned, new joiners in their first week included.
The recording platform governs recording retention. Match it to the schedule applied to the related chat, and rehearse a retrieval by case id or by user and date. A recording nobody can locate via the helpdesk route counsel will genuinely use is not retained in any sense that counts. Carry out that retrieval test ahead of the first live matter, not in the middle of it.
New starters in a covered role need the policy on the day they become able to place a call, not at the close of onboarding. Someone with two accounts is recorded only on whichever account carries the policy, so map the accounts before go-live. Meeting recording begun with the Record button is no substitute for compliance recording and must not be presented as one in the control statement. Test three call types: inbound PSTN, outbound PSTN and Teams-to-Teams, because proving only one leaves the others unverified. Where disclosure plays at the start of the call, listen to it on an actual handset, since a clip set too quietly is a disclosure that never happened. Size capacity from peak concurrent calls rather than the daily average, because the bot shortage surfaces at the peak. Reconcile call logs against recording logs for the same hour rather than the same day, because the gap shows up in the busy hour. Prove required mode by disabling the bot for a test user inside a maintenance window and confirming the call fails. Write the fallback procedure before the first outage, even where the procedure reads "do not place the call". Covered users who move role should drop the policy as they leave the desk, otherwise you end up recording people you no longer intend to. Re-check the disclosure clip after every vendor upgrade, since upgrades are when audio prompts get lost. Read retention back from the recorder's own settings screen rather than from the sales proposal. Keeping a user on leave inside the policy is correct while their account can still place calls; once the account is disabled, the policy is moot.