MiFID II: the seven questions an auditor asks first
Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…
Read article →Security
Capturing the interaction is half the job. The other half is evidencing every access, with no exceptions and no gaps.

There is an asymmetry many organisations discover too late: recording an interaction is the easy part. The effort, the infrastructure and the technology all concentrate on capture. But a compliance recording is not worth anything for merely existing, it is worth what it can be trusted for. And that trust rests on a question the regulator invariably asks: who accessed this record, when, and on what grounds? Without a tamper-proof answer, the recording itself falls under suspicion.
A recording anyone can reach, leaving no trace, is a liability rather than an asset. It holds personal data subject to the GDPR, sensitive market information and, frequently, confidential client content. If the organisation cannot demonstrate who listened to what, it is not just failing a control, it is opening a confidentiality weakness that can contaminate the evidential value of the whole archive. Evidencing access is not a complement to capture; it is the condition of its credibility.
The starting point is least privilege: each user reaches only what their role requires. That translates into clearly defined profiles, where access follows from the role rather than being granted case by case:
Integration with Active Directory, LDAP or Azure AD ensures these profiles reflect real corporate identity, and that someone leaving the organisation has their access revoked immediately, without depending on a parallel manual process.
The decisive question in an audit is not «does the access log exist?». It is «could that log have been altered by someone with something to hide?». An audit trail is only worth what its immutability is worth.
An audit trail only does its job if it is tamper-proof, meaning that no user, system administrators included, can edit or delete it. Every relevant action leaves a permanent record: playing a recording, exporting it, running a search, a denied access attempt, a change to a retention policy. The record captures the user, the exact moment, the action and the object it applied to. Immutability is what separates an operational log, which exists for diagnostics, from a regulatory audit trail, which exists as evidence.
This requirement has direct regulatory backing. Delegated Regulation (EU) 2017/565, which implements MiFID II, requires records to be kept on a medium that prevents manipulation or alteration. DORA, in turn, requires detailed event logs that allow incidents to be reconstructed. In both cases, an access trail that can be edited does not meet the requirement.
The riskiest moment in the life of a recording is when it leaves the archive. An uncontrolled export cancels every preceding control: once the file is out, it is no longer under the audit trail. Extraction should therefore follow a workflow, request, justification, approval by someone other than the requester, and a record of the entire sequence. Separating who asks from who authorises is the control that stops any single individual removing content unsupervised. Each export is itself documented in the tamper-proof log.
There is a further benefit that shows up outside the audit: deterrence. When every user knows that each access is recorded permanently and can be reviewed, behaviour itself changes. Improper access stops being a low-cost temptation and becomes an act that leaves a trace and will have to be justified. A tamper-proof audit trail does not only serve to reconstruct what happened; it reduces the chance of something happening that should not.
In an inspection, the audit trail is often the first thing examined, before the content of the recordings. The reason is simple: it demonstrates governance maturity. An organisation that knows, at any moment, who accessed each record, when and why, conveys control. One that does not conveys the opposite, and from that moment on every recording it produces carries an implicit doubt. Capture proves the interaction happened. The audit trail proves the organisation deserves to be keeping it.
Published by the uPlayback team, a Grupês product. Three decades of experience in compliance recording.
Continue reading
MiFID II Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…
Read article →
Sovereignty Where your recordings live has stopped being a technical decision. It is a decision about legal exposure, and it belongs to the board.
Read article →
DORA Since January 2025, operational resilience is a regulatory outcome, not a document. What that demands of every capture pipeline.
Read article →Compliance, integrations and deployment answered live, with your questions on the table and no generic pitch.