MiFID II

MiFID II: the seven questions an auditor asks first

Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide an audit.

MiFID II: the seven questions an auditor asks first

A MiFID II audit rarely begins with a request for one specific recording. It begins with an indirect test: the auditor wants to know whether the organisation controls its own archive. The first questions are not about what was said on a call, they are about whether that call can be found, evidenced and retained for the right length of time. Anyone who answers these seven questions comfortably has already cleared the hardest part of the inspection.

1. Can you retrieve a specific interaction in minutes?

The first question is almost always operational. The auditor names a client, a date and a channel, then watches how long it takes for the interaction to appear on screen. What is at stake is not whether the recording exists, but whether it can be located in a single portal, by business criteria, without calling in technical teams or exporting databases by hand.

Article 16(7) of MiFID II and Delegated Regulation (EU) 2017/565 require records to be available at the request of the competent authority. In supervisory practice, «available» has been read as retrievable independently and promptly, not as «existing somewhere on some medium».

2. Who listened to this recording, when, and on what grounds?

The second question turns the focus to access. Every playback, export or search must leave a trace. The auditor looks for an audit trail that records the user, the moment, the action and, ideally, the reason attached to the access. An archive that returns the recording but cannot say who touched it raises more questions than it answers.

3. Is retention configured by channel and by jurisdiction?

MiFID II sets a minimum retention period of five years, extendable to seven at the request of the competent authority. But the auditor knows that «five years for everything» is the mark of an immature system. Different channels and different jurisdictions impose different rules, and a credible archive reflects that granularity.

  • Trading voice and orders: the full regulatory retention period, no exceptions.
  • Chat and messaging channels tied to transactions: treated exactly like the equivalent voice.
  • Interactions with no transactional relevance: shorter policies, aligned with the minimisation principle.
  • Jurisdictions with their own regimes: local rules applied by policy, not by manual exception.

4. Where does the data physically reside?

Location has stopped being an infrastructure detail. The auditor asks which territory the recordings live in, under which jurisdiction the hosting providers operate, and who can lawfully demand access to that data. The answer has to be precise and documented, not an estimate.

In an audit, the question that separates the prepared from everyone else is not «do you have the recording?». It is «can you prove who accessed it, show where it is, and guarantee it will still be there five years from now?».

5. Can you export evidence with verifiable integrity?

Retrieving a recording to listen to it is one thing; handing it over as evidence is another. The fifth question is about controlled export: the file leaves with its metadata, with a record of the export itself, and with assurance that nothing was altered between the archive and the recipient. An export without a chain of custody carries fragile evidential weight.

6. And if you need to migrate platforms, is the data portable?

Retention periods almost always outlast the life of any vendor. The auditor, and before the auditor a prudent compliance department, asks what happens to the recordings at the end of a contract. Portability in open formats, with the associated metadata, is what stops a change of supplier from turning into a regulatory incident.

7. What is the RPO and the RTO of this archive?

The last question is about resilience, and this is where MiFID II meets DORA, in force since January 2025. The auditor wants to know how much data can be lost in an incident (RPO) and how long the archive takes to become available again (RTO). These figures have to be documented, tested, and consistent with the obligation to keep records accessible throughout the retention period.

Seven questions, one shared logic: MiFID II compliance is not measured by the ability to record, but by the ability to govern what has been recorded. Find, evidence, retain and demonstrate, in that order. An archive built around those four capabilities answers all seven questions before the auditor has finished the first.

Published by the uPlayback team, a Grupês product. Three decades of experience in compliance recording.

Continue reading

More from our blog.

Digital sovereignty: why the Cloud Act changes your architecture Sovereignty

Digital sovereignty: why the Cloud Act changes your architecture

Where your recordings live has stopped being a technical decision. It is a decision about legal exposure, and it belongs to the board.

Read article →
DORA in practice: RPO, RTO and the end of the generic DR plan DORA

DORA in practice: RPO, RTO and the end of the generic DR plan

Since January 2025, operational resilience is a regulatory outcome, not a document. What that demands of every capture pipeline.

Read article →
Voice, chat and email: why three systems are a risk Platform

Voice, chat and email: why three systems are a risk

Compliance fails at the seams. A single governed archive is what makes a compliance project achievable.

Read article →

Ready when you are.

Compliance, integrations and deployment answered live, with your questions on the table and no generic pitch.

Book a Demo Take the assessment