Digital sovereignty: why the Cloud Act changes your architecture
Where your recordings live has stopped being a technical decision. It is a decision about legal exposure, and it belongs to the board.
Read article →MiFID II
Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide an audit.

A MiFID II audit rarely begins with a request for one specific recording. It begins with an indirect test: the auditor wants to know whether the organisation controls its own archive. The first questions are not about what was said on a call, they are about whether that call can be found, evidenced and retained for the right length of time. Anyone who answers these seven questions comfortably has already cleared the hardest part of the inspection.
The first question is almost always operational. The auditor names a client, a date and a channel, then watches how long it takes for the interaction to appear on screen. What is at stake is not whether the recording exists, but whether it can be located in a single portal, by business criteria, without calling in technical teams or exporting databases by hand.
Article 16(7) of MiFID II and Delegated Regulation (EU) 2017/565 require records to be available at the request of the competent authority. In supervisory practice, «available» has been read as retrievable independently and promptly, not as «existing somewhere on some medium».
The second question turns the focus to access. Every playback, export or search must leave a trace. The auditor looks for an audit trail that records the user, the moment, the action and, ideally, the reason attached to the access. An archive that returns the recording but cannot say who touched it raises more questions than it answers.
MiFID II sets a minimum retention period of five years, extendable to seven at the request of the competent authority. But the auditor knows that «five years for everything» is the mark of an immature system. Different channels and different jurisdictions impose different rules, and a credible archive reflects that granularity.
Location has stopped being an infrastructure detail. The auditor asks which territory the recordings live in, under which jurisdiction the hosting providers operate, and who can lawfully demand access to that data. The answer has to be precise and documented, not an estimate.
In an audit, the question that separates the prepared from everyone else is not «do you have the recording?». It is «can you prove who accessed it, show where it is, and guarantee it will still be there five years from now?».
Retrieving a recording to listen to it is one thing; handing it over as evidence is another. The fifth question is about controlled export: the file leaves with its metadata, with a record of the export itself, and with assurance that nothing was altered between the archive and the recipient. An export without a chain of custody carries fragile evidential weight.
Retention periods almost always outlast the life of any vendor. The auditor, and before the auditor a prudent compliance department, asks what happens to the recordings at the end of a contract. Portability in open formats, with the associated metadata, is what stops a change of supplier from turning into a regulatory incident.
The last question is about resilience, and this is where MiFID II meets DORA, in force since January 2025. The auditor wants to know how much data can be lost in an incident (RPO) and how long the archive takes to become available again (RTO). These figures have to be documented, tested, and consistent with the obligation to keep records accessible throughout the retention period.
Seven questions, one shared logic: MiFID II compliance is not measured by the ability to record, but by the ability to govern what has been recorded. Find, evidence, retain and demonstrate, in that order. An archive built around those four capabilities answers all seven questions before the auditor has finished the first.
Published by the uPlayback team, a Grupês product. Three decades of experience in compliance recording.
Continue reading
Sovereignty Where your recordings live has stopped being a technical decision. It is a decision about legal exposure, and it belongs to the board.
Read article →
DORA Since January 2025, operational resilience is a regulatory outcome, not a document. What that demands of every capture pipeline.
Read article →
Platform Compliance fails at the seams. A single governed archive is what makes a compliance project achievable.
Read article →Compliance, integrations and deployment answered live, with your questions on the table and no generic pitch.