By Sagar Shankaran, Founder of CallSphere
Understand MiFID II call recording obligations, retention periods, and enforcement risks so your financial firm stays compliant and avoids costly penalties.
Key takeaways
The Markets in Financial Instruments Directive II (MiFID II) came into force on January 3, 2018, and its communication recording requirements remain one of the most operationally demanding aspects of financial regulation in Europe. Eight years later, regulators continue to issue fines for non-compliance — the FCA alone levied over 12 million GBP in communication-recording-related penalties in 2025.
For any firm that receives and transmits orders, executes transactions, or provides investment advice within the EU or UK, MiFID II Article 16(7) mandates the recording and retention of all telephone conversations and electronic communications related to — or intended to relate to — client orders and transactions.
This is not optional. It is not limited to trades that actually execute. The phrase "intended to relate to" captures exploratory conversations, price discussions, and even calls where the client decides not to proceed.
Under MiFID II and the associated delegated regulation (EU 2017/565), firms must record:
flowchart LR
CALLER(["Client or Lead"])
subgraph TEL["Telephony"]
SIP["Twilio SIP and PSTN"]
end
subgraph BRAIN["Financial Services AI<br/>Agent"]
STT["Streaming STT<br/>Deepgram or Whisper"]
NLU{"Intent and<br/>Entity Extraction"}
TOOLS["Tool Calls"]
TTS["Streaming TTS<br/>ElevenLabs or Rime"]
end
subgraph DATA["Live Data Plane"]
CRM[("CRM and Notes")]
CAL[("Calendar and<br/>Schedule")]
KB[("Knowledge Base<br/>and Policies")]
end
subgraph OUT["Outcomes"]
O1(["KYC pre-fill done"])
O2(["Funding instructions sent"])
O3(["Compliance officer<br/>escalation"])
end
CALLER --> SIP --> STT --> NLU
NLU -->|Lookup| TOOLS
TOOLS <--> CRM
TOOLS <--> CAL
TOOLS <--> KB
NLU --> TTS --> SIP --> CALLER
NLU -->|Resolved| O1
NLU -->|Schedule| O2
NLU -->|Escalate| O3
style CALLER fill:#f1f5f9,stroke:#64748b,color:#0f172a
style NLU fill:#4f46e5,stroke:#4338ca,color:#fff
style O1 fill:#059669,stroke:#047857,color:#fff
style O2 fill:#0ea5e9,stroke:#0369a1,color:#fff
style O3 fill:#f59e0b,stroke:#d97706,color:#1f2937
The scope is deliberately broad. ESMA's Q&A guidance (updated through 2025) clarifies that:
MiFID II establishes these minimum retention periods:
| Communication Type | Minimum Retention | Extended Retention |
|---|---|---|
| Telephone recordings | 5 years | 7 years (at regulator's request) |
| Electronic communications | 5 years | 7 years (at regulator's request) |
| Face-to-face meeting notes | 5 years | 7 years (at regulator's request) |
| Order and transaction records | 5 years | 7 years (at regulator's request) |
The FCA in the UK applies slightly different rules post-Brexit. SYSC 10A requires firms to retain recordings for a minimum of 6 months, but most FCA-regulated firms retain for 5-7 years to align with broader MiFID II standards and to protect themselves in dispute resolution.
The recordings must meet specific quality and accessibility standards:
Hear it before you finish reading
Talk to a live CallSphere AI voice agent for financial services in your browser — 60 seconds, no signup.
The most common compliance gap we see is unrecorded mobile phone usage. When traders or sales agents use personal mobile phones for client calls — even briefly — those conversations fall within MiFID II scope if they relate to orders or transactions.
Solutions include:
Recording the audio is necessary but not sufficient. Regulators expect searchable metadata:
Without this metadata, firms cannot comply with the "promptly retrievable" requirement, which has triggered enforcement actions even when the audio recordings themselves existed.
Recordings must be stored in a way that prevents tampering and unauthorized access. Common failures include:
The recording layer must intercept and capture all in-scope communications. For VoIP systems, this typically works through one of three methods:
SIP Forking: The SIP proxy forks each call's media stream to a dedicated recording server. The recording happens at the network level, so agents cannot disable it.
SIPREC (RFC 7865/7866): An industry-standard protocol for session recording. The Session Border Controller (SBC) sends a copy of the media to a Session Recording Server (SRS) using standardized signaling.
Application-Level Recording: The calling platform records within its own application layer. This is the most common approach for cloud-based VoIP platforms like CallSphere, where recording is handled server-side before the media reaches the agent's browser.
Still reading? Stop comparing — try CallSphere live.
See the financial services AI agent handle a real call — complete, industry-specific, and live in your browser. No signup.
Compliant storage requires:
When a regulator requests recordings — and they will — firms need to produce them quickly:
CallSphere's compliance module is designed around these three layers, providing end-to-end recording, immutable storage, and rapid retrieval without requiring firms to assemble their own infrastructure.
The FCA has taken enforcement action against multiple firms for recording failures:
ESMA conducts periodic peer reviews of national competent authorities' supervision of MiFID II recording requirements. The 2025 peer review found that:
Use this checklist to audit your firm's compliance posture:
Yes. MiFID II's recording obligations apply to any firm providing investment services to clients within the EU/EEA, regardless of where the firm is headquartered. Third-country firms operating under equivalence regimes or reverse solicitation exemptions should consult legal counsel, but the safest approach is to record all communications with EU-based clients. Post-Brexit, UK firms serving EU clients must comply with both MiFID II (for EU activity) and FCA SYSC 10A rules (for UK activity).
No. Under MiFID II, clients cannot opt out of call recording for communications related to orders and transactions. The recording obligation overrides the client's preference. However, firms must inform clients that calls are being recorded (typically via an automated announcement), and if a client refuses to be recorded, the firm should not proceed with the transaction by phone — it should direct the client to a recorded channel or document the conversation in writing.
ESMA's 2025 guidance on algorithmic and automated communications clarifies that any AI-driven or automated communication that relates to order reception, transmission, or execution falls within the recording scope. This includes voice AI agents, chatbots providing investment information, and automated order confirmation calls. The recording must capture both the AI's output and the client's responses. Firms deploying voice AI should ensure their AI platform produces recordings that meet the same quality and metadata standards as human agent calls.
Penalty frameworks vary by jurisdiction. The FCA can impose unlimited fines and has demonstrated willingness to issue seven-figure penalties for recording failures. CySEC penalties can reach up to 1 million EUR per violation, and ESMA can recommend coordinated enforcement across member states. Beyond direct fines, firms face reputational damage, increased regulatory scrutiny, and potential loss of authorization.
Yes, if those calls relate to client orders or transactions. ESMA guidance specifically includes internal communications about client order handling within the recording scope. The practical challenge is distinguishing order-related internal calls from general operational discussions. Most firms address this by recording all calls on trading desk lines and using metadata tagging to classify recordings during or after the call.
Written by
Sagar Shankaran· Founder, CallSphere
Sagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
London fintechs from Canary Wharf to Shoreditch are building production agents on OpenAI AgentKit 1.0 — the patterns that work for FCA-regulated workloads.
Why a single AI call across state lines can be recorded legally in 38 states and illegally in 12, and the disclosure model that resolves it without breaking the agent's flow.
How to deploy AI voice agents in SEC and FINRA-regulated financial services with built-in compliance guardrails, audit trails, and required disclosures.
Achieve GDPR-compliant call recording with this guide to lawful bases, DPIAs, data subject rights, and retention for European business communications.
Call recording compliance for AI voice agents — TCPA two-party consent states, CCPA disclosure, GDPR, and audit trails.
Ensure AML/CFT calling compliance with this guide covering transaction monitoring, suspicious activity reporting, and communication audit trails.
© 2026 CallSphere LLC. All rights reserved.
Made within New York
Watch how CallSphere handles real customer calls, schedules appointments, and processes payments — live.
Try Live DemoBook a DemoCalculate Your ROI