MiFID II guide
MiFID II record-keeping requirements
If it isn’t recorded, it didn’t happen. MiFID II requires firms to keep records good enough for a supervisor to reconstruct every step of the advice process. Here is what to keep, for how long, and in what form.
MiFID II requires investment firms to keep records of all their services, activities and transactions. The records must be sufficient for the supervisor to check that the firm has complied with all its obligations, including those towards clients. The general rule is in Article 16(6) of MiFID II. The detail, including the minimum list of records in Annex I, is in Articles 72 to 76 of Delegated Regulation (EU) 2017/565.
What the records must make possible
The test is reconstruction. A supervisor should be able to take any piece of advice and answer these questions from the records alone:
- What did the firm know about the client at the time, and where did that information come from?
- Which questions did the client answer, and in which version?
- How was suitability or appropriateness assessed, and with what result?
- What was recommended, and how was it explained in the statement of suitability?
- What costs were disclosed?
- Which warnings were given, and what did the client decide?
- Who did what, and when?
How records must be kept
Article 72(1) requires records to be kept in a medium that allows future reference by the competent authority, in a way that meets five conditions:
- the competent authority can access them readily and reconstitute each key stage of the processing of each transaction;
- any corrections or amendments, and the content of the records before them, can be easily ascertained;
- records cannot otherwise be manipulated or altered;
- the medium allows IT or other efficient analysis when the volume or nature of the data makes manual analysis impractical; and
- the arrangements comply irrespective of the technology used.
Which records to keep for advice
Annex I of the Delegated Regulation lists the minimum records, and other articles add to it. For an advice business, the core set is:
| Record | Where the requirement comes from |
|---|---|
| Client information and client categorisation | Annex I DR; Annex II MiFID II |
| Suitability assessment, including the questions and answers and their version | Art. 25(2) MiFID II; Art. 54 DR; ESMA suitability guidelines |
| Statement of suitability and periodic suitability reports | Art. 25(6) MiFID II; Art. 54(12) DR |
| Appropriateness results, warnings and client decisions | Art. 25(3) MiFID II; Art. 56(2) DR |
| Sustainability preferences and any adaptation, with the client’s explanation | Art. 54 DR as amended by DR 2021/1253 |
| Costs and charges disclosures | Art. 24(4) MiFID II; Art. 50 DR |
| The client agreement, setting out rights and obligations | Art. 73 DR |
| Orders, transactions and order-handling | Annex I; Art. 74–75 DR; MiFIR Art. 25 |
| Telephone conversations and electronic communications relating to transactions | Art. 16(7) MiFID II; Art. 76 DR |
How long to keep records
MiFID II sets five years as the baseline retention period, and competent authorities can require up to seven years. The explicit five-to-seven-year rule appears in Article 16(7) for recorded telephone conversations and electronic communications. MiFIR Article 25 sets five years for order and transaction data. National rules can be stricter, and the client agreement must be kept for at least as long as the client relationship lasts.
Retention periods are a minimum. Anti-money laundering rules, local limitation periods and complaints handling often mean firms keep advice records longer. Set the period deliberately in a written retention policy.
Recorded communications
Article 16(7) requires firms to record telephone conversations and electronic communications relating to transactions concluded when dealing on own account, and to services involving the reception, transmission and execution of client orders. This applies even if the conversation doesn’t result in a transaction. Clients must be told in advance that calls are recorded. Recordings must be provided to the client on request and kept for five years, or up to seven where the competent authority requests it.
Record-keeping and GDPR
MiFID II retention is a legal obligation, which is a lawful basis for processing personal data under the GDPR. The GDPR’s storage limitation principle still applies. Keep records for as long as the rules require, then delete or anonymise them on a defined schedule.
Record-keeping checklist
- Every advice event can be reconstructed end to end from the records
- Records are append-only, with every correction traceable
- Each answer is stored with the exact question version the client saw
- Documents are stored as the client received them (for example PDF/A), with a hash
- Timestamps and user identities are recorded for every step
- A written retention policy covers MiFID II, AML and national requirements
- Records can be searched and exported quickly when the supervisor asks
How Tervan keeps the evidence
Tervan records every answer, question version, document and flow step with a timestamp and hash. Your auditors can trace any piece of advice, answer by answer.
- Question set Suitability, retail v4.2 opened by Anne Karlsen
- 23 answers locked, hash 3f9a07…c21e
- Statement of suitability generated in Norwegian
- Signed by client with e-ID
- Signed by advisor with e-ID
- Archive copy uploaded to document server
- CRM updated, webhook returned 200
The audit trail for one annual review, from opening the question set to the CRM update. Each line is timestamped, and the locked answers and generated documents are hashed.
Archive copies go to your own document server over SFTP or S3, so records stay in the systems you already govern. Tervan keeps its own audit log alongside, for at least five years or up to seven where your regulator requires it.
Frequently asked questions
How long must MiFID II records be kept?
MiFID II sets five years as the baseline, and competent authorities can require some records to be kept for up to seven years. The explicit five-to-seven-year rule applies to recorded telephone conversations and electronic communications. National rules and other laws, such as anti-money laundering rules, can require longer.
What records does MiFID II require for advice?
Records of the information collected about the client, the suitability or appropriateness assessment and its result, the advice given and the statement of suitability, any warnings and the client’s decisions, costs disclosures, client agreements and the orders and transactions that followed.
Can MiFID II records be stored in the cloud?
Yes, as long as the storage meets the conditions in Article 72 of Delegated Regulation 2017/565 and the firm’s outsourcing arrangements meet its regulator’s requirements. The supervisor must be able to access the records readily, corrections must be traceable, and records must not be open to manipulation.
How does MiFID II record-keeping interact with GDPR?
Keeping records to meet MiFID II is a legal obligation, which is a lawful basis for processing under GDPR. Firms should still limit retention to what the rules require and delete or anonymise records once the retention period ends.
This guide is general information about EU rules, not legal advice. National implementation and your regulator's guidance can add requirements. Check the primary sources linked above before relying on it.