MiFID II guide

MiFID II record-keeping requirements

If it isn’t recorded, it didn’t happen. MiFID II requires firms to keep records good enough for a supervisor to reconstruct every step of the advice process. Here is what to keep, for how long, and in what form.

Last reviewed MiFID II Art. 16(6)–(7) · DR 2017/565 Art. 72–76, Annex I

MiFID II requires investment firms to keep records of all their services, activities and transactions. The records must be sufficient for the supervisor to check that the firm has complied with all its obligations, including those towards clients. The general rule is in Article 16(6) of MiFID II. The detail, including the minimum list of records in Annex I, is in Articles 72 to 76 of Delegated Regulation (EU) 2017/565.

What the records must make possible

The test is reconstruction. A supervisor should be able to take any piece of advice and answer these questions from the records alone:

  • What did the firm know about the client at the time, and where did that information come from?
  • Which questions did the client answer, and in which version?
  • How was suitability or appropriateness assessed, and with what result?
  • What was recommended, and how was it explained in the statement of suitability?
  • What costs were disclosed?
  • Which warnings were given, and what did the client decide?
  • Who did what, and when?

How records must be kept

Article 72(1) requires records to be kept in a medium that allows future reference by the competent authority, in a way that meets five conditions:

  1. the competent authority can access them readily and reconstitute each key stage of the processing of each transaction;
  2. any corrections or amendments, and the content of the records before them, can be easily ascertained;
  3. records cannot otherwise be manipulated or altered;
  4. the medium allows IT or other efficient analysis when the volume or nature of the data makes manual analysis impractical; and
  5. the arrangements comply irrespective of the technology used.

Which records to keep for advice

Annex I of the Delegated Regulation lists the minimum records, and other articles add to it. For an advice business, the core set is:

Record Where the requirement comes from
Client information and client categorisation Annex I DR; Annex II MiFID II
Suitability assessment, including the questions and answers and their version Art. 25(2) MiFID II; Art. 54 DR; ESMA suitability guidelines
Statement of suitability and periodic suitability reports Art. 25(6) MiFID II; Art. 54(12) DR
Appropriateness results, warnings and client decisions Art. 25(3) MiFID II; Art. 56(2) DR
Sustainability preferences and any adaptation, with the client’s explanation Art. 54 DR as amended by DR 2021/1253
Costs and charges disclosures Art. 24(4) MiFID II; Art. 50 DR
The client agreement, setting out rights and obligations Art. 73 DR
Orders, transactions and order-handling Annex I; Art. 74–75 DR; MiFIR Art. 25
Telephone conversations and electronic communications relating to transactions Art. 16(7) MiFID II; Art. 76 DR

How long to keep records

MiFID II sets five years as the baseline retention period, and competent authorities can require up to seven years. The explicit five-to-seven-year rule appears in Article 16(7) for recorded telephone conversations and electronic communications. MiFIR Article 25 sets five years for order and transaction data. National rules can be stricter, and the client agreement must be kept for at least as long as the client relationship lasts.

Retention periods are a minimum. Anti-money laundering rules, local limitation periods and complaints handling often mean firms keep advice records longer. Set the period deliberately in a written retention policy.

Recorded communications

Article 16(7) requires firms to record telephone conversations and electronic communications relating to transactions concluded when dealing on own account, and to services involving the reception, transmission and execution of client orders. This applies even if the conversation doesn’t result in a transaction. Clients must be told in advance that calls are recorded. Recordings must be provided to the client on request and kept for five years, or up to seven where the competent authority requests it.

Record-keeping and GDPR

MiFID II retention is a legal obligation, which is a lawful basis for processing personal data under the GDPR. The GDPR’s storage limitation principle still applies. Keep records for as long as the rules require, then delete or anonymise them on a defined schedule.

Record-keeping checklist

  • Every advice event can be reconstructed end to end from the records
  • Records are append-only, with every correction traceable
  • Each answer is stored with the exact question version the client saw
  • Documents are stored as the client received them (for example PDF/A), with a hash
  • Timestamps and user identities are recorded for every step
  • A written retention policy covers MiFID II, AML and national requirements
  • Records can be searched and exported quickly when the supervisor asks

How Tervan keeps the evidence

Tervan records every answer, question version, document and flow step with a timestamp and hash. Your auditors can trace any piece of advice, answer by answer.

Audit trailIngrid Berg, annual review
  1. Question set Suitability, retail v4.2 opened by Anne Karlsen
  2. 23 answers locked, hash 3f9a07…c21e
  3. Statement of suitability generated in Norwegian
  4. Signed by client with e-ID
  5. Signed by advisor with e-ID
  6. Archive copy uploaded to document server
  7. CRM updated, webhook returned 200

The audit trail for one annual review, from opening the question set to the CRM update. Each line is timestamped, and the locked answers and generated documents are hashed.

Archive copies go to your own document server over SFTP or S3, so records stay in the systems you already govern. Tervan keeps its own audit log alongside, for at least five years or up to seven where your regulator requires it.

Frequently asked questions

How long must MiFID II records be kept?

MiFID II sets five years as the baseline, and competent authorities can require some records to be kept for up to seven years. The explicit five-to-seven-year rule applies to recorded telephone conversations and electronic communications. National rules and other laws, such as anti-money laundering rules, can require longer.

What records does MiFID II require for advice?

Records of the information collected about the client, the suitability or appropriateness assessment and its result, the advice given and the statement of suitability, any warnings and the client’s decisions, costs disclosures, client agreements and the orders and transactions that followed.

Can MiFID II records be stored in the cloud?

Yes, as long as the storage meets the conditions in Article 72 of Delegated Regulation 2017/565 and the firm’s outsourcing arrangements meet its regulator’s requirements. The supervisor must be able to access the records readily, corrections must be traceable, and records must not be open to manipulation.

How does MiFID II record-keeping interact with GDPR?

Keeping records to meet MiFID II is a legal obligation, which is a lawful basis for processing under GDPR. Firms should still limit retention to what the rules require and delete or anonymise records once the retention period ends.

This guide is general information about EU rules, not legal advice. National implementation and your regulator's guidance can add requirements. Check the primary sources linked above before relying on it.

See MiFID II advice running inside your own portal.

In 30 minutes we'll embed a suitability flow in a sample portal, generate the statement of suitability and send it for signature, end to end.

Or write to hello@tervan.io