How To Prepare For MiFID II Compliant Call Recording
*Updated 15 September 2026*
A call recording solution can be compliant when it is installed and develop gaps months or years later.
Employees move to Microsoft Teams. Mobile contracts change. New messaging applications are introduced. Contact centres migrate to the cloud. Routing changes during a resilience project. Each change can alter which conversations are captured and how records are stored.
That is why MiFID II recording should be reviewed as a live control environment, not simply technology that was signed off at deployment.
This has become even more important following the FCA's update to SYSC 10A on 23 October 2025. Firms within scope are now explicitly required to maintain an effective written recording policy, review new communication media, train employees, monitor compliance and demonstrate their recording arrangements to the FCA when requested.
The FCA's August 2025 review of off-channel communications reinforces the point. Most firms reviewed were still identifying breaches of their internal communications policies, with 41% of recorded breaches involving employees at director level or above.
For compliance and IT teams, the question is therefore not simply “Do calls get recorded?”
It is “Does the recording environment still work across every communication route the business now uses?”
When Should A MiFID II Recording Setup Be Reviewed?
Recording should be reassessed whenever the communications environment changes materially.
Typical triggers include:
- Migrating users to Microsoft Teams or another UC platform
- Changing SIP or telephony providers
- Moving a contact centre to the cloud
- Introducing a new mobile estate
- Approving new messaging applications
- Enabling new remote working arrangements
- Changing call routing or disaster recovery
- Acquiring another business
- Introducing new offices or user groups
- Changing recording or storage platforms
- Introducing AI transcription or analytics
- Updating retention or data governance policies
The FCA's current approach is technology-neutral. This means firms should assess new communication media as they are introduced rather than relying on a policy written around older technology.
The Britannic Six-Test Recording Health Check
Britannic recommends testing six areas when reviewing an existing recording environment.
| Test | A Healthy Environment | Warning Signs | |
| Scope | Current users, roles and regulated activities are mapped | Recording scope still reflects an older organisation | |
| Channels | Approved voice, mobile and digital channels are known and controlled | Employees regularly use channels outside the recording environment | |
| Capture | Relevant communications are consistently recorded | Missing calls, unexplained gaps or inconsistent recording | |
| Retrieval | Records can be found and replayed quickly | Searches depend on manual investigation or incomplete metadata | |
| Resilience | Failover routes continue to meet recording requirements | DR or alternative routing bypasses recording | |
| Governance | Testing, training and ownership are documented |
|
Any red or amber area should trigger further investigation before the firm assumes its existing solution remains appropriate.
Where Do Recording Gaps Commonly Appear?
The most difficult gaps are often created outside the recording platform itself.
Mobile And Remote Communications
If regulated conversations can take place on mobile devices, firms need to understand whether those conversations remain within the approved recording environment.
The FCA requires reasonable steps to prevent employees from conducting relevant communications on privately owned equipment that the firm cannot record or copy.
Unified Communications
Moving users from traditional telephony into Microsoft Teams or another UC environment can alter call routing and recording architecture.
Internal calls, external calls and different user groups should therefore be tested rather than assuming that a migration automatically preserves existing recording behaviour.
Business Continuity
Failover can create hidden recording gaps.
If calls are diverted to another platform, number or location during an outage, organisations should verify that the alternative journey still meets the required recording policy.
Digital Channels
The FCA's off-channel review specifically highlights the continued challenge of employees using communications outside monitored and permitted channels.
A new messaging application should therefore trigger a compliance assessment before employees begin using it for regulated activity.
Can The Firm Prove Its Recordings Are Complete?
Successful recording is only part of the requirement.
Records also need to remain accessible and appropriately protected.
Under SYSC 10A, records generally need to be retained for five years, increasing to up to seven years where requested by the FCA.
Current FCA requirements also state that relevant records should be stored in a durable medium that allows them to be replayed or copied while preventing the original record from being altered or deleted.
A practical retrieval test should therefore ask:
- Can a specific interaction be found quickly?
- Is the correct customer or employee attached to it?
- Is the date and time accurate?
- Is the recording complete?
- Can it be replayed?
- Is access restricted appropriately?
- Can changes and access be audited?
- Does the record remain available for the required retention period?
Testing retrieval using real scenarios is more valuable than assuming the archive is working because storage utilisation appears normal.
What Role Should Transcription And Analytics Play?
Transcription can make large recording estates easier to search and analyse.
Britannic's recording and transcription proposition can help organisations create searchable communication records and derive further insight from customer interactions.
Analytics can support areas such as:
- Search and investigation
- Quality management
- Compliance reviews
- Complaint analysis
- Customer sentiment
- Training
- Identifying unusual interaction patterns
However, transcription should complement the underlying recording rather than replace it.
For regulated communications, the priority remains reliable capture, retention and governance of the original interaction.
Does Recording Meet Data Protection Requirements Too?
Regulatory recording requirements do not remove wider data protection responsibilities.
ICO guidance notes that organisations should limit call recording to what is necessary and make workers and customers aware of relevant monitoring. It also recommends considering proportionality and the impact on privacy.
This means firms need to balance regulatory retention with appropriate access, security and deletion policies.
MiFID II and UK GDPR should therefore be considered together rather than as separate technology requirements.
MiFID II Recording Review Checklist
A practical review should confirm:
- In-scope employees and activities are current
- All approved communication channels are documented
- Mobile communications are included where required
- UC and cloud calling routes have been tested
- Off-channel communications are controlled
- New applications are assessed before approval
- Recording gaps are automatically identified where possible
- Failover and DR routes have been tested
- Records can be found and replayed
- Retention periods are configured correctly
- Original records cannot be improperly altered
- Access permissions are reviewed
- Employees receive appropriate training
- Recording policies reflect current technology
- Compliance testing is documented
- Ownership between IT and compliance is clear
The important point is not simply to complete the checklist once.
The review should be repeated whenever the communication environment changes.
Keep Recording Controls Aligned With The Business
Communications environments rarely remain static.
A compliant recording design can gradually become less effective as platforms, users and working practices change around it.
Britannic helps financial services organisations review recording coverage across existing communications environments and integrate recording, transcription, analytics, resilience and communications technology around current operational and compliance requirements. Britannic's wider financial services proposition also covers secure communications, cloud platforms, contact centres and integrated customer engagement.
Organisations unsure whether their existing recording setup still reflects their current communications environment can book a complimentary recording review with Britannic to identify potential coverage, resilience and retrieval gaps.