MiFID II Call Recording in Financial Services
*Updated 15 September 2026*
Financial services communications now take place across office phones, mobiles, Microsoft Teams, cloud communications platforms, messaging tools and face-to-face meetings.
For compliance teams, the challenge is no longer simply whether calls are being recorded. Firms need to know which communications fall within scope, whether approved channels are being captured consistently and whether records can be protected, retrieved and evidenced when required.
For UK firms, MiFID II-derived recording requirements are incorporated into the FCA Handbook through SYSC 10A. The FCA strengthened these requirements in October 2025, adding clearer expectations around written recording policies, management oversight, technology-neutral controls, employee training and ongoing monitoring.
The issue remains highly relevant. An FCA review published on 7 August 2025 found that most firms reviewed continued to identify breaches of their policies around off-channel communications. Of the breaches identified, 41% involved employees at director level or above.
The priority for financial services firms should therefore be clear.
Capture regulated communications consistently, control the channels employees use and be able to prove that the recording framework works.
What Communications Need To Be Recorded?
The short answer
Firms within scope of SYSC 10A must take reasonable steps to record relevant telephone conversations and retain electronic communications relating to specified activities in financial instruments.
Importantly, this includes communications intended to result in a transaction even when the transaction does not ultimately take place.
The FCA rules apply to communications made using equipment provided by the firm or equipment the firm has accepted or permitted for business use.
This means the compliance question is wider than the traditional desk phone.
| Requirement | What It Means In Practise |
| Telephone calls | Relevant business calls need to be captured where the recording rules apply |
| Electronic communications |
|
| Approved devices | Firm-provided and permitted devices need to form part of the recording policy |
| Unapproved channels | Firms should prevent employees using channels that cannot meet recording requirements |
| Client notification | Clients must be informed about applicable recording |
| Retention | Records are normally retained for five years and up to seven years where requested by the FCA |
| Record integrity | Records must remain complete, accurate, accessible and protected against alteration or deletion |
The FCA also introduced more detailed requirements in October 2025 around face-to-face interactions, including recording specified information about relevant meetings in a durable medium.
Why Are Off-Channel Communications A Compliance Risk?
The biggest recording gap is often not the call recorder itself.
It is the communication taking place somewhere else.
Employees may move between business phones, mobiles, Microsoft Teams, messaging applications and personal devices throughout the day. If an employee conducts in-scope activity through a channel the organisation cannot capture, the firm can create a gap in its compliance record.
The FCA's 2025 review defined off-channel communications as interactions taking place outside the monitored and recorded channels permitted by the firm. It found ongoing breaches across all levels of seniority.
This is why the updated FCA requirements are explicitly technology-neutral.
Rather than maintaining a static list of applications, firms need a process for assessing every new communication medium before it is approved for regulated business.
What Should A Modern MiFID II Recording Environment Cover?
A recording strategy should follow the employee rather than one particular telephone system.
| Communications Environment | Recording Consideration |
| Desk phones | Ensure all relevant inbound and outbound conversations are captured |
| Mobile calling |
|
| Microsoft Teams & UC | Ensure regulated communications remain recordable as users move to cloud calling |
| Digital messaging |
|
| Contact centres |
|
| Face-to-face meetings |
|
Britannic's voice recording, compliance and transcription solutions can support communications recording across modern business environments while providing searchable transcription and analytics alongside the original interaction.
Platforms such as Mitel MiContact Centre Business can also support interaction recording, quality management and speech analytics where organisations need contact centre recording alongside wider communications compliance.
What Has Changed In The FCA Recording Rules?
One of the most important updates came into force on 23 October 2025.
SYSC 10A now explicitly requires affected firms to establish and maintain a written recording policy appropriate to their size, organisation and business.
The requirements include:
- Identifying which telephone and electronic communications fall within scope
- Defining procedures for exceptional circumstances where recording is unavailable
- Providing effective management oversight
- Keeping recording arrangements technology-neutral
- Reassessing controls when new communication media are permitted
- Maintaining records of approved devices and users
- Training employees
- Monitoring compliance on a proportionate and risk-based basis
- Demonstrating policies, procedures and oversight to the FCA when requested
This moves the conversation beyond “Is the recorder switched on?”
The more useful question is “Can the organisation demonstrate that its complete recording control environment is working?”
Britannic's Five-Part Recording Assurance Framework
Britannic recommends reviewing regulated communications through five areas.
| Stage | Key Question |
| Capture | Are all relevant communications being recorded or retained? |
| Control | Are employees using only approved devices and channels? |
| Protect | Are records secure, complete and protected against alteration? |
| Retrieve |
|
| Review | Are recording policies, technologies and employee behaviour tested regularly? |
A weakness in any one area can undermine the wider compliance environment.
For example, a high-quality recording platform provides limited protection if employees can conduct regulated conversations through an unapproved mobile application.
How Long Must MiFID II Recordings Be Kept?
The FCA Handbook requires records covered by SYSC 10A to be retained for five years, with the period increasing to up to seven years when requested by the FCA.
The current article's reference to retention potentially extending to ten years should therefore be removed.
Records also need to remain readily accessible and capable of being replayed or copied, with the original protected against alteration or deletion.
Retention should therefore be considered alongside:
- Storage capacity
- Access permissions
- Search and retrieval
- Encryption
- Resilience and backup
- Data protection
- Deletion at the end of the appropriate retention period
The ICO also advises organisations to limit recording to what is necessary and ensure workers and customers understand relevant monitoring arrangements.
Can AI Help With MiFID II Recording Compliance?
Yes, but AI should support the recording control environment rather than be presented as a regulatory requirement.
Transcription and conversation analytics can make large volumes of recorded communication easier to search and review.
They can help compliance teams identify:
- Relevant conversations
- Keywords and phrases
- Potential conduct risks
- Customer complaints
- Quality issues
- Training requirements
- Patterns requiring further investigation
AI does not replace the requirement to capture, retain and govern the underlying communications correctly.
The original recording remains the compliance foundation.
This distinction is important because the current article suggests firms are expected to implement AI-driven monitoring. The FCA requirements instead focus on effective policies, recording, retention, oversight and proportionate monitoring.
Why Does Recording Resilience Matter?
A recording gap can occur even when employees follow the correct process.
Platform failures, network outages, configuration changes and integrations can interrupt capture.
The October 2025 FCA rules now explicitly require firms to document what should happen in exceptional circumstances when an approved conversation or communication cannot be recorded and retain evidence of those circumstances.
Firms should therefore consider recording resilience alongside their wider communications architecture.
That means understanding:
- What happens if the primary recorder fails
- Whether recording continues during communications failover
- How missing recordings are detected
- Who receives alerts
- How incidents are documented
- How recording is tested following platform changes
For regulated organisations, communications resilience and recording resilience should form part of the same design.
MiFID II Recording Compliance Checklist
Financial services firms should regularly review whether:
- All in-scope communications have been identified
- The recording policy reflects current FCA requirements
- Voice, mobile and UC environments are covered
- Approved electronic communications can be retained
- Personal and unapproved channels are controlled
- New communication applications are assessed before use
- Relevant employees and devices are documented
- Employees receive appropriate training
- Clients receive the required recording notifications
- Recordings are retained for the correct period
- Records cannot be altered or deleted improperly
- Recordings can be searched and retrieved quickly
- Access to recordings is appropriately controlled
- Recording continuity and failover are tested
- Monitoring identifies potential policy breaches
- Policies are reviewed following significant technology changes
Compliance should be reviewed whenever the communications environment changes, not simply before an audit.
Building Compliance Into Modern Financial Communications
Financial services organisations continue to adopt cloud communications, mobile working, digital channels, AI and integrated customer service platforms.
Recording controls need to develop alongside them.
The strongest approach is not to restrict innovation unnecessarily. It is to ensure every approved communications channel enters a consistent governance framework before employees begin using it for regulated activity.
Britannic helps financial services organisations integrate voice recording, transcription, analytics and communications technology across existing and modern UC environments while considering resilience, security and regulatory requirements.
Financial services organisations reviewing their recording environment can book a complimentary meeting with Britannic to assess channel coverage, resilience, retention and potential compliance gaps.