In this article 01. MiFID II call recording in 2026: from sampled playback to full surveillance 02. What MiFID II actually requires you to record 03. SYSC 10A: the UK version of the rules 04. Storage and retention: durable, tamper resistant and reconstructable 05. From sampling to surveillance: how expectations have changed 06. Trade reconstruction in practice 07. A practical MiFID II recording compliance checklist 08. How Business Systems helps MiFID II call recording in 2026: from sampled playback to full surveillance When the Markets in Financial Instruments Directive II came into force in 2018, most firms treated the recording obligation as a technology procurement exercise. Buy a recording platform, switch it on for the trading floor, tick the box. Nearly a decade on, recording the calls has turned out to be the easy part. The requirements that now determine whether a firm passes regulatory scrutiny are the harder ones: whether every in scope channel is actually captured, whether records are stored in a form that cannot be tampered with, whether the firm can reconstruct the full life of an order on demand, and whether its surveillance genuinely detects misconduct rather than sampling around it. This guide sets out what MiFID II call recording and record keeping obligations look like in 2026, how the UK’s SYSC 10A rules apply, and why supervisory expectations have quietly moved from recording plus occasional playback to automated, complete surveillance. What MiFID II actually requires you to record The core obligation sits in Article 16(7) of MiFID II. Firms must record telephone conversations and keep copies of electronic communications that relate to the reception, transmission and execution of client orders, and to dealing on own account. The scope is deliberately wide in three ways that still catch firms out. First, it covers conversations that are intended to result in a transaction even where no transaction actually follows. A call discussing an intention to trade is in scope from the moment it happens, regardless of the outcome. Second, it applies across channels. Fixed lines, mobiles, e-comms platforms, enterprise collaboration tools and consumer messaging apps are all capable of carrying in scope communications, and the obligation follows the conversation rather than the device. Third, firms must take all reasonable steps to prevent staff from making in scope communications on private equipment or channels the firm cannot record or copy. A trader moving a client conversation to a personal messaging app is a breach in the making, which is why the recording rules and the off channel enforcement trend are two halves of the same problem. We cover that side in detail in our guide to WhatsApp compliance in financial services. SYSC 10A: the UK version of the rules Since the UK left the European Union, the recording obligations for UK firms have lived in the FCA Handbook rather than directly in the directive. SYSC 10A onshores the MiFID II requirements and applies them to firms carrying on regulated activities such as receiving, transmitting and executing orders, portfolio management and dealing on own account. The substance closely mirrors Article 16(7): record relevant telephone conversations, retain relevant electronic communications, notify clients that calls are recorded, and take reasonable steps to prevent the use of devices and channels the firm cannot capture. The FCA extended the spirit of the regime further than the European baseline in one respect, bringing retail investment advice within reach of taping requirements, with a written note alternative available to certain smaller firms. Any firm relying on that alternative should be honest with itself about how defensible a contemporaneous written note looks next to a recording when a dispute or investigation arises. The practical point for compliance teams is that Brexit changed the address of the rules without softening them. FCA supervisory work and Market Watch commentary in recent years have repeatedly pressed firms on recording coverage, retention quality and surveillance capability. UK firms answering to the FCA face expectations at least as demanding as their European peers, and firms operating on both sides of the Channel need to satisfy both regimes at once. Storage and retention: durable, tamper resistant and reconstructable Recording a conversation is worthless if the record cannot be trusted or found. Article 72 of the MiFID II Delegated Regulation sets the storage standard: records must be kept in a durable medium, in a form that prevents the original from being altered or deleted, and in a way that leaves them readily accessible to the regulator on request. Records must be retained for at least five years, extendable to seven at the request of the competent authority, and clients are entitled to request copies of recordings of their own conversations. The same provision carries the requirement that shapes modern recording architecture more than any other: records must allow the full reconstruction of the order lifecycle. Every material stage of an order, from the first client conversation through transmission and execution, needs to be traceable across the records the firm holds. That is straightforward when everything sits in one coherent store with consistent metadata. It is close to impossible when recordings are scattered across a legacy voice logger on the trading floor, a separate mobile capture tool, a Teams recording bot and an e-comms archive, each with its own retention rules, formats and search interfaces. This is where older recording estates quietly fail the 2026 test. Many platforms deployed for the original MiFID II deadline are now approaching end of life, and fragmented estates accumulated through mergers and platform changes create exactly the gaps and inconsistencies that Article 72 was written to prevent. From sampling to surveillance: how expectations have changed The most significant shift since 2018 has little to do with recording itself. It concerns what firms are expected to do with the recordings. In the early years of the regime, a common compliance model was periodic sampling: a compliance officer plays back a selection of recorded calls each month and documents the review. Regulators have made increasingly clear that this is no longer sufficient. The direction of travel across European and UK supervision is towards automated surveillance across the full body of communications, with firms in Europe now expected to have automated systems in place rather than relying on manual spot checks. The Market Abuse Regulation is the other driver. MAR does not itself mandate recording, but it requires firms to detect and investigate potential market abuse, and complete communication records are the essential evidence base for doing so. A surveillance function that only ever looks at a two per cent sample cannot credibly claim to be detecting abuse across the other ninety eight per cent. Effective communications surveillance in 2026 also has to be smarter than a keyword list. Staff who intend to misbehave know which words and phrases trigger alerts, so lexicon only monitoring catches the careless rather than the determined. Modern trade surveillance and e-comms surveillance approaches look for themes, behavioural patterns and contextual signals across channels, including hard to monitor content such as voice notes and emojis, and they connect communications data with trade data so that suspicious patterns surface even when no forbidden word is ever spoken. The prerequisite for any of this is consolidated, high quality recording data. Surveillance tooling layered over a fragmented estate inherits every blind spot underneath it. Trade reconstruction in practice Trade reconstruction is where all of these obligations converge, and it is the scenario worth planning around because it arrives with a deadline attached. A regulatory request typically asks the firm to recreate the complete context of a trade or series of trades: who said what, when, on which channel, and why the trade occurred. That means pulling the fixed line and mobile calls, the chat messages, the emails and the order records for the relevant people and period, assembling them into a coherent timeline, and handing them over in a readable format, often within days. Firms with a unified recording estate can treat this as a search problem: query once, across all channels, export, done. Firms with fragmented systems experience it as a crisis project, with teams manually trawling separate archives, reconciling clocks and metadata between platforms, and discovering gaps at the worst possible moment. The difference between the two is rarely the surveillance or archiving software itself. It is the architectural decision, made years earlier, about whether every channel would feed one coherent data structure. It is also worth rehearsing reconstruction before a regulator asks. Running a mock request against a real historic trade is one of the cheapest assurance exercises available to a compliance team, and it reliably surfaces coverage gaps, retention inconsistencies and export problems while they are still fixable quietly. A practical MiFID II recording compliance checklist For teams reviewing their position against the 2026 standard, the following checks cover the ground that supervisory visits and enforcement cases keep returning to. Channel coverage audit. Map every channel where in scope conversations can occur, including mobiles, Teams and messaging apps, and confirm each one is captured. Pay particular attention to channels added since the recording estate was first deployed. Retention and durability review. Confirm records are held in a durable, tamper resistant form for at least five years, that retention policies are consistent across channels, and that legal holds can be applied reliably. Private device controls. Evidence the reasonable steps taken to prevent in scope business on unrecordable channels: policies, device management, attestations and monitoring for breaches. Surveillance capability. Assess whether monitoring extends across all captured channels and beyond simple keyword matching, and whether communications surveillance connects to trade surveillance. Reconstruction and export testing. Run a mock trade reconstruction end to end, and test that data can be exported in standard readable formats without dependency on any single vendor. Vendor and platform assurance. Check the certifications, resilience and support arrangements of every platform in the recording chain, especially any approaching end of life. How Business Systems helps Business Systems has worked with regulated firms on recording and monitoring for more than three decades, spanning trader voice, fixed line, mobile and Microsoft Teams environments. As a vendor neutral specialist, Business Systems helps firms consolidate fragmented legacy estates into a single compliant call recording architecture, add surveillance and analytics on top of trusted capture, and prove reconstruction capability before a regulator asks for it. If you are reviewing your recording estate against MiFID II and SYSC 10A, our consultants can help you find the gaps and plan the fix. For collaboration platforms specifically, see our guide to Microsoft Teams call recording compliance, and for the general law on recording calls in the UK, see is call recording legal? Get in touch Written by: Dhruva Gupta
Blog 19 August, 2026 WhatsApp Compliance in Financial Services WhatsApp compliance in financial services: why a ban is no longer enough For years, the standard answer to WhatsApp in regulated firms was simple: ban it. Write a policy prohibiting business communication on personal messaging apps, ask staff to sign it, and move on. That approach has now failed publicly, repeatedly and expensively. In 2024,
Blog 22 July, 2026 The Cost of Attrition: Why Workforce Engagement Management is a Self-Funding Strategy Contact centre attrition remains one of the most expensive challenges facing customer support leaders. CX Today reports annual turnover rates of 35-45% remain common across the industry, with each departure costing between £10,000 and £15,000 in recruitment, onboarding and lost productivity. For a 200-seat operation, that equates to roughly £700,000-£1.35 million in annual attrition costs
Blog 30 April, 2026 Customer Experience Tools: How to Choose (and Implement) the Right CX Platform for Your Business Choosing the right customer experience platform is a major decision for many businesses. The platform you choose shapes how customers interact with your business across every channel, determines what insights you can extract from those customer interactions, and influences whether or not your teams can deliver consistently excellent service. Yet many organisations approach this decision
Blog 16 April, 2026 Conversational AI in UK Contact Centres: Moving Beyond Basic Chatbots Many contact centres in the UK have implemented chatbot technology in some form or another, but with varying degrees of success. Recent industry research reveals that nearly 70% of customers become frustrated with chatbots and prefer speaking to human agents, and abandonment rates for basic chatbot interactions continue to remain stubbornly high. The problem isn’t
Blog 10 April, 2026 Proactive Customer Service: How Contact Centres Can Use Proactive AI to Anticipate Customer Needs The traditional model of customer service is almost entirely reactive: a customer discovers a problem, contacts your organisation, and waits for a solution. This approach places the burden squarely on the customer, requiring them to identify issues, navigate your contact channels, and often endure multiple interactions before their problem is solved. Proactive customer service powered
Blog 29 January, 2026 Microsoft Teams Recording Without the Risk: A Practical Guide for Regulated Organisations Microsoft Teams has become the backbone of collaboration across financial services, insurance, the public sector and other regulated industries. Trading conversations, client discussions, internal decisions and approvals are now happening daily across voice, video, chat and shared files. That shift brings opportunity, but it also introduces risk. For organisations operating under regulations such as FCA,
Blog 5 December, 2025 The clock is ticking: Why end-of-life recording systems are a critical compliance risk Outdated recording technology isn’t just an inconvenience, it’s a ticking time bomb for regulated firms. For financial services and other heavily regulated industries, end-of-life (EoL) voice recording systems can create dangerous blind spots. When vendors withdraw support, these unsupported platforms become vulnerable, exposing your firm to major compliance penalties under frameworks like MiFID II, FCA,
Blog 20 November, 2025 Proactive AI vs Reactive AI: Understanding the Difference Artificial intelligence is changing the way organisations across the UK engage with customers, but all AI solutions aren’t created equal. Many still rely on reactive models that respond only once a customer makes contact. Proactive AI takes a more advanced approach, identifying needs and acting before the customer does. Understanding the key differences between proactive