AuditXYZ

Compliance Framework

Markets in Financial Instruments Directive 2014/65/EU (MiFID II)

MiFID II is the EU's comprehensive framework for investment services regulation. This guide covers transaction reporting, best execution, investor protection, and compliance requirements for financial firms.

$200,000–$5,000,0009–24 monthsAudit Required2018 (effective date, with ongoing regulatory technical standards)
Issuing BodyEuropean Parliament and Council of the European Union
First Published2014-06-12
Latest Version2018 (effective date, with ongoing regulatory technical standards)
Typical Cost$200,000–$5,000,000
Typical Timeline9–24 months
Audit RequiredYes
Audit FrequencyContinuous regulatory supervision by national competent authorities. Annual compliance reviews recommended.
Geographyeuropean-union, united-kingdom

MiFID II: EU Markets in Financial Instruments Directive Guide

The Markets in Financial Instruments Directive II (MiFID II) is the European Union's landmark regulation governing investment services and financial markets. Effective since January 2018, it replaced MiFID I with significantly expanded requirements covering investor protection, market transparency, and transaction reporting. MiFID II is complemented by the Markets in Financial Instruments Regulation (MiFIR), which contains directly applicable provisions that apply uniformly across EU member states without requiring national implementation. Together, MiFID II and MiFIR form the cornerstone of EU securities regulation.

What MiFID II Is and Who Issues It

MiFID II (Directive 2014/65/EU) was adopted by the European Parliament and Council in May 2014, with application beginning January 3, 2018 after a one-year delay from the original 2017 target. It is implemented by EU member states through national legislation, while MiFIR (Regulation 600/2014) applies directly without transposition.

The European Securities and Markets Authority (ESMA) plays a central role in MiFID II implementation, publishing regulatory technical standards (RTS), implementing technical standards (ITS), guidelines, and opinions that fill in the details of the Directive's requirements. ESMA also coordinates between national competent authorities (NCAs) — the securities regulators in each member state — that supervise compliance within their jurisdictions.

MiFID II has been subject to significant review since its implementation. The MiFID II review process, coordinated by the European Commission, has led to targeted amendments including the Capital Markets Recovery Package (2021), revisions to the equity research unbundling requirements, adjustments to tick size regimes, and changes to derivatives trading obligations. The Commission's ongoing Capital Markets Union agenda continues to drive amendments to MiFID II and MiFIR.

Who Must Comply

MiFID II applies to a broad range of entities in the EU/EEA financial markets:

Investment firms providing investment services (execution, portfolio management, investment advice, underwriting) or ancillary services (custody, credit to investors, foreign exchange) must be authorized under MiFID II and comply with its conduct and organizational requirements.

Credit institutions (banks) providing investment services are subject to MiFID II's conduct requirements, though they are authorized under the Capital Requirements Directive rather than MiFID II itself.

Regulated markets (stock exchanges), multilateral trading facilities (MTFs), and organized trading facilities (OTFs) operating in the EU must be authorized under MiFID II and comply with its market structure requirements.

Data reporting services providers — including approved reporting mechanisms (ARMs), approved publication arrangements (APAs), and consolidated tape providers (CTPs) — face registration and operational requirements.

Third-country firms (non-EU investment firms) serving EU professional clients and eligible counterparties may operate in the EU without branch requirements where ESMA has adopted an equivalence decision for their home jurisdiction, subject to conditions. EU branches of third-country firms face national authorization requirements.

Post-Brexit, the UK has maintained an onshored version of MiFID II through the Financial Services and Markets Act and UK statutory instruments. The UK FCA has been amending UK MiFID II in ways that diverge from the EU version, creating increasing compliance complexity for firms operating in both jurisdictions.

Key Requirements Explained in Depth

Best Execution

Firms executing client orders must take all sufficient steps to obtain the best possible result for clients, taking into account price, costs, speed, likelihood of execution and settlement, size, nature, and any other relevant considerations. For retail clients, best execution is assessed primarily on price and costs.

Firms must maintain and make public best execution policies and annual best execution quality reports disclosing data on execution venues and achieved execution quality. These reports — required under regulatory technical standard RTS 27 (since suspended for equity instruments) and RTS 28 on execution quality — allow clients and the market to assess whether firms are delivering best execution in practice.

Transaction Reporting

MiFID II requires investment firms to report complete and accurate details of transactions in financial instruments to their national competent authority no later than the close of business on the working day following the transaction. Reports must contain 65 data fields per transaction covering counterparty identification, instrument details, price, quantity, venue, and transaction timing.

The reporting obligation uses legal entity identifiers (LEIs) to identify counterparties, and transaction reporting failures have been a significant area of regulatory action — ESMA and NCAs have issued multiple fines for incomplete, late, or inaccurate transaction reports. Firms must ensure data quality and completeness across their trading systems and reporting infrastructure.

Pre- and Post-Trade Transparency

Trading venues and systematic internalisers (SIs) — firms that deal on own account when executing client orders — must publish pre-trade quotes and post-trade data for equity and non-equity instruments. This transparency regime was substantially extended from MiFID I, covering fixed income, derivatives, and other non-equity instruments for the first time. The calibration of transparency requirements based on liquidity thresholds has been an area of ongoing regulatory adjustment.

Investor Protection: Suitability and Appropriateness

Before providing investment advice or portfolio management services, firms must conduct a suitability assessment of the client's knowledge, experience, financial situation, investment objectives, and risk tolerance. The assessment must be documented and the firm must only recommend or manage products suitable for the client. Suitability reports must be provided to retail clients before transactions.

For non-advised services involving complex financial instruments, firms must conduct an appropriateness assessment to determine whether the client has the knowledge and experience to understand the risks.

Product Governance

MiFID II's product governance requirements (PROD) require manufacturers and distributors of financial products to identify target markets for their products and ensure products are designed to meet the needs of those target markets. Manufacturers must define a target market for each product and identify types of clients for whom the product is not appropriate (a "negative target market"). Distributors must assess target markets and distribute products only to clients within the positive target market.

Inducements and Research Unbundling

MiFID II significantly restricted the use of inducements — payments or benefits given or received in connection with providing investment services that could impair the firm's duty to act in clients' best interests. Research provided by third parties was required to be paid for separately by firms (unbundled from execution commissions) unless firms use their own resources or maintain a research payment account funded by a specific client charge.

The EU partially reversed the research unbundling requirement in 2024, allowing firms to pay for research by bundling it with execution commissions for certain instruments, recognizing that unbundling had reduced research coverage of small and mid-cap companies.

Record-Keeping and Communications Recording

Firms must record all telephone conversations and electronic communications that relate to client orders, whether the conversation results in a transaction or not. Records must be retained for at least five years (and up to seven years at competent authority request) and be available to the firm and regulators on request. The scope of communications that must be recorded — extending to video calls, messaging apps, and encrypted channels — has been an ongoing source of regulatory guidance and enforcement.

Audit and Assessment Process

MiFID II compliance is assessed through continuous regulatory supervision:

MechanismFrequencyScope
Regulatory examinationPeriodic (risk-based)NCA review of conduct, transaction reporting, organizational requirements
Transaction reporting reconciliationContinuousNCAs compare firm reports with venue reports
Best execution monitoringOngoingInternal monitoring; periodic competent authority review
Product governance reviewsPeriodicNCA assessment of target market adherence and product design

Transaction reporting reconciliation is a near-continuous process — NCAs reconcile firm transaction reports against the reports received from trading venues, identifying discrepancies that indicate reporting failures. Firms should implement their own pre-submission validation to minimize differences.

Costs and Timeline

Institution TypeImplementation TimelineAnnual Compliance Cost
Mid-sized investment firm9–15 months$200,000–$1,000,000
Large investment bank15–24 months$1,000,000–$5,000,000
Systematic internaliser12–18 months$500,000–$2,000,000

Initial implementation for large firms has historically run well above these ranges due to technology system costs.

  • MiFID I: MiFID II retained and significantly expanded MiFID I's authorization, conduct, and market structure requirements. The transition from MiFID I to MiFID II involved substantial new obligations in transaction reporting, product governance, and investor protection.
  • GDPR: About 20% overlap, primarily in record-keeping requirements for client communications and personal data in suitability assessments. GDPR's data minimization principles interact with MiFID II's mandatory data retention requirements. See HIPAA for health data parallels.
  • Basel III: Capital requirements under Basel III interact with MiFID II for investment firms that are also credit institutions. See the Basel III guide.
  • FATF/AML: Investment firms must implement AML programs alongside MiFID II compliance, covering customer due diligence, suspicious transaction reporting, and sanctions screening. See the FATF guide.
  • PSD2: Payment-related services provided by investment firms intersect with PSD2 payment service requirements. See the PSD2 guide.

How Automation Helps

MiFID II's transaction reporting, communications recording, and best execution monitoring requirements are highly technology-dependent. Compliance automation tools support the governance and policy layer:

  • Policy management tools maintain conduct policies, best execution policies, and product governance documentation aligned to MiFID II requirements
  • Training tracking records mandatory annual compliance training for investment services staff
  • Vendor risk management supports third-party oversight of ARMs, data vendors, and execution venues
  • Incident and breach tracking manages regulatory notification obligations

LowerPlane supports MiFID II compliance governance alongside other EU regulatory requirements including GDPR and DORA. With 50-plus frameworks and $4,000 per year starting price (free tier available), rated 9.4/10 on AuditXYZ, LowerPlane integrates multi-framework European financial regulation compliance in a single platform. See /compare/best-compliance-automation-platforms for the full comparison.

Frequently Asked Questions

What is the difference between MiFID II and MiFIR?

MiFID II is a Directive — it must be transposed into national law by each EU member state, allowing some flexibility in implementation. MiFIR is a Regulation — it applies directly and uniformly across all EU member states without national transposition, ensuring consistent application. In practice, MiFID II contains organizational and conduct requirements for investment firms, while MiFIR contains the market-wide transparency and transaction reporting requirements that apply uniformly across the EU. Together they are often referred to collectively as "MiFID II/MiFIR" or simply "MiFID II."

Who needs an LEI and how do you get one?

A Legal Entity Identifier (LEI) is a 20-character reference code that uniquely identifies legal entities engaged in financial transactions. MiFID II requires LEIs for both the firm reporting a transaction and its counterparties that are legal entities. Without a valid LEI, a firm cannot report a transaction, and many venues will not accept orders from clients lacking an LEI. LEIs are issued by local operating units (LOUs) accredited by the Global LEI Foundation. Initial registration costs around $65–$130 and renewal is required annually.

What is a systematic internaliser under MiFID II?

A systematic internaliser (SI) is an investment firm that, on an organized, frequent, systematic, and substantial basis, deals on own account when executing client orders outside a regulated market, MTF, or OTF. Investment firms must assess whether they meet the SI thresholds quarterly. SIs face obligations to publish firm quotes in liquid instruments, execute trades at published quotes for orders up to standard market size, and report their SI status to their NCA. The SI regime extends MiFID II's transparency requirements to significant OTC trading activity by investment firms.

How does the research unbundling reversal affect compliance programs?

The 2024 EU amendment allowing bundling of research and execution commissions for certain instruments reversed one of MiFID II's most controversial requirements. Under the new rules, firms can choose to bundle or unbundle research costs. Firms that elect to bundle must disclose this to clients. Compliance programs need to be updated to reflect the firm's chosen approach, update client disclosures, and establish controls consistent with the selected methodology. UK firms operating under UK MiFID II face different rules, as the UK had already moved to a more flexible approach earlier.

What are the consequences of transaction reporting failures?

Transaction reporting failures are actively enforced by ESMA and NCAs. Fines issued across the EU for reporting failures have reached into the tens of millions of euros for individual firms. Common failures include: late reports, reports with missing or incorrect data fields, failure to report certain transaction types, and insufficient data quality controls. Beyond direct fines, reporting failures can indicate systemic compliance weaknesses that attract broader supervisory attention. Firms should implement pre-submission validation against ESMA's published validation rules and regularly reconcile reported data against internal trade records.

Request a MiFID II consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

MiFID IMedium60%
GDPRMinimal20%

Related frameworks

Get matched with a MiFID II auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools