Today, professional exchanges take place everywhere: on landlines, mobile phones, Microsoft Teams, Zoom, or even via unified communications platforms that have established themselves.
For a long time, MiFID compliance was a relatively narrow topic. Financial institutions focused their efforts on trading rooms, where the obligations to record communications were clearly identified.
This vision is now a thing of the past.
Today, professional exchanges take place everywhere: on landlines, mobile phones, Microsoft Teams, Zoom, or even via unified communication platforms which have established themselves in the daily lives of employees. Uses have evolved much faster than the architectures which were supposed to govern them.
And this is precisely where the real risk now lies.
An architecture that has piled up over the years
Very few financial institutions have designed their communication system with a global approach.
The reality is very different.
Landline telephony came first. Then professional smartphones. Then came collaborative tools, accelerated by the generalization of teleworking. Finally, to meet regulatory requirements, different recording solutions were gradually added.
Each new layer met an immediate need.
None have really been designed to be consistent with the previous ones.
Over the years, information systems departments have inherited complex environments, made up of heterogeneous technologies, multiple suppliers, distinct contracts and independent maintenance cycles.
This complexity often remains invisible… until the day it is necessary to demonstrate that the whole thing really works without disruption.
The real risk has become technical
MiFID II requires investment firms to take all reasonable steps to record relevant communications made in the course of their professional activities.
On paper, the principle is clear.
In practice, its application has become much more difficult.
Each new communication channel authorized by the company potentially creates a new compliance perimeter.
The problem is no longer just regulatory.
It becomes deeply technical.
Because a recording tool installed several years ago often continues to function without anyone really checking its ability to cover current uses: new versions of collaborative software, evolution of operating systems, new terminals, new mobility practices or even new remote connection methods.
In other words, yesterday’s compliance is not automatically today’s.
The DSI becomes one of the guarantors of proof
Historically, compliance was primarily the responsibility of the RCCI while infrastructure remained the responsibility of the IT department.
This boundary has gradually become blurred.
When a regulator today asks to reconstruct a complete audit trail, the question goes far beyond the existence of a recording policy.
You must be able to demonstrate that each relevant communication, whatever the channel used, has actually been captured, preserved and can be reproduced.
This demonstration now relies as much on the technical architecture as on the compliance procedures.
The CIO no longer only provides tools.
He becomes one of the actors in the establishment’s capacity to provide this proof.
Three questions every CIO should ask themselves
A few simple questions allow you to assess the real robustness of a communication architecture.
· Does an advisor who continues a customer conversation on their mobile phone benefit from exactly the same level of recording as from their landline?
· Do the different communication tools deployed in the company offer homogeneous coverage or do they rely on several independent solutions that must be maintained separately?
· When an update occurs on a collaborative platform or on a terminal, is there a mechanism to immediately verify that the continuity of the recording is still ensured?
If these answers require several checks or several interlocutors, it is likely that the architecture already contains areas of uncertainty.
Compliance can no longer be a succession of layers
For years, the answer was to add a new tool every time a new use appeared.
Software for mobile.
A connector for Teams.
An application for videoconferencing.
Another tool for archiving.
This logic made it possible to respond quickly to the needs of the moment.
But it has also increased the technical dependencies, the interfaces to maintain and the risks of rupture between the different components.
As digital uses diversify, this approach is now showing its limits.
The challenge is no longer just to record more communications.
It consists of building an architecture capable of ensuring this continuity in a coherent manner, regardless of the channel used.
More and more players are therefore questioning approaches where recording, conservation and restitution mechanisms are integrated as close as possible to communication infrastructures, in order to limit break points and reduce dependence on a multiplication of application layers.
Compliance then ceases to be a function added a posteriori to become an intrinsic characteristic of the infrastructure.
Rethinking compliance before uses overtake us
Communication tools will continue to evolve.
Conversational artificial intelligence, new collaborative environments and increasingly mobile uses will further transform professional exchanges in the coming years.
In this context, compliance can no longer be considered as a simple regulatory subject.
It becomes a real architectural challenge.
The CIO is no longer just the one who guarantees the availability of systems. It also becomes one of the guarantors of their ability to demonstrate, at any time, the conformity of communications to the regulator.
This is undoubtedly the real change introduced by MiFID: less an evolution of the obligations themselves than a profound transformation of the way in which financial institutions must now design their digital infrastructures.