Financial regulation

MiFID II and MAR,explained

8 min read · Updated July 2026

MiFID II (Directive 2014/65/EU) and MiFIR govern how investment firms and trading venues operate in the EU: how clients are treated, how orders are executed, and what has to be reported. MAR (Regulation 596/2014) sits alongside them and governs market integrity: insider dealing, unlawful disclosure of inside information, and market manipulation.

Two regimes, one operating reality

MiFID II is about conduct and market structure. MAR is about abuse. Firms tend to run them together because the evidence overlaps heavily: the same order records, communications archives and surveillance alerts serve both, and the same governance sits over them.

After Brexit the UK onshored both, so a firm operating either side of the Channel typically runs one control set mapped to two rulebooks that have started to diverge in detail.

MiFID II: investor protection

  • Client categorisation: retail, professional, or eligible counterparty, with the protections scaling accordingly.
  • Suitability and appropriateness: for advice and portfolio management, evidence that the recommendation fits the client, and a suitability report to back it.
  • Product governance: manufacturers define a target market and distributors sell into it, with feedback flowing back the other way.
  • Costs and charges: aggregated ex-ante and ex-post disclosure, including the effect of costs on returns.
  • Inducements and research: tight limits on what can be received, and research paid for explicitly rather than bundled into execution.

MiFID II: execution, reporting and records

Best execution requires you to take all sufficient steps to obtain the best possible result for the client, and to be able to demonstrate it rather than assert it. Transaction reporting under MiFIR requires complete and accurate reports to the competent authority by the end of the following working day, which is where most data-quality remediation projects start.

The records obligation is the one that surprises new entrants: telephone and electronic communications relating to transactions have to be recorded and retained, normally for five years and longer if a competent authority asks. Algorithmic trading brings its own control requirements, including testing, kill functionality and clock synchronisation.

MAR: what it prohibits

MAR prohibits insider dealing, unlawfully disclosing inside information, and market manipulation, and it applies to instruments admitted to trading on regulated markets, MTFs and OTFs, plus certain related instruments. It reaches beyond banks: an issuer with shares on a growth market is squarely in scope.

MAR: what it makes you do

  • Disclose inside information to the market as soon as possible, or record a valid delay with the reasons and the timeline.
  • Maintain insider lists, kept current and precise about who knew what and when.
  • Manage transactions by persons discharging managerial responsibilities and people closely associated with them, including notification and closed periods before results.
  • Run surveillance and file suspicious transaction and order reports where there is a reasonable suspicion.
  • Follow the market-soundings procedure when information is passed to potential investors ahead of a transaction.

How it relates to security frameworks

The overlap with ISO 27001 and SOC 2 is real but partial. Retention and integrity of records, access control over inside information, logging, change control over trading and surveillance systems, and vendor oversight all map across cleanly. What does not map is the conduct substance: suitability, best execution, target markets, and the reporting obligations. A sensible approach is to satisfy the shared controls once and treat the conduct requirements as their own layer on top.

Frequently asked questions

What is the difference between MiFID II and MiFIR?

MiFID II is a directive, so member states transpose it into national law, and it covers authorisation, conduct and organisational requirements. MiFIR is a regulation that applies directly and covers transparency, transaction reporting and trading obligations. Firms feel them as one regime.

Does MAR apply to companies that are not banks?

Yes. Any issuer with instruments admitted to trading on a regulated market, MTF or OTF is in scope, along with the people who work for it. Issuers carry the disclosure, insider list and managers-transactions obligations even if they never trade for clients.

How long do MiFID II records have to be kept?

The general expectation is five years, including recorded telephone and electronic communications relating to transactions, and up to seven years where the competent authority requires it. Retention needs to be provable, so the archive has to be tamper-evident and retrievable, not just present.

Do this in a fraction of the time

Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.

Related guides

Due diligence

What is a DDQ (due-diligence questionnaire)?

Due diligence

DDQ vs RFP: what is the difference?

RFPs

RFP vs RFI vs RFQ: what is the difference?

RFPs

The RFP response process: a step-by-step guide

RFPs

How to build an RFP content library

RFPs

The bid/no-bid decision: when to respond to an RFP

Security questionnaires

How to respond to security questionnaires faster

Security questionnaires

SIG vs CAIQ vs VSAQ: the security questionnaires explained

Security questionnaires

Vendor security assessment checklist

Compliance

SOC 2 vs ISO 27001: what is the difference?

Compliance

ISO 27001 readiness checklist: how to prepare for certification

Compliance

SOC 2 for startups: a practical guide

Compliance

GDPR compliance for SaaS: a practical guide

Compliance

HIPAA compliance for software vendors

Compliance

PCI DSS compliance, explained

Compliance

The NIST Cybersecurity Framework, explained

Compliance

ISO 42001, the AI management standard, explained

Compliance

ISO 27017 and ISO 27018: cloud security and privacy, explained

Compliance

ISO 22301 and business continuity, explained

Compliance

DORA, explained

Compliance

Cyber Essentials, explained

Compliance

The CCPA and CPRA, explained

Compliance

NIST 800-53, explained

Compliance

NIST 800-171 and CMMC, explained

Compliance

FedRAMP, explained

Compliance

HITRUST CSF, explained

Financial regulation

BSA/AML, explained

Financial regulation

The FATF 40 Recommendations, explained

Financial regulation

Consumer credit and fair lending, explained

Due diligence

Third-party risk management (TPRM): a practical guide

Putting MiFID II and MAR into practice? See Diligio Compliance for MiFID II and MAR.