MiFID II and MAR,explained
MiFID II (Directive 2014/65/EU) and MiFIR govern how investment firms and trading venues operate in the EU: how clients are treated, how orders are executed, and what has to be reported. MAR (Regulation 596/2014) sits alongside them and governs market integrity: insider dealing, unlawful disclosure of inside information, and market manipulation.
Two regimes, one operating reality
MiFID II is about conduct and market structure. MAR is about abuse. Firms tend to run them together because the evidence overlaps heavily: the same order records, communications archives and surveillance alerts serve both, and the same governance sits over them.
After Brexit the UK onshored both, so a firm operating either side of the Channel typically runs one control set mapped to two rulebooks that have started to diverge in detail.
MiFID II: investor protection
- Client categorisation: retail, professional, or eligible counterparty, with the protections scaling accordingly.
- Suitability and appropriateness: for advice and portfolio management, evidence that the recommendation fits the client, and a suitability report to back it.
- Product governance: manufacturers define a target market and distributors sell into it, with feedback flowing back the other way.
- Costs and charges: aggregated ex-ante and ex-post disclosure, including the effect of costs on returns.
- Inducements and research: tight limits on what can be received, and research paid for explicitly rather than bundled into execution.
MiFID II: execution, reporting and records
Best execution requires you to take all sufficient steps to obtain the best possible result for the client, and to be able to demonstrate it rather than assert it. Transaction reporting under MiFIR requires complete and accurate reports to the competent authority by the end of the following working day, which is where most data-quality remediation projects start.
The records obligation is the one that surprises new entrants: telephone and electronic communications relating to transactions have to be recorded and retained, normally for five years and longer if a competent authority asks. Algorithmic trading brings its own control requirements, including testing, kill functionality and clock synchronisation.
MAR: what it prohibits
MAR prohibits insider dealing, unlawfully disclosing inside information, and market manipulation, and it applies to instruments admitted to trading on regulated markets, MTFs and OTFs, plus certain related instruments. It reaches beyond banks: an issuer with shares on a growth market is squarely in scope.
MAR: what it makes you do
- Disclose inside information to the market as soon as possible, or record a valid delay with the reasons and the timeline.
- Maintain insider lists, kept current and precise about who knew what and when.
- Manage transactions by persons discharging managerial responsibilities and people closely associated with them, including notification and closed periods before results.
- Run surveillance and file suspicious transaction and order reports where there is a reasonable suspicion.
- Follow the market-soundings procedure when information is passed to potential investors ahead of a transaction.
How it relates to security frameworks
The overlap with ISO 27001 and SOC 2 is real but partial. Retention and integrity of records, access control over inside information, logging, change control over trading and surveillance systems, and vendor oversight all map across cleanly. What does not map is the conduct substance: suitability, best execution, target markets, and the reporting obligations. A sensible approach is to satisfy the shared controls once and treat the conduct requirements as their own layer on top.
Frequently asked questions
What is the difference between MiFID II and MiFIR?
MiFID II is a directive, so member states transpose it into national law, and it covers authorisation, conduct and organisational requirements. MiFIR is a regulation that applies directly and covers transparency, transaction reporting and trading obligations. Firms feel them as one regime.
Does MAR apply to companies that are not banks?
Yes. Any issuer with instruments admitted to trading on a regulated market, MTF or OTF is in scope, along with the people who work for it. Issuers carry the disclosure, insider list and managers-transactions obligations even if they never trade for clients.
How long do MiFID II records have to be kept?
The general expectation is five years, including recorded telephone and electronic communications relating to transactions, and up to seven years where the competent authority requires it. Retention needs to be provable, so the archive has to be tamper-evident and retrievable, not just present.
Do this in a fraction of the time
Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.
Related guides
What is a DDQ (due-diligence questionnaire)?
Due diligenceDDQ vs RFP: what is the difference?
RFPsRFP vs RFI vs RFQ: what is the difference?
RFPsThe RFP response process: a step-by-step guide
RFPsHow to build an RFP content library
RFPsThe bid/no-bid decision: when to respond to an RFP
Security questionnairesHow to respond to security questionnaires faster
Security questionnairesSIG vs CAIQ vs VSAQ: the security questionnaires explained
Security questionnairesVendor security assessment checklist
ComplianceSOC 2 vs ISO 27001: what is the difference?
ComplianceISO 27001 readiness checklist: how to prepare for certification
ComplianceSOC 2 for startups: a practical guide
ComplianceGDPR compliance for SaaS: a practical guide
ComplianceHIPAA compliance for software vendors
CompliancePCI DSS compliance, explained
ComplianceThe NIST Cybersecurity Framework, explained
ComplianceISO 42001, the AI management standard, explained
ComplianceISO 27017 and ISO 27018: cloud security and privacy, explained
ComplianceISO 22301 and business continuity, explained
ComplianceDORA, explained
ComplianceCyber Essentials, explained
ComplianceThe CCPA and CPRA, explained
ComplianceNIST 800-53, explained
ComplianceNIST 800-171 and CMMC, explained
ComplianceFedRAMP, explained
ComplianceHITRUST CSF, explained
Financial regulationBSA/AML, explained
Financial regulationThe FATF 40 Recommendations, explained
Financial regulationConsumer credit and fair lending, explained
Due diligenceThird-party risk management (TPRM): a practical guide
Putting MiFID II and MAR into practice? See Diligio Compliance for MiFID II and MAR.