Learn key rules around the investor protection framework and how it impact your organisation.

Markets in Financial Instruments Directive II

CRD VI: reshaping the EU banking landscape

What is MiFID and how does it impact the financial sector?

MiFID is a cornerstone of EU financial regulation, shaping how investment firms operate, interact with clients, and distribute financial products. It establishes a harmonised framework to promote transparent, fair, and efficient markets while strengthening investor protection and trust across the financial system.


What is it?

 MiFID II is the EU’s primary legislative framework governing investment services and activities. It has applied across the European Economic Area since January 2018, replacing the original Markets in Financial Instruments Directive (MiFID I) and extending its scope to cover investment firms, trading venues, data reporting service providers, and third country firms accessing EU markets. The directive establishes rules governing how financial instruments are traded, how clients must be protected, how firms must organise themselves internally, and how markets must operate — spanning client classification and suitability, product governance, costs and charges disclosure, best execution, and transaction reporting. Read together with its accompanying regulation, MiFID II is the cornerstone of EU capital markets regulation, across asset managers, credit institutions, brokers, investment advisers, and any entity providing investment services or performing investment activities within the EEA. MiFID II fundamentally reshapes how investment services are delivered across Europe — its reach extends from front-office conduct to back-office reporting, and from retail client protection to wholesale market structure.

Why does it matter?

MiFID II has three key pillars according to the regulator’s objectives:

MiFID II sets detailed requirements for how firms must treat their clients — from initial classification through ongoing suitability assessments, product governance, and disclosures.

The framework imposes extensive pre- and post-trade transparency requirements on trading venues and systematic internalisers, aiming to improve price discovery and market efficiency across asset classes.

MiFID II is one of the central pillars of supervisory surveillance across the EU, establishing harmonised conduct obligations that national competent authorities are required to actively monitor and enforce. In Luxembourg, the CSSF has consistently designated MiFID II as a priority topic within its annual supervisory programme, reflecting the jurisdiction's role as a major hub for cross-border investment services and fund distribution. On-site inspections targeting MiFID II compliance are conducted on a recurring basis, making a robust and audit-ready compliance framework an operational necessity for any firm active in the Luxembourg market.

Key regulatory themes and business consequences

Pillars define the regulatory substance of MiFID II — each with distinct firm-level obligations:

Before any investment service is provided, clients must be classified as retail, professional, or eligible counterparty to determine the applicable level of protection.

Business impact: Classification drives every downstream obligation — suitability, disclosure, product eligibility, and reporting. It requires front office staff to apply documented criteria at onboarding, compliance to maintain and review the classification framework, and core systems to store and propagate classification status accurately across all processes. Misclassification is a primary source of regulatory sanction.

Firms must provide prescribed information about themselves and collect sufficient client information to perform the controls required by the client's level of protection.

Business impact: On-boarding is the firm's main point of regulatory exposure — incomplete client data creates cascading failures across suitability, product governance, and reporting. It requires a structured client data model in core systems, disciplined data collection by front office, and clear ownership across compliance and operations. Firms that streamline this process digitally gain both compliance quality and commercial efficiency.

Suitability assessments are required before investment advice and portfolio management; appropriateness checks apply to non-advised execution in complex products — both calibrated to the client's profile.

Business impact: This is the highest area of conduct risk and regulatory sanction exposure in the industry. It demands automated suitability engines linked to client profiles and product catalogues, documented outcomes retained per transaction, and workflow controls that block execution where assessments are incomplete. The suitability framework directly shapes which products can be recommended to which clients — making it a strategic as well as a compliance matter.

Manufacturers must define target markets and conduct product reviews; distributors must ensure products reach only the clients for whom they are designed.

Business impact: Product governance creates a dual obligation that requires sustained coordination between manufacturers and distributors. Core systems must embed target market parameters at the product level and enforce eligibility checks at point of sale. Management bodies are explicitly accountable for oversight of the product governance process, making this a board-level concern with direct implications for product strategy and distribution model design.

Firms must provide clients with all relevant information on services rendered — including transaction confirmations, periodic statements, portfolio valuations, cost disclosures, and loss alerts.

Business impact: Reporting obligations are operationally intensive, requiring accurate aggregation of all direct and indirect costs across the full-service chain, timely delivery of disclosures, and robust data infrastructure. Ex-ante and ex-post cost disclosures in particular demand close coordination between product, finance, and operations. Reporting quality is increasingly a commercial differentiator — poor reporting generates both regulatory and reputational risk.

MiFID II strictly regulates third-party payments — inducements are only permissible where they demonstrably enhance the quality of service to the client and are fully disclosed.

Business impact: Inducements rules directly challenge traditional distribution economics, particularly for firms relying on retrocessions or third-party commissions. All inducements must be registered, tested against the quality enhancement standard, and disclosed to clients on an ex-ante and ex-post basis. Business introducer arrangements must be formalised and compliant. For many firms, this requires a fundamental review of distribution and pricing strategy.

Firms must retain records of all services, transactions, client communications, and organisational arrangements — including telephone and electronic communications — in a tamper-proof, regulator-accessible format.

Business impact: Records are the evidentiary foundation of any regulatory defence. Gaps are treated by supervisors as gaps in compliance. This requires a centralised, structured record-keeping architecture, a minimum five-year retention policy, and the ability to reconstruct individual transactions on demand. Front office staff must understand that verbal instructions and telephone conversations are subject to recording obligations — a significant cultural and operational change for many firms.

All personnel providing investment advice or information on financial instruments must meet defined competence standards set out in ESMA guidelines, with supervised practice periods applying before full authorisation.

Business impact: This is an explicit governance obligation — management bodies must ensure staff have sufficient time and resources to achieve and maintain competence. It requires a firm-wide competence framework by role, individual assessment and tracking via HR systems, ongoing CPD (Continuous Professional Development) monitoring, and regular reporting to senior management. Firms that treat this as a genuine investment rather than a compliance exercise build stronger advisory capability and reduce conduct risk over time.

Regulatory timeline

 MiFID II is an in-force framework — its core rules apply today, while targeted reforms continue to refine specific areas of the regime.

MiFID II Timeline Timeline horizontale MiFID avec texte en noir. 2007 MiFID I First harmonised EU framework for investment services ✓ Completed 2011 – 2014 MiFID II Proposal & adoption Revised framework post-financial crisis ✓ Completed Jan 2018 Application MiFID II & MiFIR entered into force across the EEA ✓ Completed Ongoing Reforms CMU & Retail Investment Strategy reviews ● Now Retail Investment Strategy Conduct & advice ↗ Ahead

How we can help

Regulatory Gap Analysis

Assessment of a firm's existing MiFID II framework against applicable regulatory requirements, identifying deficiencies and prioritising remediation actions through structured gap-to-compliance mapping. 

Remediation Support

Assistance in addressing findings raised by the CSSF following on-site inspections, or by internal/external auditors, including root cause analysis, action plan design, implementation support, and follow-up evidence documentation. 

Regulatory Assistance in Implementation of New Investment Services

End-to-end regulatory support when a firm launches or expands investment services, covering the design of the control framework, drafting of client-facing documentation, policies and procedures, and translation of regulatory requirements into operational and system specifications.

Licensing Support (Top-Up)

Guidance through the CSSF authorisation process for firms seeking to extend their existing licence with additional MiFID II investment services or activities, including application file preparation and regulatory dialogue support.

Support in the Performance of Controls (1LoD & 2LoD)

Hands-on assistance to business lines (1LoD) and compliance functions (2LoD) in designing, executing, and documenting MiFID II-related controls, including control testing, thematic reviews, and reporting to governance bodies.

Contact us

Cécile Liégeois

Clients & Markets Leader, PwC Luxembourg

Tel: +325 621 332 245

Isabelle Melcion-Richard

Advisory Partner, Regulatory & Compliance, PwC Luxembourg

Tel: +352 49 48 48 2469

Dirk Kruse

Advisory Director, Risk & Compliance, PwC Luxembourg

Tel: +352 621 334 102

Follow us