Financial compliance field guide
MiFID II Call Recording for Cisco CUCM and Webex: Retention, Search, and Proof
Turn the MiFID II recording duty into a tested Cisco capture, protected retention, ready-retrieval, and completeness-monitoring workflow.
Signal path
Where call-recording.com intervenes
From technical requirement to working recording
Call Observe supports approved Cisco and Webex capture paths with health, delivery, search, access, retention, and audit controls; the regulated firm remains responsible for scope, policy, monitoring, and evidence.
Short answer
MiFID II requires an in-scope investment firm to record specified telephone conversations and electronic communications connected with dealing on own account and client-order services. The duty can apply when a conversation is intended to lead to a transaction even if no transaction is completed.
A Cisco call-recording design must therefore do more than create audio. It must identify the regulated people and channels, give advance notice, prevent business on unapproved channels, capture complete calls, protect the records, retain them for the required period, retrieve them promptly, and monitor whether the policy works.
Call Observe from call-recording.com can support those technical controls for approved Cisco CUCM, CUBE, and supported Webex Calling paths. The firm remains responsible for regulatory scope and operation.
Which communications are in scope?
MiFID II Article 16(7) covers relevant telephone conversations and electronic communications involving dealing on own account and the provision of client-order services. It includes communications intended to result in transactions, even when no transaction follows.
The scope is based on activity, not simply job title or telephone number. Map:
- regulated entities and business units;
- traders, salespeople, advisers, supervisors, and support roles;
- desk phones, soft clients, mobiles, remote devices, queues, and shared lines;
- inbound, outbound, internal, transferred, and conference calls; and
- approved voice, email, chat, meeting, and mobile channels.
ESMA's scope guidance should be read with the rules and the firm's competent-authority guidance. Legal and compliance teams should approve the final activity map.
What notice and equipment rules apply?
Clients must be notified in advance that relevant communications are recorded. Firms must take reasonable steps to record communications made, sent, or received using equipment provided to an employee or contractor, or using private equipment whose use has been accepted or permitted.
The operational response is to define approved channels, make the notice repeatable, restrict or prohibit unrecorded alternatives, train staff, and monitor exceptions. A disclosure at the start of a Cisco queue does not control a conversation that moves to a personal mobile or an unapproved messaging app.
How long must MiFID II recordings be kept?
MiFID II sets a five-year period for the Article 16(7) records, with extension up to seven years when requested by the competent authority. Retention must be configured from the applicable start event and coordinated with legal holds, investigations, privacy duties, and any longer obligation that applies.
Do not turn “five years” into a single global setting for every call. Non-MiFID calls may have a shorter justified period. The call-recording retention guide compares the main frameworks and the decisions a schedule needs.
What must retrieval and record protection prove?
Article 76 of Delegated Regulation 2017/565 adds important operating detail. A firm needs a written policy, management oversight, training, monitoring, controls over quality and completeness, ready accessibility, and a durable format that prevents alteration or deletion of the original record.
An acceptance test should prove that an authorized reviewer can:
- search by a known person, number, date, queue, or call identifier;
- find the complete interaction and related segments;
- play both sides with correct timestamps and metadata;
- see capture, delivery, access, and export evidence;
- apply the approved retention or hold rule; and
- export a review copy without silently changing the retained original.
The firm should also prove that an unauthorized person cannot perform those actions.
Why call completeness is a regulatory control
A retention setting cannot protect a call that was never captured. Cisco estates can create blind spots when:
- a Built-In Bridge is disabled or unsupported;
- a line has the wrong recording profile;
- a mobile or remote call uses a different media source;
- a call bypasses the CUBE carrying the SIPREC policy;
- a codec offer has no match;
- only one RTP stream reaches the recorder; or
- a hold, transfer, or conference creates an unlinked segment.
Call Observe reports missing RTP streams and codec negotiation failures through the dashboard notification panel and configurable email. The CUCM troubleshooting guide explains those signals. Use them as operational evidence, then reconcile expected regulated calls with recorded calls on a defined schedule.
How Call Observe supports the control set
For supported recording paths, Call Observe provides:
- customer-hosted Cisco capture and encrypted outbound delivery;
- encrypted cloud storage;
- organization-scoped roles, search, and playback;
- retention controls and audit history;
- visible delivery state, local persistence, and durable retry;
- recording-health notifications; and
- one review workflow for supported CUCM and Webex Calling recordings.
The recording-integrity design, security architecture, and compliance controls brief describe the supporting architecture. Procurement still needs to test the exact durable-record, export, legal-hold, supervision, and retrieval requirements against the firm's policy.
MiFID II implementation checklist
- Obtain a counsel-approved map of regulated activities, people, devices, call types, and locations.
- Define the approved recording notice and prove it runs before the in-scope conversation.
- Block or govern private devices and off-channel communications.
- Map every call path to Built-In Bridge, CUCM network-based recording, CUBE SIPREC, Webex Calling, or another approved source.
- Test both audio directions, metadata, transfers, conferences, mobility, alternate routes, and failover.
- Configure five-year retention and any competent-authority extension, holds, and controlled deletion.
- Prove ready search, playback, export, original-record protection, and client-access handling.
- Run risk-based quality and completeness monitoring and send exceptions to accountable owners.
Bottom line
MiFID II recording is a completeness and governance obligation. The firm must know which communications are in scope, keep staff on approved channels, capture the full interaction, protect it, find it, and show that monitoring catches gaps.
Call Observe can supply the Cisco recording, health, delivery, search, access, retention, and audit controls for supported paths. The regulated firm must decide scope, approve the policy, configure the system, and retain evidence that the controls work.
Where call-recording.com intervenes
From technical requirement to working recording
Call Observe supports approved Cisco and Webex capture paths with health, delivery, search, access, retention, and audit controls; the regulated firm remains responsible for scope, policy, monitoring, and evidence.
Source ledger
Primary references and technical evidence
Validate version-specific commands, legal scope, and policy decisions against the current source applicable to your environment.
Legal and compliance content is general information, not legal advice. Cisco behavior and commands vary by product release, platform, firmware, and call flow.
Continue the research