
If It Is Not Written It Never Happened. Telephone Recording Just Added a But!
Compliance functions know the supervisory rule well: if it is not written down, it never happened! Document the reasoning, keep the trail and be ready years later to show an inspector what you did and why. The instruction is sound. The trouble starts when good record keeping becomes an assumption that capturing more and retaining it for longer must provide more protection.
Telephone recording is where that assumption gets tested. On 10 September 2026 the Autorité des Marchés Financiers published the results of a SPOT inspection campaign on telephone conversation recordings at five asset management companies, covering 1 January 2023 to 31 December 2025. Taken as a list of failures the report is unremarkable. Taken as a study of what happens when the documentation instinct meets a system that also processes personal data, it repays a careful read.
The control issues are relevant beyond France. MiFID-derived recording requirements apply to firms within scope across the EU, while the UK FCA maintains a corresponding recording regime for specified firms and activities under SYSC 10A. The precise perimeter depends on the firm, the activity and the instrument.
1. What the Sample of Fifteen Showed
Two firms on the panel had defined a five-year retention period during the review period. One of them later extended its stated period to seven years, in October 2025. Both were in fact holding a ten-year recording history. A third firm had set retention at group level at seven years, and a fourth had a policy stating that recordings were not archived at all while retaining conversations going back to February 2022.
Surplus retention did not guarantee retrievability, although the two findings do not map neatly onto one another. The inspection team asked each firm for its list of orders placed by voice across the three years, selected a sample of fifteen, and requested the recordings documenting each transaction. Three firms supplied all fifteen. Two did not. One of the firms with a ten-year history was unable to provide five of its fifteen, while the other ten-year firm produced everything requested. The second firm missing five recordings had to obtain them from the brokers the orders had been transmitted to, because the conversations had taken place on a mobile phone that was not being recorded.
What separated the firms was whether the right line was captured and whether the mechanism worked. One firm had recorded no telephone lines between July 2022 and August 2023, following an incident its internal control only identified afterwards, leaving no audit trail for 47 orders placed by voice in that window. Another discovered in August 2025 that incoming calls to one of its managers' lines had gone unrecorded for several years, and logged the anomaly as an incident.
Mobiles are where the gap is widest. All five firms had extended recording to mobile phones, using professional devices, personal devices with professional use, or a mixture of the two. In every case the recorded calls were only those placed through a mobile application connected to the company telephone system, which means the arrangement depended on staff choosing that application over the phone's own dialler. None of the firms had implemented controls to verify consistent use of the recording application. One firm did conduct an internal survey in September 2025, which found five employees communicating with prospects or clients from their mobiles without using it, after which it went back to its telephony provider to check that the application was working and to deal with the technical difficulties some users had hit.
What this means in practice: the AMF records as poor practice the failure to control the installation and use of the recording application by employees who have a mobile phone. If your firm has extended recording to mobiles and has never verified that calls reach the archive, the extension exists on paper more than in fact.
2. Who Is Recorded, and the Reason for Each Function
Two firms on the panel had simply stated that telephone conversation recording applied to all their employees. The approvals on the panel came either directly from a senior manager or from a committee on which one sat. Formal approval, however, does not itself explain why every function belongs inside the recording perimeter.
The recordings contain the personal data of everyone on the call, so the processing needs a lawful basis, and the basis a regulated firm naturally reaches for is compliance with a legal obligation. The CNIL sets out four cumulative conditions for that basis, on top of the general necessity test. The obligation must come from EU or Member State law. It must be imperative and sufficiently clear and precise, which rules out a mere option or authorisation. It must at minimum define the purposes of the processing. And it must bind the controller rather than the data subjects. The controller has to be able to demonstrate that the basis is valid and to revisit that assessment where there is a material change in the conditions of processing, for example its purpose, the data processed or the retention period.
In practice this supports a function-specific and purpose-specific assessment rather than a single firm-wide declaration. Functions whose staff place or transmit orders, or conduct conversations aimed at leading to relevant transactions within the applicable rules, are likely to fall within the regulatory perimeter. Recording outside that perimeter requires a separately identified purpose and legal basis, which is what a blanket statement leaves undone.
The AMF points to the practice of one firm on the panel, which set out in its policy the functions whose telephone extensions were recorded and gave the reason for recording each of them. That is more work than a single sentence covering everyone, and it is where the justification actually sits.
The regulator states the underlying tension plainly enough. Financial regulation pushes firms towards breadth of persons, communications and retention in order to secure traceability and limit non-compliance risk. The data protection framework rests on minimisation and storage limitation. Reconciling the two calls for a precisely defined recording perimeter and a documented justification of the retention period chosen.
3. The Legal Basis Shapes Which Rights Apply
Processing founded on compliance with a legal obligation is not subject to the right to object or the right to data portability. Processing founded on legitimate interests is subject to the right to object, but not to data portability. The broader point is that the legal basis affects which rights can be exercised, and a recording policy that never identifies its basis does not, by itself, show an employee which rights apply.
The two bases are not interchangeable in this context. The CNIL position cited by the AMF is that a management company may only make permanent and systematic recordings of employee telephone conversations where this arises from a legal obligation laid down in sufficiently clear and precise terms. Where the recording pursues a purpose that does not explicitly arise from a legal obligation, the example given being an internal control objective of checking that an employee is not providing investment services by telephone, the authority considers that it can only be done by sampling, on an ad hoc and random basis, and subject to guarantees covering employee rights, authorised access, security and information provision.
Practitioner interpretation, not a finding of the AMF: the ability to interrupt a recording sits awkwardly between the two frameworks, though the tension is one of system design rather than an irreconcilable regulatory conflict. The AMF treats one firm's feature allowing employees to stop recording at the start of a call as a risk, because a business call that should have been captured may be suppressed, deliberately or by accident. The CNIL fact sheet on workplace call recording approaches a different question, namely how to keep genuinely personal calls private, and looks for either lines outside the recording system or a means of stopping the recording. Reconciling them is possible, but not by leaving a universal stop button on every extension. The practical answer is to protect personal calls through a defined route, whether an unrecorded line or a clearly scoped mechanism, while ensuring that calls falling within the mandatory recording perimeter cannot bypass recording.
One note on sources. The CNIL fact sheet the AMF footnotes carries a notice on the live page stating that it is out of date and being updated, and it is dated May 2009. On 9 July 2026 the CNIL published broader guidance on monitoring employee activity, setting out three cumulative conditions for any monitoring device, namely that it satisfies the justification and proportionality tests, that it goes to the staff representative bodies under the applicable thresholds, and that it is brought to the attention of the people concerned beforehand. That guidance also notes that constant surveillance is generally excessive and that the employer must be able to prove the necessity and proportionality analysis was carried out, while recognising that technology-specific rules may apply on top. Firms should read the July 2026 employee-monitoring guidance alongside the applicable sector-specific requirements, and treat the older telephone-recording fact sheet cautiously because the CNIL now marks it as obsolete and under revision.
4. Advice Calls Need a Documented Boundary
Investment advice presents a different scoping problem. The AMF does not say that every advice conversation must be recorded. What it does make clear is that treating advice as automatically outside the recording perimeter is unsafe.
The French implementation of the recording obligation names the reception and transmission of orders and does not name investment advice as a separate trigger. It does, however, catch telephone conversations aimed at leading to transactions concluded
in the context of client order services, even where the conversation never leads to a transaction or to the service being provided. A conversation connected with advice can therefore fall inside the obligation where it is aimed at leading to a transaction. On the AMF's reading, a firm holding both advice and RTO (reception and transmission of orders) permissions, or one providing an order handling service when marketing fund units or shares, will need to record conversations likely to contain both the advice and the order placement.
Firms are expected to distinguish between advice conversations that can and cannot lead to a transaction, using a risk-based approach determined by the firm, justified and formalised inside the recording policy, with its implementation documented. The report separately notes, at one firm, controls on the advice business that were not sufficiently substantiated because the listening sample was not detailed. Documenting where the boundary sits and documenting how it is tested are two different exercises.
5. Erasure Is a Documented Control Too
No firm on the panel had explicitly formalised in its policy the process for erasing recordings at the end of the chosen retention period. That is not the same as saying nobody could delete anything. Three of the five had tools capable of automatic erasure once the period expired, although their procedures did not define the process or the frequency for erasing recordings that had gone past it, and one firm formalised in October 2025 an annual meeting of a committee responsible for evaluating the data destruction to be carried out, including recordings that had reached the end of their retention period during the preceding year.
The absence of a written erasure process matters in both directions. The AMF links it to effective compliance with the retention period and to the need to supervise deletion closely enough to prevent recordings being altered or erased prematurely while they are still required.
The retention figures are worth restating because they differ by activity. For the provision of investment services the period is five years. For AIF management it is at least five years. For UCITS management it is at least six months and may not exceed five years. Running differentiated periods by activity is awkward for a firm with several permissions, and the AMF identifies a uniform five-year period, as the common denominator, as good practice. For investment-service records, the competent authority may require the five-year period to be extended to seven years, so firms subject to that requirement need the technical ability to do so. This should not be read as a general seven-year extension for every activity, since the same report states that UCITS management recordings may not exceed five years.
There is one timing point worth checking. For investment-service records, the retention period runs from the date the recording is created, not from the date the related order is eventually executed. One firm raised the case of a stop order with no validity period, which can remain live for years before execution. The recording evidencing the original instruction may therefore reach the end of its retention period before the order is filled. The AMF expects firms to adjust their arrangements to preserve traceability in cases of that kind.
6. What a Defensible Policy Contains
Gathered together, the panel's good and poor practices produce a short and fairly specific list.
Start with a single policy rather than provisions scattered across an order placement procedure, a data retention procedure, an IT charter and a code of ethics. Failure to collate all the applicable provisions into a single policy is recorded as poor practice. At one firm, the relevant provisions were scattered across several procedures until October 2025. At another, the recording and archiving procedure did not cover telephone recordings until February 2024. Within it, the recorded functions should be listed with the reason for recording each one, and the retention period stated with the reasoning behind it and with the extension mechanism provided for where the activity attracts it.
The erasure process should be formalised, including how and how often recordings that have reached the end of the retention period are dealt with. As a matter of practitioner good practice rather than an AMF finding, it is also worth assigning clear ownership of that process.
The risk-based reasoning on advice calls needs to be visible, along with evidence of how it is applied in practice.
Access arrangements should not depend on a technical intermediary. At two firms the compliance officer had to raise a request with an IT or telephony team to obtain recordings, which the AMF notes can delay the investigation of an incident or a dispute and introduces an operational risk of partial selection or unintentional modification. A register tracking access requests made by recorded employees is recorded as good practice.
Business continuity plans should carry a telephone and recording system failure scenario. Only one firm on the panel had mapped it. Two had described IT failure scenarios without following them through to telecommunications, and two had nothing of the kind.
Controls should be directed at telephone recording explicitly rather than reaching it incidentally through order processing or GDPR compliance reviews. The panel's controls missed a policy gap at one firm, a recording system incident at another, and a manager routinely placing orders from an unregistered mobile at a third. Listening to a sample of orders placed by voice each quarter is recorded as good practice.
Finally, awareness for new joiners on arrival and for all staff annually. No firm on the panel provided regular training on the subject, and the effectiveness of the recording regime depends in part on staff understanding the tools and using them correctly, particularly on mobile devices.
The Rule, With Its Qualification
Only 19% of respondents to a questionnaire sent to all French management companies in summer 2025 said they used voice order placement, and at the firms that do use it the channel is marginal by volume. That is part of why it deserves attention rather than a reason to relax. Electronic systems carry time stamping, archiving and audit trail functionality natively. The voice channel does not, which is why the regulator concludes that it presents a potentially increased level of operational and non-compliance risk despite being quantitatively less frequent, and why it justifies continued specific vigilance in internal control systems.
The rule about writing things down survives, with a qualification attached. It was always an instruction to document the reasoning rather than to accumulate the artefacts, and the distinction is visible in the inspection results. One firm held a ten-year recording history and still could not provide five of fifteen requested recordings. Another firm with the same ten-year history produced everything requested. What mattered was whether the right communications were captured, retrievable and retained for a justified period.
Know what supervisors are looking for. Recording scope, retention and the controls that sit over them are recurring themes in the functional responsibilities of an asset management firm under MiFID II, and they are examined in detail in our seminar programme.
Explore seminars at cpds.academy
Sources.Autorité des Marchés Financiers, Summary of SPOT inspections relating to telephone conversation recordings by asset management companies, 10 September 2026. Commission Nationale de l'Informatique et des Libertés, fact sheets on workplace call recording, the legal obligation basis, BYOD good practice and purpose definition, together with its guidance of 9 July 2026 on monitoring employee activity. Regulatory provisions referenced are drawn from Delegated Regulation (EU) 2017/565, Delegated Regulation (EU) No 231/2013, the French Monetary and Financial Code and the AMF General Regulation. The UK position referred to is the FCA regime under SYSC 10A.
This article is provided for general information and professional development purposes. It does not constitute legal or regulatory advice, and firms should assess their own arrangements against the requirements applicable to them.

Article by Nikolas Demetriades
Published 14 Sep 2026