
Triangular Passporting: How ESMA Expects the Cross-Border Structure to Work
In a supervisory briefing dated 7 July 2026, ESMA set out how MiFID II applies to triangular passporting (ESMA35-243228190-8065). The arrangement is not new, and neither is the term. What the briefing offers is a single place where the structure, the MiFID II principles that govern it, and ESMA's supervisory expectations sit together.
1. What the Briefing Does
Triangular passporting has been discussed before. The briefing itself calls it "so-called Triangular Passporting," points back to earlier work by the Commission and by CESR, ESMA's predecessor, and cites a January 2023 EBA Q&A already titled "Triangular passport" in the payment-services context. The label was in circulation well before this document.
The contribution here is consolidation. Definition, underlying MiFID II principles, supervisory expectations for firms, and the allocation of responsibility between authorities are drawn into one text. ESMA is careful to state its status: non-binding, no new legal obligations, no comply-or-explain mechanism. The aim is convergence β getting national competent authorities to read the existing rules the same way when they encounter this arrangement.
2. What Triangular Passporting Is
ESMA's definition runs as follows. An authorised investment firm uses a branch or tied agent established through the freedom of establishment (Article 35 MiFID II) in a host Member State (Member State B) to provide investment services under the freedom to provide services (Article 34 MiFID II) in another host Member State (Member State C).
Put plainly: a firm licensed in Member State A uses a branch or tied agent in Member State B to serve clients in Member State C. Not every cross-border branch is doing this. The defining feature is the third state β services reaching clients in a country that is neither the firm's home nor the location of the branch.
Why firms structure things this way is not left to guesswork. The briefing lists geographic, cultural or linguistic proximity; brand building or brand differentiation, since a licensed entity can run different brands in different Member States; process streamlining, for instance by centralising ancillary services in a local branch; and easier access to cross-border markets. NCAs report having seen the practice used multiple times.
3. MiFID II Does Not Explicitly Cover or Prohibit It
On the law, ESMA is direct. MiFID II does not explicitly cover, nor prohibit, triangular passporting where a firm uses its Article 34 passporting rights, even though the services reaching Member State C are provided via a branch or tied agent established in Member State B.
The document is non-binding: not subject to any comply-or-explain mechanism for NCAs, not new policy, and not a prescription of how to supervise. NCAs are expected to apply it within a reasonable timeframe, and proportionately to the size, risk profile, nature, scale and complexity of a firm's practices.
Practical point: the briefing itself is non-binding and creates no new legal obligations, but it does explain how supervisors expect firms to apply the MiFID II requirements that do bind them. The status of the document leaves those underlying obligations exactly where they were; it simply shows how supervisors read them.
4. The Principle Underneath: The Branch Is Not the Provider
Everything in the briefing rests on a principle carried over from MiFID I. Quoting a Commission services paper embedded in the CESR Protocol on the supervision of branches, ESMA restates that any cross-border operation through a branch outside the territory of the Member State in which this branch is located is a provision of services by the investment firm and not by the branch as a separate legal entity. The principle predates MiFID II, but ESMA considers it still largely relevant because the same underlying logic continues to apply to the freedom to provide services. The briefing uses it as a basis for its more detailed expectations under MiFID II.
What follows is not complicated. Where a firm provides cross-border services in Member State C via a branch in Member State B, it is the firm that holds the MiFID II licence and the firm that exercises the passporting right. The branch has no legal personality of its own, no separate authorisation, and therefore no passport.
Tied agents arrive at the same destination by a different path. A tied agent does have separate legal personality, but because it acts under the full and unconditional responsibility of the single firm on whose behalf it operates, it sits under that firm's licence. This is the point that decides where supervision lands later in the briefing.
5. What ESMA Expects of Firms
Several expectations follow. The ones set out below have the clearest operational consequences.
Tied-agent agreements should authorise cross-border services expressly. A tied agent has its own legal personality, so ESMA looks for the agreement between firm and agent to set out express authority to provide services cross-border on the firm's behalf. The reasoning is control: provision from Member State B into Member State C carries regulatory and compliance consequences for the firm, which must therefore retain control over the geographical scope of the agent's activities.
Passporting notifications should describe the arrangement accurately. Where a firm relies on triangular passporting, its notification to the home NCA should say so β naming the intention to use a branch or tied agent in Member State B to provide services in Member State C. The briefing points to the Article 34 templates in the Annexes of Commission Implementing Regulation (EU) 2017/2382, and notes a cover letter to Annex I can flag the branch or tied agent in Member State B.
Notifications should keep pace with the operating model. The notification should cover the services and activities the firm means to provide cross-border into Member State C, together with any changes. Restructure the operation and rely on triangular passporting for something already notified, and the home NCA should hear about it through an updated Annex I notification.
An internal assessment of the risks the model creates. ESMA expects a firm to assess the risks arising specifically from this cross-border model and to revisit that assessment where necessary. The categories named are investor protection, money laundering and terrorist financing, responsibilities where services are outsourced, and third-party risk, and ESMA observes that these risks increase when internal processes must answer to more than two jurisdictions at once. The briefing requires an internal assessment and regular review where necessary, but does not specify a particular format.
No forum shopping. The structure should not be used to circumvent supervisory competences or to select preferred regulatory practices through forum shopping. Establishing a branch or tied agent in Member State B solely to passport services onward to Member State C could, ESMA says, be considered not in line with Article 35.
Get the sequence right. The branch or tied agent should be established and fully operational in Member State B under Article 35, within the timeframes set there, before any cross-border service flows from B to C under Article 34. Both notifications can be submitted together, but services into Member State C may only begin once the Article 35 time period has expired.
6. What ESMA Expects Firms to Tell Clients
Three disclosure expectations sit at the centre of the investor-protection concern.
Clients in Member State C should be told, clearly, that the service comes from the firm through a branch or tied agent established in Member State B. They should also be told which authority stands behind that service: the home Member State's NCA supervises what they receive through the branch or tied agent, not the host NCA of the Member State where the branch or tied agent is established.
Then there is complaints and redress. Article 75(1) MiFID II requires Member States to make sure firms sign up to at least one extra-judicial mechanism for consumer complaints, and on that footing ESMA expects firms to tell clients β clearly and without misleading them β how to reach complaints and redress procedures, and what investor compensation scheme, if any, applies. ESMA adds that ADR mechanisms relevant to cross-border provision can be affiliated with the EU Financial Dispute Resolution Network (FIN-NET).
Underlying all of it: leaning on an existing branch or tied agent should not cost investors their rights or muddy who is responsible for what inside the firm, and anything a client is told should be fair, clear and not misleading.
7. Complaints Handling
Two of the complaints expectations carry direct process consequences.
Language comes first. Given the firm's general duty to act honestly, fairly and professionally in its clients' best interests, ESMA takes the view that a client should be able to complain in any language the firm has used with them β in marketing communications or in contractual documents.
Routing comes next. A Member State C client's complaint should be accepted whether it lands at the head office in Member State A or at the branch or tied agent in Member State B. Those complaints should also be included in the complaints-handling procedure required under Article 26 of the MiFID II Delegated Regulation. The firm should record the complaints and the measures taken to resolve them, and should allow clients and potential clients to submit complaints free of charge.
Practical point: a firm marketing in a language its complaints function cannot handle has a gap to close, and so does one whose complaints register lives at branch level and never captures Member State C clients. Both turn on documents the firm already holds β a sensible place to begin when reading the briefing against your own arrangements.
8. Where Supervisory Responsibility Sits
The allocation under Articles 34 and 35 breaks down like this.
Organisational requirements β including the branch or tied agent in Member State B β fall to the home NCA. Conduct of business for what the branch or tied agent does within Member State B falls to the host NCA there.
The cross-border dimension is where the allocation becomes less obvious. The home NCA supervises the provision of all cross-border services by the firm, wherever they originate β the home state, or a branch or tied agent established elsewhere. So for services provided into Member State C under a triangular arrangement, the home NCA is responsible for supervising both the organisational requirements and the conduct-of-business requirements. The logic runs straight back to section 4: a branch or tied agent holds no passport of its own; that right belongs to the licensed entity, under home supervision.
ESMA is candid that this can be awkward to run without cooperation across the authorities involved. Its own example: the home NCA might need to inspect the branch or tied agent on site in Member State B, where help from the host NCA there may be essential β even though that authority is neither competent nor responsible for services provided cross-border into other host states.
With a tied agent in the picture, ESMA flags coordination between the home NCA and the NCA where the agent is registered as important to avoiding blind spots, given the agent's separate legal personality and its potential exposure to national legislation under Article 29(6) MiFID II.
9. Reading the Briefing in Context
The following is commentary. It is an interpretation of the briefing, not a statement by ESMA.
A document that disclaims itself as often as this one does is easy to underrate: non-binding, no comply-or-explain, not new policy, not exhaustive. Those disclaimers are an accurate account of its legal status. They say nothing about its purpose.
The purpose is convergence. An authority looking at a triangular structure before this briefing was hardly starting from nothing β the MiFID II articles, a Commission services paper, the CESR Protocol on the supervision of branches, Commission Delegated Regulation (EU) 2017/586 and Commission Implementing Regulation (EU) 2017/980 were all there, alongside the EBA's own handling of the term. The briefing gathers those threads into one statement of how they fit together for this arrangement, so authorities read them consistently. It gives NCAs a common supervisory understanding of how responsibilities are allocated under the existing framework, rather than creating or changing the legal framework.
For a firm, the practical value is in the mapping. Each expectation points at material the firm typically already holds or can produce: the passporting notification, the tied-agent agreement, the internal risk assessment, the client-facing information, the complaints records. What the briefing does not do is settle which of these are legally required in any given case β that turns on the applicable MiFID II provisions and the firm's own arrangements. What it does do is show where a firm running this structure can sensibly look first.
10. Questions Worth Asking Internally
Does the passporting notification on file describe the structure as it runs today, or as it ran when the notification went in?
Where a tied agent in Member State B serves clients in Member State C, does the agreement authorise that expressly?
Does the internal risk assessment treat the triangular model as a whole, or only the individual passporting arrangements that make it up?
Could a client in Member State C tell, from the documents they were given, which authority supervises their service and where to send a complaint?
Source
ESMA, Supervisory briefing on Triangular Passporting, ESMA35-243228190-8065, dated 7 July 2026.
Know what supervisors are looking for. Our seminars cover the practical implementation of suitability, marketing-communications and product-governance requirements.
Explore seminars at cpds.academy
This article is for educational purposes and does not constitute legal or regulatory advice.

Article by Nikolas Demetriades
Published 01 Aug 2026