← Back to updates
ESMA

ESMA

European Securities and Markets Authority

Medium Impact

ESMA follow-up finds improved but uneven supervision of cross-border investment firms

Published

Jul 20, 2026

Topics

MiFID II, Cross-border investment services, Retail investor protection, Supervisory convergence, Authorisation, Ongoing supervision, Enforcement, NCA cooperation

Executive Summary

ESMA’s 20 July 2026 follow-up report reviews actions taken by AFM, BaFin, CNB, CSSF, CySEC and MFSA after the 2022 peer review on supervision of cross-border investment services to retail clients under MiFID II freedom to provide services. The report does not create new direct firm obligations, but it is an important supervisory signal for investment firms and credit institutions operating across EU/EEA borders. ESMA finds tangible progress: more structured authorisation scrutiny, expanded cross-border data collection, greater use of risk indicators, improved monitoring and more agile cooperation between authorities. ESMA also highlights continuing growth and complexity in cross-border retail activity, with 370 firms serving about 10.5 million retail clients in 2024 and significant concentration in certain jurisdictions. Residual concerns remain. ESMA recommends more structured AFM authorisation and supervision practices, monitoring of Czech credit institutions if cross-border activity grows, more intrusive BaFin-led supervisory work beyond audits, and continued CySEC focus on timely cooperation and enforcement against repeat infringers.

What Changed

modifiedNCA authorisation gatekeeping for cross-border business

Previous

The 2022 peer review assessed CZ, DE, LU, NL and CY authorisation practices as only partially meeting expectations for cross-border activity controls.

New

Several NCAs now use more structured authorisation methodologies or checklists; AFM still relies more on discretionary follow-up and is encouraged to systematise its approach.

modifiedRisk-based ongoing supervision now incorporates cross-border data more explicitly

Previous

The 2022 peer review found that several NCAs did not sufficiently or systematically consider cross-border risks in supervisory arrangements and monitoring.

New

Cross-border data is increasingly used to prioritise monitoring, reviews, investigations and inspections, though AFM and Czech credit institution supervision remain less systematic in ESMA’s assessment.

modifiedScale of cross-border retail investment services remains a supervisory priority

Previous

Comparable ESMA data before 2022 was not available; the original peer review was based on earlier supervisory evidence of investor-protection concerns.

New

Between 2022 and 2024, ESMA reports a 39% increase in EU/EEA cross-border retail clients, with changing jurisdictional concentration and increased relevance of some newer outbound markets.

modifiedIntrusive supervision and enforcement remain uneven

Previous

The 2022 peer review found shortcomings or insufficient evidence in several NCAs’ enforcement and sanctioning approaches to cross-border activity.

New

ESMA acknowledges stronger actions since the peer review, while recommending continued proportional use of enforcement where cross-border retail risks, complaints or repeat breaches warrant it.

modifiedCySEC cooperation process improved but should remain under review

Previous

The 2022 peer review assessed CySEC’s cooperation with other NCAs as partially meeting expectations and recommended closer monitoring of response times.

New

CySEC has implemented structural monitoring and process changes; ESMA views the trend as positive but recent and therefore requiring continued attention.

Business Impact

Who is affected

Directly affected

AFM, BaFin, CNB, CSSF, CySEC and MFSA as the NCAs assessed in ESMA’s follow-up.

Indirectly affected

MiFID II investment firms and credit institutions providing investment services to retail clients cross-border under the freedom to provide investment services, plus compliance, legal, risk, complaints, marketing, product governance, internal audit and senior management functions supporting those businesses.

Jurisdictions

European Union/European Economic Area, Cyprus, Czechia, Germany, Luxembourg, Malta, Netherlands

Business processes

MiFID II authorisation and variation-of-permission submissions, Article 34 MiFID II passporting notification governance, Cross-border retail business risk assessment and risk scoring, Host-country marketing and language-control review, Complaints management and complaints MI by host jurisdiction, Thematic reviews, investigations and on-site inspection preparation, Enforcement escalation and repeat-breach governance

Estimated effort

Medium

Compliance risk

Medium

Affected Reports

Cross-border business authorisation / programme-of-operations packMiFID II Article 34 passporting notification workflow controlCross-border retail services supervisory MI dashboardHost-jurisdiction complaints and remediation MIInternal audit / compliance monitoring plan for cross-border services
FieldValidation rule
Host Member State / target jurisdictionESMA reports that NCAs increasingly assess exact cross-border scope, host Member States served and consistency with passporting notifications.
Number of retail clients by host Member StateESMA identifies this as a key data item used in cross-border monitoring and risk scoring.
Complaints relating to cross-border servicesESMA highlights complaints data as a supervisory risk indicator and reports 2024 complaint concentrations in Germany and Cyprus.
Languages used for marketing, contracts and client communicationsESMA notes that several NCAs now scrutinise language capability and foreign-language control arrangements at authorisation and supervision stages.
Distribution methods and marketing plansESMA reports that CNB and other NCAs request or assess distribution and marketing arrangements for cross-border services.
Tied-agent use in cross-border servicesESMA states that BaFin’s additional questionnaire can request information on tied agents used for cross-border services.
Revenue or activity generated through free provision of servicesESMA describes this as a cross-border risk exposure criterion used in CSSF’s supervisory approach.
Products or instruments offered cross-borderESMA states that some NCAs consider whether risky instruments are provided cross-border when assessing risk.

Recommended Actions

7 suggested next steps· derived from source analysis
  1. 1
    AI generatedStep 1 of 7

    Map current cross-border retail activity by host Member State, client numbers, products, complaints, revenue and marketing channels to identify businesses likely to attract heightened NCA scrutiny.

  2. 2
    AI generatedStep 2 of 7

    Review authorisation, variation and passporting governance so submissions can evidence governance, local compliance, language controls, complaint handling and operational capacity for each material host market.

  3. 3
    AI generatedStep 3 of 7

    Strengthen cross-border complaints MI by tracking complaints by host country, product, channel, root cause, remediation status and recurrence, with escalation to senior management for outliers.

  4. 4
    AI generatedStep 4 of 7

    Test marketing, onboarding and client communications in host-country languages, including affiliate or influencer activity, against MiFID II conduct and product governance controls.

  5. 5
    AI generatedStep 5 of 7

    Update compliance monitoring and internal audit plans to include a representative sample of cross-border clients, files, marketing materials and complaint cases.

  6. 6
    AI generatedStep 6 of 7

    For firms supervised in Germany or Cyprus, prepare for potentially more intrusive supervisory engagement where retail-client volumes, complaints or prior findings are material.

  7. 7
    AI generatedStep 7 of 7

    Maintain an enforcement-readiness file documenting remediation of past findings, repeat-issue analysis and management accountability, especially for firms with prior supervisory actions.

Timeline

other

2021

ESMA’s Board of Supervisors launched the original peer review to assess how NCAs supervise cross-border activities and promote consistent investor protection across the EU.

publication

2022

ESMA published the peer review report identifying weaknesses in authorisation, ongoing supervision and enforcement for cross-border investment services and issuing recommendations to six NCAs.

publication

Dec 2022

ESMA published a MiFID II supervisory briefing to help NCAs supervise cross-border investment services consistently with the peer review recommendations.

effective date

Sep 1, 2024

CNB’s new internal licensing methodology became effective, requiring more detailed information on cross-border services, languages, distribution methods and marketing plans per host Member State.

implementation

May 2025

The ESAs’ system for exchange of information relevant to fitness and propriety assessments went live; ESMA reports more than 650 authority requests between May and December 2025.

publication

Jul 20, 2026

ESMA published the follow-up report on supervision of cross-border activities of investment firms.

Sources

AI-generated analysis is based on the following primary sources. Always verify against the official publication.

Related Evidence

Verified source support for this analysis

The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.

Receive updates like this by email

Get AI-generated analysis for the regulators and topics you care about.

Pulse is built by Datox. Datox automates AIFMD Annex IV and SEC Form PF reporting end to end.

See the Datox platform