ESMA
European Securities and Markets Authority
ESMA peer review calls for stronger supervision of cross-border MiFID II investment services
Published
Jul 20, 2026
Topics
MiFID II, Investment firms, Cross-border services, Passporting, Retail investor protection, Supervisory convergence, Authorisation, Ongoing supervision, Enforcement
Executive Summary
ESMA published a peer review report on 10 March 2022 assessing how six national competent authorities supervise cross-border activities of MiFID II investment firms and relevant credit institutions targeting retail clients under the freedom to provide investment services framework. The report does not create a new direct reporting obligation for firms, but it is a significant supervisory signal. ESMA found that home supervisors generally process passport notifications adequately, but many do not sufficiently gather or use information on where firms are actually active, the scale of cross-border client activity, products offered, complaints, marketing, language risks and internal controls. ESMA recommends that authorities strengthen authorisation scrutiny, ongoing monitoring, investigations, enforcement and home-host cooperation. CySEC is singled out for two Article 16 ESMA Regulation recommendations because of the scale and risk profile of Cypriot firms’ cross-border activities, particularly in speculative products. Investment firms should expect more granular supervisory challenge and evidence requests on cross-border business models, governance, marketing and investor-protection controls.
What Changed
Previous
No published ESMA peer review assessment had benchmarked these six NCAs across the full cross-border MiFID II supervisory cycle.
New
ESMA has published findings, assessment tables, recommendations and good practices for AFM, BaFin, CNB, CSSF, CySEC and MFSA.
Previous
Many NCAs treated cross-border plans within a general, holistic authorisation review and did not consistently evidence specific scrutiny of cross-border organisation, controls or marketing arrangements.
New
ESMA expects more qualitative scrutiny of cross-border business plans, organisational arrangements, internal controls and distribution models where firms intend to serve clients in other Member States.
Previous
Several NCAs did not regularly collect or use up-to-date information on whether, where and to what extent passported firms were actually active cross-border.
New
ESMA recommends periodic collection and supervisory use of data such as jurisdictions, client types and numbers, services provided and instruments involved.
Previous
Supervisory activity often relied on domestic-facing monitoring, complaint triggers or general firm-level reviews rather than a cross-border risk lens.
New
ESMA calls for close monitoring and use of supervisory tools according to identified risks, including stronger and timelier enforcement where needed.
Previous
Cooperation was often written and complaint-specific.
New
ESMA suggests more regular exchanges of intelligence, evidence and supervisory views, and exploring practical arrangements such as delegation of tasks.
Business Impact
Who is affected
Directly affected
EU/EEA national competent authorities supervising MiFID II investment firms and credit institutions providing cross-border investment services to retail clients, especially AFM, BaFin, CNB, CSSF, CySEC and MFSA.
Indirectly affected
MiFID II investment firms, relevant credit institutions, senior management, compliance, risk, internal audit, passporting/legal teams, marketing and distribution teams, retail brokers, CFD providers and retail clients.
Jurisdictions
European Union, European Economic Area, Cyprus, Czech Republic, Germany, Luxembourg, Malta, Netherlands
Business processes
MiFID II authorisation applications, Article 34 passport notification governance, Material change assessment under MiFID II authorisation conditions, Cross-border activity inventory and MI, Retail client onboarding and jurisdictional targeting controls, Marketing communications and social media monitoring, Complaints handling and host regulator intelligence management, Internal control testing over cross-border activities, Regulatory inspection and enforcement response
Estimated effort
Medium
Compliance risk
Medium
Affected Reports
| Field | Validation rule |
|---|---|
| Host Member State or jurisdiction of activity | ESMA identifies the need for NCAs to collect and use information on whether, where and to what extent firms are actually active cross-border. |
| Type and number of clients by cross-border market | ESMA states that relevant cross-border data should include client types and client numbers to support risk assessment and supervisory planning. |
| Investment services and activities provided cross-border | ESMA’s supervisory expectations include information on the activities and services provided under the freedom to provide services framework. |
| Financial instruments or products involved | ESMA identifies instruments involved, including higher-risk products such as CFDs, as relevant to cross-border supervisory risk assessment. |
| Cross-border complaints and requests from other NCAs | ESMA treats complaints and host-NCA requests as important supervisory intelligence for identifying investor-protection concerns. |
Recommended Actions
- 1Confirmed actionStep 1 of 7
treat the report as a supervisory-convergence signal, not as a new directly binding firm reporting rule; monitor follow-up from the firm’s home NCA.
- 2AI generatedStep 2 of 7
maintain a current inventory of passported and actually active jurisdictions, client numbers, client types, services, instruments and distribution channels.
- 3AI generatedStep 3 of 7
update authorisation, passporting and material-change governance so cross-border business plans, local marketing and internal-control capacity are documented before launch.
- 4AI generatedStep 4 of 7
strengthen evidence that compliance, risk and internal audit functions test cross-border activity, including local-language websites, social media, complaints and outsourcing or introducer arrangements.
- 5AI generatedStep 5 of 7
prepare for more granular supervisory data requests and thematic reviews by reconciling passport notifications against actual client and revenue activity by Member State.
- 6AI generatedStep 6 of 7
for high-risk retail products, especially CFDs or other speculative products, reassess marketing, appropriateness, client communications, complaints and remediation triggers.
- 7AI generatedStep 7 of 7
establish a clear workflow for handling host regulator enquiries, investor complaints and intelligence that may be escalated to the home NCA.
Timeline
other
Date not specified
Period under review for ESMA’s peer review of NCA supervision of cross-border activities.
other
2020
ESMA’s Board of Supervisors decided, through the ESMA Annual Work Programme 2021, to launch the peer review.
other
Jan 28, 2021
ESMA Board of Supervisors approved the mandate for the peer review.
implementation
Feb 2021
Peer Review Committee sent questionnaires to the NCAs in scope.
implementation
Date not specified
Remote on-site visits to the six NCAs took place.
publication
Mar 10, 2022
ESMA published the peer review report.
Sources
AI-generated analysis is based on the following primary sources. Always verify against the official publication.
- Peer Review ReportEuropean Securities and Markets AuthorityMar 10, 2022Peer review on supervision of cross-border activities of investment firms ↗
https://www.esma.europa.eu/sites/default/files/library/esma42-111-5534_report_peer_review_cross_border_activities_investment_firms.pdf
- DirectiveEuropean UnionMay 15, 2014Directive 2014/65/EU on markets in financial instruments (MiFID II) ↗
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32014L0065
- RegulationEuropean UnionNov 24, 2010Regulation (EU) No 1095/2010 establishing the European Securities and Markets Authority ↗
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32010R1095
- Delegated RegulationEuropean UnionJul 14, 2016Commission Delegated Regulation (EU) 2017/1943 on information and requirements for authorisation of investment firms ↗
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32017R1943
- Implementing RegulationEuropean UnionDec 14, 2017Commission Implementing Regulation (EU) 2017/2382 on standard forms, templates and procedures for transmission of information under MiFID II ↗
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32017R2382
Related Evidence
Verified source support for this analysis
The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.
Receive updates like this by email
Get AI-generated analysis for the regulators and topics you care about.