← Back to updates
ESMA

ESMA

European Securities and Markets Authority

Medium Impact

ESMA peer review calls for stronger supervision of cross-border MiFID II investment services

Published

Jul 20, 2026

Topics

MiFID II, Investment firms, Cross-border services, Passporting, Retail investor protection, Supervisory convergence, Authorisation, Ongoing supervision, Enforcement

Executive Summary

ESMA published a peer review report on 10 March 2022 assessing how six national competent authorities supervise cross-border activities of MiFID II investment firms and relevant credit institutions targeting retail clients under the freedom to provide investment services framework. The report does not create a new direct reporting obligation for firms, but it is a significant supervisory signal. ESMA found that home supervisors generally process passport notifications adequately, but many do not sufficiently gather or use information on where firms are actually active, the scale of cross-border client activity, products offered, complaints, marketing, language risks and internal controls. ESMA recommends that authorities strengthen authorisation scrutiny, ongoing monitoring, investigations, enforcement and home-host cooperation. CySEC is singled out for two Article 16 ESMA Regulation recommendations because of the scale and risk profile of Cypriot firms’ cross-border activities, particularly in speculative products. Investment firms should expect more granular supervisory challenge and evidence requests on cross-border business models, governance, marketing and investor-protection controls.

What Changed

newESMA peer review findings on cross-border MiFID II supervision

Previous

No published ESMA peer review assessment had benchmarked these six NCAs across the full cross-border MiFID II supervisory cycle.

New

ESMA has published findings, assessment tables, recommendations and good practices for AFM, BaFin, CNB, CSSF, CySEC and MFSA.

modifiedGreater focus on cross-border plans at authorisation

Previous

Many NCAs treated cross-border plans within a general, holistic authorisation review and did not consistently evidence specific scrutiny of cross-border organisation, controls or marketing arrangements.

New

ESMA expects more qualitative scrutiny of cross-border business plans, organisational arrangements, internal controls and distribution models where firms intend to serve clients in other Member States.

modifiedActual cross-border activity data should feed supervision

Previous

Several NCAs did not regularly collect or use up-to-date information on whether, where and to what extent passported firms were actually active cross-border.

New

ESMA recommends periodic collection and supervisory use of data such as jurisdictions, client types and numbers, services provided and instruments involved.

modifiedMonitoring, investigations and enforcement should address cross-border risks

Previous

Supervisory activity often relied on domestic-facing monitoring, complaint triggers or general firm-level reviews rather than a cross-border risk lens.

New

ESMA calls for close monitoring and use of supervisory tools according to identified risks, including stronger and timelier enforcement where needed.

modifiedHome-host cooperation should become more proactive

Previous

Cooperation was often written and complaint-specific.

New

ESMA suggests more regular exchanges of intelligence, evidence and supervisory views, and exploring practical arrangements such as delegation of tasks.

Business Impact

Who is affected

Directly affected

EU/EEA national competent authorities supervising MiFID II investment firms and credit institutions providing cross-border investment services to retail clients, especially AFM, BaFin, CNB, CSSF, CySEC and MFSA.

Indirectly affected

MiFID II investment firms, relevant credit institutions, senior management, compliance, risk, internal audit, passporting/legal teams, marketing and distribution teams, retail brokers, CFD providers and retail clients.

Jurisdictions

European Union, European Economic Area, Cyprus, Czech Republic, Germany, Luxembourg, Malta, Netherlands

Business processes

MiFID II authorisation applications, Article 34 passport notification governance, Material change assessment under MiFID II authorisation conditions, Cross-border activity inventory and MI, Retail client onboarding and jurisdictional targeting controls, Marketing communications and social media monitoring, Complaints handling and host regulator intelligence management, Internal control testing over cross-border activities, Regulatory inspection and enforcement response

Estimated effort

Medium

Compliance risk

Medium

Affected Reports

Cross-border activity inventory/data collection controlMiFID II passport notification and Article 34 status trackerAuthorisation and material-change review file for cross-border business plansComplaint and host-NCA intelligence log for cross-border clientsMarketing communications and social media monitoring control, including non-domestic languages
FieldValidation rule
Host Member State or jurisdiction of activityESMA identifies the need for NCAs to collect and use information on whether, where and to what extent firms are actually active cross-border.
Type and number of clients by cross-border marketESMA states that relevant cross-border data should include client types and client numbers to support risk assessment and supervisory planning.
Investment services and activities provided cross-borderESMA’s supervisory expectations include information on the activities and services provided under the freedom to provide services framework.
Financial instruments or products involvedESMA identifies instruments involved, including higher-risk products such as CFDs, as relevant to cross-border supervisory risk assessment.
Cross-border complaints and requests from other NCAsESMA treats complaints and host-NCA requests as important supervisory intelligence for identifying investor-protection concerns.

Recommended Actions

7 suggested next steps· derived from source analysis
  1. 1
    Confirmed actionStep 1 of 7

    treat the report as a supervisory-convergence signal, not as a new directly binding firm reporting rule; monitor follow-up from the firm’s home NCA.

  2. 2
    AI generatedStep 2 of 7

    maintain a current inventory of passported and actually active jurisdictions, client numbers, client types, services, instruments and distribution channels.

  3. 3
    AI generatedStep 3 of 7

    update authorisation, passporting and material-change governance so cross-border business plans, local marketing and internal-control capacity are documented before launch.

  4. 4
    AI generatedStep 4 of 7

    strengthen evidence that compliance, risk and internal audit functions test cross-border activity, including local-language websites, social media, complaints and outsourcing or introducer arrangements.

  5. 5
    AI generatedStep 5 of 7

    prepare for more granular supervisory data requests and thematic reviews by reconciling passport notifications against actual client and revenue activity by Member State.

  6. 6
    AI generatedStep 6 of 7

    for high-risk retail products, especially CFDs or other speculative products, reassess marketing, appropriateness, client communications, complaints and remediation triggers.

  7. 7
    AI generatedStep 7 of 7

    establish a clear workflow for handling host regulator enquiries, investor complaints and intelligence that may be escalated to the home NCA.

Timeline

other

Date not specified

Period under review for ESMA’s peer review of NCA supervision of cross-border activities.

other

2020

ESMA’s Board of Supervisors decided, through the ESMA Annual Work Programme 2021, to launch the peer review.

other

Jan 28, 2021

ESMA Board of Supervisors approved the mandate for the peer review.

implementation

Feb 2021

Peer Review Committee sent questionnaires to the NCAs in scope.

implementation

Date not specified

Remote on-site visits to the six NCAs took place.

publication

Mar 10, 2022

ESMA published the peer review report.

Sources

AI-generated analysis is based on the following primary sources. Always verify against the official publication.

Related Evidence

Verified source support for this analysis

The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.

Receive updates like this by email

Get AI-generated analysis for the regulators and topics you care about.

Pulse is built by Datox. Datox automates AIFMD Annex IV and SEC Form PF reporting end to end.

See the Datox platform