MiFID II
- Obligation
- Investment firms operating in EU member states must retain records sufficient to reconstruct the orders and transactions they executed. Records must capture what happened, when, and by whom. Where automated tools contribute to that process, firms need records of what those tools did. An agent that queries a pricing database, reads a position file, or calls a market data API is touching systems that MiFID II governs.
- Levee control
- The immutable audit trail records every agent request against covered systems before the request completes. The trail captures the agent identifier, the resource requested, the action taken, the policy applied, and the timestamp. The record cannot be altered after the fact.
- Evidence produced
- A time-ordered log of every agent interaction with financial systems, including denials. Sufficient to reconstruct agent activity over any period. Exportable for regulatory submission.
What this does not cover
Levee addresses the records-retention and access-control dimension of MiFID II obligations. Legal and compliance counsel should confirm how Levee's trail maps to the specific obligations of the firm's regulatory perimeter. Levee does not make a firm “MiFID II compliant” as a blanket claim.