Telappliant
Communications Guide · 20 August 2026

FCA-compliant phone systems: what regulated firms need

Call recording, retention and MiFID II obligations explained, and how to choose a compliant cloud phone platform.

By the Telappliant team

Financial services team on compliant recorded phone calls

FCA-regulated firms cannot treat the phone system as a commodity purchase. Call recording, retention and data handling requirements are enforced obligations, and getting them wrong is a regulatory finding, not just an IT gap.

What the FCA actually requires

Under SYSC 10A, firms carrying out relevant business, including advice, order execution and arranging deals, must record calls and retain them for a minimum period, generally five years, and make them available to the regulator on request. MiFID II carries equivalent recording and retention duties for firms in scope.

What a compliant phone system needs to do

  • Record all in-scope calls automatically, with no reliance on staff remembering to switch it on
  • Capture calls made from mobiles, softphones and Teams Phone, not just desk handsets
  • Store recordings securely with tamper-evident retention for the required period
  • Provide fast, auditable retrieval by date, number or user for regulator requests
  • Log who accessed a recording and when

The mobile and home working gap

The biggest compliance exposure in 2026 is not the office desk phone, it is the adviser taking client calls on a personal or unmanaged mobile from home. A compliant setup routes all business numbers through the platform so mobile calls are recorded exactly the same way as office calls, rather than relying on staff discipline.

Choosing a platform

  • Confirm recording coverage extends to every device and channel staff actually use
  • Check retention periods are configurable to at least five years and cannot be shortened by a user
  • Ask where recordings are stored and whether that meets your data residency policy
  • Confirm export formats and search speed against a realistic regulator request scenario
  • Check the platform's own compliance credentials and audit history

Beyond the tick-box

Recording exists to protect the firm as much as the regulator. A well-implemented system also gives compliance teams sentiment analysis, dispute resolution evidence and training material, turning a legal obligation into a genuine risk-management tool.

Next steps

Frequently asked questions

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a UK technology partner

Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.

  • UK-based people, real account management
  • Honest recommendations - even if it's not us
  • Practical AI where it adds value, not hype
UK business team reviewing plans together before a consultation
Call us Book consultation