FCA-compliant phone systems: what regulated firms need
Call recording, retention and MiFID II obligations explained, and how to choose a compliant cloud phone platform.
By the Telappliant team

FCA-regulated firms cannot treat the phone system as a commodity purchase. Call recording, retention and data handling requirements are enforced obligations, and getting them wrong is a regulatory finding, not just an IT gap.
What the FCA actually requires
Under SYSC 10A, firms carrying out relevant business, including advice, order execution and arranging deals, must record calls and retain them for a minimum period, generally five years, and make them available to the regulator on request. MiFID II carries equivalent recording and retention duties for firms in scope.
What a compliant phone system needs to do
- Record all in-scope calls automatically, with no reliance on staff remembering to switch it on
- Capture calls made from mobiles, softphones and Teams Phone, not just desk handsets
- Store recordings securely with tamper-evident retention for the required period
- Provide fast, auditable retrieval by date, number or user for regulator requests
- Log who accessed a recording and when
The mobile and home working gap
The biggest compliance exposure in 2026 is not the office desk phone, it is the adviser taking client calls on a personal or unmanaged mobile from home. A compliant setup routes all business numbers through the platform so mobile calls are recorded exactly the same way as office calls, rather than relying on staff discipline.
Choosing a platform
- Confirm recording coverage extends to every device and channel staff actually use
- Check retention periods are configurable to at least five years and cannot be shortened by a user
- Ask where recordings are stored and whether that meets your data residency policy
- Confirm export formats and search speed against a realistic regulator request scenario
- Check the platform's own compliance credentials and audit history
Beyond the tick-box
Recording exists to protect the firm as much as the regulator. A well-implemented system also gives compliance teams sentiment analysis, dispute resolution evidence and training material, turning a legal obligation into a genuine risk-management tool.



