Skip to content

19 June 2026

Your dialer is a compliance system, not a phone system

Brokers evaluating VOIP usually compare call quality and per-seat pricing. The questions that matter are about recording, retention and retrieval.

Tech For ForexCompliance engineering3 min read

When a brokerage shortlists a VOIP provider, the comparison sheet usually has columns for call quality, per-seat price and CRM integration. Then it goes to compliance, and the whole thing is rebuilt around questions nobody on the sales side asked.

It saves time to start with those questions.

Why recording is the product

Under MiFID II and equivalent regimes, firms must record telephone communications that relate to the reception, transmission and execution of orders. That is not a best practice, it is an obligation, and it applies to conversations your retention desk has every day.

The obligation has three parts, and each one is a product requirement:

  1. Record the communication
  2. Retain it for a defined period
  3. Produce a specific one on request, within a deadline

A phone system that does the first and is vague about the second and third has solved a third of your problem.

The questions compliance will ask

Is recording automatic, and can an agent disable it?

It must be automatic on every inbound and outbound call, with no agent action to start it and no ability to stop it. A system where recording is a button an agent presses is a system that will one day be missing the call you need.

Where is the archive, and can we choose?

Data residency is a real constraint for a regulated firm. If your archive sits in a jurisdiction your compliance function has not approved, that is a finding waiting to happen. Ask where recordings are stored by default and whether the region is selectable.

How long is retention, and who sets it?

Retention requirements vary by regime and can be extended by a regulator during an investigation. The correct answer from a vendor is that retention is configurable to your obligation. A vendor who states a fixed period as a product guarantee has not understood the question.

How do we find one specific call?

This is the requirement that separates real systems from adequate ones. When a regulator asks for every conversation with a specific client in a date range, you need to produce them inside the deadline.

Retrieval should work by client, by agent, by date range, by phone number, and by linked CRM record. If retrieval means asking a vendor to run a query for you, your deadline now depends on their support queue.

Who is allowed to listen, and is that logged?

Recordings contain personal and financial data. Access should be a permission, held by named roles, and every access should itself be logged. "Anyone in the CRM can play any recording" will not survive an audit.

Is the archive tamper-evident?

A recording you can quietly edit is not evidence. Look for tamper-evident storage, so you can demonstrate a recording is what it was when it was made.

Where CRM integration actually matters

Integration is usually sold as an agent convenience — click a number in the CRM and the call dials.

That is pleasant. The part that matters is that every call is linked to the client record, so the conversation history sits alongside the trading history, the deposits and the support tickets. When you reconstruct what a client was told before a disputed trade, you want one timeline, not three systems and a spreadsheet.

A shortlist that survives compliance

Ask every vendor:

  • Is recording automatic and non-disableable by agents?
  • Where is the archive stored, and can we select the region?
  • Is retention configurable to our requirement rather than fixed?
  • Can we retrieve by client, agent, date and CRM record, ourselves?
  • Is recording access role-based and logged?
  • Is the archive tamper-evident?
  • Does every call link to the client record automatically?

If a vendor's first answer to all seven is about call quality, they are selling to the wrong person in your organisation.


This describes common obligations under MiFID II and similar regimes. Your specific requirements depend on your regulator and jurisdiction — take your own compliance advice.

Working on this problem right now?

Bring us the specifics and we will tell you what we would do.