Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Aeriandi Study Highlights UK Financial Institutions Are Unprepared For MiFID II Legislation And Unaware Of Extent Of Penalties
Study & Research

Aeriandi Study Highlights UK Financial Institutions Are Unprepared For MiFID II Legislation And Unaware Of Extent Of Penalties

ISBuzz TeamBy ISBuzz TeamMarch 15, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

‘73% Risk & Compliance Managers in Financial Sector Admit They’re Not Aware of Penalties of up to 5 Million Euros or 10% of Annual Turnover vs 58% of IT Managers and Decision Makers’

 Oxford. A study of IT managers and decision makers and Risk & Compliance managers within UK financial services businesses, reveals a lack of preparation and understanding of the requirements of MiFID II legislation due to come into force in January 2018.

The study, carried out in January 2017 for voice security services company Aeriandi, shows managers and decision makers within these institutions have little understanding of the severity of potential penalties and are struggling to apply the legislation to their businesses.

Key findings

  • Almost three quarters (73%) of Risk & Compliance managers in Financial Sector admit they’re not aware of penalties of up to 5 million euros or 10 per cent of annual turnover vs only 58 per cent of IT managers and decision makers
  • 17 per cent of Risk & Compliance managers are unaware a company could receive a cease and desist order for non-compliance
  • Almost a quarter of those surveyed (22%) say that, although they feel they understand the MiFID II legislation, they are not sure how it applies to their organisation
  • Over a quarter (29%) do not yet have the technology or the infrastructure needed in place for compliance
  • Only 10 per cent are currently communicating with partners and suppliers about their preparations for compliance with MiFID II

The study highlights a concerning gap between general awareness and understanding of the legislation and an understanding of the practical detail, knowledge and planning that is needed to prepare for compliance.

Understanding of the legislation peaks in firms with 50,001 – 100,000 employees, with 88 per cent saying they are totally confident in their understanding of the legislation.  It then falls sharply to 67 per cent in organisations with 100,001 – 150,000 employees, and again to 65 per cent in companies with 150,001+ employees.

When comparing the responses of IT professionals and those responsible for managing Risk & Compliance within a business, IT teams have a better overall understanding of the consequences of non-compliance.  62 per cent of Risk & Compliance managers admitted to not knowing a company can be fined up to 5 million euros or 10 per cent of annual turnover, compared to only 42 per cent of IT managers and decision maker’s.

It would appear however that a countdown to compliance has begun and organisations are now starting to invest time and money in preparations.  30 per cent of respondents say that budget has been allocated this year to help with preparations, and over a third (36%) report that policy and procedure have now been developed.

Matt Bryars, Co-founder and CEO at Aeriandi, commented: “There appears to be a real lack of detailed knowledge around MiFID II in UK financial services organisations.  With less than a year to go until penalties for non-compliance will kick in, you’d hope that those responsible for delivering compliance – the IT and risk & compliance teams – would have this nailed.  However, for many, preparations are still at a very early stage.

“Organisations must understand the key areas of impact on their business and start to plan for change.  For example, call recording requirements under MiFID II will become mandatory for all areas of financial advice.  So anyone making a call in which they recommend products or aim to make a transaction will have to record that call – and then keep that recording secure for five years.  Ultimately compliance and IT teams will have their work cut out for them   They’ll need to carry out a detailed risk analysis, mapping out the required processes and procedures required under MiFID II, and then determine task by task if their existing solutions will be adequate or if the organisation finds it needs to procure and roll out a new set of tools and supporting processes.”

About the Study

This study was carried out by research company Opinion Matters on behalf of Aeriandi in January 2017.  It was conducted amongst a sample of 250 professionals working in the UK’s Financial Sector in companies which process payment transactions over the phone and have 1000+ employees.  The sample was split equally between Managers with Risk/Compliance in their job titles and IT Decision Makers/IT Managers

For more information on Aeriandi’s award winning solutions, please visit www.aeriandi.com

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Enhance Your Digital Crime and Security Practices Today

March 28, 20249 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}