Native recording and compliance recording are different tools
Native Teams recording is a user-initiated feature. For private calls and group chats, the recording is saved to the OneDrive for Business of the person who started it. Channel meeting recordings go to the SharePoint site tied to the channel. One vendor guide puts the compliance problem plainly: the file lands with an individual user or a specific site, not in a central, organization-wide vault. That is a vendor's view, but it matches how the storage model works.
Compliance recording is a separate, policy-driven design. Microsoft says Teams is enhanced to offer compliance recording through integrations with certified, third-party solutions. Microsoft's documentation says these solutions let compliance officers capture communications to meet regulations such as MiFID II, Dodd-Frank, FDCPA, HIPAA and GDPR. Microsoft does not certify that your whole program is compliant. It certifies partner integrations, and the rest is up to the firm.
How the admin-controlled model works
Per Microsoft's setup guidance, the model has three steps:
- An admin creates a compliance recording application instance in the tenant, using the partner's application ID. The documented cmdlet is
New-CsOnlineApplicationInstance. - The admin creates a compliance recording policy with
New-CsTeamsComplianceRecordingPolicyand links the recorder application to it. - The admin assigns the policy with
Grant-CsTeamsComplianceRecordingPolicy. Policies can apply at the tenant, per-user or security-group level.
Once this is in place, the recorder is invited into conversations automatically according to the policy. Microsoft's example then checks the assignment with Get-CsOnlineUser. That check confirms assignment only. It does not prove the recorder actually joins calls.
One caveat on "users cannot disable it"
The Wordwatch claim that users cannot switch compliance recording off is only partly backed by Microsoft. Microsoft says that, depending on the partner solution and its configuration, users might not be able to disable the recording and might not have access to it. Behavior varies by vendor and by setup, so test it rather than assume it.
Coverage gaps to check before you say "Teams Phone is recorded"
Microsoft lists limits that matter on a trading floor:
- Compliance recording is not supported for E911 emergency calling, for users in Survivable Branch Appliance mode, or for PSTN calls for India users.
- For call queues, inbound calls answered by agents can be covered by the call-queue feature without assigning agents a policy. Outbound agent calls need a compliance recording policy and are treated as outbound user calls.
- Eligible licenses include Microsoft 365 A3/A5/E3/E5/G3/G5, Business Premium and Business Standard, Office 365 A3/A5/E3/E5, Teams Rooms Pro or Basic, and Teams Shared Device. Confirm against your own deployment.
- Users are told when recording is happening. Teams desktop, web, mobile, Teams Phones and Teams Rooms show a visual notice. SIP phones and PSTN callers get an audio notice.
Support is another practical point. Microsoft supports only solutions from its listed certified partners and may reject cases involving non-certified products. Operational problems go to the partner first. The partner list changes, so check the live list instead of relying on a vendor's marketing page.
For developers, partner recording bots must run on a Windows virtual machine deployed in Azure. Firewall rules must allow the Azure public IP range outbound and the Teams IP range inbound.
What the rules actually say
The report cites MiFID II Article 16(7) and FCA SYSC 10A. The FCA Handbook text lines up with several points in the article:
- Firms must take all reasonable steps to record relevant telephone conversations and keep copies of relevant electronic communications. This covers firm-provided equipment and equipment the firm has permitted.
- The rule covers communications intended to result in the relevant activities, even if they never lead to a trade.
- Records are kept for five years, and up to seven years where the FCA requests it. The FCA's record-keeping schedule says the same. Seven years is not an automatic default.
- Records must be stored so they can be replayed or copied, and kept in a format that does not allow the original to be altered or deleted. They must also be readily accessible.
- Firms need a written recording policy that identifies in-scope calls, including relevant internal ones. They must also set procedures for exceptional circumstances when recording is not possible, and keep the evidence.
- Firms must monitor compliance in a proportionate, risk-based way, and be able to show policies and management oversight to the FCA on request.
The Handbook's "unalterable" storage requirement is expressed as a format that does not allow the original record to be altered or deleted. That is close to the article's "unalterable form" wording. However, the Handbook text reviewed does not use the phrases "original format" or "chain of custody." Treat those as good evidential practice and as Wordwatch's framing, not as quoted rule text.
The scope also needs care. The FCA's off-channel review says the regime captures communications about the regulated activities in SYSC 10A. It does not cover discussions of non-regulated matters such as meeting logistics. So the rule does not mean every Teams call at a regulated firm must be recorded. Your written policy has to say which ones are in scope. There is also a narrow optional-exemption route for certain firms serving mainly retail clients, with note-taking conditions.
The FCA's off-channel review: what it does and doesn't say
The FCA published its multi-firm review on 7 August 2025. Here are the verified figures:
- The FCA surveyed eleven wholesale banks.
- Three firms reported no breaches. Eight disclosed a total of 178 breaches, with 131 concentrated in three firms.
- 41% of breaches involved individuals at director grade or above.
The FCA warns that a breach of a firm's internal policy may not be a breach of FCA rules. So "178 confirmed policy breaches" is accurate, but it should not be read as 178 regulatory violations. The FCA also says a high number may reflect effective detection, while a low one does not prove the framework works.
The vendor-failure point is confirmed. Some firms reported third-party vendor challenges, according to the FCA's own text. These included service outages that disrupted recording and monitoring, data reconciliation problems, and delayed or missing recorded data. The FCA also reminds firms that SYSC 10A responsibilities cannot be transferred to third parties. Buying a certified recorder does not move the liability.
The MiFID II review is a separate matter
The 2024 MiFIR and MiFID II review was announced by the Council of the EU on 20 February 2024. It covered consolidated tapes, a general ban on payment for order flow with a transitional phase-out by 30 June 2026 for some member states, and new commodity derivatives rules. The Council summary does not mention recording obligations. It does not prove that Article 16(7) was left untouched either, so that claim would need a check against the amending legal texts. Also, the FCA rules above apply to UK firms under the UK Handbook, which is a separate framework from the EU legislation.
Where the Wordwatch claims need caution
- The 52% and 34% survey figures are vendor-commissioned. The report gives no sample size, respondent profile or question wording that we could check. Treat them as indicative at best.
- "Teams has become the telephony itself" on many desks is a vendor claim about trends. It is plausible, but it is not independently measured here.
- "Regulators expect one reconstructable thread" across turret, Teams, chat and mobile is a sensible operating goal. The FCA text reviewed does not state it in those words. What the rules do require is effective recording, monitoring and the ability to demonstrate oversight.
- "Native recording is inadequate" is a reasonable conclusion for regulated voice. It is a judgment, though, not a Microsoft statement.
A practical checklist for admins and compliance teams
- Map the estate. List which users, endpoints (desktop, mobile, Teams Phones, Teams Rooms, SIP, PSTN) and call types are in scope.
- Check licensing and certification. Confirm that user licenses are eligible and that the recorder is on Microsoft's current certified list.
- Verify policy assignment. Use the documented cmdlets, then place real test calls, inbound and outbound, to prove the recorder joins.
- Test the exceptions. Look at call queues, E911, SBA mode and any India PSTN usage.
- Write the policy. Record what is in scope, how failures and outages are handled, and how evidence of exceptions is kept.
- Reconcile and monitor. Compare recordings with call and trade data, and review samples on a risk basis.
- Prove retrieval. Make sure you can retrieve an intact record, replay it, and show it hasn't been altered. Do this within the five-year period, or seven if the FCA asks.
- Hold the vendor to account. Track outages and missing data. The FCA's review found those problems at real firms.
Bottom line
The article's core point stands. Native Teams recording is a user tool with scattered storage, and policy-based compliance recording through a certified partner is the route Microsoft documents for regulatory capture. Beyond that, the real exposure sits in gaps: unsupported call types, misassigned policies, vendor outages and records that can't be tied to trades. In the FCA's words, accountability stays with the firm. The test is whether you can prove a call was recorded and retrieve it intact. Having a compliance recording license does not prove that.
References
- Teams Phone recording: where native capture fails MiFID II - FinTech Global FinTech Global · 2026-10-05T11:12:44+00:00
- Microsoft Teams compliance recording (third-party) - Microsoft Teams | Microsoft Learn learn.microsoft.com
- Set up compliance recording in Microsoft Teams - Microsoft Teams | Microsoft Learn learn.microsoft.com