If your firm operates investment services across EU member states, you're now subject to a supervisory model that's fundamentally different from what existed three years ago. National competent authorities (NCAs) across the EU have retooled their approaches to cross-border oversight, and ESMA’s latest follow-up report confirms the shift: data-driven, risk-based supervision is now the standard.
This checklist translates ESMA's findings into actionable steps for compliance teams managing cross-border investment services. Whether you're a home-state NCA or a firm preparing for scrutiny, these items reflect what regulators now expect when they assess your cross-border operations.
Prerequisites
Before you begin this checklist, confirm:
- You have a current inventory of cross-border investment services. This includes all jurisdictions where you provide services under MiFID II passporting rights.
- You can identify the home and host NCAs for each service line. Know who supervises what.
- You maintain records of all regulatory notifications submitted for cross-border activities. These form the baseline for supervisory assessments.
- You have access to operational data that reflects cross-border activity volumes, client counts, and transaction patterns. Regulators will ask for it.
Cross-Border Supervision Readiness Checklist
Authorization and Notification Controls
1. Cross-border business plans are current and detailed.
Your authorization file should include a specific plan for each cross-border market, not a generic statement of intent. This includes jurisdiction-specific client acquisition strategies, staffing models, complaint-handling procedures, and risk mitigation measures tailored to local market conditions. If you submitted a cross-border notification more than two years ago and haven't updated it, you're behind.
2. Notification records match actual service delivery.
Compare what you told your home NCA you'd do against what you're actually doing. Ensure service types, marketing channels, and client segments align with your original notification. Discrepancies trigger enforcement referrals under the enhanced cooperation protocols ESMA documented.
3. You've mapped material changes that require re-notification.
MiFID II doesn't define "material change" precisely, so you need an internal threshold. Establish a documented policy that defines materiality, such as expanding into retail clients when you notified for professional clients only, adding new product categories, or opening a branch versus operating cross-border. Test your policy against recent business changes.
Data-Driven Supervision Capabilities
4. You can produce cross-border activity metrics on demand.
NCAs are using data to identify outliers and risk concentrations. You should be able to generate the same view they're building. This includes dashboards or reports showing client acquisition trends by jurisdiction, transaction volumes, complaint rates, and revenue attribution by host state. If you need two weeks and a consultant to pull this data, you're not ready.
5. Risk indicators are defined for each cross-border jurisdiction.
Generic risk assessments don't satisfy the "risk-based" supervision model. Develop jurisdiction-specific risk factors, such as regulatory change velocity, enforcement trends, client sophistication levels, and competitive intensity, with assigned owners who monitor and report quarterly. Document why you assess Germany differently from Cyprus.
6. Supervisory data requests have defined response protocols.
NCAs are coordinating more closely, which means data requests arrive faster and expect quicker turnaround. Establish a documented procedure that assigns ownership, sets internal deadlines (at least 48 hours before the external deadline), and includes a quality review step. Track response times and accuracy as KPIs.
Cooperation and Enforcement Readiness
7. You know which NCAs are cooperating on your supervision.
ESMA's report highlights that NCAs from the Netherlands, Germany, the Czech Republic, Luxembourg, Cyprus, and Malta have strengthened cooperation mechanisms. Maintain a matrix showing which NCAs supervise which of your activities, evidence of coordination (joint inspections, shared findings), and documented points of contact at each authority.
8. Enforcement case referrals have a documented escalation path.
When a host NCA identifies an issue, they're now more likely to refer it for enforcement action. Develop an internal protocol that defines when compliance issues get escalated to the legal team, board risk committee, or home NCA. Include thresholds, such as potential fines above €50K, repeat violations, or client harm.
9. Cross-border complaints are tracked separately and analyzed for patterns.
Host NCAs pay attention to complaint volumes as a proxy for consumer protection failures. Maintain a complaint register that tags cross-border complaints by jurisdiction, categorizes by issue type, and calculates resolution time. Review quarterly for patterns that might signal systemic issues.
Supervisory Approach Calibration
10. Your compliance resources scale with cross-border complexity.
ESMA's report notes that supervisory approaches must match the scale and complexity of cross-border activities. Apply that logic internally. Ensure compliance staffing, budget, and technology increase proportionally with cross-border revenue or client count. If cross-border represents 40% of revenue but gets 10% of compliance resources, you have a gap.
11. You've assessed whether your supervisory model matches evolving risks.
Retail cross-border investment services continue to expand, which means risks evolve. Conduct an annual review to determine whether your monitoring, testing, and reporting cadence still fits the risk profile. Document the assessment and any changes you make.
Common Mistakes
- Treating all cross-border markets identically. NCAs in Luxembourg operate differently from those in Malta. Your supervision model should reflect that.
- Assuming host NCAs won't enforce. The enhanced cooperation ESMA documented means host NCAs now have clearer paths to escalate issues. They're using them.
- Relying on static authorization files. If your cross-border business plan hasn't been updated since initial authorization, you're operating on outdated assumptions.
- Waiting for data requests to build data capabilities. By the time an NCA asks, you're already late. Build the reporting infrastructure before you need it.
Next Steps
If you checked fewer than nine items, prioritize the gaps in authorization controls and data capabilities first. These are the areas where ESMA saw the most improvement and where scrutiny will intensify.
For firms with significant outbound cross-border activities, schedule a review with your home NCA. Ask explicitly how they're adapting their supervisory approach to match your scale and complexity. That conversation will reveal what they expect from you.
Finally, monitor ESMA's ongoing work on supervisory convergence. The follow-up report confirms that cross-border supervision is tightening, not loosening. Your compliance program needs to keep pace.





