MiFID II in practice
what the Czech National Bank expects from licensed firms in the Czech Republic
The Markets in Financial Instruments Directive II (MiFID II), transposed via Act No. 256/2004 Coll. (ZPKT), governs investment services in the Czech Republic. As of 2026, the Czech National Bank (CNB) maintains stringent expectations for licensed firms. The landscape has matured through the "MiFIR Review" and ESG integration, requiring compliance with specific benchmarks established by ESMA and national decrees.

Key takeaways
Article contents
- Quick summary
- The foundational role of the Czech National Bank in MiFID II oversight
- Navigating the authorization process and initial compliance requirements
- The framework of client protection and conduct of business
- Critical organizational requirements and internal control frameworks
- Market transparency and transaction reporting
- Algorithmic trading requirements
- Capital requirements (IFR/IFD) and prudential oversight
- Enforcement and sanctions
- Recent regulatory developments (2025-2026)
For firms holding CNB licenses, compliance requires deep familiarity with the interaction between MiFID II, MiFIR (Markets in Financial Instruments Regulation), the Prudential Regime for Investment Firms (IFR/IFD), and the Digital Operational Resilience Act (DORA), which is fully applicable as of 2025.
The foundational role of the Czech National Bank in MiFID II oversight
The CNB serves as the integrated financial market supervisory authority. Its mandate involves authorizing investment firms, monitoring ongoing compliance, conducting on-site inspections, and imposing sanctions. The relationship between the CNB and a licensed firm is dynamic.
The CNB operates under a risk-based supervisory approach (SREP - Supervisory Review and Evaluation Process), prioritizing resources toward firms with higher risk profiles, complex business models, or significant retail client exposure.
The CNB publishes official decrees ( vyhlášky ) and supervisory benchmarks ( úřední sdělení ) that communicate its expectations. A critical area of focus in 2026 remains cross-border activities. Based on ESMA guidance and CNB practice, regulators rigorously assess whether firms claiming to operate cross-border have sufficient substance in the Czech Republic.
Understanding CNB supervisory expectations: the three foundational pillars
The CNB's supervisory approach rests on three fundamental pillars:
1. Continuous Regulatory Reporting: Known as výkaznictví , this involves the automated submission of standardized data (via the SDAT system) regarding financial health, capital adequacy, and liquidity. This is not merely annual reporting but frequent (monthly/quarterly) data transmission that the CNB uses to monitor market stability.
2. Prudential Rules (IFR/IFD): Unlike banks governed by CRR, most investment firms are subject to the Investment Firms Regulation (EU) 2019/2033 (IFR) and Directive (EU) 2019/2034 (IFD). This regime requires firms to hold capital based on the highest of three metrics: their permanent minimum capital requirement, their fixed overheads requirement, or their "K-factors".
3. Internal Governance and "Fit & Proper" Standards: Firms must maintain a resilient governance framework. The CNB enforces strict "fit and proper" assessments for management board members and key function holders (Compliance, Risk, Internal Audit), scrutinizing their professional competence, reputation, and lack of conflict of interest.
Navigating the authorization process and initial compliance requirements
Under Section 5 of Act No. 256/2004 Coll., investment services can only be provided with CNB authorization. The licensing process is rigorous and typically takes 6 to 12 months. The CNB assesses whether the applicant's organizational structure, risk management, and capital are adequate.
For the authorization assessment, firms must demonstrate:
- Initial Capital: Depending on the scope of services, usually EUR 75,000, EUR 150,000, or EUR 750,000 (as per IFR and Section 8a of Act No. 256/2004 Coll.).
- Headquarters in CZ: Real management and decision-making must occur within the territory.
- Personnel: Identification of at least two persons who effectively direct the business (the "four-eyes principle").
The framework of client protection and conduct of business
MiFID II's conduct of business rules (Sections 15–15r of Act No. 256/2004 Coll.) dictate how firms treat clients.
- Retail Clients: Receive the highest protection. Mandatory suitability/appropriateness tests, full cost disclosure (ex-ante and ex-post), and restrictions on inducements apply.
- Professional Clients: Receive fewer protections. This category includes entities authorized to operate in financial markets, large undertakings meeting specific balance sheet/turnover criteria, and institutional investors.
- Eligible Counterparties (ECP): Receive the lowest level of protection, applicable mainly for dealing on own account and execution services.
Best execution obligations
Under Section 15l of Act No. 256/2004 Coll. and Article 27 of MiFID II, firms must take "all sufficient steps" to obtain the best possible result for clients. This is not limited to price but includes cost, speed, likelihood of execution, and settlement.
In 2026, with the Consolidated Tape (CT) provisions from the MiFIR review being implemented, firms are expected to utilize improved market data to validate their execution quality. The CNB expects firms to:
- Monitor execution quality continuously, not just annually.
- Compare their execution venues against relevant market data (using APAs or CTPs).
- Explicitly justify why specific venues are chosen in their execution policies.
Critical organizational requirements and internal control frameworks
Investment firms must implement organizational requirements pursuant to Section 12a of Act No. 256/2004 Coll. and Delegated Regulation (EU) 2017/565.
1. Compliance Function: Must be independent, adequately resourced, and have direct access to the management body.
2. Risk Management: Must be distinct from operational functions.
3. DORA Compliance (New Standard): As of January 2025, Regulation (EU) 2022/2554 (DORA) mandates that investment firms implement a comprehensive ICT risk management framework, report major ICT-related incidents to the CNB, and conduct digital operational resilience testing.
Risk table: organizational and operational compliance failures
|
Risk Area |
CNB Enforcement Approach |
|
Inadequate Compliance Resources |
The CNB views understaffed compliance departments as a systemic governance failure. Remedial measures often include mandatory hiring plans and suspension of business expansion. |
|
Transaction Reporting Errors |
Failure to report transactions (under Art. 26 MiFIR) or poor data quality leads to administrative fines. The CNB cross-references reports with trade repositories. |
|
Client Asset Protection |
Commingling client funds with firm funds is a severe breach. It can lead to immediate license suspension and criminal complaints. |
|
Conflicts of Interest |
Inadequate disclosure of inducements or group-structure conflicts results in fines and mandatory remediation of remuneration policies. |
Client categorization, suitability, and appropriateness
- Suitability Assessment (Advisory/Portfolio Management): The firm must verify that the investment meets the client’s investment objectives, financial situation (including ability to bear losses), and knowledge/experience.
- Sustainability Preferences (ESG): Firms are legally obliged to ask clients about their sustainability preferences (Taxonomy-aligned, SFDR sustainable investments, or PAI consideration) and match products accordingly.
- Appropriateness Test (Execution Only): For complex products (e.g., derivatives, CFDs, certain structured deposits), the firm must assess if the client has the knowledge/experience to understand the risks. If not, a warning must be issued.
Note: Under the MiFIR Review/Retail Investment Strategy packages, the definition of "complex products" remains broad, and "execution only" services for complex products are strictly limited.
Market transparency and transaction reporting
MiFIR (Regulation EU No 600/2014) mandates transparency.
- Pre-trade transparency: SIs (Systematic Internalisers) and trading venues must publish quotes.
- Post-trade transparency: Details of transactions must be published as close to real-time as technically possible.
- Transaction Reporting (Art. 26 MiFIR): Firms must report complete and accurate details of transactions in financial instruments to the CNB (T+1 basis).
A common deficiency identified by the CNB is the failure to reconcile front-office data with the reports actually received by the regulator.
Algorithmic trading requirements
Under Section 12k of Act No. 256/2004 Coll., firms engaging in algorithmic trading must:
- Notify the CNB of their strategy.
- Have systems comprising "kill switches" and trading limits.
- Perform stress testing of algorithms before deployment.
With the prevalence of AI in trading, the CNB in 2026 also scrutinizes the governance of AI models (alignment with the AI Act where applicable) to ensure they do not facilitate market manipulation.
Capital requirements (IFR/IFD) and prudential oversight
As noted, most investment firms fall under the IFR/IFD regime (implemented via Act No. 256/2004 Coll. and Decree No. 22/2021 Coll.).
- Class 2 Firms: Subject to K-factors (Risk-to-Client, Risk-to-Market, Risk-to-Firm).
- Class 3 Firms (Small and Non-interconnected): Capital requirement is the higher of permanent minimum capital or fixed overheads.
- ICAAP: All firms must maintain an Internal Capital Adequacy Assessment Process (ICAAP) to estimate capital needs for risks not fully captured by Pillar 1 (e.g., reputational risk, strategic risk).
Enforcement and sanctions
The CNB's sanctioning powers under Act No. 256/2004 Coll. include:
- Fines: Up to CZK 130,000,000 (approx. EUR 5 million) or 10% of total annual turnover for legal entities.
- Management Ban: Individuals can be banned from regulated functions.
- License Withdrawal: The ultimate sanction for persistent or severe breaches.
- Publicity: Sanctions are published on the CNB website, causing reputational damage.
Intersection with other regulations (AML, GDPR, MiCA)
- AML/CFT: Act No. 253/2008 Coll. requires rigorous Customer Due Diligence (CDD).
- MiCA: The Markets in Crypto-Assets Regulation (Regulation EU 2023/1114) is fully applicable. Firms dealing in crypto-assets must distinguish between financial instruments (MiFID II) and crypto-assets (MiCA).
- DORA: Operational resilience is now a prerequisite for MiFID compliance.
Recent regulatory developments (2025-2026)
- PFOF Ban: The ban on Payment for Order Flow is enforced, requiring firms to route orders based solely on execution quality, not rebates.
- Value for Money: Increased supervisory focus on costs and charges, ensuring products offer value to retail investors.
- Consolidated Tape: Implementation steps for a centralized data stream for EU equity and non-equity markets are underway.
Executive summary for management
For senior management, MiFID II compliance in 2026 is not a "tick-box" exercise. It requires:
1. Capital planning under the IFR/IFD regime.
2. IT budgets allocated for DORA compliance and transaction reporting.
3. Active governance where the board takes responsibility for the firm's compliance culture.
Conclusion
The Czech National Bank expects investment firms to be proactive, financially stable, and operationally resilient. The regulatory framework is complex, integrating MiFID II, IFR, DORA, and local legislation. Non-compliance carries significant financial and reputational risks.
If your firm requires assistance with CNB authorization, compliance audits, or remediation of supervisory findings, seek specialized legal guidance at consultation@arws.cz.
About the author
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 400,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.
