The assessment is Article 25(2). The record is ESMA Guideline 12. Most firms run the first well and reconstruct the second afterwards.

Most tools sold as "MiFID II suitability software" calculate whether a recommendation fits a client profile: questionnaire in, risk score out, product eligibility checked. That is suitability assessment, and every serious advisory platform does it. What firms fail inspections on is different: proving, months or years later, what was actually known about the client at the moment of advice, where that knowledge came from, and that the recommendation followed from it. That is suitability evidence, and it is the part almost no system produces while the work happens. On 6 May 2026 that stopped being an opinion.

What is the MiFID II suitability test?

The MiFID II suitability test is the assessment an investment firm must run before giving investment advice or managing a portfolio. Article 25(2) of MiFID II obliges the firm to obtain the information needed to understand three things about the client: their knowledge and experience with the relevant products, their financial situation including the capacity to bear loss, and their investment objectives including risk tolerance and, since 2022, their sustainability preferences. Articles 54 and 55 of Delegated Regulation (EU) 2017/565 turn that obligation into process: assess the information, document the assessment, and for advice, give the client a suitability report. The ESMA guidelines on suitability (ESMA35-43-3172) apply since 3 October 2023, and Circular CSSF 23/835 applies them to firms supervised in Luxembourg.

The test itself is rarely where firms fail. The assessment runs and the advice fits. What goes missing is the evidence that the client's file matched reality at the moment of advice, which is the problem the rest of this guide is about.

What does MiFID II actually require a firm to keep?

The obligation is a chain, not a document. Under Article 25 of MiFID II, an investment firm providing advice must obtain the necessary information on the client's knowledge and experience, financial situation including the ability to bear losses, and investment objectives including risk tolerance, and must give the retail client a suitability statement specifying how the advice meets their characteristics. The delegated rules (Articles 54 and 55 of Delegated Regulation (EU) 2017/565) spell out what "necessary information" means, and the record-keeping obligations require the firm to retain records sufficient to demonstrate the whole process, not only its output.

Two documents make the standard concrete for supervision. The ESMA Guidelines on certain aspects of the MiFID II suitability requirements set out how firms are expected to collect, maintain and update client information and to ensure the suitability assessment is demonstrable. In Luxembourg, Circular CSSF 23/835 applies those guidelines, making them the baseline the CSSF supervises against. A firm evaluating software should read its requirements off those two texts, not off a vendor's feature list.

What does ESMA35-43-3172 require, and what did supervisors find?

ESMA35-43-3172 is the reference number of the ESMA Guidelines on certain aspects of the MiFID II suitability requirements. ESMA issued them on 3 April 2023 and they have applied since 3 October 2023, the same day the 2018 guidelines (ESMA35-43-1163) ceased to apply. In Luxembourg, Circular CSSF 23/835 of 16 May 2023 applies them. It covers investment firms, credit institutions providing investment advice or portfolio management, UCITS management companies and external alternative investment fund managers.

There are twelve general guidelines. Eleven of them describe how the assessment should be run. The twelfth is record-keeping: firms are expected to maintain recording and retention arrangements that keep the suitability assessment transparent after the fact.

Supervisors have now measured how that is going. On 6 May 2026 ESMA published the results of a Common Supervisory Action. It ran across 2024 and 2025, covering 29 national competent authorities and 245 firms: 153 credit institutions and 89 investment firms. Among the documentation findings: only the final preferences expressed by the client are documented, without retaining information on the steps. The CSSF published the results for Luxembourg entities on 17 June 2026. It stated that it will continue to oversee the application of these rules through a proportionate supervisory approach.

That action examined sustainability preferences inside the suitability assessment, not the suitability file as a whole, and it should be read in that scope. Within that scope it is the clearest public evidence of the pattern this page describes. The answer is kept. The path to it is not.

Why do firms with suitability software still fail on evidence?

Because the assessment and the proof live in different places. The suitability engine holds the questionnaire result. The reasons behind the recommendation, the client's actual circumstances as they evolved, the conversations where objectives changed, all of that sits in mailboxes, call notes and meeting summaries that no compliance system reads. When an inspection or a complaint arrives, the file gets reconstructed afterwards, from memory, unevenly across relationship managers. Reconstruction is the risk: it is slow, it is incomplete, and it is the hardest thing to defend precisely because it was written after the fact.

The gap has a shape. Roughly 80% of what a firm knows about its clients lives in unstructured communications rather than structured systems. The information that would satisfy the evidence standard already exists inside the firm. It is in the mail, the call notes and the meeting summaries that the compliance stack does not read. What is missing is a system that reads it and writes the record while the work happens. Today a person assembles it afterwards, under time pressure.

What does a MiFID II suitability record actually look like?

Below is one record from Luscent's demonstration environment. The client is synthetic. The shape is the point: every field an inspection would ask for is written at the time of the advice, not reconstructed later.

Field

Value

Record

EV-2026-0614

Client

Klein Family Office, Luxembourg

Relationship Manager

Élodie Renard

Advice given

25.06.2026, 14:20 CEST, portfolio review

Record written

25.06.2026, 14:52 CEST

Rule applied

MIFID2-SUIT-25, deterministic

Confidence

100

A rule produced this record, not a model.

Financial situation, capital preservation. 42.000.000 EUR under advice. Liquidity need of 3.000.000 EUR stated by the client on 05.06.2026.

Recommendation. Reduce the European small-cap sleeve from 12% to 6% and hold the proceeds in the existing money-market line until the September review.

What was known, and where it came from.

Date

Source

What it evidences

05.06.2026

Mail

Liquidity need stated by the client

20.05.2026

Call note

Objectives and horizon restated

07.05.2026

Mail

Opened the exchange

04.02.2026

Assessment

Suitability questionnaire on file

Read the four rows in order and the recommendation follows from them without anyone having to remember anything. That is the property the record is for. The same record, with the surrounding product context, is on the Luscent product page.

Suitability engines vs evidence software: what each one produces



Suitability engine

Evidence software

Core question

"Does this product fit this profile?"

"Can we prove what we knew, when, and why we advised this?"

Input

Questionnaire, risk profile, product data

The firm's actual communications: mail, meetings, calls, notes

Output

Suitability result, product eligibility

Audit-ready record: source, rule applied, decision, decision-maker, timestamp

When the record is written

At assessment, then frozen

Continuously, as the relationship evolves

Failure mode at inspection

Profile stale, circumstances changed unrecorded

Largely eliminates reconstruction

Typical vendors

Advisory platforms, portfolio systems

Relationship intelligence platforms

The two are complementary. A firm needs the engine to assess and the evidence layer to demonstrate. What it should not do is assume that buying the first delivers the second.

How evidence generation works when it is done properly

A credible evidence system has properties a compliance officer can test in a demo:

  1. It reads what already exists. Communications the firm already produces, connected read-only, with nothing written back into the systems of record.

  2. Consent and lawful basis are recorded before anything is read, and identifiers are removed before any model sees content.

  3. Compliance outcomes come from deterministic rules, never from a model. A rule produces the same result on the same input every time, which is the property an auditor needs and a probabilistic model does not have.

  4. Every output carries its working: the source messages, the rule that fired, the model and version that read them, and the person who decided.

  5. The record is immutable and retained for the supervisory horizon (Luscent retains the audit trail for seven years; MiFID II sets five years as the minimum).

  6. A person stays in the loop. The system recommends and records; the relationship manager decides. Software that claims to decide suitability for the firm is mis-sold: under MiFID II the firm remains responsible for the assessment regardless of the technology used.

How Luscent fits this picture

Luscent is the system of intelligence for wealth management: an EU-native AI platform for private banks, family offices, external asset managers, and independent advisors. It reads client communications (emails, call notes, meeting summaries) to surface relationship insights and generate compliance evidence automatically. Client data is processed and stored in the EU, on EU infrastructure.

For suitability specifically, Luscent generates the evidence as the work happens: each Signal carries its source messages, the deterministic rule that gated it, and the decision the relationship manager took, written to an immutable audit trail. It sits beside an existing CRM and advisory stack rather than replacing them, connecting read-only to Microsoft 365 and Salesforce. The compliance engine covers MiFID II (Article 25), GDPR, the EU AI Act (Article 50) and Brazilian CVM/ANBIMA resolutions in the same deterministic rules core. Swiss FinSA and FinIA are on the roadmap and are not shipped.

This page describes what the software produces, not what your firm is obliged to do; it is not legal advice, and the suitability assessment remains the firm's responsibility at all times.

Frequently asked questions

What is the MiFID II suitability test? The assessment a firm must run before advising a client: knowledge and experience, financial situation including capacity to bear loss, and investment objectives including sustainability preferences, under Article 25(2) of MiFID II and Articles 54 and 55 of Delegated Regulation 2017/565. In Luxembourg, Circular CSSF 23/835 applies the ESMA guidelines.

What is suitability evidence under MiFID II? The demonstrable record of the whole advisory process: what the firm knew about the client, where that information came from, how the recommendation followed from it, and the suitability statement given to the client. Under MiFID II record-keeping obligations the firm must be able to demonstrate the process, not merely store its result.

What does a MiFID II suitability record have to contain? Enough to demonstrate the process, not merely its result. That means what the firm knew about the client, the dated sources it came from, the rule applied, the recommendation, who decided, and when the record was written. A worked example is above.

Is a completed suitability questionnaire enough evidence? No. The ESMA guidelines expect client information to be collected, maintained and kept up to date, and the record to demonstrate the assessment. A questionnaire frozen at onboarding does not show that changed circumstances were noticed or acted on.

What is ESMA35-43-3172? The reference number of the ESMA Guidelines on certain aspects of the MiFID II suitability requirements. ESMA issued them on 3 April 2023 and they have applied since 3 October 2023. There are twelve general guidelines; the twelfth covers record-keeping. In Luxembourg, Circular CSSF 23/835 of 16 May 2023 applies them.

What is CSSF Circular 23/835? The circular of 16 May 2023 by which the CSSF applies the ESMA Guidelines on certain aspects of the MiFID II suitability requirements, with effect from 3 October 2023. It covers investment firms, credit institutions providing investment advice or portfolio management, UCITS management companies and external alternative investment fund managers.

Can AI decide whether advice is suitable? It should not, and under MiFID II the responsibility cannot move to the software: the firm remains responsible for the suitability assessment. The defensible use of AI is reading and organising the underlying communications; the compliance outcome should come from deterministic rules, and the decision from a person.

Does Luscent replace our advisory platform or CRM? No. Luscent is an intelligence and evidence layer over the systems a firm already runs. It reads from Microsoft 365 and Salesforce and writes nothing back into them.

Sources: MiFID II (Directive 2014/65/EU), Article 25; Commission Delegated Regulation (EU) 2017/565, Articles 54 and 55; ESMA Guidelines on certain aspects of the MiFID II suitability requirements (ESMA35-43-3172, issued 3 April 2023, applicable 3 October 2023); Circular CSSF 23/835 of 16 May 2023; ESMA public statement on the results of the Common Supervisory Action on MiFID II sustainability aspects (ESMA35-915049491-6291, 6 May 2026); CSSF communication of 17 June 2026. Last updated: 11 September 2026.

Diagram of a relationship manager handover: the record transfers, the understanding stays in one mailbox, and what the firm keeps against the client instead.

Guides

When a Relationship Manager Leaves, What Does the Firm Keep?

Sep 9, 2026

Guides

Luxembourg Wealthtech and AI: The Map, and the Missing Category | Luscent

Aug 24, 2026