Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why does MiFID II require more detailed cost…
Governance, Ownership & Risk

Why does MiFID II require more detailed cost and risk disclosure to clients?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

MiFID II requires detailed disclosure so investors can understand both the direct costs and the practical risks of a financial product before committing capital. Clear information reduces information asymmetry, limits misleading sales practices, and supports more cautious decision-making. It also helps firms prove that clients received understandable, relevant, and comparable information about what they were being offered.

Why MiFID II pushes cost and risk disclosure beyond a simple price label

mifid ii is built around informed investment decisions, so the disclosure has to show more than headline fees. Clients need enough detail to compare products on a like-for-like basis, understand where charges come from, and see how product structure can affect outcomes. That is why the regime focuses on clarity, comparability, and practical impact rather than marketing language.

What the disclosure is trying to make visible

In practice, the rule is trying to surface the full economic picture of an investment recommendation or sale. That includes product charges, distribution costs, and any costs tied to advice, as well as the main risks that could affect value, liquidity, or capital preservation. The point is not to overwhelm clients with data, but to stop important cost or risk elements being hidden in fine print or split across documents.

For firms, this means the disclosure must be understandable to the intended client, not just technically complete. A compliant disclosure should help a retail client see what they are paying, what they could lose, and how the product compares with alternatives, because those are the facts that actually change the investment decision.

Why regulators care about comparability and conduct

MiFID II treats disclosure as a conduct control, not just a documentation exercise. If costs are fragmented, exaggerated by presentation choices, or mixed with unrelated product descriptions, clients can be nudged toward unsuitable choices without realising it. Clear cost and risk disclosure reduces that asymmetry and makes it harder for firms to rely on opaque or selective presentation.

That is also why firms need a defensible method for calculating, aggregating, and presenting charges and risks consistently across products. A one-off marketing summary is not enough if it cannot be reconciled with the underlying product facts, because the regime expects disclosures to be reliable, comparable, and capable of review.

Risk and Threat Considerations

When cost and risk disclosure is too shallow, the main risk is mis-selling through omission, distortion, or poor comparability. Clients may accept products whose real cost burden or risk profile is materially higher than they believed, which can create suitability problems, complaints, remediation cost, and supervisory exposure.

Failure mechanism: firms obscure the true economic impact of a product, or present risk in a way that downplays downside scenarios, liquidity constraints, or cumulative charges. That weakens client understanding and can turn disclosure into a formalistic box-tick rather than a decision control.

Impact: the client may make a decision on incomplete information, while the firm faces legal, conduct, and reputational consequences if the disclosure cannot show that the client received clear and relevant information before investing.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5PM-11 — Mission and Business Process DefinitionMiFID II disclosure supports informed decisions within a governed business process.
Recommendation — Define the client-disclosure process so costs and risks are consistently captured and reviewed.
ISO/IEC 27001:2022A.5.31 — Legal, statutory, regulatory and contractual requirementsMiFID II is a regulatory obligation governing how investment costs and risks are disclosed.
Recommendation — Map disclosure obligations to regulatory requirements and retain evidence of compliance.
SOC 2 (AICPA)CC2.3 — Commitment to competence and responsibilitiesClear disclosure depends on accountable ownership for accurate client information.
Recommendation — Assign accountable owners for disclosure content, calculation, and approval.

Practitioner Guidance

What to verify: test the disclosure against the actual client journey, not the product sheet alone. If a retail client cannot quickly identify total cost, material downside risk, and the main comparison point versus alternatives, the disclosure is probably too weak to serve its purpose.

What good looks like: the cost view is internally consistent across advice, product, and distribution layers, and the risk view reflects the product’s real behaviour under adverse conditions. The best disclosures are the ones that can be explained back in plain language without losing the key facts.

Practitioner takeaway: treat disclosure as evidence of informed consent, not a compliance appendix, because the standard is whether the client could reasonably understand the trade-off well enough to decide.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org