INTELLIGENCE TOOL
Financial Regulation
Automated reporting, real-time regulatory alerts and data clean rooms for financial institutions and asset managers.
Intelligent regulatory surveillance for institutions that cannot afford surprises.
Financial institutions operate under constant regulatory pressure. DORA, MiCA, MiFID II — each quarter brings new obligations. Our solution automates monitoring so your compliance team can focus on what matters: implementing, not tracking.
DORA / MiCA / MiFID monitoring
Automated tracking of regulatory changes with customised alerts by institution and regulatory scope.
Regulatory reporting
Automated generation of compliance reports for supervisors — CNMV, Banco de España, AEPD.
Data clean rooms
Secure sharing of regulatory information between institutions without exposing personally identifiable data.
Impact analysis
Assessment of the impact of new regulations on portfolios, operations and existing structures.
NormaVex analyses an internal policy and highlights any deviations from the applicable regulations. The regulatory risk map shows where the enforcement activity of Spanish supervisory authorities is concentrated. The derivatives simulator outlines the obligations associated with a transaction under MiFID II, MiFIR, EMIR and REMIT, with a focus on energy derivatives. All three are free to use and provide an indicative result.
Understand the result
What does the result mean?
Each tool provides a different reading, and none of them constitutes a legal opinion. This is how each result is interpreted.
A gap identified by the policy auditor does not in itself constitute a breach. It indicates that the text of the policy does not include, or only partially includes, an obligation that the relevant standard does require. The seriousness of the issue depends on whether the obligation stems from a directly applicable regulation or a Level 2 implementing measure, and the supervisor assesses the matter on the basis of the written text.
The fact that a particular area on the map shows a concentration of sanctions means that supervisory activity is intense in that area and that the breaches giving rise to them are recurring within the sector. It does not imply a breach in itself. For a compliance team, it is a priority for review; it helps to organise the work and justify where resources are allocated.
In the simulator, the output lists the obligations associated with the derivative, the reporting to an authorised registry under EMIR, the potential for centralised clearing if thresholds are exceeded, the exchange of collateral in non-cleared OTC contracts and, for energy derivatives, REMIT obligations towards ACER. If the results indicate that thresholds have been exceeded, that the activity is restricted or that a potential investigation is likely, the case requires professional analysis.
How do I know which financial regulations apply to my organisation?
The order in which the legislation is read matters. Level 1 consists of the Union’s Regulations and Directives; the former are directly applicable, whilst the latter are implemented through transposition, in Spain primarily via Law 6/2023 on Securities Markets and Investment Services. Level 2 comprises the RTS, ITS and delegated acts, which specify deadlines, formats and thresholds. Level 3 comprises the Guidelines and Q&As issued by ESMA and the EBA, and the criteria set by the CNMV.
Here’s an example. A payment institution wishing to hold crypto-assets in custody starts with MiCA at Level 1, which restricts this activity to providers authorised by the CNMV as the competent authority. It then moves on to the RTS and ITS, which set out the application process and governance requirements, and concludes with the guidelines and Q&As from ESMA, the EBA and the CNMV. At the same time, it checks compliance with DORA, which applies across almost the entire sector.
If your organisation requires regulatory advice – from licensing to representing you before the regulator – please see our financial regulation section.
Methodology and sources
What they rely on
All three tools are based on the official texts published on EUR-Lex and in the BOE, in particular DORA (Regulation (EU) 2022/2554), MiCA (Regulation (EU) 2023/1114), EMIR (Regulation (EU) No 648/2012, as amended by Regulation (EU) 2019/834), MiFID II (Directive 2014/65/EU) and REMIT (Regulation (EU) No 1227/2011, as amended by Regulation (EU) No 2024/1106).
Levels 2 and 3 – technical standards, guidelines and Q&As – are taken from publications by ESMA, EBA and the CNMV. The results are for guidance only and do not constitute legal advice.
Frequently asked questions
What people ask on financial regulation
Since when has DORA been in force, and to which organisations does it apply?
What are an RTS and an ITS?
How do MiCA and MiFID II differ?
Which derivatives must be reported under EMIR, and to whom?
What is REMIT and who does it affect?
What is an ESMA Guideline, and does it apply to me?
How often should internal policies be reviewed?
Related analysis
On the blog
Does your institution need automated regulatory surveillance?
Request a complimentary personalised demo.
