Perspectives · Fund regulation

ESMA looked at fund managers' control functions and found the governance

On 11 May 2026 ESMA published the final report on the common supervisory action it ran with national regulators during 2025 on the compliance and internal audit functions of UCITS management companies and alternative investment fund managers. Supervisors across the EU and the EEA took part, and ESMA reports that most fund managers comply with the key requirements. The recurring weaknesses were governance weaknesses: the independence of the control functions, the quality of internal policies and whether they were applied in practice, and the depth of senior management and board oversight. The report also records that national authorities take different views on whether a third-party internal audit arrangement amounts to delegation. This perspective is general information, not legal advice.

18 May 2026 · Fund regulation

The exercise

What a common supervisory action is

ESMA sets the scope, every national regulator runs the same review of its own firms, and the results are compared. The 2025 action covered how managers had implemented the compliance and internal audit requirements of the UCITS Directive, AIFMD and their implementing measures. No new law comes out of it. It is supervisors telling the market where they looked and what they were unwilling to accept.

The headline

Satisfactory overall, with a list underneath

Most regulators judged overall compliance satisfactory, and then reported recurring weaknesses that were sharper in some jurisdictions than others. They also found significant differences in the quality and practical implementation of arrangements depending on the size, nature and complexity of the firm. That is a polite way of saying that a policy written for a large house and adopted by a small one did not survive contact with the small one.

The three findings

Independence, implementation and oversight

Independence: whether the compliance and internal audit functions can reach an unwelcome conclusion and report it, without the person responsible also owning the activity being reviewed. Implementation: whether the internal policies are of adequate quality, and whether anyone followed them after they were approved and filed. Oversight: whether senior management and the board received what they needed, considered it and acted.

None of the three is a missing file. Each is a gap in what can be shown. A firm asked to demonstrate independence is asked who holds the function, what else that person does and to whom they report. A firm asked to demonstrate oversight is asked for the paper recording what the board was told, when, and what it decided.

Delegation

The same contract, two different answers

The report notes divergent national practice on whether engaging a third party to perform internal audit counts as delegation under AIFMD and the UCITS Directive. That matters to a manager with entities in more than one member state, because delegation carries notification duties, oversight duties and a supervisor's continuing interest in whether the manager has become a letter-box. One outsourcing contract can be a delegation in one jurisdiction and an ordinary service arrangement in another.

A group cannot take a consistent position across jurisdictions without first being able to state the position at all. That means a list: for each authorised entity, who performs each control function, whether internally or through a group company or a third party, under which contract, and what was notified to which regulator. Very few groups can produce that list from a system. Most produce it from the memory of the person who arranged it.

The evidence

Make the board pack part of the record

Oversight becomes provable when three things are held together: the report that went to the board, the date it went, and the minute recording what the board decided about it. Spread across an inbox, a shared drive and a secretary's folder, they are three artefacts a reviewer has to assemble. Held against the entity, they are the answer to the supervisor's question.

Do the same for the functions themselves. Record who holds compliance and who holds internal audit for each authorised entity, the appointment document, the reporting line and the date the appointment took effect. Record each delegate and what was delegated to it. This is not another policy to write. It is being able to answer, entity by entity, the questions a policy asserts the answer to.

In Alethia

Officers, delegates and decisions against the entity

Officers and their appointments sit against the entity they serve, with the appointment documents attached and dated. Board and committee papers, terms of reference and minutes are filed against that same entity, so what was put to a board and what it decided lives with the vehicle it concerns.

Service arrangements are recorded the same way: the contract attached to the entity, and a compliance obligation carrying the review or notification date and its owner. Alethia does not perform the compliance function and does not speak to a national regulator on a manager's behalf. When the next supervisory action arrives, who holds internal audit for this entity, under what contract, and what the board saw are questions the register already answers, with the audit trail showing when each entry was made and by whom.

Questions

What the supervisory action found

Does this report change the rules we have to follow?

No. A common supervisory action does not make law. It reports how national regulators found firms applying the existing UCITS and AIFMD requirements, and it signals what those regulators will examine next.

Our national regulator gave us a satisfactory outcome. Are we finished?

Not necessarily. Most regulators rated overall compliance satisfactory and still found recurring weaknesses, and ESMA asked national authorities to follow up on the breaches and vulnerabilities identified, to understand their root causes and to see remedial action through.

Is outsourcing our internal audit a delegation?

It depends on the jurisdiction. ESMA's report records that national authorities take divergent views on whether a third-party internal audit arrangement amounts to delegation under AIFMD and the UCITS Directive. A group operating in several member states should confirm the position for each authorised entity, one at a time.

Be able to show what the board was told

Keep the appointment, the reporting line, the delegate, the paper that went to the board and the decision that followed against the entity they belong to, so oversight can be evidenced when a supervisor asks.