ESMA: Weaknesses in Compliance and Internal Audit for Fund Managers (CSA 2025)
ESMA publishes the results of the 2025 Common Supervisory Action: general compliance with AIFMD and UCITS, but weaknesses in independence, governance, and internal policies require corrective actions.
— Studio LX20 Law Firm
The context
On 11 May 2026, ESMA published the final report on the Common Supervisory Action (CSA) conducted during 2025 with all EU and EEA national competent authorities on the compliance and internal audit functions of fund managers. The exercise, launched on 14 February 2025, assessed the level of compliance of UCITS management companies and AIFMs with the requirements of the AIFMD and the UCITS Directive and their implementing measures, in particular Articles 9-11 of Directive 2010/43/EU and Articles 60-62 of Delegated Regulation (EU) No 231/2013.
The overall outcome
The overall assessment is positive: most managers comply with the key requirements of the two frameworks. However, authorities identified recurring governance weaknesses, concentrated in three areas: the independence of control functions, the quality and effective application of internal policies, and the oversight exercised by senior management and the management body.
The noteworthy finding is qualitative: most entities had formal policies and procedures, but authorities found marked differences in their quality and practical implementation, depending on the size, nature, and complexity of the individual manager; in some more serious cases, smaller managers lacked basic compliance policies. Compliance "on paper" was not sufficient.
The weaknesses identified
Compliance function. Among the most frequent shortcomings: non-compliance risk assessments that were too generic, failing to translate into operational priorities and recommendations; incomplete reporting to senior management; late involvement of the function, which was asked to validate decisions already made rather than contributing ex ante.
Internal audit function. Incomplete documentation (manuals, audit charters, audit plans), particularly where activities were outsourced to third parties; inconsistent quality and granularity of reports; improperly invoked principle of proportionality; group policies not formally adopted at the local entity level; in some cases, the compliance function had never been audited. The oversight by the management body was found to be reactive rather than proactive in several cases.
Outsourcing and groups. Where managers rely on third-party providers or group entities, authorities noted weak oversight of agreements (SLAs, KPIs, evidence of the actual performance of controls) and divergent national practices on whether such arrangements constitute a "delegation" under AIFMD and UCITS. ESMA is clear on one point: the manager remains fully responsible for compliance, regardless of outsourcing. Managers controlled by banking groups are also reminded not to rely exclusively on the parent company's risk assessment methodologies, which may underestimate local risks.
ESMA's expectations
The report provides clear operational guidance for managers:
- consult control functions before making relevant strategic decisions (entering new markets, new asset classes, establishing new funds, delegations);
- ensure control functions have adequate authority, independence, and resources (in terms of FTEs), with remuneration methodologies that do not compromise their objectivity;
- establish defined escalation procedures for disagreements between control functions and business units;
- maintain documented internal control mechanisms: reporting lines, training programs, updated risk assessments, compliance monitoring plans, and tracking of corrective actions.
Implications for Italian managers
Italian asset management companies (SGRs) (and SICAFs/SICAVs that directly manage their own assets) fall within the scope of the exercise. In Italy, the organisational requirements for the compliance and internal audit control functions are governed by the Bank of Italy Regulation of 5 December 2019 (Part IV, Title IV, Articles 47–49) and the Consob Intermediaries Regulation, together with the Union legislation referred to by ESMA. Supervision is exercised jointly by the Bank of Italy (for sound and prudent management and risk containment profiles) and Consob (for transparency and fairness of conduct), according to their respective powers.
The reference organisational framework remains that of the Bank of Italy Regulation of 5 December 2019 and the Consob Intermediaries Regulation, together with Union legislation, but it is evolving. With Legislative Decree No. 39 of 13 March 2026, Italy has transposed AIFMD II (Directive (EU) 2024/927), applicable from 16 April 2026; the related implementing provisions from the Bank of Italy and Consob—expected to be adopted by 16 October 2026—will particularly affect delegation and outsourcing, i.e., one of the areas of weakness identified by ESMA. Managers should therefore calibrate their corrective actions taking into account both the expectations expressed in the CSA and the new framework being finalised.
The CSA is not, in itself, a sanctioning exercise: at present, most authorities do not foresee sanctioning actions. However, ESMA expects national authorities to follow up on the identified breaches and vulnerabilities, analyse their causes, and ensure timely corrective actions, using enforcement powers where appropriate: it is in the national follow-up that the risk materialises. The areas highlighted indicate where domestic supervision will focus its attention in future inspection cycles.
What to do now
For managers, the report is a self-assessment benchmark. The priority checks are:
- review the non-compliance risk assessment, which must map risks to the manager's actual activities and produce actionable recommendations, not generic themes;
- verify the ex ante involvement of compliance in strategic decisions and delegations;
- review internal audit documentation and the formal adoption of group policies at the local level;
- strengthen oversight of outsourcing agreements (SLAs, KPIs, evidence of controls), with clarity on their potential qualification as delegation—also in view of the new implementing provisions for AIFMD II;
- for managers within banking groups, develop a proprietary risk assessment, not one merely derived from the parent company's;
- evidence of proactive oversight by the management body over control functions.
*This contribution is for informational purposes only and does not constitute legal advice. For an assessment of a specific organisational setup, a specific consultation is advisable.*