READ
News

Fund managers’ risk management function under scrutiny. Are you prepared?

Date:August 25, 2026

On 3 July 2026, ESMA announced a new Common Supervisory Action (CSA) focusing on the risk management function of UCITS management companies and AIFMs. In 2026 and 2027, national competent authorities across the EU will jointly assess how organisations comply with risk management requirements. The focus will be specifically on the effectiveness, independence and expertise of the risk management function.

What will the AFM investigate?

The review will focus on compliance with the risk management requirements applicable to managers falling within the UCITS and AIFMD frameworks. For the organisations selected, the AFM will specifically assess three areas:

  • The governance and structure of the risk management function;
  • The identification, measurement and monitoring of risks;
  • Reporting to senior management and governing bodies.

ESMA considers risk management a key function for both investor protection and financial stability. Organisations must be able to demonstrate that material risks, such as market, credit, liquidity, counterparty and operational risks, are adequately identified, measured, monitored and managed.

What areas of attention do we see in the market?

The announced CSA does not introduce new expectations. Supervisors have long expected organisations not only to have a risk management policy in place, but also to be able to demonstrate that it is effectively applied in practice. Based on our experience, it is precisely this practical implementation and demonstrability that often presents a challenge.

  • The independent positioning of the risk management function within smaller organisations;
  • Clearly defining risk appetite, translating it into specific limits and demonstrably monitoring compliance with those limits;
  • Demonstrating the rationale behind risk assessments and periodic evaluations;
  • Liquidity risk management, stress testing and the application of liquidity management tools (LMTs);
  • The quality and frequency of management reporting and evidence that these reports are discussed by the relevant governance bodies.

We also see that organisations relying on the principle of proportionality do not always sufficiently substantiate why its application is appropriate.

Areas of attention identified in previous supervisory reviews

The focus of the announced review is consistent with the findings of the AFM’s risk management review conducted at the end of 2020. The main areas of attention identified at the time included:

  • Risk management policies not being kept up to date;
  • Insufficient demonstrable independence of the risk management function;
  • A lack of documented methodologies for risk identification and monitoring;
  • Insufficient evidence of evaluations of the effectiveness of the risk management function.

It is reasonable to expect that the AFM will take these previous findings into account in its upcoming review, meaning that shortcomings in these areas may carry greater weight.

What does this mean for your organisation?

For organisations within scope, this announcement provides a good opportunity to critically assess whether compliance with risk management requirements is sufficiently embedded in their policies and, importantly, whether the key elements can be demonstrated to work effectively in practice. The areas of attention identified through our experience, together with the findings from the AFM’s previous review, provide a useful starting point for this assessment.

Need support?

If you would benefit from an external perspective when preparing for this review, we would be happy to assist. We can provide support at different levels of depth:

  • Quick scan: Based on the risk management documentation you provide, we identify the main areas for improvement and provide suggestions on how these can be addressed.
  • Assessment of compliance with relevant laws and regulations: Based on the full AIFMD regulatory framework, we assess whether your organisation complies with the applicable requirements and provide suggestions for addressing any identified gaps.

In addition, we can support you in following up on and addressing findings resulting from either the quick scan or a full compliance assessment.

Please contact Rene Verkade or Jodie Lam from Projective Group’s Legal, Risk & Compliance practice for an informal discussion about how we can provide targeted support tailored to your organisation.