Final Remarks
ESMA’s CSA confirms that while the fund management industry is broadly compliant, the real challenge lies in moving from formal compliance to effective and demonstrable control frameworks. The findings highlight a persistent gap between policies on paper and practices in reality, particularly in areas such as resourcing and proactive involvement of control functions.
In an environment marked by increasing regulatory scrutiny, product complexity, and cross-border activity, compliance and internal audit functions are expected to evolve into strategic partners capable of anticipating risks, rather than merely reporting them.
For fund managers, this represents both a risk, as weaknesses may trigger supervisory attention and remediation requirements, and an opportunity to strengthen governance, enhance investor confidence, and build more resilient operating models.
Ultimately, firms that embed control functions into decision-making, invest in capabilities, and ensure robust execution will be best positioned to meet regulatory expectations and support sustainable growth.
How EY can help
EY can support fund managers in assessing and strengthening their compliance and internal audit frameworks in light of ESMA’s findings:
- Perform independent gap assessments: benchmark your compliance and internal audit functions against ESMA expectations and leading market practices to identify weaknesses and prioritize remediation actions
- Enhance governance frameworks: redesign reporting lines, committee structures and interaction models to reinforce independence, oversight and effective challenge
- Strengthen documentation and control frameworks: implement robust policies, procedures and registers, and ensure full audit trails for decisions, monitoring activities and remediation actions
- Optimize resourcing and operating models: assess staffing levels, roles and responsibilities, and support the design of scalable target operating models aligned with your business complexity.
- Embed control functions in strategic processes: integrate compliance and internal audit into product governance, delegation models, and market expansion initiatives to ensure risks are identified ex ante
- Formalize escalation and remediation processes: design structured escalation frameworks, tracking tools and reporting dashboards to improve visibility, accountability and timely resolution of findings
- Develop tailored risk assessment methodologies: build or refine entity-level risk frameworks that reflect your specific activities, including cross-border setups and delegated structures
- Leverage technology and data analytics: deploy digital solutions to enhance monitoring, automate controls, and improve reporting quality and efficiency
- Support internal audit transformation: enhance audit methodologies, improve report quality, and ensure risk-based coverage, including dedicated reviews of compliance functions
With a combination of regulatory expertise, operational experience and technology capabilities, EY helps fund managers move beyond “tick-the-box” compliance towards robust, effective and forward-looking control environments.