The Central Bank has published its feedback report on the Common Supervisory Action on Compliance and Internal Audit Functions in the Investment Funds Sector, flowing from ESMA’s EU-wide review. It found firms broadly in line with regulatory expectations but with a clear set of areas to work on. The detail is where a Board should spend its time.
A Board can have full visibility of everything its compliance and internal audit functions do — and still not own any of it. That distinction runs right through the report, and it should stop every fund management company Board. It is the one I flagged last November as one of five supervisory priorities for 2026 — the effectiveness of the second and third lines — and it lands in the same month as the Central Bank’s delegation review, asking Boards for much the same thing: test your arrangements against it, and put a time-bound remediation plan in place before the gaps become findings.
“Receiving a Group presentation once a year is visibility. Being able to show that your Board shaped the plan, challenged the coverage and tracked the findings to closure is ownership.”
The two themes that cut across both functions
The first is that reliance on the Group does not move the accountability. The defining feature of the Irish model is reliance on the Group, and it is where the report concentrates. Every firm in the sample had outsourced the internal audit function’s activities to Group, some with very little interaction. Compliance frameworks and policies were often set at Group level, in some cases approved there before the local Board ever saw them. And Group risk ratings, built around Group priorities, can dilute the coverage a local entity receives. None of this is prohibited. All of it carries one warning: the Board and senior management remain ultimately responsible and accountable, whoever does the work.
The second is that visibility is not ownership. The line to be most wary of in the report is that Boards often had visibility of assurance activity but, in the Central Bank’s phrase, potentially lack sufficient ownership and accountability. Receiving a Group presentation once a year is visibility. Being able to show that your Board shaped the plan, challenged the coverage and tracked the findings to closure is ownership. The report ties the gap between the two to Board minutes that do not record the discussion — but that covers two different failures. In some firms the discussion never happened, which is a real ownership gap. In others it did, and simply went unminuted, which is an evidencing gap, not an ownership one. The report treats both the same way, as in effect not done — fair on the first, harsh on the second, since a Board that challenged the plan but failed to record it has proof to produce, not ownership to build. Either way, the remedy starts in the minutes.
What the Central Bank found on compliance
On compliance, the Central Bank wants a single compliance framework captured in one document rather than a fragmented set of policies, so the Board can see the whole picture at once. It wants standard operating procedures, because compliance teams are small irrespective of firm size and a single departure can set the function back. It wants compliance monitoring plans that carry owners, timelines and trackers, and that come to the Board for approval rather than for mere notification. And it is pointed about passive monthly Excel checklists and over-reliance on delegate attestations, expecting attestations to carry enough detail and raw data for active assessment rather than passive reliance. None of this needs headcount. It needs intent and discipline.
What the Central Bank found on internal audit
On internal audit, the questions are about independence and local coverage rather than existence. The sharpest finding is an internal audit plan that simply replicated the firm’s own compliance monitoring plan, which rightly drew a challenge on independence: if the third line only re-runs what the second line already planned, it is echoing compliance, not testing it. The report is explicit that the audit plan should cover all key areas, including compliance itself. It also notes Group audit plans routed through Group committees before the firm’s Board could shape them, and Group risk ratings that thin local coverage. The expectation is a robust, independent internal audit function reporting directly to the Board, with formalised follow-up on findings and escalation of failures.
What this means, and what to do
Overall, a Common Supervisory Action is not a newsletter to be filed. The Central Bank supports a proportionate approach: proportionality does not mean the fundamental principles of independence, adequate resourcing and robust oversight can be ignored. It has asked firms to review their arrangements against the report and to develop time-bound remediation plans for any gaps, and it will follow up through ongoing supervisory engagement. The firms that act now will answer a short letter rather than enter a remediation programme.
For the compliance function, the practical steps are to consolidate to a single, entity-specific framework, write the standard operating procedures that protect you against turnover, rebuild the monitoring plan around risk with clear owners, timelines and trackers and take it to the Board for approval, and replace passive attestations with evidence you can actually test.
For internal audit, confirm the plan is set for your entity rather than simply inherited from the Group, make sure it is genuinely independent of the compliance plan and covers compliance itself, ensure your Board shapes the coverage and sees findings early rather than after Group governance has closed them, and put a formal mechanism in place to track remediation and escalate failures.
Read together, these are not a scattered list of fixes. They are the two themes above, reliance that does not transfer accountability, and the difference between visibility and ownership, applied function by function.
There is one awkwardness worth naming. The report’s central concern is independence and over-reliance on the Group, yet the gap analysis it now asks for would often be run by the very compliance and internal audit functions whose independence is in question. A self-assessment risks reproducing the exact blind spot under review. Here, more than in most exercises, independent eyes are not a workaround: because independence is the subject, they are the most credible way to show the Board, and the Central Bank, that the judgement behind the plan is objective.
Let’s Talk
That is exactly the review we run at Vantage Point Partners: read the supervisory signal, test the assurance model against it, and close the gaps before they become findings. If you would like to discuss a rapid, independent look at your second and third lines, get in touch at paul.traynor@vpp.ie.
Vantage Point Partners – Protect. Optimise. Grow.
Paul Traynor is Managing Partner of Vantage Point Partners, which advises regulated financial services firms (ManCos, investment firms, fund administrators and digital-asset service providers) on governance, control frameworks and regulatory engagement. He is a Chartered Accountant and CBI-approved PCF, and has led several Central Bank commissioned reviews of regulated firms.