Insights

UCITS management companies and AIFMs need to get ahead of ESMA’s 2nd & 3rd line CSA

December 9th, 2025 at 11.01am

Integrated Second- and Third-Line Assurance: Get ahead of ESMA’s CSA on the second and third lines

The European Securities and Markets Authority’s (ESMA) 2025 Common Supervisory Action (CSA) focuses on whether UCITS management companies and AIFMs have effective, independent, and well-resourced compliance (second line) and internal audit (third line) functions. National regulators will conduct on-site inspections throughout 2025, with ESMA publishing a consolidated report in 2026.

This scrutiny creates a strong case for modernising and integrating assurance. Integration means better coordination between Compliance and Internal Audit—not merging functions—to remove duplication, close assurance gaps, and provide boards with a single, coherent view of control effectiveness while preserving Internal Audit’s independence.

 Key Design Principles

  1. One Assurance Universe – Maintain a consolidated view of risks, controls, and assurance coverage across the organisation.
  2. Coordinated Planning – Hold quarterly “risk huddles” to align thematic monitoring and audits so the right topics are tested at the right depth.
  3. Reliance Rules – Internal Audit may leverage Compliance testing when evidence is robust but must validate independence, sample adequacy, and testing quality.
  4. Shared Artefacts – Use a single issues register, consistent rating scales, common taxonomies, and a combined assurance dashboard for the Board.
  5. Governance Clarity – Update charters, policies, and reporting lines to define roles and protect independence.

 Risk Function Independence

Under CBI CP86 and the Fund Management Company Effectiveness Guidance, the Risk function must remain independent from Compliance and Internal Audit. It should continue as a standalone second-line function, reporting directly to the Board Risk Committee.

 Preparing for Supervisory Scrutiny

Supervisors will expect firms to evidence:

  • Documented internal audit and compliance methodologies
  • Risk-based planning linked to enterprise risk assessments
  • Combined assurance maps showing who covered which risks, when, and what was found
  • Consistent dashboards, heatmaps, and single issues registers
  • Clear safeguards protecting Internal Audit’s independence

 

Bottom Line

ESMA’s CSA creates both urgency and opportunity. Firms that redesign their second- and third-line assurance model now will be better positioned to:

  • Demonstrate control effectiveness
  • Optimise resources
  • Strengthen board oversight
  • Meet heightened supervisory expectations in 2026

Let’s Talk

If you want independent, pragmatic advice to protect your business, optimise performance, and grow sustainably, we’d love to work with you. If you would like to discuss how we can help you re-imagine your second and third lines please do get in touch at enquiries@VPP.ie

Vantage Point Partners – Protect. Optimise. Grow.

Delegation and control functions: two reviews, one deadline

The delegation review carries the hard date: a time-bound remediation plan in place before the end of 2026. The CSA feedback asks for time-bound plans without naming a date, with follow-up through ongoing supervisory engagement. Year end is the sensible anchor for both, and a review needs to start by early November to be board-approved in time.

Talk to us