Delegation, compliance and internal audit

Independent review of your delegation arrangements and your control functions, against the Central Bank’s two 2026 reports, delivered to the board.

In July 2026 the Central Bank published two reports that ask Irish fund management companies for the same thing in two different places: gap-analyse what you have, and put a time-bound remediation plan in front of your board. One looks at delegation. The other looks at compliance and internal audit. Most firms need both, and they are not the same piece of work.


Two reviews, one deadline

The delegation review carries the hard date. Every fund management company is expected to gap-analyse its arrangements against the report and have a time-bound remediation plan in place before the end of 2026.

The CSA feedback does not name a date. It asks firms to review their arrangements against the report and to develop time-bound remediation plans, with follow-up through ongoing supervisory engagement. Year end is the sensible anchor for both: the evidence overlaps, the board conversations overlap, and a firm that arrives at its next supervisory engagement with one plan covering both is in a materially better position than one that has done neither.

To be board-approved before 31 December, either review needs to start by early November.


The delegation review

Thematic review of delegation across the fund management company sector, published 23 July 2026.

The Central Bank was, on the whole, reassured — and then asked every board to mark its own homework. The findings cluster across five themes: governance, portfolio management, delegate oversight, risk management and data. Read together they are not five separate observations but one question asked five ways: can this firm form, evidence and stand over its own independent judgement, or is it in substance relying on someone else to do so?

This is a board matter rather than a compliance exercise. It goes to whether the board and its Designated Persons are genuinely in control of the funds they are responsible for, and under the Individual Accountability Framework and SEAR it lands on named individuals.

Read our analysis of the delegation review →


The CSA on compliance and internal audit

Feedback on the Common Supervisory Action on compliance and internal audit functions in the investment funds sector, following ESMA’s EU-wide review.

Two themes cut across both functions. First, reliance on the Group does not move the accountability: internal audit activity outsourced to Group with very little interaction, compliance frameworks approved at Group before the local board saw them, Group risk ratings that thin local coverage. Second, visibility is not ownership: boards that had sight of assurance activity without shaping the plan, challenging the coverage or tracking findings to closure.

The sharpest single finding was an internal audit plan that simply replicated the firm’s own compliance monitoring plan — the third line echoing the second rather than testing it.

Read our analysis of the CSA feedback →


The awkwardness in what has been asked for

Both reports have independence at their centre. The delegation review asks whether the firm leans too heavily on connected parties. The CSA asks whether the second and third lines are independent enough of the Group, and of each other. Yet the gap analysis each now calls for would usually be run by the very people whose independence is in question. A self-assessment risks reproducing the exact blind spot under review.

Because independence is the subject, independent eyes are not a workaround. They are the most credible way to show your board — and the Central Bank — that the judgement behind the plan is objective.


Three ways to engage

1. The Combined Review — both, run together

Recommended for most fund management companies. One diagnostic across delegation and the control functions, one set of board conversations, one board-ready remediation plan. The evidence overlaps heavily — Designated Person allocation, board composition and tenure, delegate oversight, risk data and reporting all serve both reports — so two pieces of work become one.

  • Duration. Four to six weeks.
  • Fee. Fixed.
  • Deliverable. A single board-approvable plan covering both reports, every gap rated red, amber or green against the Central Bank’s specific expectations rather than a generic checklist, with a named owner and a deadline against each.
  • Who it is for. The board, the chief executive, or an independent non-executive director.

2. The Delegation Diagnostic — standalone

A rapid, structured assessment of your arrangements against each of the five themes in the delegation review. It draws on a focused review of the documents that carry the substance — the business plan, the delegate oversight and risk frameworks, the Designated Person allocation, board composition and tenure, the data architecture — and candid conversations with the board, the Designated Persons and the key control functions. Deeper work follows only where the diagnostic shows red, so effort follows risk.

  • Duration. Three to four weeks.
  • Fee. Fixed.
  • Deliverable. A prioritised, board-approvable action plan with owners and realistic deadlines, rated red, amber or green across all five themes.
  • Who it is for. The chief executive, or an independent non-executive director.

3. The Control Functions Gap Review — standalone

An independent assessment of your second and third lines against the Central Bank’s CSA feedback and the ESMA assessment framework. We test your compliance and internal audit functions from outside them, rather than asking them to test themselves.

  • Duration. Three to four weeks.
  • Fee. Fixed.
  • Deliverable. A board-ready report: every gap rated, with a named owner and a deadline against each. This is the time-bound remediation plan the Central Bank has asked for.
  • Who it is for. The board, or the chair of the audit and risk committee.

Outsourced and co-sourced internal audit

For firms too small to carry a chief audit executive and too regulated to go without one.

  • Basis. Retainer.
  • Scope. A risk-based annual audit plan built for your entity and approved by your committee; the audits delivered; a status report and attendance at each committee; formal tracking of findings to closure and escalation of failures.
  • Why it answers the feedback. Two of the Central Bank’s findings were audit plans inherited from Group rather than set for the entity, and the absence of a formal mechanism to track remediation.

We currently provide the outsourced internal audit function to a regulated firm in Ireland, reporting into its risk and audit committee.

Designated Person and board appointments

Where the board needs the capability inside the governance structure rather than beside it. Paul Traynor holds a current Central Bank pre-approval controlled function and fitness and probity approval, and previously held a CSSF-approved Head of Internal Audit role in Luxembourg.


Why an independent firm, and why this one

  • Reviews required by the Central Bank. We have led several such reviews for regulated firms in Ireland.
  • No audit conflict. We do not audit the firms we assure, so we can take work the large firms are conflicted out of.
  • A partner does the work. The same partner attends your committee.
  • We have sat on your side of the table. Managing Director at BNY, Partner at EY leading wealth and asset management consulting, and a current Central Bank approved PCF.

Let’s talk

We run independent reviews of your delegation arrangements and your control functions against the Central Bank’s 2026 reports, separately or together, delivered as a board-ready remediation plan with owners and deadlines. To have it approved before the 31 December deadline, the work needs to start by early November.

paul.traynor@vpp.ie