Dutch Regulator Finds Governance Gaps Behind Otherwise Mature Fund Manager Controls
Key Takeaways
- Compliance Documentation: The AFM found that many fund managers maintain compliance documentation, but it is often outdated, incomplete, or insufficiently aligned with monitoring and reporting activities.
- Outsourcing Oversight: While compliance and internal audit activities may be outsourced, fund managers remain fully responsible and are expected to retain internal expertise and actively oversee external providers.
- Proportionality Decisions: The regulator said firms should better document and justify governance decisions made under the principle of proportionality, including the combination of roles or changes to internal audit structures.
- Governance Controls: The AFM reiterated the importance of maintaining a clear separation between operational activities and control functions to support sound and controlled business operations.
Deep Dive
The Dutch Authority for the Financial Markets (AFM) has identified several areas where fund managers should strengthen their compliance and internal audit functions, despite finding that many firms have those functions broadly well organized.
The observations come from an AFM review of Dutch fund managers conducted as part of a European Common Supervisory Action (CSA) coordinated by the European Securities and Markets Authority (ESMA). The regulator said it expects firms to use the findings to improve governance and internal controls.
The AFM found that compliance documentation, including monitoring plans and reports, is generally in place across most fund managers, but said the quality of that documentation varies considerably. According to the regulator, some documentation is outdated, incomplete, or overly general, while planning, monitoring, and reporting do not always align effectively.
The regulator warned that these shortcomings increase the risk that compliance issues will not be identified or addressed in a timely manner. It said fund managers should regularly update compliance documentation and ensure it reflects the specific risks facing their organizations.
The review also highlighted concerns around outsourcing arrangements. While fund managers are permitted to engage external providers to perform compliance or internal audit activities, the AFM emphasized that ultimate responsibility remains with the fund manager.
According to the regulator, some organizations rely too heavily on external providers, which can reduce the effectiveness of control functions and obscure risks. The AFM said firms should retain sufficient internal knowledge and involvement while actively overseeing outsourced compliance and internal audit work.
The regulator also called for stronger justification when firms apply the principle of proportionality, such as combining compliance roles or reorganizing internal audit functions.
The AFM said it frequently found that the rationale for such decisions was either absent or insufficiently documented. It expects fund managers to clearly demonstrate why their chosen governance structure is appropriate for the nature, scale, and complexity of their business.
In addition, the regulator reiterated the importance of maintaining a clear separation between operational activities and control functions, saying this contributes to sound and controlled business operations.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

