ESMA Risk Management Function CSA: The 2026-2027 Supervisory Review

On 3 July 2026, ESMA told every UCITS management company and alternative investment fund manager in the European Union that their risk management function is next in line for coordinated scrutiny. The announcement launched a Common Supervisory Action, an exercise ESMA will run with national competent authorities throughout 2026 and 2027, with a final report due in 2028. The ESMA risk management function CSA adds no new return and no new template. Its whole mechanism is supervisory: NCAs walk into individual firms with a shared checklist, asking one blunt question about a function most managers assume is already in order.

That question is whether the risk management function is genuinely effective, independent and expert, or whether it exists mainly on the organisation chart and in a policy that no one has stress-tested. ESMA framed the objective as assessing how market participants comply with key risk-related provisions under the UCITS and AIFMD frameworks, with the focus on effectiveness, independence and expertise. Supervisors will look at governance, at how risks are identified and measured, and at what reaches the people who are supposed to act on them.

For a portfolio manager or a conducting officer, the practical stakes sit in the evidence file. A firm that can show board risk reporting with real escalation, tested risk limits and a risk function that can say no to the front office will pass a supervisory conversation quickly. A firm whose risk register was last updated at authorisation will not.

Related reading: our AIFMD II liquidity management tools guide.

The dates that frame this exercise

This is a multi-year exercise with a calendar worth pinning to the wall now, because the supervisory contact can land in either of two years.

  • 3 July 2026: ESMA announced the CSA and its common assessment framework.
  • Throughout 2026 and 2027: NCAs conduct the assessment on their supervised managers, using the shared methodology.
  • 2028: ESMA publishes a final report with the results of the exercise.
  • 16 April 2026: AIFMD II (Directive (EU) 2024/927) applies, so the review runs against the newly strengthened liquidity and delegation regime rather than the 2013 baseline alone.
  • 16 April 2027: certain AIFMD II transposition measures apply from this date, including the UCITS Article 20a-related provisions specified in Article 3 of Directive (EU) 2024/927.

There is no filing deadline attached to the CSA, and no submission window opens. The urgency is different in kind. A national supervisor can request documentation, run a questionnaire or open an on-site visit at any point across two calendar years, and the material it asks for describes work that should already be in place, not work a firm can begin once the request arrives.

What ESMA actually announced, and what it did not

The scope is precise, and precision matters here because the label “risk management” travels across several regimes. This CSA covers UCITS management companies and AIFMs. It runs against the UCITS and AIFMD frameworks. MiFID investment firms are outside it, and there is no reference to MiFID II in the announcement, so a standalone portfolio manager authorised only under MiFID is not the target of this particular exercise.

ESMA set three areas for NCAs to examine: the governance and organisation of the risk management function; the identification, measurement and monitoring of risks; and reporting to senior management and governing bodies. It also named the risk categories in play, describing risk management as the function that keeps material risks such as market, credit, liquidity, counterparty and operational risks properly identified, measured, monitored and managed.

A Common Supervisory Action works differently from a single-firm inspection, and treating it as one inspection scaled up misreads the mechanism. NCAs apply a common assessment framework that ESMA developed, setting the scope, methodology, supervisory expectations and timeline so that a manager in Dublin, Luxembourg or Frankfurt is measured against the same yardstick. Supervisors then share what they find through ESMA to push convergence in how the rules are applied. The output is a public report on practice across the EU plus individual follow-up by each NCA, rather than a new rulebook. Anyone who has watched a prior CSA land will recognise the pattern from ESMA’s MiFID II sustainability preferences CSA, which followed the same design of shared methodology, coordinated review and a convergence-focused write-up.

The legal spine the review runs against

The announcement cites no article numbers, so the useful preparation is to map the “key risk-related provisions” ESMA referred to. The obligations sit at two levels for each framework, and the Level 2 detail is where a supervisor forms a view.

For UCITS managers, the risk management process is required by Article 51 of Directive 2009/65/EC. The implementing detail comes from Commission Directive 2010/43/EU. Article 12 of that directive requires a permanent risk management function that is hierarchically and functionally independent from operating units, with a proportionality derogation that member states may allow where it is appropriate given the nature, scale and complexity of the business. The risk-management chapter then sets out the operational duties: Article 38 on the risk management policy, Article 39 on assessment, monitoring and review of that policy, Article 40 on the measurement and management of risk, Article 41 on the calculation of global exposure, Article 42 on the commitment approach, Article 43 on counterparty risk and issuer concentration, Article 44 on procedures for valuing OTC derivatives, and Article 45 on reports on derivative instruments.

For AIFMs, the anchor is Article 15 of Directive 2011/61/EU, which requires the risk management function to be functionally and hierarchically separated from operating units, including from portfolio management, and requires adequate systems to identify, measure, manage and monitor all risks relevant to each fund’s strategy. Commission Delegated Regulation (EU) No 231/2013 fills in the Level 2 obligations in its risk management section: Article 38 on risk management systems, Article 39 on the permanent risk management function, Article 40 on the risk management policy, Article 41 on assessment, monitoring and review of the risk management systems, Article 42 on the functional and hierarchical separation of the function, Article 43 on safeguards against conflicts of interest, Article 44 on risk limits, and Article 45 on risk measurement and management.

Reading the two regimes side by side shows why ESMA can run one exercise across both. The UCITS and AIFMD risk management obligations were deliberately built to be similar in nature, so a common assessment framework can test the same themes of separation, policy, limits, measurement and reporting whichever framework a manager operates under.

Governance and organisation of the risk management function

The first area ESMA named is the governance and organisation of the risk management function, and the recurring supervisory concern is independence that is real rather than nominal. Both frameworks require the function to be hierarchically and functionally separated from the units it checks, and in the AIFMD text that separation extends explicitly to portfolio management. The point of the separation is that the person measuring the risk of a position cannot be the same person, or answer to the same person, who took it.

Independence is easy to assert and harder to evidence, and this is where a supervisory review tends to press. A reporting line on an org chart is a starting point, not a conclusion. Article 42 of Delegated Regulation 231/2013 and the equivalent UCITS provisions expect safeguards that let the function operate independently, with the authority and access to information it needs to do its job. Where a smaller manager relies on the proportionality derogation to combine functions, the regulation requires that derogation to be appropriate and proportionate to the nature, scale and complexity of the business, and a supervisor will expect to see that judgment documented rather than assumed. Combining the head of risk with a revenue-generating role, without any compensating safeguard, is the kind of arrangement a CSA is designed to surface.

Identification, measurement and monitoring, the second focus area

The second area covers whether risks are identified, measured and monitored across the material categories ESMA listed. This is the operational heart of the function, and it is where a policy document meets, or fails to meet, the daily reality of a portfolio.

The framework requires a risk management policy that identifies the risks a fund is exposed to, procedures to measure them, and limits to contain them. For UCITS, Article 51 of Directive 2009/65/EC requires the process to assess exposure to market, liquidity and counterparty risks and to all other material risks including operational risk, and the Level 2 rules add the calculation of global exposure and the treatment of counterparty risk and issuer concentration. For AIFMs, Article 44 of Delegated Regulation 231/2013 requires quantitative or qualitative risk limits, and the surrounding articles require those limits to be measured and managed on an ongoing basis.

A limit that is set once and never tested is the classic finding. Monitoring means a limit is measured against the live portfolio, a breach triggers escalation, and the escalation is recorded and acted on. A risk register that lists risks without owners, thresholds or evidence of review reads as a compliance artefact rather than a live control. Liquidity risk deserves particular attention in this cycle, because the AIFMD II liquidity management tools regime now requires managers of open-ended funds to select liquidity management tools from a harmonised EU list and build them into fund documentation, which raises the bar for what a credible liquidity risk process looks like. Valuation of harder-to-price assets is a neighbouring pressure point that supervisors have examined in their own thematic work, as our note on the CSSF illiquid asset valuation review sets out.

Reporting to management, the third focus area

The third area is reporting to senior management and governing bodies, and it is the one most easily under-evidenced because the work happens in meetings. Article 41 of Delegated Regulation 231/2013 requires the AIFM to assess, monitor and review the risk management systems and, in practice, to keep senior management and the governing body informed of the risk picture and of any material breach. The UCITS regime carries the same expectation that the outputs of the function reach the people accountable for the fund.

From an auditor’s-eye view, reporting is proven by artefacts. Board and management risk packs, a documented risk appetite, minutes showing that a limit breach was discussed and resolved, and a clear escalation path all evidence that the function feeds decision-making. A quarterly report that never changes, or that the board receives but does not interrogate, tells a supervisor that reporting is a formality. The expertise limb of ESMA’s stated focus lands here too: a governing body needs enough understanding to challenge what the risk function brings it, which is why management-body suitability and knowledge sit alongside this review, as covered in our guide to the ESMA and EBA suitability assessment guidelines.

How AIFMD II shifts what good looks like

The timing of this CSA is not accidental in effect, even if the announcement does not spell out the connection. AIFMD II, Directive (EU) 2024/927, applies from 16 April 2026, weeks before the CSA was announced. It strengthens several of the exact areas the review touches: liquidity risk management for open-ended funds, delegation oversight, and supervisory reporting. Managers of open-ended AIFs must now select liquidity management tools from the harmonised list and integrate them into their liquidity risk framework, and AIFMD II introduces changes to supervisory reporting under Article 24, with implementation timing depending on the relevant transposition measures and applicable Level 2 measures.

Read together, the sequence suggests supervisors will assess risk management functions against a regime that has just been upgraded, rather than the 2013 settlement in isolation. That is an interpretation of the calendar rather than an ESMA statement, so treat it as a planning assumption. The safe reading for a fund manager is that a risk function which has already absorbed the AIFMD II liquidity and delegation changes will present better than one still running its pre-April 2026 processes. The enhanced reporting workstream is worth tracking in parallel, and our breakdown of the AIFMD II Annex IV reporting changes maps what the granular data set now demands.

What prior CSAs tell you supervisors will look for

ESMA has run this play before, and the earlier exercises are the best available guide to where the findings will cluster. In the 2020 CSA on UCITS liquidity risk management, ESMA reported that overall compliance was satisfactory in most cases, while identifying shortcomings in a few. The 2020 UCITS liquidity CSA identified weaknesses including insufficient monitoring and governance practices in some firms, with NCAs following up on individual cases.

The 2025 CSA on the compliance and internal audit functions of fund managers, whose final report ESMA published on 11 May 2026, followed the same shape. Its stated aim was to assess, foster and enforce adherence to the key AIFMD and UCITS provisions relevant to those functions, and it closed with an annex of good and poor practices and a summary of the follow-up actions NCAs took or envisaged. The 2026-2027 risk management CSA is built on that template, so managers should monitor the final ESMA report and any supervisory convergence material that ESMA publishes following the exercise.

The common thread across both prior exercises is that supervisors distinguish a control that exists from a control that works. Second and third-line oversight that never catches anything, documentation that describes a process no one runs, and reliance on assumptions the manager cannot evidence are the findings that recur. A risk function should expect the same test.

Preparing before your NCA makes contact

Because the assessment window spans two years and the request can arrive unannounced, the practical work is to assemble the evidence a supervisor would ask for and to fix the gaps that assembly reveals. A focused walkthrough helps more than a broad gap analysis.

  • Confirm the risk management function is hierarchically and functionally separated from portfolio management, and where a proportionality derogation is used, document why it is appropriate to the firm’s nature, scale and complexity.
  • Refresh the risk management policy so it names the material risks for each fund, states how each is measured, and sets limits, then check the last review date against Article 39 (UCITS) or Article 41 (AIFMD) review expectations.
  • Test that risk limits are measured against live portfolios, that breaches escalate, and that the escalation is recorded, rather than trusting that limits are simply respected.
  • Pull the last four board or management risk reports and check they show change over time, a real risk appetite and evidence that the governing body engaged with what it received.
  • Reconcile the liquidity risk process with the AIFMD II liquidity management tools now required for open-ended funds, so the CSA does not surface a gap that AIFMD II already opened.
  • Check that the second and third lines of defence actually review the risk function, since prior CSAs found the absence of that oversight repeatedly.

None of this is a legal opinion on any firm’s position, and where an arrangement is finely balanced the right step is to take advice rather than guess. The regulation sets the requirements described above; how a given manager meets them depends on its funds, its strategies and its structure.

Frequently Asked Questions

Which firms are in scope of the ESMA risk management function CSA?

UCITS management companies and alternative investment fund managers across the EU. The announcement does not extend the exercise to MiFID investment firms, and it references the UCITS and AIFMD frameworks rather than MiFID II. Self-managed investment companies and internally managed AIFs may fall within the relevant UCITS or AIFMD framework where they are subject to the underlying risk management requirements.

Is there a reporting deadline or a template to file?

No. A Common Supervisory Action is a supervisory review, not a reporting obligation, so no return is created and no submission window opens. The relevant dates are the 2026-2027 assessment period and the 2028 final report. What a firm provides is whatever documentation, questionnaire responses or on-site access its national competent authority requests.

What does ESMA mean by effectiveness, independence and expertise?

Effectiveness is whether the function actually identifies, measures and controls risk rather than documenting it. Independence is the hierarchical and functional separation from operating units, including portfolio management, that both frameworks require. Expertise covers whether the risk staff, and the governing body they report to, have the knowledge to run and challenge the process. The three focus areas of governance, risk monitoring and reporting map onto these tests.

Which legal provisions will supervisors assess against?

For UCITS, Article 51 of Directive 2009/65/EC and the risk management provisions of Commission Directive 2010/43/EU, including the permanent risk management function in Article 12. For AIFMs, Article 15 of Directive 2011/61/EU and the risk management section of Commission Delegated Regulation (EU) No 231/2013, Articles 38 to 45. The announcement names no article numbers, so these are the underlying provisions the “key risk-related provisions” phrase points to.

How does AIFMD II affect the exercise?

AIFMD II, Directive (EU) 2024/927, applies from 16 April 2026 and strengthens liquidity risk management, delegation oversight and supervisory reporting. It is a reasonable planning assumption that supervisors will assess risk functions against the upgraded regime, particularly the requirement for open-ended funds to use liquidity management tools from the harmonised list, though ESMA has not stated that link explicitly.

What did earlier CSAs find that this one is likely to repeat?

The 2020 UCITS liquidity CSA identified areas for improvement, including weaknesses in some firms’ liquidity risk management practices, and NCAs followed up on individual cases. The 2025 CSA on compliance and internal audit functions produced an annex of good and poor practices. Expect the risk management CSA to distinguish controls that exist from controls that work, and to close with a good-and-poor-practices annex.

Will there be enforcement at the end of the CSA?

ESMA describes the exercise as assessing, and in prior CSAs fostering and enforcing, adherence to the framework, with each NCA taking its own follow-up. Outcomes in earlier exercises ranged from remediation of individual weaknesses to broader convergence work, and the published report focuses on practice across the EU. Any consequence for a specific firm is a matter for its national competent authority, so this article does not predict outcomes.

Related Articles

Key Takeaways

  • ESMA launched a Common Supervisory Action on the risk management function of UCITS management companies and AIFMs on 3 July 2026, to run through 2026 and 2027 with a final report in 2028.
  • The review targets effectiveness, independence and expertise across three areas: governance and organisation of the function, identification and monitoring of risks, and reporting to senior management and governing bodies.
  • There is no filing or template. Supervisors request documentation, questionnaires or on-site access at any point across the two-year window, so the evidence has to exist before contact.
  • The underlying provisions are Article 51 UCITS and Commission Directive 2010/43/EU for UCITS managers, and Article 15 AIFMD and Commission Delegated Regulation (EU) No 231/2013, Articles 38 to 45, for AIFMs.
  • MiFID investment firms are outside this CSA, and the announcement makes no reference to MiFID II.
  • AIFMD II applies from 16 April 2026, so the risk function is measured against a strengthened liquidity and delegation regime rather than the 2013 baseline.
  • Prior CSAs found weak second and third-line oversight and controls that exist on paper but do not catch breaches. This exercise is designed to distinguish a control that works from one that merely exists.

Sources and References

  • ESMA, “ESMA launches Common Supervisory Action with NCAs on the risk management function”, 3 July 2026: esma.europa.eu
  • Directive 2009/65/EC (UCITS), Article 51: eur-lex.europa.eu
  • Commission Directive 2010/43/EU (UCITS implementing directive), risk management provisions: eur-lex.europa.eu
  • Directive 2011/61/EU (AIFMD), Article 15: eur-lex.europa.eu
  • Commission Delegated Regulation (EU) No 231/2013 (AIFMD Level 2), Articles 38 to 45: eur-lex.europa.eu
  • Directive (EU) 2024/927 (AIFMD II): eur-lex.europa.eu
  • ESMA, results of the 2020 Common Supervisory Action on UCITS liquidity risk management: esma.europa.eu
  • ESMA, Final Report, 2025 CSA on compliance and internal audit functions of fund managers (ESMA34-1436284137-2305), 11 May 2026: esma.europa.eu

Where the ESMA risk management function CSA leaves risk teams

The message of this CSA is that supervisors have moved from asking whether a risk management function exists to asking whether it does anything. Across two years, NCAs working from one ESMA framework will test the same themes at managers of very different sizes: is the function separate, does it measure and limit the risks that matter, and does the governing body hear and act on what it produces. The firms that come through cleanly will be the ones that treated risk management as a live control rather than an authorisation formality, and that had already folded the AIFMD II changes into their process. The rest have until their NCA calls to close the gap between the policy on the shelf and the practice on the desk.

Last updated: July 2026

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts