CySEC Circular C795: ESMA's 2026 review of risk management at UCITS ManCos and AIFMs
European Securities and Markets Authority (ESMA)AnnouncementIssued
By the ExamPass CY editorial teamPublished
- Funds
- Governance
Short answer
On 3 July 2026 ESMA launched an EU-wide common supervisory action on the risk management function of UCITS management companies and AIFMs, to run through 2026 and 2027. CySEC Circular C795 of 12 August 2026 tells Cyprus fund managers that a targeted thematic review, on-site or desk-based, is planned for late 2026 to early 2027. No new rules apply, but firms should check now that their risk function is independent, properly resourced and reporting effectively to senior management and the board.
At a glance
- What changes
- No new rules: supervisors across the EU, including CySEC, will review how UCITS management companies and AIFMs organise and run their risk management function.
- Who is affected
- UCITS management companies, internally managed UCITS, AIFMs and internally managed AIFs supervised by CySEC, and their risk, compliance and board members.
- UCITS management companies and internally managed UCITS
- AIFMs and internally managed AIFs
- Risk managers, boards and senior management of fund managers
- Compliance officers and internal auditors
- What to do
- Check the independence, resources, expertise and reporting of the risk management function, document the evidence and close gaps before the review starts.
- By when
- Now — CySEC's thematic review is planned for late 2026 to early 2027
What is ESMA's common supervisory action about?
On 3 July 2026 ESMA launched a common supervisory action (CSA) on the risk management function of UCITS management companies and alternative investment fund managers (AIFMs). National supervisors will carry it out with ESMA during 2026 and 2027, using a common assessment framework that sets the scope, method, supervisory expectations and timeline. ESMA plans to publish a final report on the results in 2028.
The aim is to test how firms comply with the key risk provisions of the UCITS and AIFMD frameworks. Supervisors will look at three areas: how the risk management function is governed and organised; how risks are identified, measured and monitored; and how risk information reaches senior management and governing bodies. ESMA gives market, credit, liquidity, counterparty and operational risk as examples of the material risks involved.
What will CySEC do, and when?
CySEC relayed the CSA in Circular C795 of 12 August 2026. According to published summaries, the circular is addressed to UCITS management companies, internally managed UCITS, AIFMs and internally managed AIFs. CySEC plans a targeted thematic review in late 2026 and early 2027, through on-site inspections, desk-based reviews or both, covering a representative sample of Cyprus fund managers.
Before that work starts, CySEC asks firms to check that their risk management arrangements remain appropriate, effective and proportionate to their activities. The CSA itself creates no new obligations; it tests how firms apply the existing ones.
What do the rules already require?
For UCITS management companies, Article 12 of Commission Directive 2010/43/EU requires a permanent risk management function that is hierarchically and functionally independent from operating units. National law may allow a derogation only where it is appropriate and proportionate to the nature, scale and complexity of the business, and the firm must then show safeguards against conflicts of interest. The function implements the risk policy, ensures compliance with each fund's risk limit system, including the statutory limits on global exposure and counterparty risk, and reports regularly to the board and senior management on risk levels, limit breaches and the adequacy of the risk process. It must have the authority and access to information it needs.
For AIFMs, Article 15 of the AIFM Directive requires risk management to be functionally and hierarchically separated from operating units, including portfolio management, and risk systems to be reviewed at least once a year. Delegated Regulation (EU) No 231/2013 adds detail on the permanent risk function and its independence. In Cyprus these rules sit in the UCITS Law 78(I)/2012 and the AIFM Law 56(I)/2013; see our study note on AIFM risk and liquidity management.
What should fund managers check now?
A practical self-assessment can follow ESMA's three areas. On governance: is the risk function independent of portfolio management in its reporting line and pay, with enough people, expertise and systems for every fund, including cross-border and delegated mandates? On measurement: do limits, stress tests and liquidity monitoring match each fund's actual strategy, and are breaches escalated and recorded?
On reporting: do the board and senior management receive regular reports comparing risk levels with each fund's agreed risk profile, with limit breaches and remedial action, and do the minutes show that the board challenged them? Smaller firms relying on a proportionality derogation should be able to explain why it is justified and which safeguards protect the function's independence. Keeping this evidence in one place will make an on-site or desk-based review easier.
In the official wording
“The focus will be on the effectiveness, independence and expertise of the risk management function.”
When does it apply?
Applies now
- The existing UCITS and AIFMD rules on a permanent, independent risk management function: Commission Directive 2010/43/EU, Article 12; AIFM Directive, Article 15; Delegated Regulation (EU) No 231/2013.
- CySEC's request in Circular C795 that fund managers check their risk management arrangements are appropriate, effective and proportionate.
- The CSA runs during 2026 and 2027; CySEC's thematic review is planned for late 2026 to early 2027.
Applies later
No later dates announced.
What to do
- Confirm that the risk management function is permanent and independent from portfolio management and other operating units, or document the proportionality derogation and its safeguards.No fixed deadline
- Check that risk staff have the expertise, authority, data and systems they need for every fund managed.No fixed deadline
- Review risk limits, stress tests and liquidity monitoring for market, credit, liquidity, counterparty and operational risk, fund by fund.No fixed deadline
- Review the content and frequency of risk reports to senior management and the board, including limit breaches and remedial action.No fixed deadline
- Assemble the evidence (policies, organisation chart, risk reports, board minutes) for an on-site or desk-based review.No fixed deadline
In the exam
Risk management by UCITS management companies and AIFMs belongs to the UCITS and alternative investment fund topics of the CySEC Advanced and Basic exams.
Related study notes
Preparing for an exam?
Practise the topics behind this update
Exam-style questions with a hint before you answer and a full explanation after, chapter by chapter.
- CySEC AdvancedSee the CySEC Advanced packsTry the free demo
- CySEC BasicSee the CySEC Basic packsTry the free demo
Sources
- ESMA launches Common Supervisory Action with NCAs on the risk management function (opens in a new tab)
ESMAOfficial text
- Circular C795: ESMA 2026 Common Supervisory Action on the risk management function of UCITS management companies and AIFMs (opens in a new tab)
CySECOfficial text
- Commission Directive 2010/43/EU (UCITS organisational requirements, conflicts of interest, conduct of business and risk management) (opens in a new tab)
EUR-LexOfficial text
- Directive 2011/61/EU on Alternative Investment Fund Managers (AIFMD) (opens in a new tab)
EUR-LexOfficial text
- Commission Delegated Regulation (EU) No 231/2013 supplementing the AIFMD (opens in a new tab)
EUR-LexOfficial text
- CySEC warns Cyprus funds of EU-wide risk management review (opens in a new tab)
Cyprus MailCommentary
Summary prepared by the ExamPass CY editorial team; it is not the official text. Quotations are reproduced from the source for the purpose of reporting and review.
This document has been drafted using material downloaded from ESMA's website. ESMA does not endorse this publication and in no way is liable for copyright or other intellectual property rights infringements nor for any damages caused to third parties through this publication.
© European Union, https://eur-lex.europa.eu. EU material is reused with credit and has been summarised; only the Official Journal of the European Union is authentic.