What organisation, risk management and internal audit must an investment firm have?
The organisational requirements of MiFID II for investment firms and banks providing investment services: structure, people, controls, continuity and accounts, plus the risk management and internal audit functions.
By the ExamPass CY editorial teamLast reviewed 6 min read
Topic 1 of 12 · all topics in this chapter
On this page
Short answer
An investment firm needs clear decision-making procedures and documented reporting lines, staff who know the procedures and have the skills they need, internal controls at all levels, orderly records, secure information systems, a business continuity policy and accounting that can deliver true and fair reports when CySEC asks. It must evaluate these arrangements regularly. Where appropriate and proportionate, it needs an independent risk management function and a separate, independent internal audit function; a firm without a risk function must be able to show on request that its risk policies and procedures meet those requirements.
Organisational requirements at a glance
| Point | Rule |
|---|---|
| Structure | Procedures for taking decisions and a structure with documented reporting lines and allocation of functions |
| People | Staff know the procedures they must follow and have the skills, knowledge and expertise needed; combining roles is allowed only if each is still done soundly, honestly and professionally |
| Controls and records | Internal control mechanisms at all levels, effective internal reporting, adequate and orderly records |
| Information and continuity | Security, integrity and confidentiality of information; a continuity policy to keep or quickly restore essential data, functions and services |
| Accounts | Timely financial reports giving a true and fair view, in line with accounting standards, delivered when CySEC requests them |
| Regular evaluation | Monitor and regularly evaluate the arrangements and fix deficiencies |
| Risk management | Policies identifying risks and, where appropriate, the firm's risk tolerance (sustainability risks included since 2 August 2022); independent function where appropriate and proportionate |
| Internal audit | Where appropriate and proportionate, separate and independent: audit plan, recommendations, follow-up, reporting |
| Proportionality | The size and complexity of the business and the range of services decide how each requirement is met |
Source: Delegated Regulation (EU) 2017/565, Articles 21, 23, 24 and 25; Law 87(I)/2017, Article 17.
What must the firm's organisation include?
The Delegated Regulation sets a common checklist. A firm needs procedures for taking decisions and a structure that sets out, clearly and in writing, who reports to whom and who is responsible for what. Its relevant persons must know the procedures they have to follow, and it must employ people with the skills, knowledge and expertise their jobs require. It needs internal control mechanisms at every level, effective internal reporting and communication, and adequate, orderly records of its business and organisation.
Staff may hold several roles, but only if that does not stop them doing any one of them soundly, honestly and professionally. Proportionality runs through all of this: the firm designs each arrangement according to how large and complex its business is and which services it offers, but it cannot skip items on the list. Since 2 August 2022 the firm must also take sustainability risks into account when meeting these requirements. The same organisational rules apply to banks when they provide investment services, with the Central Bank of Cyprus as their supervisor.
Terms used in this note
- Relevant person
- A director, partner, manager, employee or tied agent of the firm, or another person involved in providing its investment services.
- Risk tolerance
- The level of risk the firm decides it is willing to accept, set through its risk management policies.
- Internal audit function
- A separate, independent function that examines and evaluates the firm's systems and controls and follows up its recommendations.
How must information, continuity and accounts be protected?
Systems and procedures must keep information secure, intact and confidential. A business continuity policy must aim, if systems or procedures are interrupted, to preserve essential data and functions and keep services running or, where that is not possible, to recover them and resume services in good time. Since 17 January 2025 the EU's Digital Operational Resilience Act (DORA) sets the detailed rules for ICT risk, and Law 87 was aligned with it in February 2025.
Accounting policies and procedures must allow the firm, when CySEC asks, to deliver financial reports promptly that give a true and fair view of its financial position and follow the applicable accounting standards. Finally, the firm must monitor these arrangements and evaluate on a regular basis whether they are adequate and effective, and act on any deficiencies.
When does a firm need risk management and internal audit functions?
Every firm needs risk management policies that identify the risks arising from what the firm does and how it operates and, where appropriate, fix how much risk it is prepared to accept; arrangements to manage those risks; and monitoring of whether the policies work, whether staff comply and whether remedial measures are effective. Where appropriate and proportionate, it must set up an independent risk management function that implements the policies and reports to and advises senior management. A firm that has no such function must be able to show, on request, that its policies and procedures still meet these requirements.
Also where appropriate and proportionate, the firm must have an internal audit function that is separate and independent from its other functions and activities. It sets an audit plan to examine the firm's systems, controls and arrangements, issues recommendations, checks that they are followed and reports on its work. It examines and evaluates the firm's systems and controls rather than running them. ESMA's guidelines add that an internal audit function may not be combined with the compliance function. Written reports on risk management and internal audit go to senior management at least annually, as described in What must a CIF's board and senior management do to govern the firm?
How to think about it
Picture three layers. The first is the everyday machinery: structure, people, controls, records, information security, continuity and accounts, all scaled to the business but none optional. The second watches risk: policies for everyone, an independent function where the business justifies it, and proof on request where it does not. The third checks the whole: internal audit, independent and separate, recommending but not running things.
Common mistakes
Treating proportionality as an exemption. It changes how each requirement is met, not whether it applies.
Giving internal audit an operational role. It audits, recommends and follows up; it does not take the operational decisions or run the processes it audits.
Assuming every firm must have a risk function. It is required where appropriate and proportionate; otherwise the firm must be able to show on request that its policies and procedures meet the requirements.
Merging internal audit with compliance. Where an internal audit function is required, it must be separate and independent from all the firm's other functions and activities, compliance included.
Legal references
- Commission Delegated Regulation (EU) 2017/565 (MiFID II organisational requirements and operating conditions), as amended (opens in a new tab)
Article 21 (general organisational requirements) · Article 23 (risk management) · Article 24 (internal audit) · Article 25 (reports to senior management)
- The Investment Services and Activities and Regulated Markets Law of 2017 (Law 87(I)/2017), consolidated Greek text on CyLaw (amendments up to Law 183(I)/2025) (opens in a new tab)
Article 17 (organisational requirements, as amended by Law 12(I)/2025) · Article 3(3) (application to credit institutions)
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) (opens in a new tab)
- Commission Delegated Regulation (EU) 2021/1253 (sustainability factors, risks and preferences) (opens in a new tab)
Practise this topic
Test what you just read
The Chapter 3 pack has 155 exam-style questions, 18 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 53 free Chapter 3 flashcards →