Delegation Under Review: What the Central Bank of Ireland Found About Group Influence

Delegation Under Review: What the Central Bank of Ireland Found About Group Influence

In July 2026 the Central Bank of Ireland published the feedback report from its review of delegation in the Irish funds sector. The overall verdict was positive. The list of shortcomings, read together, points to something more specific about where authority sat in practice.

1. What the Central Bank did

The review began in 2025 and examined delegation practices among Fund Management Companies (FMCs) authorised in Ireland, concentrating on governance, oversight arrangements and the effectiveness of control frameworks for delegated activities.

Four components made up the exercise. A quantitative data request went to all FMCs, seeking information on the scale and structure of delegation arrangements. A qualitative survey, also issued to all FMCs with a bespoke version for third-party FMCs, covered governance, oversight and monitoring practices. Beyond that came a desk-based review of approximately 40 FMCs covering approximately 4,600 investment funds, and on-site inspections at 21 FMCs providing coverage of 40 percent of assets under management across approximately 3,000 investment funds, with supervisors meeting senior personnel at each firm.

The sample was constructed deliberately, taking in scale, operating model, the geographic mix of delegates across the EU, UK and rest of the world, the range of investment strategies, the split between retained and delegated activity, and supervisory knowledge of firms indicating exposure to higher delegation risks.

The report also records a definitional point at the outset. Although it uses the term delegation throughout, the Central Bank has been clear that delegation and outsourcing are the same thing, subject to the same rules and requirements.

2. The verdict was positive

The overall message from the review is encouraging. FMCs operating a delegation model were found to have good governance frameworks, controls, oversight processes and data capabilities in place. On compliance, the finding is direct: FMCs are in compliance with regulatory requirements and largely meet supervisory expectations.

The Central Bank attributes that to genuine progress over recent years, including the implementation of its Fund Management Companies Guidance, and to firms adapting to an operating environment shaped by Brexit, Covid-19 and geopolitical turbulence. Strong levels of substance and decision making within the FMC are described as the norm.

A small number of FMCs fell materially short. Those firms are now subject to time-bound risk mitigation programmes, and supervisory engagement with them has already commenced.

3. A recurring concern across the findings

Findings are organised across five themes: governance, portfolio management, risk management, delegate oversight and data capabilities. Taken individually they look like five separate lists of housekeeping items. Read together, and particularly across governance and delegate oversight, they keep returning to the same question: whether responsibility and independent challenge remained meaningfully anchored in the authorised FMC.

On governance, board independence needed enhancement for a small number of FMCs. This arose in particular where group influence on the board was too high, compounded at times by directors serving beyond best-practice tenure limits. Some FMCs also demonstrated an over-reliance on group-level committees, where local representatives had limited influence to independently challenge delegate decisions or performance issues. Separately, examples were found of the need for resource enhancement, including cases where designated persons were not sufficiently senior or were performing too many roles.

The delegate oversight findings run parallel. There were instances of FMCs relying on group processes for delegate due diligence rather than conducting their own direct assessment, and, relatedly, instances of insufficient representation of local FMC management at the group-level committee considering delegation oversight. Designated Persons and Operational Risk functions were insufficiently involved in delegate oversight at some firms, with some FMCs also engaging group or seconded personnel.

Related concerns appear elsewhere too. Under portfolio management, some FMCs were unable to demonstrate suitable autonomy over oversight and decision making. Under risk management, some could not demonstrate robust independent challenge.

Practical point: The report does not suggest that using group resources is inherently problematic. The supervisory issue is whether the authorised FMC itself retains clear responsibility, sufficient independent challenge and practical decision-making authority.

4. Where group involvement counted in firms' favour

Taking this report as a signal that group support is viewed with suspicion would be a misreading, because the Central Bank recorded the opposite as a positive finding.

FMCs leveraged group expertise, shared services and resource pools to strengthen delegate due diligence, on-site reviews and ongoing monitoring. Where clear governance structures and defined roles sat within those arrangements, they ensured accountability and effective coordination of oversight activities across the group, supporting consistent delegate management.

Group input therefore appears in the report both as a strength and, in other firms, as a source of concern. What distinguishes the positive findings is that the local entity retained defined roles, documented accountability and the ability to challenge what came back to it.

5. Portfolio management: autonomy, and the transition question

Where portfolio management activities were delegated, oversight was found to be robust and generally well executed. Firms evidenced regular delegate engagement, detailed performance analysis, comprehensive reporting and clear escalation pathways for decision making. Appropriate contingency planning was also demonstrated, facilitating continuity of service in the event of termination of portfolio management delegates. Firms retaining some or all portfolio management showed commensurate substance and resourcing for it.

Against that, some FMCs were unable to demonstrate suitable autonomy with respect to oversight and decision making of delegated portfolio management activities. Some operated an unstructured approach, lacking documented procedures, performance standards and regular monitoring. And in some instances, limited attention was being given to establishing explicit wind-down or transition procedures where a third-party portfolio manager is unable to continue to fulfil its mandate.

That last point is worth reading alongside the report's separate finding under data capabilities that some FMCs had not established processes and contingency arrangements to manage potential data loss or interruption.

Practical point: The report treats both as part of the oversight picture: how the arrangement is monitored while it is functioning, and what happens when the arrangement or a critical flow of information breaks down.

6. Risk management and the data differentiator

Risk management activity is largely retained by FMCs, with variability in what is actually undertaken. Frameworks were generally well established, underpinned by clear policies and procedures, and supported in most cases by appropriately resourced risk functions. Where retained, risk management operated as a core function enabling independent oversight, the setting of risk limits and appropriate monitoring of compliance. Firms demonstrating independent verification of delegated risk activities did so through shadow or independent checks with real-time data access and pre-trade compliance controls.

Three areas needed work. Where FMCs engage delegates to support core elements of risk management activities, governance and risk management measures require enhancement to meet the expectations in the Central Bank's Cross Industry Guidance on Outsourcing. Risk management resourcing needed strengthening at some firms. And some FMCs were unable to demonstrate robust independent challenge or access to real-time data, relying instead on delegate reporting.

On that last point the report is direct about the significance of data: access to timely and accurate data emerged as a material differentiator in the effectiveness of risk management frameworks.

There is also an expectation about the balance of delegation itself. Where an FMC operates a delegation model, the Central Bank expects a well-considered balance between portfolio management and risk management delegation, so that the overall degree of delegation is not disproportionate and meets the requirements of relevant legislation.

7. Where the oversight bar sits

The supervisory expectations section sets out the standard against which all of this was assessed. Three points from it matter to anyone running an oversight framework.

A clear due diligence methodology should be applied consistently across all delegates, including sub-delegates, with an appropriate level of on-site engagement, and there should be defined objectives and triggers for due diligence supported by consistent documented evidence trails.

Oversight frameworks should carry a strong level of formality, depth and accountability, and FMCs should not rely solely on due diligence questionnaires or self-reporting by the delegate.

Where aspects of risk management are delegated, an appropriate depth of verification of delegate outputs supporting FMC decision making must be retained.

Practical point: A returned questionnaire, a delegate's own performance report and a delegate's self-assessment all originate with the delegate. The report's expectation is that oversight frameworks carry formality, depth and accountability beyond that material.

8. Why this reaches beyond Ireland

This is an Irish supervisory publication and its immediate supervisory findings and action requirement concern Irish-authorised FMCs. But two of the core legal frameworks on which it draws are EU-level.

The report anchors its analysis to the UCITS requirement that a management company shall not delegate its functions to the extent that it becomes a letterbox entity, and to the AIFMD Level 2 criteria for determining whether an FMC should be considered a letterbox entity, which include the extent of delegation of investment management functions.

Alongside those sit the Central Bank's own frameworks, which are Irish: the Fund Management Companies Guidance and the Cross Industry Guidance on Outsourcing. The guidance position is that delegation does not reduce the FMC board's ultimate responsibility, and that the company must at all times retain and exercise overall control of its management.

Practitioner commentary: because the UCITS and AIFMD requirements are EU-level, I think the issues examined in this review will be relevant to management companies operating under the same European frameworks outside Ireland. More broadly, the underlying evidential question, whether an authorised entity can show that it retained the capability, knowledge and authority to oversee what it delegated, is one that other regulated firms using significant group outsourcing arrangements may also recognise. Those are my own observations. The Central Bank's report concerns Irish-authorised FMCs and does not make findings about firms in other jurisdictions or sectors.

9. What comes next

The Central Bank has stated that it will engage in a review of governance arrangements for FMCs this year, including enhancements to the current framework as regards delegation. Areas in scope include simplifying the guidance, simplifying and reinforcing the pre-approval controlled function framework for FMCs, enhancing governance requirements, and considering how the Individual Accountability Framework and Senior Executive Accountability Regime might be proportionately applied to the funds sector.

The feedback report says the governance review will take place during 2026 but gives no more precise timing, and it does not state when any resulting consultation would take place.

Practitioner commentary: in my view, that last point is particularly relevant where formal responsibility sits with named individuals in one entity while substantial decision-making influence sits elsewhere in a group.

Separately, Directive (EU) 2024/927 sets a later application date for certain supervisory-reporting provisions. Article 3 requires Member States to apply the measures transposing Article 1(12),and those transposing Article 2(7) insofar as it concerns Article 20a of Directive 2009/65/EC, from 16 April 2027. The other transposing measures were to apply from 16 April 2026. That timetable comes from the Directive rather than from the Central Bank's feedback report.

10. What the report actually requires

The action required section is short. All FMCs should consider the contents of the report with input from the FMC Board and conduct an analysis of the supervisory expectations and observations set out in it. FMCs are expected to put in place a time-bound plan by year end to address any gaps identified in their day-to-day operational, resourcing and governance arrangements in respect of delegation, ensuring these are in line with all relevant rules and guidance.

This report does not impose that deadline on firms outside Ireland. It does, however, provide a detailed account of what one European supervisor looked for, what it regarded positively and what it considered insufficient. In my view, management companies operating elsewhere can use those observations as a useful reference point when assessing their own delegation arrangements.

Know what supervisors are looking for. Supervisory reviews like this one set out, in the regulator's own words, the standard that oversight frameworks are measured against. Our seminars work through what meeting that standard looks like in practice for regulated firms.

Explore seminars at cpds.academy

This article is based on the Central Bank of Ireland Feedback Report, Review of Delegation in the Irish Funds Sector (July 2026),except where content is expressly identified as practitioner commentary or is attributed to a separate named source. It is provided for general information and does not constitute legal or compliance advice.

Sources:
Central Bank of Ireland, Review of Delegation in the Irish Funds Sector, Feedback Report, July 2026
Directive (EU) 2024/927, EUR-Lex

Nikolas Demetriades

Article by Nikolas Demetriades

Published 18 Aug 2026