ESMA’s May 2026 supervisory convergence guidance on compliance and internal audit in funds is not just another regulatory update—it is a warning shot. For fund managers already grappling with DORA’s ICT risk requirements, the guidance reveals systemic audit deficiencies that, if left unaddressed, will expose firms to heightened supervisory scrutiny and potential enforcement. Compliance officers and CTOs must act now to close these gaps before 2026 enforcement intensifies.
ESMA’s May 2026 supervisory convergence guidance on compliance and internal audit in funds is not just another regulatory update—it is a warning shot. For fund managers already grappling with DORA’s ICT risk requirements, the guidance reveals systemic audit deficiencies that, if left unaddressed, will expose firms to heightened supervisory scrutiny and potential enforcement. Compliance officers and CTOs must act now to close these gaps before 2026 enforcement intensifies.
---
Why ESMA's Audit Convergence Guidance Changes the DORA Compliance Game
ESMA’s guidance, published in May 2024 (ESMA34-45-1875), is the first cross-sector supervisory convergence measure explicitly linking fund managers’ internal audit functions to DORA’s ICT risk management framework. While DORA itself does not prescribe audit methodologies, ESMA’s guidance fills this gap by mandating that internal audit functions assess compliance with DORA’s Chapter II (ICT risk management) and Chapter IV (ICT-related incident reporting) as part of their annual audit plans.
Key implications:
- Audit scope expansion: Internal audit must now evaluate ICT risk controls, not just financial or operational controls. This aligns with DORA Article 26(1), which requires financial entities to ensure their internal audit functions are "independent and objective."
- Convergence with other frameworks: ESMA’s guidance explicitly references the EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) and ISO 27001, creating a de facto audit standard for DORA compliance.
- Supervisory expectations: National competent authorities (NCAs) will use this guidance to benchmark fund managers’ audit practices during inspections. Firms that treat DORA as a "check-the-box" exercise will face enforcement actions.
For fund compliance teams, this means internal audit can no longer operate in a silo. It must become a proactive partner in DORA implementation, with a mandate to challenge ICT risk assessments and incident response protocols.
---
The Three Compliance Gaps ESMA Identified Across EU Fund Managers
ESMA’s guidance highlights three recurring deficiencies in fund managers’ DORA implementations, based on supervisory reviews conducted in 2023-2024:
1. **Misalignment Between ICT Risk Assessments and Audit Plans**
Many firms treat DORA’s ICT risk assessment (required under Article 6) as a standalone exercise, separate from internal audit’s annual planning. ESMA found that:
- Only 30% of audits reviewed included ICT risk controls in their scope, despite DORA’s explicit requirements.
- Audit reports rarely referenced DORA’s Article 28 (ICT-related incident management) or Article 30 (testing of ICT systems), leaving critical gaps in oversight.
Regulatory risk: NCAs may interpret this as a failure to meet DORA’s Article 26(2), which requires internal audit to "assess the adequacy and effectiveness of the financial entity’s internal control mechanisms."
2. **Lack of Audit Independence in ICT Governance**
ESMA observed that internal audit functions often report to the same C-level executives responsible for ICT risk management (e.g., CTOs or CISOs). This creates a conflict of interest, as auditors may hesitate to challenge ICT risk decisions made by their reporting lines.
Regulatory risk: DORA Article 26(1) mandates that internal audit functions must be "independent of the operational functions they audit." Firms that fail to restructure reporting lines may face enforcement under Article 50 (administrative penalties).
3. **Inadequate Documentation of ICT Risk Controls**
Many fund managers rely on generic IT policies (e.g., password management, access controls) without mapping them to DORA’s specific requirements. ESMA found that:
- Less than 20% of firms maintained a DORA-specific audit register linking controls to Articles 6-30.
- Incident response plans often lacked root-cause analysis (required under Article 18(2)), making it impossible for auditors to verify compliance.
Regulatory risk: Without a traceable audit trail, firms cannot demonstrate compliance during NCA inspections, increasing the likelihood of fines under Article 50.
---
How Internal Audit Functions Must Evolve Under DORA (Beyond the Checklist)
DORA’s audit requirements go beyond traditional financial audits. Internal audit must now:
- 1Adopt a risk-based audit methodology aligned with DORA’s Article 6 (ICT risk management framework).
- 2Integrate ICT risk controls into annual audit plans, with a focus on Article 28 (incident management) and Article 30 (testing).
- 3Ensure independence by reporting directly to the board or audit committee, not the CTO or CISO.
Key Changes to Audit Methodologies
| Traditional Audit Approach | DORA-Aligned Audit Approach |
|---|---|
| Focus on financial controls | Focus on ICT risk controls (e.g., access management, encryption, incident response) |
| Annual or biennial audits | Continuous or risk-triggered audits (e.g., after major ICT incidents) |
| Generic IT policies | DORA-specific controls mapped to Articles 6-30 |
| Reporting to CFO/CTO | Reporting to board/audit committee (independence) |
Practical Steps for Audit Teams
- 1Update the audit charter to explicitly include DORA’s ICT risk requirements.
- 2Train auditors on DORA—many lack expertise in cybersecurity or ICT risk management.
- 3Leverage existing frameworks: Use ISO 27001 or NIST CSF to structure ICT risk controls, then map them to DORA.
- 4Conduct "shadow audits"—test ICT risk controls before the official audit to identify gaps.
---
ICT Risk Assessment and Audit: Bridging DORA Chapter II and Audit Independence
DORA’s Chapter II (ICT risk management) is the foundation of audit compliance. Internal audit must verify that:
- ICT risk assessments (Article 6) are conducted at least annually and cover all critical functions.
- ICT risk controls (Article 7) are implemented and tested (e.g., penetration testing, vulnerability scans).
- Incident response plans (Article 18) are documented, tested, and updated after incidents.
The Audit Independence Challenge
ESMA’s guidance emphasizes that internal audit must challenge ICT risk decisions, not just validate them. This requires:
- Separate reporting lines: Internal audit should report to the board or audit committee, not the CTO or CISO.
- Unrestricted access: Auditors must have the authority to review all ICT systems, including third-party service providers (Article 28(5)).
- Whistleblower protections: Auditors must be able to escalate findings without fear of retaliation.
Case Study: A Mid-Sized EU Fund Manager’s Remediation
An EU mid-cap fund manager discovered during a pre-DORA audit that its incident response plan had not been updated since 2021. The internal audit team:
- 1Mapped the plan to DORA Article 18 and identified gaps in root-cause analysis.
- 2Conducted a tabletop exercise to test the plan’s effectiveness.
- 3Updated the plan to include automated incident logging (required under Article 18(2)).
- 4Reported findings to the board, ensuring independence from the CTO.
---
Practical Roadmap: Remediating Audit Deficiencies Before 2026 Enforcement
Fund managers must act now to close audit gaps before NCAs intensify enforcement in 2026. Here’s a 12-month roadmap:
**Phase 1: Assessment (Months 1-3)**
- Gap analysis: Compare current audit practices against ESMA’s guidance and DORA Articles 6-30.
- Stakeholder alignment: Ensure the board, CTO, and CISO understand internal audit’s expanded role.
- Resource planning: Train auditors on DORA or hire external experts.
**Phase 2: Remediation (Months 4-9)**
- Update the audit charter to include DORA’s ICT risk requirements.
- Restructure reporting lines to ensure audit independence.
- Develop a DORA audit register mapping controls to specific Articles.
- Conduct a "shadow audit" to test ICT risk controls before the official audit.
**Phase 3: Validation (Months 10-12)**
- Engage an external auditor to review DORA compliance.
- Document all findings and remediation actions in an audit-ready register.
- Present results to the board with a clear action plan for 2026.
---
Red Flags: Common Audit Failures in DORA Compliance Reviews
ESMA’s guidance highlights several red flags that trigger NCA enforcement actions:
- 1Generic IT policies: Using off-the-shelf IT policies that don’t reference DORA Articles.
- 2Lack of incident root-cause analysis: Failing to document lessons learned from ICT incidents (Article 18(2)).
- 3No testing of ICT systems: Skipping penetration tests or vulnerability scans (Article 30).
- 4Third-party risk oversight gaps: Not auditing critical ICT service providers (Article 28(5)).
- 5Audit scope limitations: Excluding ICT risk controls from annual audit plans.
Enforcement risk: Firms exhibiting these red flags may face Article 50 penalties (up to €10 million or 2% of global turnover, whichever is higher).
---
Building an Audit-Ready DORA Register and Documentation Framework
DORA compliance requires traceable documentation to demonstrate adherence