The European Securities and Markets Authority (ESMA) has set a May 2026 deadline for supervisory convergence on compliance and internal audit functions in the funds sector. For CTOs at asset managers and fund administrators, this initiative is not just another regulatory update—it is the first clear signal of how DORA’s ICT audit requirements will be enforced across borders. With harmonized expectations on the horizon, the time to align your audit program is now.
The European Securities and Markets Authority (ESMA) has set a May 2026 deadline for supervisory convergence on compliance and internal audit functions in the funds sector. For CTOs at asset managers and fund administrators, this initiative is not just another regulatory update—it is the first clear signal of how DORA’s ICT audit requirements will be enforced across borders. With harmonized expectations on the horizon, the time to align your audit program is now.
Why ESMA's Funds Sector Audit Convergence Matters Now
DORA (Regulation 2022/2554) entered into force on 17 January 2025, but its audit provisions—particularly Articles 24 to 27 on internal audit and ICT audit—remain open to interpretation. ESMA’s convergence initiative fills this gap by translating DORA’s principles into sector-specific expectations for UCITS management companies, AIFMs, and fund administrators. The goal is twofold: reduce inconsistent enforcement across member states and ensure that ICT audit findings directly inform supervisory risk assessments.
For CTOs, this means three immediate shifts:
- 1Audit findings will feed into ESMA’s supervisory risk dashboard, increasing transparency for national competent authorities (NCAs).
- 2ICT audit scope will expand beyond traditional IT controls to include third-party risk, data integrity, and operational resilience.
- 3Convergence will standardize reporting formats, reducing the burden of multiple audits but raising the bar for evidence quality.
The funds sector is the first to face this level of scrutiny under DORA, making it a bellwether for other financial subsectors. If your audit program is not yet aligned with ESMA’s expectations, you risk being flagged in the first wave of supervisory reviews.
The Supervisory Gaps ESMA Identified (and What They Mean for Your ICT Controls)
ESMA’s 2024 peer review of fund managers’ compliance and internal audit functions revealed three critical gaps that will shape its convergence priorities:
1. Inconsistent ICT Audit Coverage
Many fund managers treat ICT audit as a subset of general IT controls, focusing on cybersecurity but neglecting DORA’s broader requirements. ESMA expects ICT audits to assess:
- ICT risk management frameworks (DORA Article 6), including how ICT risks are identified, measured, and reported to senior management.
- Third-party ICT service providers (DORA Article 28), with a focus on contractual clauses, exit strategies, and concentration risk.
- Operational resilience testing (DORA Article 26), including scenario-based testing of ICT systems supporting critical functions.
*Action for CTOs*: Audit plans must explicitly map to these areas, with clear evidence of testing methodologies (e.g., penetration testing, tabletop exercises).
2. Weak Linkages Between Compliance and Internal Audit
ESMA found that compliance functions often lack visibility into ICT audit findings, while internal audit teams rarely assess whether compliance controls are effectively implemented. DORA blurs these lines by requiring:
- Compliance functions to monitor ICT risk (DORA Article 5(4)), including the adequacy of ICT controls.
- Internal audit to evaluate compliance with ICT policies (DORA Article 24), not just their existence.
*Action for CTOs*: Establish a formal process for sharing ICT audit findings with compliance teams, and ensure internal audit includes compliance controls in its scope.
3. Inadequate Reporting to Senior Management
DORA Article 25 requires internal audit to report directly to the management body, but ESMA’s review found that many fund managers still route findings through middle management. This delays escalation of critical ICT risks.
*Action for CTOs*: Audit reports must include a dedicated section for ICT risks, with clear escalation paths to the board or audit committee.
Compliance Audit vs. Internal Audit: DORA's Blurred Lines in Fund Management
DORA’s audit provisions create a dual-track system where compliance and internal audit functions overlap but serve distinct purposes. Understanding this distinction is critical for CTOs preparing for ESMA’s convergence initiative.
Compliance Audit Under DORA
The compliance function (DORA Article 5) is responsible for:
- Monitoring adherence to ICT policies and procedures, including those governing third-party providers.
- Identifying gaps in ICT risk management and recommending corrective actions.
- Reporting to senior management on the effectiveness of ICT controls.
*Key challenge*: Compliance teams often lack technical expertise to assess ICT controls, relying instead on self-assessments from IT teams. ESMA expects compliance to validate these assessments through independent testing or third-party reviews.
Internal Audit Under DORA
The internal audit function (DORA Article 24) must:
- Provide independent assurance on the effectiveness of ICT risk management, including compliance with DORA’s requirements.
- Assess the adequacy of ICT controls through testing, not just documentation reviews.
- Report directly to the management body (e.g., board or audit committee) on ICT risks and control deficiencies.
*Key challenge*: Internal audit teams may not have the resources or expertise to conduct deep technical assessments (e.g., penetration testing, code reviews). ESMA’s convergence initiative will likely require collaboration with external specialists or upskilling internal teams.
Where the Lines Blur
DORA requires both functions to:
- Share findings to avoid duplication and ensure consistency.
- Align on risk assessments, particularly for third-party ICT providers.
- Coordinate with the ICT risk management function (DORA Article 6) to ensure audit findings inform risk mitigation strategies.
*Action for CTOs*: Develop a RACI matrix to clarify roles and responsibilities between compliance, internal audit, and IT teams. Ensure that ICT audit findings are documented in a shared repository accessible to all three functions.
ICT Audit Scope Under DORA: What Funds Sector CTOs Must Prepare For
ESMA’s convergence initiative will standardize the scope of ICT audits in the funds sector. Based on DORA’s requirements and ESMA’s peer review findings, CTOs should prepare for audits that assess the following areas:
1. ICT Risk Management Framework
- Governance: How ICT risks are identified, assessed, and reported to senior management (DORA Article 6).
- Policies and Procedures: Existence and effectiveness of ICT risk management policies, including those for third-party providers.
- Risk Appetite: Whether the fund manager has defined its risk appetite for ICT risks and how it is monitored.
*Evidence required*: Risk registers, board minutes, and policy documents demonstrating oversight of ICT risks.
2. Third-Party ICT Service Providers
- Contractual Clauses: Whether contracts with ICT providers include DORA-mandated clauses (e.g., right to audit, exit strategies).
- Concentration Risk: Assessment of reliance on a single provider for critical ICT services.
- Ongoing Monitoring: Processes for monitoring third-party providers’ compliance with contractual obligations.
*Evidence required*: Contracts, due diligence reports, and monitoring logs.
3. Operational Resilience
- Critical Functions: Identification of ICT systems supporting critical functions (DORA Article 26).
- Testing: Evidence of scenario-based testing (e.g., cyberattack simulations, disaster recovery drills).
- Incident Response: Processes for detecting, responding to, and recovering from ICT incidents.
*Evidence required*: Testing reports, incident logs, and recovery time objectives (RTOs).
4. Data Integrity and Confidentiality
- Data Protection: Controls to ensure the confidentiality, integrity, and availability of data (aligned with GDPR and DORA Article 9).
- Access Management: Processes for managing user access to ICT systems, including privileged access.
- Encryption: Use of encryption for data at rest and in transit.
*Evidence required*: Data protection policies, access logs, and encryption key management procedures.
5. Audit Trail and Reporting
- Documentation: Retention of audit logs and evidence of testing (DORA Article 27).
- Reporting: Processes for escalating ICT audit findings to senior management and NCAs.
*Evidence required*: Audit reports, escalation logs, and evidence of remediation actions.
Practical Checklist: Aligning Your Audit Program to ESMA's Convergence Expectations
To prepare for ESMA’s May 2026 convergence deadline, CTOs should use the following checklist to align their audit programs with DORA’s requirements:
1. Governance and Oversight
- [ ] Establish a formal ICT audit charter approved by the board or audit committee.
- [ ] Define roles and responsibilities for compliance, internal audit, and IT teams in a RACI matrix.
- [ ] Ensure ICT audit findings are reported directly to the management body (DORA Article 25).
2. ICT Risk Management Framework
- [ ] Document ICT risk management policies and procedures, including those for third-party providers.
- [ ] Define and monitor the fund manager’s risk appetite for ICT risks.
- [ ] Align ICT risk assessments with the broader enterprise risk management framework.
3. Third-Party ICT Providers
- [ ] Review contracts with ICT providers to ensure they include DORA-mandated clauses (e.g., right to audit, exit strategies).
- [ ] Assess concentration risk and document mitigation strategies.
- [ ] Implement ongoing monitoring of third-party providers’ compliance with contractual obligations.
4. Operational Resilience
- [ ] Identify ICT systems supporting critical functions and document their dependencies.
- [ ] Conduct scenario-based testing (e.g., cyberattack simulations, disaster recovery drills) and document findings.
- [ ] Define and test recovery time objectives (RTOs) and recovery point objectives (RPOs).
5. Data Integrity and Confidentiality
- [ ] Implement controls to ensure the confidentiality, integrity, and availability of data.
- [ ] Document processes for managing user access to ICT systems, including privileged access.
- [ ] Use encryption for data at rest and in transit, and document key management procedures.