MFSA Thematic Review: What AIFM and UCITS Managers Should Be Doing Now

The Malta Financial Services Authority (“MFSA”) recently issued a Dear CEO Letter outlining the findings of its thematic review on the compliance and internal audit functions of management companies of alternative investment funds (“AIFs”) and Undertakings for Collective Investment in Transferable Securities (“UCITS”) funds. The exercise forms part of a broader Common Supervisory Action launched by the European Securities and Markets Authority (“ESMA”) in February 2025, aimed at strengthening internal governance and control frameworks across the European asset management sector.

Through this review, the MFSA assessed whether Maltese fund management companies maintain effective second- and third-line control functions, supported by robust governance, internal control arrangements, and risk management frameworks. The findings provide important insights for UCITS management companies, alternative investment fund managers (AIFMs), and self-managed funds, highlighting several areas where improvements are expected.

Regulatory Framework

The thematic review assessed compliance with the requirements established under the UCITS Directive 2009/65/EC and the Alternative Investment Fund Managers Directive 2011/61/EU (“AIFMD”), as transposed into Maltese law through the MFSA’s Standard Licence Conditions applicable to investment services licence holders and collective investment schemes. Management companies are expected to maintain independent compliance and internal audit functions capable of detecting regulatory risks, monitoring compliance and supporting investor protection.

Key Findings from the MFSA Review

The review was conducted through a self-assessment questionnaire circulated to a representative sample of management companies, followed by supervisory meetings and additional follow-up requests for clarification. Several recurring weaknesses were identified across the sector.

Compliance Function Governance and Documentation

The MFSA observed that breach escalation procedures were sometimes absent or poorly documented, with some companies relying on informal communication. Clear procedures are essential to ensure material compliance concerns are promptly reported to management and the board. Policies and procedures should be reviewed at least annually to reflect regulatory and organisational changes.

Conflicts of Interest Management

Some firms failed to maintain up-to-date conflicts of interest registers, with insufficient detail on the nature of conflicts, affected parties, and mitigating measures. Registers should be dynamic, updated promptly, and conflicts should be discussed regularly at board or committee meetings.

Compliance Training and Reporting

The review highlighted gaps in structured compliance training programmes, increasing the risk of regulatory breaches. Certain compliance reports were also incomplete, omitting breaches of investment restrictions or material valuation errors. Firms should ensure timely training and comprehensive compliance reporting to the board.

Risk-Based Compliance Monitoring

A key finding of the review related to deficiencies in compliance monitoring plans (“CMPs”). In several cases, compliance monitoring activities were not supported by a formal compliance risk assessment, resulting in monitoring programmes that were not clearly aligned with the firm’s risk profile.

The MFSA also identified situations where certain operational areas were not included in compliance monitoring activities, including:

  • cross-border passporting activities
  • website and marketing communications
  • delegated functions
  • cybersecurity risks
  • sustainability disclosures

Management companies are therefore expected to adopt a clearly articulated risk-based approach to compliance monitoring, ensuring that higher-risk activities receive appropriate oversight.

The Authority also emphasised the importance of proper documentation of compliance testing and remediation plans, including root-cause analysis, clear corrective actions, and defined timelines for resolving deficiencies.

Strengthening Board Oversight

Boards often did not document discussions on compliance matters or follow up on deficiencies promptly. The MFSA emphasised that boards retain ultimate responsibility for regulatory compliance, and best practice is to receive quarterly compliance reports, summarising monitoring activities, findings, and remedial actions.

Oversight of Delegated Compliance Functions

Where compliance functions are outsourced, management companies must ensure effective oversight of the delegate. The MFSA noted that certain firms lacked structured procedures to review the performance of outsourced compliance providers. In some cases, the resignation of a delegated compliance officer occurred without sufficient handover arrangements, potentially disrupting the continuity of the compliance function. Management companies should therefore establish clear contingency arrangements and transition procedures to ensure that compliance responsibilities continue to be fulfilled without interruption.

Internal Audit Function

Where internal audit functions existed, plans were often static and progress tracking limited. Firms with regulatory derogations lacked evidence of alternative assurance arrangements. Boards should ensure alternative or outsourced arrangements provide equivalent oversight, with documented thematic reviews of key operational areas.

MFSA Expectations

Following the thematic review, the MFSA expects all management companies to conduct a gap analysis against the findings and recommendations outlined in the Dear CEO Letter.

In particular, firms are encouraged to focus on:

  • strengthening compliance monitoring frameworks
  • improving documentation of monitoring activities and board oversight
  • ensuring effective oversight of delegated functions
  • enhancing internal governance and assurance mechanisms

Conclusion

The MFSA’s thematic review highlights the critical role of robust compliance and internal audit functions in safeguarding investors and supporting sustainable fund management. For UCITS and AIFMD managers, these findings reinforce the need for independent, well-resourced, and risk-focused monitoring frameworks that protect both investors and the long-term viability of the business.