Evidencing Oversight: Data Capability After the Central Bank of Ireland’s Delegation Review of FMCs

CBI Delegation review cover

Executive summary

The Central Bank of Ireland's (CBI) July 2026 delegation review found that Irish fund management companies (FMCs) are, in general, doing this well. Where it identified gaps, the most remediable of them sit in the data layer, and closing those gaps is deliverable inside the plan period firms are now working to.

Throughout this paper we use FMC, the CBI's term for a fund management company, for the entity commonly called a ManCo.

On 23 July 2026 the Central Bank of Ireland published its feedback report on the review of delegation in the Irish funds sector. It drew on a desk-based review of approximately 40 FMCs and onsite inspections at 21, representing 40% of AUM. Ireland currently hosts 121 authorised FMCs.

The headline finding was positive and should be read that way. The Central Bank found that FMCs operating a delegation model generally have good governance frameworks, controls, oversight processes and data capabilities in place, that they are compliant with regulatory requirements, and that they largely meet supervisory expectations. The report explicitly recognises the benefits delegation delivers for investors and for the functioning of European capital markets.

The review also identified areas that would benefit from enhanced focus. Aspects for improvement included board independence, over-reliance on group-level committees, resourcing concerns, lack of contingency planning and limitations with data access. Findings were categorised across five themes: Governance, Portfolio Management, Risk Management, Delegate Oversight and Data Capabilities. A small number of FMCs fell materially short of supervisory expectations and are now subject to time-bound Risk Mitigation Plans (RMPs).

All FMCs are expected to consider the report with input from the FMC board, analyse the supervisory expectations and observations it sets out, and put in place a time-bound plan by year end to address any gaps identified in their day-to-day operational, resourcing and governance arrangements in respect of delegation.

This paper addresses one theme in detail: data capabilities. That focus is a choice, and it is NeoXam's, not the Central Bank's. We make the case for it on three grounds.

  • The specific data deficiencies the report describes are concrete and remediable within a plan period.
  • The report identifies access to timely and accurate data as a material differentiator in how effective a risk management framework proves to be.
  • The good practice the Central Bank describes under Risk Management, independent verification of delegated activity through shadow or independent checks, real-time data access and pre-trade compliance controls, is a description of a data architecture.

A necessary caveat before anything else in this paper: no software purchase, from NeoXam or anyone else, discharges a regulatory obligation or satisfies a supervisory expectation. Oversight is performed by people exercising judgement under a governance framework. Technology determines what those people can see and what they can prove. That is the limit of the claim made here.

1. What did the Central Bank’s delegation review find on data?

Generalised commentary on the review has tended to compress the data theme into the phrase "limitations with data access". The underlying findings are more specific and more useful.

The Central Bank found growing data maturity, particularly in larger firms with dedicated data teams and formal policies.

Requiring enhancement, the Central Bank observed:

  • A fragmented approach to data integration in some FMCs, with disparate systems for risk, investment, operations and compliance, resulting in manual data reconciliation
  • Some FMCs engaging delegates for pre-trade and post-trade controls and elements of investment and borrowing restrictions monitoring, including instances of overriding internal risk limits
  • Instances where FMCs had not established processes and contingency arrangements to manage potential data loss or interruption

Related findings appear under other themes. Under Risk Management, some FMCs were unable to demonstrate robust independent challenge or access to real-time data, relying instead on delegate reporting. Under Portfolio Management, limited attention was observed in some cases to explicit wind-down or transition procedures where a third-party portfolio manager is unable to continue to fulfil a mandate. Under Delegate Oversight, the Central Bank noted insufficient involvement of Designated Persons and Operational Risk functions and cautioned that FMCs should not rely solely on due diligence questionnaires or self-reporting by the delegate.

Read together, these five findings describe one problem. Fragmented data reconciled by hand makes real-time independent challenge impractical; the absence of independent data encourages reliance on the delegate for restriction monitoring, because the delegate holds the data; and an FMC with no independent data position has nothing from which to execute a transition plan or to recover from a data loss.

2. What the solution has to do, and where NeoXam fits

Sections 1 and 5 describe the regulatory position. This section is where NeoXam products are named, so it should be read as our view of the solution rather than as neutral analysis.

2.1 What data does a FMC need to evidence oversight?

An FMC does not need to replicate the administrator's book or the portfolio manager's systems. It needs sufficient independent data to verify rather than accept.

Data need Finding it addresses What has to be in place
Positions and valuations at fund and instrument level Fragmentation, independent challenge Independent ingestion and validation against a second source
Investment, borrowing and internal limit status Delegates performing restriction monitoring Rules owned and tested by the FMC, continuously rather than periodically
Breach records, including passive breaches, near misses and overrides Overriding of internal risk limits Override capture with attribution, reason code and approval trail
Liquidity data at LMT granularity AIFMD II and UCITS VI liquidity management tools Position-level liquidity classification feeding tool calibration and activation
Valuation inputs for hard-to-value assets Valuation oversight, Level 3 governance Source hierarchy, method, override and approval, reconstructable by date
Delegate performance against service standards Reliance on delegate self-reporting Measurement drawn from source data, not from the delegate's own report
Counterparty and exposure aggregation Independent challenge, risk oversight Look-through and aggregation across the fund range
Sustainability data for SFDR and fund naming Disclosure accuracy Governed ESG data with source and vintage lineage

The common characteristic is that each must be independently held, timestamped and reconstructable. Where the FMC serves multiple unconnected clients, or sits behind group information barriers, that data must also be segregated at platform level, with access permissioned by client and fund and provable after the fact.

2.2 Ingestion and validation of delegate data

NeoXam DataHub is the enterprise data management layer: it centralises, validates, enriches and distributes data across functions. For an FMC the practical effect is a single view of every delegate submission and every position, whatever format it arrived in.

Delegate data is received as the delegate produces it, normalised into the FMC's own model, and validated against independent sources on receipt, with exceptions surfaced to the FMC rather than resolved silently upstream. Depositary records matter disproportionately here, because they do not originate from the administrator and are therefore the one comparison that can catch an administrator error rather than simply restate it.

This addresses the fragmentation finding directly. The alternative to disparate systems for risk, investment, operations and compliance is not one system doing everything. It is one governed data layer beneath whatever systems those functions use.

2.3 Restriction and limit monitoring: should FMCs own pre-trade compliance?

The finding on delegates performing restriction monitoring, including instances of overriding internal risk limits, is the sharpest in the data section, because it describes control of a core FMC responsibility sitting with the party being overseen.

The Central Bank's description of good practice is explicit: independent verification of delegated risk activities, including shadow or independent checks, real-time data access and pre-trade compliance controls. Pre-trade control by the FMC is therefore the standard to aim at, not something to be argued away.

What varies is whether the structure permits it. Where the FMC can apply its own rule set to order flow, whether by operating the compliance engine that orders pass through or by owning and independently monitoring the rules configured in the delegate's system, pre-trade control is achievable and is what the Central Bank has identified as good practice. Where an external delegate trades on its own systems with no such integration, pre-trade control by the FMC is not practically available, and the FMC should be able to explain why, and demonstrate independent post-trade verification instead.

Two things hold in either case. The rules belong to the FMC, not the delegate. And overrides must be captured, attributed and reportable to the FMC rather than exercised inside a delegate's system, which is precisely the practice the review criticised.

NeoXam PMS provides an integrated compliance engine covering pre-trade and post-trade checks against statutory, regulatory and ad hoc rules, investment limit monitoring, look-through for exposure and risk, and a full audit trail. It is available in three configurations, from a full front-to-middle office deployment down to a monitoring-only configuration, so an FMC overseeing delegated mandates deploys materially less than an asset manager running its own trading desk.

The depositary performs its own statutory checks, but those are owed to the fund and its investors on the depositary's scope and timing. They are not a service the FMC can direct, and relying on them to discharge a managerial function repeats the error the review identified.

2.4 Exception-based oversight

A designated person overseeing multiple delegates across a fund range cannot review everything. The alternative to reviewing everything is not reviewing a sample. It is reviewing every exception.

Layer Function
Automated validation Every delegate submission checked on receipt against rules and independent sources
Exception generation Deviations surfaced with context and severity
Designated person review Attention directed to exceptions rather than to routine confirmation
Documented challenge Each review recorded, attributed and timestamped
Board reporting Aggregate trends reported, individual matters escalated by rule

NeoXam Aro is the reconciliation platform, providing automated reconciliation and exception management across cash, position, transaction, management fee and money market reconciliation types, with configurable matching and a complete audit trail of every resolution.

A worked example makes the difference concrete. A delegate submits its end-of-day position file. On receipt, validation compares it against the depositary record and against the FMC's own limit set, and flags a holding that has moved 40 basis points above an internal concentration limit. The exception is classified, assigned to the designated person for Investment Management, and carries the comparison and the source records with it. The designated person reviews it the same day, challenges the delegate, and records the outcome with a reason code. That record is aggregated into the next board pack automatically, and is retrievable by date if the Central Bank asks eighteen months later. In the current model, the same breach typically surfaces in a delegate's monthly pack, if it surfaces at all.

This produces the artefact the Central Bank looks for in assessing designated person effectiveness: a documented record of challenge, with reasons, over time, drawn from source data rather than from delegate self-reporting.

2.5 Where governance and workflow tooling fits

Several firms will already operate, or be considering, a governance, risk and compliance (GRC) platform. These tools manage the oversight process itself: due diligence questionnaires, action tracking, attestation, policy management, committee papers and audit trails of what was reviewed and when. Following the delegation review they are a reasonable response to the findings on governance, documentation and delegate oversight process.

A governance platform answers whether the oversight was performed, documented and closed out. It does not answer whether the delegate's numbers were correct. It records that a designated person reviewed the monthly pack. It cannot tell them the pack contained a stale price, a breached limit or a position that does not agree with the depositary's record.

That matters because three of the Central Bank's data findings are about the underlying data rather than the process applied to it: fragmented systems reconciled by hand, restriction monitoring performed by delegates, and the absence of contingency for data loss. A firm that improves only its workflow layer will have a better evidenced version of the same exposure.

The two are complementary rather than competing. Governance tooling evidences the process. A data layer evidences the facts the process depends on. Firms sequencing remediation should be clear about which finding each investment actually closes.

2.6 Audit, lineage and retrievability

CP86 includes a retrievability of records rule. The practical test is whether the FMC can reconstruct what it knew, when it knew it and what it did about it, on a specific date, months or years later. Lineage delivers this as a query rather than as an archaeology project, and it underpins the contingency capability discussed below.

2.7 Board and regulatory reporting

NeoXam Impress is the reporting and distribution layer, covering client, digital and regulatory reporting with workflow-based production, validation steps, full change tracking and multi-jurisdictional scheduling. For an FMC the relevant outputs are designated person reporting to the board, organisational effectiveness director reporting, depositary interaction, regulatory returns and investor disclosure, generated from the same validated source rather than assembled separately.

Impress is supported by a structured regulatory function at NeoXam: a dedicated team tracking regulatory change, consultations and publications, regulatory analysts assessing the impact on ratios and computations, and R&D and product teams translating that into features and reports. Off-the-shelf coverage includes the PRIIPs Key Information Document with its calculation rules, the UCITS Key Investor Information Document, AIFMD Annex IV reporting, the FinDatex European MiFID Template and European PRIIPs Template, annual and semi-annual report production, and a range of national statistical returns.

For an FMC the significance is not the template list. It is that regulatory interpretation is maintained by a specialist function rather than falling to the FMC's own compliance team to specify and to a systems integrator to build.

3. FMC operating model: from review to verification

3.1 The shift: three ManCo structures

The right shape depends on what the FMC does itself. Three structures dominate the Irish market.

Administration delegated. The FMC appoints an administrator and one or more portfolio managers, and holds no processing systems of its own. The exposure is dependence: every number the FMC reports originates with a party it is supposed to be overseeing. The priority is independent ingestion and validation of delegate data.

Third-party and super ManCo. The FMC serves multiple unconnected clients, each with its own delegates and formats. The exposure is heterogeneity and segregation, and oversight quality is something the FMC sells as well as something it is inspected on.

Administration retained in-house. The FMC performs more itself, often across several internal systems. The exposure is not delegate dependence but fragmentation between risk, investment, operations and compliance, which is the first of the Central Bank's data findings.

Current pattern Target pattern
Delegate reports, FMC reviews Delegate reports, FMC validates independently
Monthly or quarterly cycle Continuous monitoring, exception-driven escalation
Oversight evidenced by meeting minutes Oversight evidenced by system record
Designated persons assemble information Designated persons interrogate information
Restriction monitoring sits with the delegate Restriction monitoring rules owned by the FMC
Group functions provide the data view FMC holds its own data view
Contingency planning documented in principle Contingency capability demonstrable in practice

3.2 Resourcing, and what not to claim

Resourcing concerns were named in the review, including cases where designated persons were not sufficiently senior or were performing too many roles, and cases where risk management resourcing needed strengthening.

The implication runs one way. For an FMC, the argument for this investment is not headcount reduction, and presenting it as such would be both commercially wrong and regulatorily counterproductive. A firm that reduces oversight resourcing after a review which flagged resourcing as an area for enhancement has misread the report.

The argument is capability per person. A designated person spending most of their time assembling and formatting information is under-deployed relative to their regulatory purpose. Supported by automated validation and exception routing, the same individual can oversee a larger fund range with better evidenced challenge. That is the case to put to a board.

3.3 Contingency, data loss and wind-down

Three separate findings converge here: lack of contingency planning as a general theme, the absence in some FMCs of processes and contingency arrangements to manage potential data loss or interruption, and limited attention to explicit wind-down or transition procedures where a third-party portfolio manager cannot continue a mandate.

The data loss finding is the most directly addressable. An FMC whose oversight data is held in spreadsheets on individual workstations, or is retrievable only by request from a delegate, has a data continuity exposure that is straightforward to describe in a plan and straightforward to close.

Transition readiness is the harder one, and it is where independent data becomes structural rather than convenient. Replacing a portfolio manager at short notice requires the FMC to know current positions, valuations, counterparty exposures, outstanding instructions and cash position independently of the delegate being replaced. An FMC dependent on that delegate for its data view cannot execute the plan it has documented.

4. The cost case for an FMC

4.1 The FMC cost structure

FMC economics differ from those of managers and administrators. The cost base is smaller, dominated by people, and constrained at the bottom by regulatory substance expectations. The cost case therefore rests on capacity and avoided cost.

Cost driver Manual dependent Data enabled
Fund range growth Proportional resourcing increase Absorbed without proportional resourcing increase
New delegate onboarding Bespoke reporting arrangement per delegate Standard ingestion, configured
Regulatory response Project per request, group dependency Query against own data
Systems Multiple tools plus spreadsheets Consolidated platform

4.2 The avoided cost that matters most

For an FMC the dominant financial risk is not operational loss but supervisory remediation. The review confirmed that a small number of FMCs are now subject to time-bound RMPs, and that the Central Bank has commenced supervisory engagement where shortcomings were identified.

A supervised remediation programme carries external advisory cost, sustained senior management and board time, potential constraints on business development while open, and reputational consequence with clients and group. For a third-party FMC, an open remediation programme is a direct commercial impediment.

The contrast is one of control rather than scale. The cost of building data capability is known in advance, scoped by the firm and scheduled at its own pace. A remediation programme is none of those things: its scope is set by the supervisor, its timetable is fixed, and it runs until the supervisor is satisfied.

5. The regulatory case

5.1 Central Bank of Ireland

Requirement What it obliges Where data capability helps
Review of delegation in the Irish funds sector, 23 July 2026 Board-level analysis of the supervisory expectations and observations, and a time-bound plan by year end to address gaps identified Addresses the Data Capabilities findings on fragmentation, delegate-run restriction monitoring and data loss contingency
Fund Management Companies Guidance (CP86) Six managerial functions, designated person challenge, organisational effectiveness role, record retrievability, effective supervision Independent validation, documented challenge, point-in-time reconstruction
Cross Industry Guidance on Outsourcing (CP138) Register, due diligence, SLAs, ongoing monitoring and challenge, exit strategy, sub-outsourcing transparency Monitoring evidence drawn from data rather than from delegate assertion
Central Bank UCITS Regulations, S.I. No. 316 of 2026, published 10 July 2026 UCITS operating conditions, investment and borrowing restrictions, reporting Continuous restriction monitoring held by the FMC, with audit trail
AIF Rulebook, revised 5 May 2026 AIF operating conditions following AIFMD II Consistent oversight model across AIF and UCITS ranges
Conduct Standards under the Individual Accountability Framework Common and additional conduct standards apply to all regulated financial service providers and the individuals within them Attributable, timestamped decision records supporting reasonable steps
Depositary risk assessment expectations, letter of 11 May 2026 Depositaries assess FMC organisation and fund strategy risk at onboarding and on an ongoing basis An FMC with demonstrable data capability presents better under depositary assessment

On individual accountability, precision matters. SEAR does not currently apply to Irish fund management companies or fund boards. Its first wave covers credit institutions, insurance undertakings and certain investment firms. In the July 2026 report the Central Bank confirmed that its forthcoming review of FMC governance arrangements will consider how the IAF and SEAR framework might be applied proportionately to the funds sector, alongside simplifying the FMC Guidance and simplifying and reinforcing the PCF framework. Firms should plan on the basis that accountability expectations will tighten. They should not be told that SEAR already applies to them.

5.2 European Union

Regulation Obligation FMC dependency
AIFMD II and UCITS VI, transposed by S.I. 181 and 182 of 2026, in operation 1 May 2026 Selection and operation of liquidity management tools for open-ended funds, delegation substance, loan origination rules, regulatory reporting LMT calibration and activation require independent, timely liquidity and investor data
DORA (Regulation (EU) 2022/2554) ICT risk framework, incident reporting, resilience testing, third-party risk, Register of Information under Article 28(3) reported at least annually Accurate ICT inventory, including arrangements reached through delegates and group
SFDR, and the ESMA Guidelines on funds' names using ESG or sustainability-related terms Sustainability disclosure, and naming thresholds that must be evidenced on an ongoing basis Governed ESG data with source and vintage lineage

5.3 The outsourcing question, stated plainly

There is an evident tension in suggesting that an entity whose regulatory challenge is the management of delegation should address it by entering another third-party arrangement. It deserves a direct answer.

The Central Bank's position is that delegation and outsourcing are the same thing, subject to the same rules. Any arrangement under which a third-party provides or operates part of the FMC's oversight infrastructure therefore falls under the Cross Industry Guidance on Outsourcing: register entry, documented due diligence, a written agreement with service levels, ongoing monitoring, a documented exit strategy and sub-outsourcing transparency. Where the arrangement involves ICT services it also requires entry in the DORA Register of Information.

The distinction that matters to a supervisor is between outsourcing a function and outsourcing the infrastructure through which the FMC exercises its own control. Delegating restriction monitoring to a portfolio manager moves a control to the party being controlled. Using a third-party platform to run the FMC's own monitoring does not: the rules, the limits, the exceptions and the decisions remain with the FMC.

The test an FMC should be able to satisfy is substitutability. Could it continue to operate, or transition, if the arrangement ended? That analysis belongs in the file before signature, not after.

6. The NeoXam suite

  • NeoXam DataHub: enterprise data management that centralises, validates, enriches and distributes data across functions. Ingests delegate data in any format, validates real-time, holds FMC’s governed record with full lineage.
  • NeoXam PMS: integrated compliance engine for pre-trade and post-trade checks, investment limit monitoring and look-through, with a full audit trail.
  • NeoXam Aro: automated reconciliation and exception management across cash, position, transaction, management fee and money market reconciliations with audit trails.
  • NeoXam Impress: Board, DP, regulatory and investor reporting generated from validated records, with a dedicated regulatory watch function.

The products share a common data integration layer, a single workflow engine, shared authentication and cloud-agnostic deployment, which is what makes phased adoption viable rather than a sequence of integration projects.

7. Where should an FMC start before year-end?

For an FMC writing a time-bound plan before year end, the sequence matters as much as the destination. A plan naming a multi-year platform programme is weaker than one naming a deliverable first phase with a date against it.

  1. Independent validation of delegate data for the highest risk funds. Deliverable and demonstrable inside a plan period. Addresses the fragmentation and manual reconciliation finding.
  2. Bring restriction and limit monitoring back inside the FMC. Addresses the finding on delegates performing restriction monitoring and overriding internal limits, which is the finding most directly about control sitting in the wrong place.
  3. Establish data continuity arrangements. Addresses the data loss and interruption finding, and is among the cheapest gaps on the list to close.

These steps map to findings the Central Bank stated explicitly under Data Capabilities. That correspondence is what makes them defensible line items in a plan, and it is the reason to sequence them first.

About NeoXam

NeoXam provides investment data management, portfolio management, accounting, reconciliation and reporting software to management companies, asset managers, asset servicers, asset owners, banks, wealth managers and market institutions.

To discuss how this paper applies to your delegation model and your time-bound plan, contact the NeoXam Ireland team.

FAQ

The Central Bank of Ireland published its feedback report on the review of delegation in the Irish funds sector on 23 July 2026. It drew on a desk-based review of around 40 fund management companies and onsite inspections at 21, representing 40% of AUM, and grouped its findings under five themes: Governance, Portfolio Management, Risk Management, Delegate Oversight and Data Capabilities.

Every FMC is expected to consider the report with input from its board, analyse the supervisory expectations and observations it sets out, and put in place a time-bound plan by year end to address any gaps in its operational, resourcing and governance arrangements for delegation.

Three things needed enhancement: fragmented data integration leading to manual reconciliation, delegates performing pre-trade and post-trade controls and restriction monitoring (including overriding internal risk limits), and missing contingency arrangements for data loss or interruption.

A UCITS management company (ManCo) is authorised to manage UCITS funds, while an alternative investment fund manager (AIFM) manages alternative investment funds. Many Irish firms hold both authorisations and are often called super ManCos. The Central Bank uses the term fund management company (FMC) for both.

Not currently. The first wave of SEAR covers credit institutions, insurance undertakings and certain investment firms. The Central Bank has said its forthcoming review of FMC governance will consider how the IAF and SEAR could apply proportionately to the funds sector.

CP86, the Central Bank’s Fund Management Companies Guidance, sets out six managerial functions overseen by designated persons, who are expected to challenge delegates rather than simply receive their reports. It also covers the organisational effectiveness role and a rule on the retrievability of records.

Appendix: sources

Regulatory positions reflect the position as at September 2026 and should be verified against current sources before reliance. This paper is commentary and does not constitute legal or regulatory advice.

Related insights

Download NeoXam brochure

Neoxam needs the contact information you provide to us to respond to your inquiry. You can withdraw your consent at any time. To learn more about the protection of your personal data, we invite you to read our Privacy Policy.