Knowledge Base
Identify and mitigate risks arising from non-compliance with laws and regulations
Which body issued the ESMA35-36-1952 guidelines incorporated into French law by AMF position DOC-2021-04?
The ESMA35-36-1952 guidelines were issued by ESMA (European Securities and Markets Authority) in April 2021. They were incorporated into French law by AMF position DOC-2021-04, which supplements the regulatory framework applicable to portfolio management companies.
Which article of Delegated Regulation 2017/565 governs the compliance function?
Article 22 of Delegated Regulation 2017/565 is specifically mentioned as governing the compliance function. This provision is supplemented by ESMA guidelines ESMA35-36-1952 of April 2021, incorporated into French law by AMF position DOC-2021-04. AMF position DOC-2014-06 details the methodologies expected of portfolio management companies.
What are the two main sources that supplement Article 22 of Delegated Regulation 2017/565 for the compliance function?
Article 22 is supplemented by two main sources: (1) ESMA guidelines ESMA35-36-1952 of April 2021, incorporated into French law by AMF position DOC-2021-04; (2) AMF position DOC-2014-06 on risk management, compliance and control systems.
What are the possible consequences of non-compliance risk for a portfolio management company?
The consequences include the engagement of civil or criminal liability, administrative sanctions imposed by the AMF, and reputational damage. AMF sanctions can reach 100 million euros or 10% of annual turnover, with publication of decisions and potential bans from practice.
The risk mapping must cover only financial and operational risks.
The comprehensive mapping covers the four major risk families defined by position DOC-2014-06: financial risks, operational risks, non-compliance risks proper, and reputation and governance risks. This exhaustive coverage is essential for identifying all risks to which the institution is exposed.
Internal audit must assess the effectiveness of the risk management framework over a cycle covering at least five years.
Internal audit must assess the overall effectiveness of the framework over a cycle covering all activities over a minimum of three years. This frequency allows for regular assessment without neglecting any aspect of activities over a reasonable period.
Categorize items by dragging them to the appropriate zones
Items to categorize:
Prevention
Detection
Correction
Corrective measures include the establishment of written policies and procedures, the definition of alert mechanisms with trigger thresholds, the creation of escalation procedures for breaches, the development of remediation plans, the monitoring of the implementation of recommendations and regular reporting to management. These measures aim to prevent and correct identified deviations.
Definition of non-compliance risk
Click to see answer
Non-compliance risk is defined as the risk that the institution fails to meet its professional obligations within the meaning of Article L.621-15 of the Code monétaire et financier. This includes breaches of applicable laws, regulations and professional standards.