The rules are still being negotiated, but AFM already expects records, ownership and outsourcing to connect.
A founder at a small regulated firm opens a request from the compliance adviser. The adviser needs the latest supplier register, evidence of management review and the reasoning behind a lighter internal-audit arrangement. The founder knows why each decision was made. The answers, however, sit across emails, meeting notes and one employee’s memory.
Nothing has gone visibly wrong. Yet ordinary work slows because the company cannot quickly reconstruct its own decisions.
That is where the European supervision debate reaches the Dutch business desk. On 22 July, the Dutch Authority for the Financial Markets, AFM, and its French counterpart, AMF, set out five conditions for effective centralised supervision at EU level. They call for risk-based and adaptive supervision, proportionate and transparent costs, accountable governance, centralised data and effective enforcement.
The two authorities support a stronger central role for the European Securities and Markets Authority, ESMA. Negotiations continue. The direction still carries a clear message for regulated firms: information must remain usable beyond the desk where someone first created it.
What supervisors can use
Central supervision depends on information that can be compared across firms and countries. A policy stored in a folder has limited value when nobody can connect it to the real process. A register weakens when its underlying data is old. A management decision becomes difficult to explain when its owner, date and reasoning have disappeared.
The following day, AFM reported findings from its review of Dutch investment-fund managers. Documentation was sometimes outdated, incomplete or too general. Planning, monitoring and reporting did not always connect well enough for management to identify weaknesses and follow them up in time.
AFM also found that proportionality choices often lacked adequate support. A smaller or less complex firm may reasonably choose a lighter arrangement. Management still needs to explain why that arrangement fits the organisation’s size, activities and risks.
This points away from compliance by professional memory. Memory can carry a small company a long way while the team remains stable. It becomes fragile when a colleague leaves, a supplier changes, an incident occurs or a supervisor asks for the story in a structured form.
The useful question is no longer simply, “Do we have a policy?” It is, “Can we show where this policy operates, who owns it and what happened when the process failed?”
Outsourcing does not move responsibility
Small regulated firms often buy expertise because maintaining every specialist function internally would waste money. That can be a sound decision. AFM draws a firm boundary around it: when compliance or internal-audit work is outsourced, responsibility remains with the investment-fund manager.
The same ownership issue appears under the Digital Operational Resilience Act, DORA. On 6 August, AFM reported that 94 percent of submitted information registers had been approved by the European Banking Authority, compared with 40 percent in 2025. AFM also stressed the quality of the registers and the data beneath them.
Some regulated firms lacked required policies or procedures. Others used documents that did not fully match the applicable rules. A licence holder remains responsible when it uses group-level policies. Local management needs to know what applies to its own entity and how that policy works in daily practice.
This returns us to the founder at the desk. An external adviser may maintain the compliance calendar. An ICT provider may hold supplier data. A group office may write the policy. None replaces the person inside the Dutch entity who can explain what applies, what changed and what management did next.
Data held elsewhere needs a way home
Centralisation creates a second practical concern. Dutch supervisory authorities have warned about dependence on a small number of ICT providers. Changing provider can be costly and complex. Open standards, interoperability and workable switching options therefore belong in the management discussion, not only in the technology plan.
A central information system helps only when the firm has reliable access, clear permissions and a workable route for retrieving or moving its data. This is part of whether management can still act when a supplier relationship changes under pressure.
The obvious response may be to buy another platform. That deserves a pause. The harder cost often sits in recurring work: updating records, reconciling data, reviewing suppliers, recording exceptions and closing actions.
Poorly connected evidence can consume cash indirectly. Customer onboarding takes longer. An adviser spends extra hours. Due diligence stalls while management searches for decisions that everyone remembers but nobody can produce. These are familiar commercial effects when information cannot move at the speed of the decision.
A firm does not need a grand transformation to improve this. It can start with one important process, such as an outsourced ICT service, a customer-acceptance route or an incident procedure. Follow the process from policy to daily operation. Identify the internal owner. Check the latest evidence, exceptions, management report and unfinished action.
Then ask a plain question: could another person reconstruct the sequence without calling the employee who usually handles it?
The control file is the business record
For a smaller firm using proportionality, the reasoning deserves the same care. The explanation should reflect today’s products, staff, systems and suppliers, rather than the company as it looked three years ago.
This is most directly a signal for regulated financial firms and the organisations serving them. Suppliers should pay attention too. Their regulated clients will increasingly need clearer contracts, reliable data access, evidence of service performance and escalation routes that work when something goes wrong.
The founder in the opening scene does not need a larger document library. The company needs a cleaner line between decision, owner, evidence and response.
Europe is still shaping the architecture of supervision. Inside the firm, the practical question is already available: if someone asks tomorrow, can the business calmly show how today’s control actually worked?
If your firm needs a clearer line between decisions, ownership and evidence, we can help you assess the practical gaps.
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- Van ontwerp tot uitvoering: AFM en AMF identificeren vijf randvoorwaarden voor effectief toezicht op EU-niveau
- Rijksoverheid - Dutch policy supports stronger ESMA supervision, but the architecture is still developing
- Autoriteit Financiële Markten - Current Dutch supervisory findings on documentation, outsourcing and proportionality
- Autoriteit Financiële Markten - Data quality is already a supervisory condition, not back-office housekeeping
- Autoriteit Financiële Markten - Later AFM evidence pressure under DORA
- Autoriteit Financiële Markten - Centralised information increases dependence on outsourced digital infrastructure
