ESMA_QA_2229
Topic
Delegation
05/07/2024
Subject Matter
Permission of AIFMs to delegate portfolio or risk management to non-supervised undertakings established outside of the EU
Question
Are AIFMs allowed to delegate portfolio or risk management to non-supervised undertakings established outside of the EU?
Level 1 Regulation
Alternative Investment Fund Managers Directive (AIFMD) Directive 2011/61/EU
ESMA_QA_2227
Topic
Capital requirements
02/07/2024
Subject Matter
Initial capital and additional own funds
Question
Are internally managed AIFs and self-managed UCITS investment companies required to maintain initial capital and additional own funds, respectively, pursuant to Article 9 of AIFMD and Articles 7 and 29 of the UCITS Directive, that are kept separate from the collective investment undertaking’s assets, meaning that the initial capital and the additional own fund should not be included in the fund’s net asset value (NAV)?
Level 1 Regulation
Alternative Investment Fund Managers Directive (AIFMD) Directive 2011/61/EU
ESMA_QA_2221
Topic
Crypto-Asset Service Provider (CASP)
21/06/2024
Subject Matter
Entities who have not applied for, or whose application for authorisation as CASPs has been refused by the end of the transition period
Question
What happens to an entity providing crypto-asset services in accordance with applicable law before 30 December 2024 that has not applied for authorisation as a CASP, or whose application for authorisation as a CASP has been refused by the end of the transition period?
Level 1 Regulation
MiCA
ESMA_QA_2220
Topic
Crypto-Asset Service Provider (CASP)
21/06/2024
Subject Matter
Entities not authorised as CASPs by the end of the transition period
Question
Where an entity providing crypto-asset services in accordance with applicable law before 30 December 2024 has applied for but has not been granted or refused authorisation by the end of the transition period, can this entity continue providing services until it is granted or refused authorisation?
Level 1 Regulation
MiCA
ESMA_QA_2219
Topic
ICT risk management
13/06/2024
Subject Matter
Questions on Microenterprises and RMF
Question
QUESTION 1: Internal Audit Frequency for Microenterprises and financial entities subject to the simplified risk management framework
Recital 43 of DORA states that microenterprises and financial entities (FEs) referred to in Article 16(1) of DORA are not required to conduct regular internal audits of their ICT risk management framework (RMF). Does it conflict with Article 28, paragraph 5 of Commission Delegated Regulation (EU) 2024/1774 (RTS) that mandates an internal audit on the ICT RMF in line with the FE’s audit plan?

QUESTION 2: ICT Testing Requirements for Microenterprises and Financial Entities – Cyber-attack scenarios
Article 11.6 of DORA excludes microenterprises from the requirement to include cyber-attack scenarios in their ICT business continuity and recovery plan testing. Does it conflict with Article 39, paragraph 1 of the Commission Delegated Regulation (EU) 2024/1774 (RTS), which mandates the inclusion of cyber-attack scenarios in the testing plans for financial entities referred to in Article 16(1) of DORA?

QUESTION 3: Recital 43 of DORA specifies that microenterprises and financial entities referred to in Article 16(1) of DORA are not required to regularly conduct risk analyses on legacy ICT systems. Does it conflict with Article 34, paragraph 1, point (e) of the Commission Delegated Regulation (EU) 2024/1774 (RTS) which mandates that financial entities referred to in Article 16(1) of Regulation (EU) 2022/2554 must manage the risks related to outdated or unsupported and legacy ICT assets?
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)