On 18 May 2026, the Central Bank of Ireland (“CBI”) published its Thematic Assessment: Compliance Function in the MiFID Investment Firm Sector (the “Thematic Assessment”). The Thematic Assessment follows a structured review of the compliance function across a number of Irish investment firms regulated under Directive 2014/65/EU on markets in financial instruments (“MiFID II”) and Irish implementing legislation (“MiFID Investment Firms”).
The findings carry direct regulatory weight and obligations for MiFID Investment Firms. The CBI has mandated that the report be discussed at each MiFID Investment Firm’s next board meeting, with that discussion formally recorded in the meeting minutes.
For compliance officers, legal teams, and senior management at MiFID Investment Firms, the report deserves careful attention as the CBI has signalled it may follow up directly through its supervisory activities.
The CBI’s key objectives of the Thematic Assessment were to assess MiFID Investment Firms’ adherence to the compliance function requirements set out in Article 22 of the MiFID II Delegated Regulation (“Delegated Regulation”) and the related ESMA Guidelines On certain aspects of the MiFID II compliance function requirements (the “ESMA Guidelines”).
In its Thematic Assessment, the CBI focused on three key considerations:
The Thematic Assessment was a supervisory response to risks identified by the CBI in its 2025 and 2026 Regulatory and Supervisory Outlook reports, including weaknesses in culture, governance and risk management.
Background
Article 22 of the MiFID Delegated Regulation mandates that investment firms must set up a permanent, independent compliance function to identify and minimise the risk of breaching MiFID II obligations. The function’s four core duties are:
Monitoring must be risk-based, and the compliance function must assess compliance risks across all investment services and activities, then build a programme that prioritises the areas of highest risk.
Furthermore, Article 22(3) of the MiFID Delegated Regulation sets out that in order to operate independently, the compliance function must have adequate authority, resources, expertise and information access. A compliance officer must be formally appointed (and replaced) by the management body. The compliance function reports ad hoc directly to the management body if a significant compliance risk is detected. Relevant persons in the compliance function may not be involved in the activities they themselves monitor, and their remuneration must not compromise their objectivity.
Findings and CBI expectations
Positive Findings
The CBI found MiFID Investment Firms to have a genuine and generally sound understanding of their obligations in relation to the compliance function.
Strategic engagement stood out as a particular strength. The compliance function was found to be actively involved in decision-making around new business lines and financial products, including holding voting membership on product approval committees.
Firms also appeared to be adequately resourced in proportion to the nature, scale and complexity of their activities. Most MiFID Investment Firms had established risk-based compliance monitoring programmes, with some extending beyond desk-based reviews to include on-site inspections of business areas. Horizon scanning was in place at most firms, enabling the compliance function to track regulatory developments and advise senior management proactively.
Negative Findings and Recommendations
Despite these positive findings, the CBI identified a number of weaknesses that MiFID Investment Firms must address and take into consideration.
Several MiFID Investment Firms were unable to demonstrate robust succession plans or contingency arrangements for compliance roles. This poses a risk, for example, where the Head of Compliance departs unexpectedly or is otherwise unavailable, firms without adequate continuity arrangements may find themselves in breach of their regulatory obligations in such transitional periods.
While all MiFID Investment Firms provided compliance training, the CBI found that direct delivery by the compliance function itself was limited in several cases. Training that is entirely delegated to HR departments or third-party providers, without active involvement from the compliance team, may not effectively embed regulatory awareness. The CBI states that effective compliance training is a critical mechanism for embedding regulatory awareness, including regulatory changes, and an appropriate compliance culture throughout a firm.
The CBI found that in some Firms, the compliance risk assessment process was insufficient in that not all identified risks were reviewed regularly in accordance with the ESMA Guidelines. The CBI also noted that some compliance plans and the documented compliance universe lacked adequate detail.
Furthermore, the CBI found that while Firms generally produced comprehensive compliance reports to the board and sub-committees, the minutes did not in all cases prove that compliance matters were discussed or challenged. Boards are ultimately accountable for the Firms they govern, and therefore, board meeting minutes should reflect the engagement of the board with compliance matters.
Following those findings, what expectations does the CBI have?
The Thematic Assessment provides helpful guidance on best practices and expectations of the CBI. In detail, the CBI lists the following expectations:
Next Steps for MiFID Investment Firms
The CBI has set out clear expectations for next steps, and these are not merely advisory. MiFID Investment Firms are required to:
Where gaps/weaknesses are identified, MiFID Investment Firms should develop and implement actions to address these in a proactive and timely manner.
Conclusion
The Thematic Assessment provides valuable insight into the CBI’s regulatory expectations regarding the operation of compliance functions within MiFID Investment Firms. Firms should use the findings as an opportunity to assess the effectiveness of their compliance frameworks, address any identified gaps, and ensure continued compliance with applicable regulatory requirements.
For further information or advice on the CBI’s Thematic Assessment, MiFID II compliance requirements, or strengthening your compliance framework, please contact us.