Search Ocorian

Laptop, teamwork and meeting with business people in office for strategy, project and research. Company growth, market report and brainstorming with employees in agency for discussion and planning

Do small AIFMs need an independent risk management function?

06 August, 2026

What does good risk management look like for everyone else?

The FCA’s consultation on the UK AIFM regime (CP26/28) is substantial and has firms talking about categorisation, thresholds and reporting. And rightly so. Those changes are significant. But the question we keep getting asked by our clients is a much simpler one:

“Do we still need an independent risk management function – and if not, what are the FCA actually expecting to see?”

Short version: most small AIFMs probably won’t need a standalone risk function. The longer version is where it gets interesting, because “no separate function” is not the same as “no independent challenge”. Here’s how we are reading it.
 

What is changing?

AIFMD risk management has been treated as an organisational chart exercise to show reporting lines, prove risk sits apart from portfolio management and tick the box. The current rules ask full-scope firms to keep the two functions functionally and hierarchically separate, or to demonstrate equivalent safeguards.

CP26/28 pulls in a different direction. The whole package is built around proportionality with requirements that scale with a firm’s size, activities, complexity and potential impact, rather than one framework stretched across firms that look nothing like each other.

The headline move is a shift from the old small/full-scope split to three NAV-based tiers:

Image
Three NAV-based tiers

The old model was never built for smaller firms

Under the current regime, smaller firms have often found themselves applying governance concepts originally developed with much larger and more complex firms in mind. In theory, an independent risk function sounds sensible. In practice, many firms with fewer than 20 people simply cannot justify a separate risk department that sits entirely outside investment activities. That does not automatically make them poorly governed.

A £300 million lower-risk private equity manager investing in a handful of long-term businesses is not exposed to the same risks as a multi-strategy hedge fund running leverage and daily liquidity. Yet historically they have often been caught by the same broad framework. The move to small, medium and large categorisation based on NAV is intended to fix exactly that. On paper, “independent risk function” sounds sensible. In practice, plenty of firms can’t sensibly carve out a risk team that sits entirely outside the investment side. That does not make them badly run.
 

So, does a small AIFM need one?

Honestly, we think that is the wrong question. The one that matters is:

Can you show effective, independent challenge – whoever provides it?

A risk department that rubber-stamps everything does not add anything. A small firm with no risk team but real, documented challenge can be in far better shape. When things go wrong, regulators do not start with the org chart; instead they start by asking who can explain the key risks, how they’re monitored, who challenges, and what happens when a limit is breached. If nobody can answer, the structure was never the problem.
 

What good looks like for small AIFMs

Good risk management in a small firm isn’t complicated, and complexity is usually the enemy. The best small managers do a handful of things properly:

Know your real risks

A register listing 60 risks isn’t risk management; it’s a filing exercise. If everything is critical, nothing is.

Strong firms know the handful of things that could genuinely hurt investors or the business, typically:

  • Investment concentration

  • Valuation risk

  • Key person dependency

  • Liquidity risk

  • Outsourcing and third-party risk

  • Cyber and operational resilience


Build in challenge somewhere

Independence doesn’t require a department. It can come from a Chief Risk Officer, Compliance Officer, a Non-Executive Director, an advisory committee, an external consultant, or a senior person outside the deal team. What matters is that someone has the standing to ask the awkward question and does.

Write the decision down

This is where firms tend to slip. Most managers know their risks and talk about them often. Far fewer record those conversations. A regulator can’t review a discussion that was never minuted. Board packs, risk reports, committee minutes and action logs are still the strongest evidence firms can have.

Judge it on outcomes

A good firm can say, ‘here is the risk we identified, this is what we did, this is who owned it, these are the actions taken to mitigate it, and this is how it is monitored going forward. That tells a far more effective story than a fifty-page framework nobody opens.
 

What good looks like for medium and large firms

This is where the tone changes. Once a firm grows – greater NAV, more complex products, multiple investors, bigger operations – it gets hard to argue that formal separation isn’t warranted. We do not read CP26/28 as easing off here. If anything, expect closer scrutiny of whether risk management influences decisions.

Image
Small vs Medium & Large AIFMs

The industry has spent years producing frameworks. The next test is proving they change what firms do.

Don’t mistake proportionality for a free pass

There’s a temptation to read “proportionate” as “less regulation”. We do not think that’s the message. The FCA is accepting that good governance takes different shapes, not that accountability is optional. Small firms may get more say over how they organise themselves. They won’t get more room on responsibility. And an outcomes-based approach makes it harder to hide behind process.
 

What firms should be thinking about now

Implementation is expected in 2028, but this isn’t a 2027 problem. A few practical questions worth working through:

Image
What firms should be thinking about now

The bottom line

The debate shouldn’t be whether every small AIFM needs a risk department. It should be whether risk management can shape decisions. A small firm with clear ownership, real challenge, useful reporting and a paper trail can easily out-govern a much bigger one running a beautiful three-lines-of-defence model that nobody truly uses.

Firms will likely gain flexibility on structure. They won’t gain flexibility on responsibility.
 

How Ocorian can help

Wherever you land in the new regime, we can help you get ahead of it:

  • Tier assessment – confirming your NAV category now and modelling where growth takes you before 2028.

  • Risk framework review – right-sizing your risk management to your tier, with proportionate governance.

  • Independent challenge – providing external oversight and challenge where a standalone function isn’t justified.

  • Risk register refresh – cutting the noise so your register reflects the risks that matter.

  • Board & MI support – designing reporting that evidences real challenge, not just process.

  • Consultation response – helping you feed into CP26/28 before it closes on 14 October 2026.

Need a deeper analysis?

Ocorian’s regulatory consultants will be publishing in-depth articles on each of the FCA’s consultation papers referenced in this article.

To discuss how the proposals may affect your business, please contact Ocorian’s regulatory consultants via Ocorian’s website.

About the author

Noma Mkwananzi is a principal consultant in Ocorian’s regulatory and compliance team. She advises banks and investment firms across the UK and Europe on prudential regulation, risk and treasury management. Her experience includes regulatory reporting, ICAAPs, ILAAPs, recovery planning, stress testing and regulatory training.