Supervision & regulator
DORA and asset managers: what the AMF's active supervision changes for you
Register, incidents, ICT third-party control: what the AMF expects from asset managers under DORA, and how to prepare without a dedicated team.

Asset management companies (in France, SGPs) occupy a particular position when it comes to DORA. They are subject to the same regulation as a large bank, but rarely have the same resources: little, if any, dedicated ICT compliance team, and a largely outsourced technology chain. And the AMF, the competent authority for asset managers, has moved from a support phase to a phase of effective supervision. Here is what that means, concretely.
A DORA reality specific to asset managers
For an asset manager, ICT risk exposure is not primarily within its own walls, but at its providers. Depositary, valuation agent, management and order-routing tools, reporting solutions, cloud hosting: most of the critical chain rests on third parties. Managing third-party risk is therefore not one pillar among others — it is the heart of the matter.
This dependence has a direct consequence: the register of information (RoI), which lists ICT contractual arrangements, becomes the central object of the framework. It is through the RoI that you demonstrate you know who does what, where the data is, and where the risks concentrate.
What the AMF expects
Expectations are structured around a few concrete requirements:
- A register of information kept up to date. The RoI is a mandatory document that integrates into the ICT risk management framework. It must be kept available to the authority and submitted according to the prescribed procedures. For a group, it may exist at both the consolidated and sub-consolidated levels.
- Control of contractual arrangements. ICT contracts supporting critical or important functions must integrate DORA's mandatory clauses (audit rights, location, reversibility, cooperation with authorities, subcontracting management). The entity must also inform its authority of any planned arrangement concerning a critical or important function.
- An incident notification process. Even with outsourced infrastructure, it is the asset manager that bears the obligation to notify a major incident — including when it occurs at a provider.
- Involved governance. The management body must be effectively involved: the subject cannot be entirely delegated to a provider or lost in operations.
The question of proportionality
DORA provides for a principle of proportionality, with simplified or lightened regimes for microenterprises and certain small structures. But beware: proportionality adjusts the intensity of the requirements, it does not remove them. It has, moreover, proven more complex to apply than expected, and several entities underestimated the resources needed. The « we're small, so barely concerned » reflex is a trap: better to check your regime precisely than to presume an exemption.
The real challenge: maintaining, without a dedicated team
The first obstacle for asset managers is not understanding DORA — the obligations are documented. It is maintaining the framework alive over time with limited resources. Every new provider, every amendment, every incident should update the register and the associated evidence. In practice, this update too often goes back into Excel files no one has time to maintain, until the annual submission or a supervisor's request forces everything to be rebuilt in a rush.
This is precisely where the gap plays out between a « partially compliant » asset manager and one able to demonstrate its compliance on demand.
How to prepare, concretely
A few priorities for an asset manager who wants to secure its position:
- Map your real dependencies: which critical functions rely on which providers, and where the concentrations are.
- Make your register of information reliable: correct provider identifiers, standalone/framework contract distinction, function classification.
- Structure a light but operational incident process, taking notification deadlines into account.
- Document governance: traces of management involvement, decisions, reviews.
- Shift from a project logic to a continuous maintenance logic.
Where Axenia fits in. Axenia was designed for entities that must maintain a demanding DORA framework without mobilising a full-time compliance team. It structures your register of information, analyses your ICT contracts clause by clause, maps your dependencies and concentrations, and keeps everything up to date — so that your compliance remains demonstrable on a continuous basis, not just on submission day.
This article presents a synthetic reading of the regulator's public expectations and does not constitute legal advice. Refer to the official texts and AMF publications for any compliance decision.
Are you an asset manager? Discover your Axenia use case → or book a demo →
