The Internal Operations Manual is not a compliance document that runs alongside the Cyprus AIFM's actual operations. It is the description of those operations. CySEC's checklist for the Internal Operations Manual does not ask whether the applicant has policies. It asks how the applicant will actually operate. Every section expects description of specific arrangements and controls, at the level of who does what, when, and how it is reviewed. This piece walks the checklist and what the framework will not accept in its place.
What the checklist asks for
The Internal Operations Manual submitted with the AIFM application covers the organisational structure of the AIFM and its permanent functions; the AIFM's risk management framework; the arrangements for conflicts of interest; and the operating conditions applied by the AIFM.
Under organisational structure the checklist expects description of the reporting lines and allocation of responsibilities; the decision-making process and the arrangements that ensure relevant persons follow the procedures for the proper discharge of their responsibilities; the internal control mechanisms that secure compliance with decisions and procedures at every level; the internal reporting and communication of information across the AIFM and with third parties; the records the AIFM keeps on its business and internal organisation; the systems and procedures that safeguard the security, integrity and confidentiality of information; the business continuity policy in the event of interruption; and the accounting policies and procedures that let the AIFM produce financial reports on request.
Each of these is a section of the manual, and each expects description of the applicant's own arrangements. The framework does not accept a description of what an AIFM in the abstract would do; it expects a description of what this AIFM will do.
The three control functions
Three permanent functions carry the AIFM's control architecture: the compliance function, the internal audit function and the risk management function.
The compliance function detects the risk of failure to meet the AIFM's obligations under the Law and reduces that risk. The manual describes the policies and procedures designed to detect the risk; the measures that minimise it; the compliance function's independence and its ability to properly perform its responsibilities; the compliance officer's duties, responsibilities and reporting obligations, including the timing of reports and the people they go to. Where the AIFM proposes that any of the compliance function's requirements should not apply given the nature, scale and complexity of the business, the applicant must demonstrate why the requirement is not proportionate and how the compliance function will remain effective without it.
The internal audit function must operate independently. The manual describes how that independence is protected and describes the function's duties and responsibilities.
The risk management function is functionally and hierarchically separated from the operating units it oversees. The manual describes the separation, the function's duties and responsibilities, the risk management systems the AIFM applies, the assessment monitoring and review process, and the risk management policy itself. The policy identifies all the relevant risks for each AIF managed, sets the procedures for assessing them, sets the techniques for measuring and managing them, sets the techniques for assessing and monitoring liquidity risk, allocates responsibilities, sets limits and justifies why those limits align with the risk profile of the AIF disclosed to investors, sets the terms and contents of reporting on risk, and describes the safeguards against conflicts of interest inside the risk function.
Valuation, the heavily-worked area
Valuation is the single most heavily-worked area of the checklist. The framework expects description of a valuation process that is sound, transparent, comprehensive and documented for each AIF managed: the policies and procedures; the obligations, roles and responsibilities of every party involved including the senior management of the AIFM; the safeguards for functional independence if the AIFM performs the valuation itself; the model and its validation if a model is used; how policies and methodologies are applied consistently; the review process for individual asset values and the escalation measures for differences or other problems; the frequency of valuation for open-ended AIFs; the NAV per unit calculation methodology; the remedial procedures if a NAV calculation is incorrect; the regular verification of units or shares in issue; and, if an external valuer is appointed, the exchange of information with the external valuer and how the valuer complies with the applicable framework.
Valuation is where the framework asks not just what the AIFM will do but how it will be reviewed, escalated, corrected and independently verified.
Delegation
Delegation is a substantive section, because the AIFM's responsibilities do not travel with the delegated function. The manual describes the delegation rules; the objective reasons for delegation; the features of the delegate; the effective supervision arrangements; the treatment of conflicts of interest arising from delegation; and the arrangements for consent and notification of sub-delegation.
For each delegation the manual describes how the AIFM's responsibilities and liability are not affected; how the AIFM's obligations towards the AIF and its investors remain unaltered; how the authorisation conditions are not undermined; the written agreement between the AIFM and the delegate; how the delegate carries out the functions in compliance with applicable law; the methods for reviewing the delegate on an ongoing basis; the actions taken if the delegate cannot carry out the functions; and how the AIFM supervises the delegated functions and manages the risks that come with delegation.
The point of the section is not that delegation is discouraged. It is that the AIFM cannot delegate the responsibility with the task.
Why the manual has to be the AIFM's own
The framework does not accept a manual that reproduces the provisions of the underlying Regulation without describing how the AIFM will operate under them. The checklist is explicit that the applicant is being asked to describe its own arrangements at the level of specific procedures, specific persons, specific timing and specific escalation. A section that says the AIFM shall comply with a given article does not answer what the checklist asks. A section that describes who reviews the general investment policy for each AIF, at what interval, against what criteria and with what escalation, does.
The point is not only that the assessment will not accept a borrowed manual. It is that the manual submitted at authorisation becomes the operating baseline the AIFM is expected to run against once the licence is granted. A manual written to describe how someone else's AIFM operates will not describe how this one operates, and the firm will find itself either running a business that does not match the manual on file, or trying to run a manual that does not fit the business it is actually building. Both are avoidable at authorisation, by writing the manual that describes the firm's own arrangements.
The manual is the operating architecture
The Internal Operations Manual is not a compliance document that runs alongside the AIFM's actual operations. It is the description of those operations, at the level of specific arrangements, specific persons and specific controls. CySEC's checklist expects description across the organisational structure, the three control functions, valuation, delegation and the operating conditions. A borrowed manual does not answer what the checklist asks, and after the licence is granted, a borrowed manual is not the one the AIFM can actually run. The manual that gets accepted is the manual that describes how this AIFM will operate, and that is the manual the firm will be able to run against.
This piece stands alongside the file itself, the timeline the file runs through and the scope of the licence granted. Further pieces in this cluster walk the personal side of the file and the post-licence year-by-year timeline.