
The Risk
Depositary Banks, Fund Management Companies and others need to protect investors' data and assets by proactively monitoring their service providers. Regulations such as AIFMD and UCITS V require banks to perform due diligence over a fund's organisation, procedures, and controls, as well as its service providers. At the same time, UCITS Management Companies and Alternative Investment Funds (AIFs) are under increasing pressure in Europe to monitor delegated activities such as transfer agency, fund distribution, administration, accounting, investment management, IT services and others. Increasingly, Fund Platforms are a service providers of interest, responsible for the safekeeping and administration of securities under custody. Given the wide range of services they can provide, a comprehensive assessment is essential.
The Solution
Thomas Murray's Fund Platform Monitoring solution eases the burden on banks and funds by administering a managed service to collect data, generate a report based on a standardised proprietary methodology and maintain data in a structured form. Thomas Murray generates a detailed assessment with overall and sub-risks rated AAA to C.
Key risk assessed include:
Asset Safety
Assert Servicing
Financial
Operational

We safeguard clients and their communities

Petroleum Development Oman Pension Fund
“Thomas Murray has been a very valuable partner in the selection process of our new custodian for Petroleum Development Oman Pension Fund.”

ATHEX
"Thomas Murray now plays a key role in helping us to detect and remediate issues in our security posture, and to quantify ATHEX's security performance to our directors and customers."

Northern Trust
“Thomas Murray provides Northern Trust with a range of RFP products, services and technology, delivering an efficient and cost-effective solution that frees our network managers up to focus on higher Value activities.”
Insights

How Often Should ODD Be Refreshed? A Practical Framework
Most allocators do a full ODD review every 12 to 36 months, but the right cadence depends on risk. Here's a practical five-step framework for deciding how often to review each manager.

Private Equity Has a Cyber Risk Blind Spot
Private equity has become much better at assessing cyber risk, but it may be looking in the wrong place.

What AI Actually Changes About the DDQ (and What It Doesn't)
AI is transforming DDQ workflows, but it doesn't change what a questionnaire actually is: self-reported data. Here's where the line falls, and what to ask before adopting an AI-assisted tool.

Beneath the Asset – Out of Sight: The State of Cybersecurity in the Private Equity Industry
The UK’s smallest investment funds are weak security link in protecting the IP needed for national growth, new Thomas Murray study finds.
Contact an expert

