Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

illustrative example: business functions of a venture capital fund manager

Ariadnah Solutions DORA 26 Aug 2025 2 min read

Defining business functions is a central requirement under the Digital Operational Resilience Act (DORA). As part of building your ICT risk management framework, you must identify the business functions your organization performs, determine their criticality, and map their dependencies. This exercise is essential because functions are the anchor point for risk assessment, impact analysis, and reporting.

To give you a head start, we have prepared an illustrative example of how the business functions of a venture capital (VC) fund manager could be defined, based on the functional requirements of the Alternative Investment Fund Managers Directive (AIFMD). Please note that this example is provided for illustration purposes only. Each organization must carefully define its own business functions according to its unique operating model, strategy, and regulatory perimeter.


01

i. core aifmd functions

  1. portfolio management Executing investment decisions in startups and growth companies, including sourcing, due diligence, structuring deals, monitoring portfolio performance, providing governance input, and planning exits.
  2. risk management Independently identifying, monitoring, and controlling risks such as startup failure, sector concentration, and liquidity exposure, setting limits, and performing stress tests to ensure compliance with fund mandates and AIFMD requirements.

02

ii. operational and administrative functions

  1. administration of the aif Managing the operational backbone of the fund, including fund accounting, legal administration, record-keeping, capital calls and distributions, investor registers, reporting, and audit coordination.
  2. valuation Establishing consistent and independent valuation procedures for illiquid equity holdings, performing periodic valuations, and ensuring independence from portfolio management or engaging an external valuer as required under AIFMD.
  3. depositary oversight Ensuring safekeeping of fund assets through an appointed depositary that monitors cash flows, verifies ownership, and supervises subscriptions, redemptions, and distributions.

03

iii. investor-related functions

  1. marketing and fundraising Promoting and offering fund units to professional investors, preparing fundraising materials, managing due diligence processes, and complying with AIFMD marketing and passporting rules.
  2. investor relations Maintaining transparent communication with investors, providing regular updates and reports, hosting annual meetings, and managing inquiries and co-investment opportunities.

04

iv. governance, compliance, and oversight functions

  1. regulatory compliance Ensuring adherence to AIFMD and related obligations, including Annex IV reporting, AML/KYC, GDPR compliance, conflict-of-interest management, and monitoring leverage and liquidity policies.
  2. delegation oversight Monitoring and controlling outsourced functions such as administration, valuation, or risk, conducting due diligence on providers, and ensuring the AIFM retains responsibility and is not reduced to a “letter-box entity.”
  3. organisational requirements and internal controls Maintaining robust governance structures, adequate human and technical resources, secure systems, accounting and record-keeping, and effective continuity and internal control measures.

05

Closing note

This example shows how business functions of a VC fund manager can be logically grouped and described under the AIFMD framework. In the DORA context, such definitions provide the blueprint for ICT risk management. Remember: this list is illustrative only. Every organization must carefully define its own business functions, aligned to its specific activities, operating model, and regulatory obligations.

Originally published on DORA Solutions Insights.

Continue with DORA

Put this question in context.

The DORA guide connects this issue to governance, ICT risk, incidents, resilience testing, third-party risk and the Register of Information.

Recommended next Read the DORA compliance guide →
Explore the operating approach See the asset and dependency approach Related analysis How to Map ICT Services to Business Functions: A Complete Yet Proportionate Approach Related analysis Business functions in DORA; The cornerstone of your ICT Risk management
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.