FCA Senior Managers Regime: A Founder's Guide
Published Updated

You're staring at a responsibilities map the night before an FCA visit. The document looks complete, but one question keeps returning: which individual is accountable for the gap the regulator is likely to test? That's the question the FCA Senior Managers Regime is designed to answer.
For founders, SM&CR isn't an annual compliance exercise or a set of forms delegated to HR. It's the operating framework that connects authorisation, governance, oversight, evidence and individual accountability. The FCA expects senior managers to understand their responsibilities, exercise effective control and show the reasonable steps they took when something went wrong.
Table of Contents
- Why the FCA Senior Managers Regime Exists
- The Three Pillars of SM&CR Explained
- Responsibilities Maps and Statements of Responsibility
- Certification Functions and Fit and Proper Assessments
- Where SM&CR Meets Consumer Duty, Operational Resilience and AI
- What the 2026 SM&CR Reforms Change in Practice
- Preparing Your Team for Regulator Scrutiny
Why the FCA Senior Managers Regime Exists
Before SM&CR, accountability could become blurred across committees, reporting lines and corporate structures. A firm might fail customers, suffer a control breakdown or mishandle a risk, yet the practical question of who owned the relevant decision was difficult to answer. The regime changed that emphasis by putting named individuals at the centre of governance.
The FCA says Parliament created the regime following legislation in December 2013, and the framework was later expanded by further legislation in May 2016 to cover all FSMA-authorised firms. The first phase launched in March 2016 for banks, building societies, credit unions and PRA-designated investment firms. Insurers came fully into the regime in December 2018, all solo-regulated firms were included in December 2019, and benchmark administrators were added in December 2020, as set out in the FCA's history of the Senior Managers and Certification Regime.

The accountability test founders should apply
The regime's logic is simple:
- Name the accountable person. Every relevant activity, business area and management function needs ownership by one or more Senior Management Function holders.
- Define the scope. The senior manager's Statement of Responsibilities must describe what they control, not what an organisation chart implies.
- Give them authority and resources. The FCA expects the responsible SMF to be sufficiently senior, credible and resourced to exercise effective oversight.
- Keep evidence. Board minutes, risk decisions, challenge records, escalation logs and remediation plans should show how the manager discharged the role.
- Test the arrangement when facts change. New products, outsourced services, overseas activity, departures and material incidents should trigger a governance review.
The FCA's Senior Managers Regime guidance makes fitness and propriety a continuing obligation. Senior Management Function holders must be fit and proper, and firms must assess their ongoing fitness and propriety at least annually.
For a founder-led firm, the pressure is sharper. One person may hold several SMF responsibilities, but combining roles doesn't remove the need for clear ownership. Nor can a founder point to a committee, adviser or parent company and assume accountability has moved elsewhere. If the firm's controls fail, the FCA will examine what the named manager knew, what they did, what they challenged and what they recorded.
Practical rule: If an SMF can't explain the firm's control environment without searching through folders, the firm probably can't evidence effective oversight.
The Three Pillars of SM&CR Explained
SM&CR operates as one accountability system with three connected pillars. For NorthGate Pay, a hypothetical payments firm preparing for authorisation, each pillar must translate into named owners, documented decisions and evidence that the controls work in practice.
The Senior Managers Regime covers individuals performing designated Senior Management Functions. Their responsibilities are allocated formally through a Statement of Responsibilities and, for enhanced firms, a Responsibilities Map. The practical catalogue includes functions identified from SMF1 through SMF29, including the newer SMF24 chief operations role where applicable.
NorthGate Pay's compliance lead might hold SMF16, the Compliance Oversight function. The head of sales may not be a senior manager, yet could fall within the Certification Regime if the role can cause material harm through client dealing or another certification function. The firm should record that reasoning rather than rely on job titles alone.

Senior managers
Senior managers require regulatory approval before performing their functions, subject to the applicable rules and later reforms. Their role extends beyond attending board meetings. They must own decisions, maintain oversight, challenge weak controls and act when resources or safeguards are inadequate.
The FCA's Senior Managers Regime requirements require firms to assess fitness and propriety at least annually. That assessment should reflect the person's actual responsibilities, conduct, competence and decisions. Keep the supporting evidence with the assessment, including challenge records, escalation decisions and remediation actions.
Certified persons
The Certification Regime covers staff whose work could cause material harm but who are not approved as SMF holders. Depending on the firm's activities and applicable thresholds, this can include material risk takers, client-dealing staff, proprietary traders and individuals responsible for algorithmic trading.
Certification is the firm's responsibility. The firm assesses each person and issues a certificate only when satisfied that they are fit and proper for the role. Treat the certificate as a current control decision, not a permanent HR status. Revisit it when responsibilities, competence, conduct or personal circumstances change, and retain evidence of the decision.
Conduct Rules
The Conduct Rules set individual standards across the relevant organisation. Tier one rules apply across the relevant staff population, while tier two rules add obligations for senior managers. Firms must ensure staff understand the rules and retain appropriate records of training and awareness.
The three pillars answer separate questions. The Senior Managers Regime identifies who owns the outcome, the Certification Regime tests whether risk-relevant staff remain suitable, and the Conduct Rules define expected behaviour. A usable SM&CR framework connects all three to day-to-day decisions and evidence.
Responsibilities Maps and Statements of Responsibility
The Responsibilities Map is not an HR template. It's the firm-wide operating picture of accountability. A Statement of Responsibilities is the individual view, showing the responsibilities allocated to a specific SMF manager.
The FCA Handbook's SYSC 24 allocation requirements require firms to allocate responsibility so that material areas aren't left uncovered. The framework also requires the accountable person to be sufficiently senior and capable of exercising effective oversight. The related SYSC 26 overall responsibility rule requires one or more SMF managers to have overall responsibility at all times for each activity, business area and management function, including work located partly or wholly outside the UK.
NorthGate Pay plans to open a Frankfurt office. The map should show who owns the relevant activity, how local management reports into the UK structure, which controls remain centralised and where escalation sits. A vague reference to “group oversight” won't demonstrate allocation. The firm needs to show the accountable SMF, their authority, reporting lines, resources and challenge arrangements.
What each document should prove
The map should let a reviewer understand the whole firm quickly. The statement should let a reviewer understand one manager's precise responsibilities without reconstructing the answer from several documents.
| Aspect | Responsibilities Map | Statement of Responsibilities |
|---|---|---|
| Purpose | Firm-wide view of accountability | Individual allocation of responsibilities |
| Scope | Activities, business areas, management functions and reporting lines | Responsibilities assigned to one SMF manager |
| Main test | Are there gaps, overlaps or unclear ownership? | Does the individual understand and control their scope? |
| Change trigger | New products, entities, outsourcing, restructures or material changes | Appointment, departure or change in the manager's role |
| Evidence | Governance structure and allocation logic | Role-specific accountability and oversight expectations |
The most common failure is shared ownership without a decision rule. For example, NorthGate Pay may describe risk management as jointly owned by the SMF3 Chief Risk Officer and SMF4 Chief Operations Function. That wording is inadequate unless the firm specifies which manager owns risk identification, control testing, operational escalation and remediation decisions.
Keep both documents aligned with board minutes, policies, committee terms of reference and application materials. If those documents describe different owners, the regulator will treat the inconsistency as a governance problem, not a formatting issue.
Certification Functions and Fit and Proper Assessments
A certification decision can fail at the first board challenge if the file shows only a signed form. Run certification as a distinct annual workflow, even when parts of it sit within performance reviews. Identify roles where poor judgment, weak competence or misconduct could cause material harm, then assess each person against the duties they will perform.
The assessment must cover honesty, integrity, competence and financial soundness. Test those criteria against regulatory history, references, disciplinary information and changes to the individual's responsibilities. A certificate for a narrow dealing role does not establish suitability for a materially broader position.

What reasonable steps look like
Build the file so another reviewer can follow the evidence and understand the conclusion. Include:
- Role scope: The job description, decision rights, reporting line and relevant certification function.
- Competence evidence: Experience, qualifications, training records and role-specific capability checks.
- Regulatory history: Regulatory references, previous approvals, disciplinary information and relevant declarations.
- Interview record: Notes showing that the firm tested judgment, knowledge and understanding of the role.
- Conduct review: Complaints, incidents, breaches, investigations and disciplinary outcomes.
- Ongoing monitoring: Evidence that the firm considered new information during the certification period.
Annual fitness and propriety assessments are expected for SMF holders. Apply the same evidence discipline to certification files, while setting a process that matches the firm's roles, controls and sources of information.
The certificate is conditional in practice
A certificate is not a reward for tenure. New conduct information should trigger a reassessment, and the firm may need to withdraw or refuse certification. Record the decision and its reasoning. An undocumented conversation will not support the firm under regulatory scrutiny.
Keep the certificate, assessment rationale, interview notes, training records and disciplinary file together. FCA Form E or equivalent internal records should be available if requested. The firm must be able to show who decided, which evidence they reviewed and why the individual remained suitable for the defined role. Treat the assessment file as a live control record, not annual paperwork completed after the fact.
Where SM&CR Meets Consumer Duty, Operational Resilience and AI
SM&CR is the accountability spine connecting overlapping regulatory programmes. A firm shouldn't maintain separate governance stories for Consumer Duty, operational resilience and AI. The same senior managers, committees and evidence files often sit behind all three.
Suppose a payments firm's automated transaction-monitoring tool creates a customer-impacting failure. The firm may need to explain customer outcomes, the resilience of an important business service, and the governance of the AI-enabled control. The regulatory questions differ, but the FCA will still ask who owned the relevant decision, what oversight existed and how the firm responded.
One incident, several evidence trails
| Regime | Lead SMF | Evidence Triggered |
|---|---|---|
| Consumer Duty | SMF responsible for customer outcomes, product governance or relevant delivery | Customer-impact analysis, outcome monitoring, complaints, board challenge and remediation |
| Operational resilience | SMF responsible for operations, technology or the important business service | Impact tolerance, testing, incident records, continuity decisions and recovery evidence |
| AI governance | SMF allocated model risk, technology or control oversight | Model approval, validation, monitoring, human challenge, vendor due diligence and change records |
The allocation must match reality. If a Chief Operations Function holder owns system availability but the Chief Risk Officer owns model risk, the firm should define how those responsibilities interact. “The board oversees AI” isn't enough. A board can challenge and approve, but an SMF must own the operational accountability for the relevant activity.
Evidence should travel with the decision
For Consumer Duty, identify the manager who can explain how the firm monitors customer understanding, support, product suitability and foreseeable harm. For operational resilience, identify who can explain important business services, tolerances, testing and remediation. For AI, identify who approved the model, challenged its limitations and ensured that human intervention remained possible.
The regulator won't be impressed by three policy documents that describe one control environment three different ways.
Founders should build a single accountability register linking each material control to its owner, evidence source, review date and escalation path. That register supports SM&CR and makes cross-regime contradictions easier to find before a supervisor does.
What the 2026 SM&CR Reforms Change in Practice

A founder preparing an SMF appointment for the board pack should treat the 2026 reforms as workflow changes, not a relaxation of accountability. The FCA has made parts of the process easier to schedule, while retaining its expectation that firms can show who owns each decision, what authority they had and which reasonable steps they took.
The FCA's PS26/6 policy statement confirms that criminal record checks for new SMF candidates will remain valid for six months rather than three, and firms will have 12 weeks to submit an SMF application. Firms will also have up to six months to notify changes to Statements of Responsibilities and Management Responsibilities Maps. The Bank of England's reforms remove the need to certify people for multiple overlapping functions, reducing certification roles by around 15%, as reported in the same policy context.
Changes that reduce operational friction
The practical gains are concentrated in administration:
- Longer document validity: Firms can complete an application without repeating a criminal record check as quickly.
- A defined submission window: The 12-week period covers submitting the application, not securing regulatory approval.
- Less duplicated certification: Overlapping functions can be removed where the revised rules apply.
- More time for map updates: Firms can group related amendments instead of treating each change as a separate filing event.
For founders, these changes support a cleaner evidence workflow. Keep the application, criminal-record check date and current Statement of Responsibilities version in one dated file. That prevents the submission window from creating avoidable rework.
The reforms do not remove the need for a complete application, a documented fitness and propriety assessment or an allocation that matches the firm's actual operating model.
Changes that still require evidence
The accountability framework, revised duty of responsibility and consolidated statements may reduce form-filling, but the underlying governance work remains. The firm still needs to define scope, authority, competence, reporting lines, resources and the reasonable steps supporting each senior manager's decisions.
A founder must prepare the candidate for regulator interviews. The candidate needs to explain the business model, key risks, outsourcing arrangements, controls, incident history and the boundaries of their own responsibility. A shorter form cannot repair unclear ownership or weak management information.
The reforms took effect in stages. Most changes began on 24 April 2026. Reporting and process changes take effect on 10 July 2026, Directory changes removing overlapping certification functions take effect on 30 July 2026, and changes aligned with non-financial misconduct reforms take effect on 1 September 2026, according to Handbook Notice 140.
The scale of the regime reinforces the need for standardised files. As of June 2025, the government consultation recorded about 262,000 regulated functions held by about 139,000 individuals with certificates. During the 2024–25 financial year, the FCA approved 5,264 applications and the PRA approved 1,130. The FCA determined 99.7% of its most recently published quarterly SM&CR applications within the current three-month statutory deadline, while 94.7% fell within the proposed two-month deadline, as reported in the 2025 government consultation paper. Maintain a dated evidence pack so high application volumes do not become an excuse for inconsistent records.
My recommendation for a founder-led firm is direct. Re-engineer repeatable administration, but keep the control framework intact. The reforms reduce filing friction. They do not reduce the governance evidence required under scrutiny.
Preparing Your Team for Regulator Scrutiny
Regulator scrutiny exposes the difference between a document that exists and a control that operates. FCA visits, section 166 reviews and skilled-person reviews can all test whether senior managers understand their responsibilities and whether the firm can produce evidence quickly.
Prepare in this order.
Establish the evidence baseline
Start with a current Responsibilities Map dated within the last 12 months. Reconcile it against Statements of Responsibilities, the organisation chart, committee terms of reference, outsourcing registers, key policies and the board's understanding of accountability.
Then check every certification file. Each file should include the annual fitness assessment, role scope, competence evidence, regulatory history, interview notes, training records and any disciplinary information. Don't accept a spreadsheet showing “complete” as a substitute for the underlying record.
Rehearse the senior managers
Each SMF should be able to give a concise opening explanation covering:
- The business area they own.
- The decisions they can make without escalation.
- The risks they monitor.
- The reports and information they receive.
- The controls they've challenged.
- The action taken when evidence was inadequate.
The manager should also produce their Statement of Responsibilities, relevant board minutes, management information, risk assessments, incident records and remediation evidence without relying on a compliance colleague to translate the documents.
Supervisors may test conduct scenarios rather than ask for definitions. Rehearse what the manager would do if a sales employee concealed a customer-impacting issue, an outsourced provider missed a control obligation, an algorithm produced unreliable results, or a board decision left a material risk without an owner.
Build a quarterly rhythm
Preparation shouldn't begin when the FCA sends a meeting request. Assign a named owner to every document the regulator could request, then review the evidence quarterly.
Use a simple control cycle:
- Map changes: Record new products, services, entities, outsourcing arrangements and departures.
- Test ownership: Confirm that every material activity still has an accountable SMF.
- Review evidence: Check board challenge, committee decisions, incidents and remediation.
- Refresh people files: Update fitness, propriety, competence and conduct information.
- Run interviews: Ask SMFs to explain their responsibilities without prompts.
- Record decisions: Keep a dated log of changes, rationale and approvals.
If an accountability document changes but the board minutes, policies and management information don't, the firm has created a contradiction.
Before any regulatory engagement, put these questions to the chair and head of compliance:
- Which SMF owns each important business service and customer outcome?
- Where do responsibilities overlap, and who has the final decision?
- What changed since the last map was approved?
- Which certification files would be hardest to produce?
- Can each SMF explain a recent challenge they made and the resulting action?
- What evidence shows the board received accurate, timely information?
- Which open remediation items could alter an SMF's scope or fitness assessment?
Glentorion helps financial and crypto businesses scope regulatory routes, prepare and review authorisation packages, align responsibilities with evidence, and ready management teams for regulator interviews. If your SM&CR documents need a practical governance review before an FCA engagement, visit Glentorion to discuss the right scope of support.
- fca senior managers regime
- smcr compliance
- uk financial regulation
- senior managers
- certification regime

