Comply Launches Financial Services' First Agentic Compliance Platform MCP Server, Enabling Teams to Build Custom AI Agents Without Developers Learn More
Blog

Top 10 Questions Firms Ask About SMCR -A Guide for Compliance Professionals

Oct 31, 2025

In today’s evolving regulatory landscape, the Senior Managers & Certification Regime (SMCR) remains one of the most critical accountability frameworks for UK financial services. As a Chief Compliance Officer (CCO), you field daily questions from senior management, HR, risk and audit about what SMCR requires, where firms most often stumble, and how upcoming reforms could reshape your programme. This article answers the top 10 questions firms ask about SMCR, translating rules into practical actions. You’ll get clear explanations of scope and firm categorisation, SMF mapping, Statements of Responsibilities (SoRs), the Certification Regime, Conduct Rules, regulatory references and the Directory, the 12-week rule, governance integration, and what the 2025–26 reform proposals may mean for your compliance plan. Throughout, we highlight efficiency plays, culture levers and board-level talking points, so you can lead with confidence and embed SMCR as part of your firm’s governance DNA. 

“Does our firm fall within the SMCR scope and which categorisation applies?” 

One of the first and most common questions firms raise is: “Does SMCR apply to us, and if so which band -Enhanced, Core or Limited-Scope?” As CCO you’ll want to lead that assessment and ensure your board understands the implications. 

Enhanced, Core and Limited-Scope firm classifications
Under the SMCR framework, firms are classified by size, complexity and risk profile into three tiers: 

  • Enhanced firms: the largest and most complex, subject to additional obligations such as extra SMFs, detailed management responsibilities maps, and more intensive supervision. Womble Bond Dickinson+1 
  • Core firms: typical solo-regulated firms that don’t meet the thresholds for Enhanced; the standard SMCR regime applies. 
  • Limited-Scope firms: smaller firms where only certain parts of the regime apply (for example, fewer SMFs or reduced obligations). Womble Bond Dickinson 

Key thresholds and how size, business model and regulatory status affect classification

For example, the FinancialConductAuthority (FCA) has proposed increasing the asset-under-management threshold for Enhanced firms from £50 billion to £65 billion, and intermediary regulated business revenue from £35 million to £45 million, to reflect inflation and reduce the burden on firms near the cusp. DLA Piper+1 Dual-regulated firms (those supervised by both the FCA and the PrudentialRegulationAuthority, PRA) must check both sets of thresholds and requirements. Overseas branches may bring additional scrutiny. 

Dual-regulated firms & overseas branches

If your firm is dual-regulated, you must consider PRA requirements alongside FCA’s -and note that thresholds may differ. Also, if you have an overseas branch or non-UK entity whose activities fall under SMCR, you must map accordingly. A practical example: a UK-based investment firm with an AUM of £60bn may currently fall as Enhanced, but under the proposed threshold increase that may shift to Core status. This has implications for the number of SMFs you must allocate, the frequency of SoR updates, training and audit oversight, and the cost-base of compliance. As CCO you should lead a scenario-modelling where you assess current classification, then test “what if” under proposed thresholds and design a roadmap accordingly. Incorporating the long-tail keyword “SMCR firm scope enhanced vs core classification” into your board-pack helps underline that this is not just a technical exercise but a strategic risk/cost exercise. 

“What are Senior Management Functions (SMFs) and how should we map them?” 

Once the firm’s scope is established, one of the next key questions is: “Which individuals are SMFs and how do we map their responsibilities effectively?” Getting this right is critical: mis-allocation or unclear mapping is a regulatory red flag. 

Defining SMFs: SMF1, SMF3, SMF16 etc.

SMFs (Senior Management Functions) are specific roles defined by the FCA / PRA which require regulator approval (in many cases) and come with prescribed responsibilities and statements of responsibilities (SoRs). For example: 

  • SMF1: Chief Executive 
  • SMF3: Executive Director 
  • SMF16: Compliance Oversight Function 
  • SMF17: Money Laundering Reporting Officer (MLRO)
    More functions exist and vary depending on firm classification. Womble Bond Dickinson+1 

Mapping to the firm’s governance structure

As a CCO, you should lead the mapping exercise: identify all individuals in senior positions, map to the relevant SMF list, analyse overlaps, identify where new roles need approval, ensure SoRs allocate responsibilities clearly, and assess whether any non-executive directors inadvertently fall into SMF scope. Practical steps: 

  1. Create an SMF inventory: current incumbents, roles, functions, responsibilities, approvals status. 
  1. Cross-check role descriptions and team structures against the SMF definitions and guidance (note that regulators are issuing more detailed guidance for SMF7, SMF18, SMF22 roles in current consultation). Passle 
  1. Where individuals perform multiple functions, assess whether separate SMF applications are needed (or whether roles should be consolidated to reduce duplication). 

Practical example: senior manager role mapping in a mid-sized investment firm

Suppose your firm has a head of compliance, a head of risk, a COO and a CFO. The head of compliance likely maps to SMF16. The head of risk might map to SMF4 (Chief Risk Function) if Enhanced firm. The COO might map to SMF24 (Chief Operations Function) or SMF18 (Other Overall Responsibility) depending on duties. You might find the CFO is also performing the SMF3 role but also holds an SMF18. Clarifying allocations, avoiding overlaps (which can open firms up to confusion over Who Does What), and ensuring each SMF holder has a clear and up-to-date SoR is vital. A unique insight: many firms allocate SMFs purely on job title, but better practice is allocate by functionality and controls influence. That way you ensure SMF mapping reflects the real accountability lines, not just job labels. Use the long-tail keyword “SMCR role mapping and prescribed responsibilities” when communicating with the board to show the strategic importance of this activity. 

“How do we allocate and maintain Statements of Responsibilities (SoRs) and Management Responsibilities Maps (MRMs)?” 

Once SMF mapping is complete, the next key question is how to document it and keep it current -hence the importance of SoRs and MRMs. 

Purpose of SoRs and MRMs

A Statement of Responsibilities (SoR) is a document stating what an SMF holder is responsible for -it outlines their responsibilities, any prescribed responsibilities allocated to them, and must be maintained up to date. The purpose is to create clarity and audit-trail that a senior manager knows what they are accountable for, and the firm can show it. For firms in the Enhanced category, a Management Responsibilities Map (MRM) is an internal document mapping out the line of roles and responsibilities inside the firm, showing who has what oversight across business-areas, controls, risk, compliance etc. 

Common pitfalls: unclear allocation, outdated versions

From a CCO perspective, common risks include: 

  • SoRs which are generic, not tailored to the individual or firm business-model. 
  • SoRs not updated when responsibilities change. Under the current regime, firms often update SoRs whenever there is a “significant change” -but the term is vague. With the reform consultations, the regulators are proposing to allow longer periods (up to six months) for SoR updates. Travers Smith+1 
  • MRMs not properly reviewed or controlled, leading to outdated governance maps which may weaken escalation lines, overlap responsibilities or fail to reflect actual controls.
    These issues may expose the firm to regulatory findings that responsibilities were not clear, accountability was blurred, or senior manager oversight was deficient. 

Best practice workflow and documentation controls

For the compliance team, implement a disciplined documentation workflow: 

  • At each SMF appointment or role-change event, trigger a review of the relevant SoR and update if required. 
  • Maintain a register of SoR versions, review dates and upcoming review triggers. 
  • For Enhanced firms, maintain the MRM centrally, review annually (or more frequently if business structure changes), and link it to the internal audit/risk schedule. 
  • Build training and awareness for SMF holders: they must sign or otherwise acknowledge their SoR, understand their prescribed responsibilities and know how they relate to the firm’s governance. 
  • Monitor that SoRs are filed timely (with the regulator if required) and internal copies are stored using version control.
    Unique insight: treat the SoR and MRM not just as regulatory documents, but as living governance artefacts. Connect them to internal performance reviews, succession planning, change-management logs, role-scopes and even board minutes. This ensures that when you’re asked by the regulator “who was responsible for X?” you can trace the chain clearly. Use the long-tail keyword “SMCR statements of responsibilities best practice” when circulating to your team. 

“What is the Certification Regime, and how do we manage certified persons?” 

For many firms the Certification Regime presents both a significant opportunity and a considerable compliance headache. As CCO, you’ll be asked: “Which roles must be certified? What are our obligations? Can we streamline?” 

Roles in scope for certification

The Certification Regime covers individuals who are not senior managers but whose roles involve significant harm risk to customers, the firm or markets. Examples include: material risk takers, those who manage others in certified roles, traders, client-money functions, certain compliance/fraud oversight roles. Womble Bond Dickinson+1
The firm is responsible for assessing whether the role is in scope, certifying the person as fit and proper, keeping records and ensuring annual (or periodic) recertification. 

Annual certification, fit and proper assessment, record-keeping

Key obligations include: 

  • The initial assessment of fitness and propriety by the firm (education, training, competence, honesty, integrity). 
  • Giving the person written notification of certification (or refusal). 
  • Maintaining a register of certified persons and certification functions. 
  • Re-certifying annually.
    This process can be administratively heavy, especially in firms with many certification functions. Many firms face duplication (for example one person may hold multiple certifications or dual-regulated firms may have overlapping roles). 

Duplication risk and efficiency opportunities (especially under reform)

The current reform proposals explicitly target duplication: the FCA estimates the number of certification roles could fall by ~15% if overlapping roles are rationalised. FCA+1 As CCO you should benchmark how many certified persons your firm holds, assess whether roles overlap, explore consolidation, and align certification timing with HR/performance review cycles. A unique insight: treat certification tracking as part of your HR/onboarding ecosystem. If onboarding, role-change, training, appraisal and exit processes all feed into certification, you reduce risk of “missed certification”. Use the long-tail keyword “what is the certification regime under SMCR” when designing your internal briefing. 

“What are the Conduct Rules and how do they apply?” 

While much of SMCR focus is on senior manager functions and certification, the Conduct Rules are arguably the regime’s behavioural backbone. Firms frequently ask: “How do we operationalise the Conduct Rules? Which staff do they apply to? What training and monitoring frameworks do we need?” 

Individual Conduct Rules vs. Senior Manager Conduct Rules

There are two tiers: 

  • Individual Conduct Rules (ICRs) -apply to a wide range of staff in SMCR firms (most employees) and include requirements such as “You must act with integrity”, “You must behave with due skill, care and diligence”, “You must be open and cooperative with regulators”. 
  • Senior Manager Conduct Rules (SMCRs) -apply to Senior Managers and include additional duties such as “You must take reasonable steps to ensure that the business of the firm for which you are responsible is controlled effectively” and “You must ensure that the business of the firm for which you are responsible complies with the relevant requirements and standards of the regulatory system”. Kennedys Law 

Training, monitoring and breach-reporting obligations

As CCO you should ensure: 

  • Conduct Rules training is provided to relevant staff (and refreshed regularly) with evidence of attendance and comprehension. 
  • Mechanisms exist for staff to speak up, report breaches or concerns without fear of retaliation -embedding a culture of challenge and “escalate early”. 
  • Breach monitoring and reporting: firms must identify, record and report reportable Conduct Rule breaches (for example when disciplinary action was taken). Under proposed reforms the FCA is considering distinguishing between reportable and non-reportable breaches. National Law Review+1 
  • Documentation: internal registers, audit trail of breaches, follow-up actions and remediation. 

Embedding a culture of accountability beyond compliance boxes

A unique insight: Many firms treat Conduct Rules training as a tick-the-box exercise. As CCO you can elevate it by connecting Conduct Rules performance into your firm’s culture and performance management framework. For example, tie Conduct Rules behaviours into senior manager appraisals or board-level risk committee minutes. Show that you monitor “escalation culture”, “challenge culture” and “speaking up” -because regulators increasingly expect firms to go beyond documentation and to demonstrate that accountability permeates culture, not just forms. Use the long-tail keyword “SMCR conduct rules obligations for individual accountability” when drafting your training and internal communications. 

“How should we handle regulatory references and the Directory requirements?” 

Another frequent question from HR, compliance and legal teams is: “What do we need to include in regulatory references for individuals, and how do the Directory / public disclosures work under SMCR?” 

What regulatory references must include and timing

Under SMCR, firms must provide regulatory references when a person ceases employment in a relevant function or is proposed to start. The reference must cover the period of employment, including whether the person was subject to disciplinary action, whether they are fit and proper, and whether the firm has concerns about their competence, honesty or integrity. Firms must respond within the timeframe set by regulators (FCA is proposing reducing the turnaround from six weeks to four weeks). Travers Smith HR and compliance should coordinate closely to ensure timely references, maintain reference-logs, and ensure consistency across leavers and joiners. 

The Public Directory (for SMFs) -obligations and updates

The FCA maintains a public Directory of SMF holders and their functions. Firms must keep the directory up to date: when a senior manager leaves or changes role, the Directory entry must be updated within the deadline. The firm also needs to update internal records, SoRs and MRMs accordingly. Under reform proposals the FCA is exploring extending the deadline for Directory updates (e.g., from 7 business days to 20 business days in some cases). Passle 

Avoiding common mis-steps and HR-compliance handover issues

From a CCO perspective, common compliance failings include: delayed reference responses, omission of relevant disciplinary matters, inconsistent wording across references, failure to liaise between HR and compliance, and missing Directory updates. To mitigate these risks: create a master HR/compliance calendar for all leavers/joiners and SMF changes, define clear responsibilities and deadlines, embed standard templates, train HR on SMCR requirements and escalate early if reference timelines are at risk. Use the long-tail keyword “managing SMCR regulatory references requirement” when briefing HR and legal. 

“What happens when we have an interim appointment -how does the ‘12-week rule’ work?” 

Firms often struggle with short-notice senior manager changes, maternity or sickness cover, or reorganisations. The “12-week rule” is a frequent point of confusion, prompting: “What cover do we have before regulatory approval? What are the obligations?” 

Current practical rule: appointing someone for up to 12 weeks without approval

Under the existing regime, if a senior manager (SMF) leaves or is temporarily absent for an unforeseen period, a firm can appoint an interim or replacement for up to 12 weeks without holding full regulator approval. During that period the interim SMF is still subject to SMCR obligations. 

Proposed reform: submit application within 12 weeks rather than decision within 12 weeks

As part of the 2025 reforms, the FCA and PRA propose that firms should have 12 weeks to submit an application for the new SMF rather than having to obtain a decision in that period. That means the interim can remain in the role while the application is under review. Passle+1 The intention is to make the rule more practicable. 

Succession planning, cover arrangements and bridging risk

However, from a compliance view you cannot rely on the 12-week rule as a default solution. As an effective CCO you should ensure: 

  • Succession plans exist for all key SMFs, identifying deputies, handover triggers and documentation. 
  • The interim appointment is assessed for fitness and propriety even if temporary. 
  • The board is informed of any interim cover exceeding a certain period (e.g., 4 weeks) and the reasons. 
  • The firm monitors usage of the 12-week rule (frequency, reasons) and ensures it is not used as a routine substitute for proper recruitment. Regulators emphasise that firms should manage transitions via notice periods and recruitment, rather than repeatedly relying on the 12-week rule. Passle Unique insight: Use your compliance dashboard to track all SMF cover periods, upcoming expirations of SMF incumbents, and 12-week rule triggers. Reporting to the board quarterly on “SMF cover risk” helps you stay ahead of regulatory scrutiny rather than reacting. Use the long-tail keyword “SMCR 12-week rule interim senior manager appointment” when drafting your internal playbook. 

“What are the key control and governance integration points for SMCR?” 

For a Chief Compliance Officer, one of the most strategic questions is: “How do we embed SMCR into our wider governance, risk and compliance (GRC) architecture, rather than treat it as a standalone compliance project?” 

Integration with HR (on-boarding, role changes), risk & compliance, audits

SMCR touches multiple business functions: governance, HR, legal, audit, risk, training, operations. Integration points include: 

  • HR / On-boarding: when recruiting or allocating an SMF or certified person role, SMCR checklist (approval application, fit and proper assessment, SoR update, certification) must be built into offer-letter, job architecture and induction. 
  • Risk & Compliance: alignment of role-responsibilities, escalation lines, threshold reviews, monitoring of conduct and breaches. 
  • Audit/Internal controls: ensuring documentation (SoRs, MRMs, certification logs, references) is auditable, change-logs exist, and controls are tested. 

Monitoring frameworks -dashboards, role-change logs, training trackers

Your compliance team should build dashboards that include: 

  • Number of SMF appointments pending approval 
  • Number of certified person role changes or overdue recertifications 
  • SoR review overdue items 
  • Number and type of Conduct Rule breaches reported 
  • SMF cover periods (including 12-week rule usage) 
  • HR leaver/joiner list and regulatory reference status
    A unique insight: by linking SMCR dashboards to your wider Key Risk Indicators (KRIs) -e.g., staff turnover in certified roles, training completion rates, number of SoR changes per quarter -you demonstrate to senior management and the board that SMCR is a living governance metric, rather than a filing obligation. Use the long-tail keyword “SMCR integration with governance risk and compliance framework” when briefing senior stakeholders. 

“What do the 2025-26 reforms mean for our compliance programme?” 

Many firms ask: “With the wave of proposed SMCR reforms (CP25/21, Treasury legislative review) what changes should we anticipate and how should we respond?” As CCO you must translate regulatory signals into actionable compliance planning. 

Overview of the consultation papers

On 15 July 2025 the FCA published Consultation Paper CP25/21 proposing changes to the SMCR. FCA+1 Concurrently the Treasury and PRA issued consultation documents on the broader review of SMCR. National Law Review+1 These reforms represent the most significant review of SMCR since its introduction. 

Key changes: reducing number of certification roles (~15 %); increasing thresholds for enhanced firms; more flexibility on SoRs

Notable reform proposals: 

  • The FCA estimates approximately 15 % reduction in certification roles may be achievable by removing duplication (e.g., individuals holding overlapping certifications). Passle 
  • The FCA proposes increasing thresholds for Enhanced firm status (AUM, revenue) to reduce the number of firms subject to highest obligations. DLA Piper 
  • The Treasury is consulting on removing the Certification Regime from primary legislation entirely, allowing the FCA/PRA via rules to redesign a more flexible regime. Mayer Brown 
  • Extended timelines for SoR submissions (up to six months) and more flexibility for role changes. Passle
    CCO action plan: gap-analysis, scenario modelling, consultation response
    Action points for you: 
  1. Conduct a gap-analysis of current SMCR framework against the proposed reforms: how many certified persons do you have? Do you have overlapping roles? What’s your pipeline for SMF changes? 
  1. Scenario-modelling: what if thresholds increase and your firm moves from Enhanced to Core? What cost/obligation change would that bring? 
  1. Engage with the regulatory consultation: many firms miss the opportunity to shape outcome. Consider submitting feedback or coordinating via trade-body. 
  1. Update internal timelines: e.g., anticipate final rules mid-2026, ensure business-change calendar captures role impacts. 
  1. Communicate with the board and senior management: share anticipated changes, timings, resource implications, and compliance-opportunities (e.g., freeing up resource from certification duplication).
    A unique insight: View the reform wave as a strategic compliance moment -not just to reduce burden, but to elevate the firm’s SMCR maturity. Use this window to streamline role frameworks, embed governance better and reposition compliance as a business-enabler rather than burden. Use the long-tail keyword “SMCR changes 2025 consultation UK” when circulating your internal briefing or board summary. 

“How do we demonstrate effective accountability to regulators and embed a culture of responsibility?” 

Finally, one of the most pressing questions: “How can we show regulators we are not just ticking boxes under SMCR, but embedding meaningful accountability, transparency and culture?” As CCO you must translate policy into practice and narrative. 

What regulators expect

The FCA states the SMCR aims to “reduce harm to consumers and strengthen market integrity by making individuals more accountable for their conduct and competence”. FCA That means firms should be able to demonstrate, in their governance, training, monitoring, documentation and escalation procedures that they are embedding individual accountability, not just for senior managers but across the business. 

Moving from “tick-box” to “thinking box”: culture, escalation, challenge, speak-up

Some suggestions: 

  • Link SMF statements and certification roles to performance criteria and behavioural expectations, e.g., appraisal of senior managers should reference “how you escalated issues” or “how you ensured your area complied with obligations”. 
  • Encourage a strong “speak-up” environment: the Conduct Rules alone don’t deliver culture -the firm must incentivise reporting of issues, near-misses, controls weakness and ensure feedback loops. 
  • Board and senior management oversight: as CCO you should provide regular reporting on SMCR metrics (SMF changes, SoR updates, certification renewals, training completion, breach trends) and ensure SMCR is on the agenda of risk/compliance committees. 

Example
Consider a situation where a senior manager (SMF16 -head of compliance) leaves and is replaced. If the new SMF’s SoR isn’t updated for six months, the firm may face regulatory censure if a compliance failure occurs in that period. However, if the firm’s governance dashboard flagged the SoR update delay, escalated it, documented board oversight and the replacement completed training and certification in advance, then the firm can demonstrate the controls and governance were in place. That evidences effective accountability, not just regulation-fulfilment.
A unique insight: Use SMCR framework as a corporate narrative to senior management about “who owns risk, who escalates, who is responsible, what we monitor”. This helps shift SMCR from being a compliance burden to being a risk-management tool, visible in board discussions, linked to remuneration/incentives, and integrated into culture. Use the long-tail keyword “embedding SMCR training and culture” when preparing your communications. 

Quick Takeaways 

  • SMCR remains the UK’s central individual-accountability regime -for SMFs, certified persons and conduct rules. 
  • Determine your firm’s categorisation (Enhanced/Core/Limited) early; classification drives obligations and resource demands. 
  • Map and document SMFs, SoRs and MRMs accurately; treat them as living governance artefacts, not static forms. 
  • Certification regime demands uplift: certified persons must be identified, assessed and tracked -treat it as part of your HR-governance ecosystem. 
  • Conduct Rules are the behavioural backbone -training, monitoring and escalation culture are essential for credible compliance. 
  • Regulatory references and Directory updates are often overlooked -ensure HR and compliance are aligned on timing, content and duties. 
  • The 12-week rule for interim senior manager cover is evolving -build succession planning, monitoring and controls around it. 
  • Integrate SMCR into your wider GRC architecture: dashboards, role-change logs, KRIs, training trackers and board reporting make a difference. 
  • 2025-26 reforms present both challenge and opportunity -use them to streamline, embed governance and elevate compliance from “form-filling” to strategic value. 
  • Avoid common pitfalls through strong role-mapping, documentation discipline, proactive reform scenario-planning and culture-driven accountability. 

For Chief Compliance Officers, the SMCR is far more than just a regulatory box to tick. It is the governance backbone of your firm’s accountability framework. By understanding the top questions -from scope and categorisation, through role mapping, SoRs, certification, conduct rules, regulatory references and interim cover -you can lead your firm with clarity and control. More importantly, by integrating SMCR into your broader governance, risk and compliance architecture, embedding robust monitoring and culture-driven accountability, you can turn a regulatory requirement into a strategic asset. With the significant reforms now underway, this is a pivotal moment for compliance leaders to act proactively: model scenarios, streamline frameworks, engage senior management and position SMCR not just as compliance, but as risk-management excellence. If you begin now, your firm will be well-placed to adapt to change, maintain robust control and demonstrate to regulators—and your board—that accountability is not simply a principle but a living reality. 

 

Table of Contents

Index