Filing a Form A to appoint a Senior Management Function (SMF) tells the Financial Conduct Authority (FCA) exactly who is expected to take the fall if a regulatory process breaks. However, it rarely tells your own team who has the authority to prevent that break in the first place. This gap between the paper filing and the daily operational reality is where most compliance failures originate.
In our experience supporting firms through the complexities of the Senior Managers and Certification Regime (SMCR), we have found that many businesses mistake the successful appointment of a candidate for the successful implementation of the regime. The former is a administrative milestone; the latter is a cultural and operational transformation. By April 2026, the regulators have made it clear that they are moving beyond assessing whether you have the right people in the right chairs to evaluating how those people exercise their specific responsibilities during a crisis.
The Core Comparison: Form-Deep Compliance vs. Operational Accountability
When you establish an FCA application or update your governance structure, the baseline requirement is simple enough to understand. You must identify and appoint your key senior managers, typically including a Chief Executive (SMF1), a Compliance Oversight function (SMF16), and a Money Laundering Reporting Officer (SMF17). Each individual submits a Form A, demonstrating their fitness and propriety through qualifications, professional history, and financial soundness.
This is "form-deep" compliance. It is the static layer of the regime that exists within your compliance manual and on the FCA’s internal systems. While essential—especially considering that 2026 FCA Authorisation standards are increasingly critical of automated or templated submissions—this layer does not actually manage risk. It merely names the person responsible for it.
True operational accountability is dynamic. It is the "practice" side of the equation. It involves how decisions are actually made, routed, and executed on a Tuesday afternoon when the Compliance Officer is in a meeting and a high-value trade is stuck in a bottleneck. If your accountability mapping stops at the regulatory filing, you have a structural vulnerability. You have created a "single point of failure" without providing that person the operational levers required to manage their mandated area of responsibility.
Across the firms we have worked with, we see a recurring pattern: the SMF17 (MLRO) is legally accountable for AML failures, but the sales team owns the onboarding software and determines the pace of customer acquisition. When those two forces collide, form-deep compliance says the MLRO is responsible. Practice says the MLRO was never given the decision rights to halt the process. This is the disconnect that leads to the 57 closed SMCR investigations the FCA recorded in recent years, where even if enforcement action was not always taken, the investigative process itself caused massive reputational and financial strain.
The Breakdown: Where SMF Mapping Fails in Practice
Most strategic plans and compliance frameworks look impressive on paper, but they crash into the messy world of cross-departmental execution. Static responsibility maps are silos. They suggest that the SMF16 owns "Compliance" as if compliance were a standalone department that exists in a vacuum. In reality, compliance is a outcome of every other business process, from marketing to product development.
As noted in Incrementa’s Guide to Business Process Flow, systemic failures usually happen in the handoffs between departments. Information gets lost between marketing and sales, or between sales and operations. In a regulated firm, these handoffs are regulatory risk zones. For example, if the marketing department creates an advertisement that overpromises returns, the SMF16 might not see it until it is already live.
The breakdown was not in the result—the non-compliant ad—it was in the handoff between the creative team and the oversight function. If your SMCR mapping does not specifically address these points of interaction, you are operating with a map that has no roads, only destinations.
We often see firms suffering from what we call "audit fatigue." They pass internal and external audits by showing their Statements of Responsibilities (SoRs), but they still face operational incidents because no one has defined the decision rights for when things go wrong. A standard SoR is a job description; an operational accountability map is a decision-operating model. Without the latter, the former is just a liability anchor for your senior managers.
Head-to-Head: The 6 Questions That Expose Execution Risk
To bridge the gap between paper and practice, we recommend moving away from the standard RACI (Responsible, Accountable, Consulted, Informed) matrix. RACI is often too passive for high-stakes regulatory environments. It tells you who to talk to, but it does not always tell you who has the final "yes" or "no" power when time is of the essence.
Instead, we apply Errol Allen’s 6 process mapping questions to reveal ownership gaps and timing bottlenecks that a basic SMCR filing misses.
-
WHO: This must clarify not just who participates, but who owns the outcome. In an SMCR context, who has the decision authority when execution stalls? If a transaction is flagged by the system, who has the final authority to override or confirm that flag, and does that person align with your SMF17’s delegated authority?
-
WHAT: What defines "done"? In compliance, "done" is not just finishing a task; it is generating the management information (MI) required to prove the task was done correctly. If your SMF16 cannot see the data, they cannot be accountable for the outcome.
-
WHEN: Establish strict timing and escalation points. If a breach is detected, how many minutes or hours can pass before it reaches the relevant SMF? The SM&CR Personal Liability Guide highlights that delays in escalation are a primary reason why the FCA pursues personal liability.
-
WHERE: Identify the systems and the data location. If your accountability map says the CEO is responsible for culture, but the data on employee conduct is buried in an HR system the CEO never looks at, the mapping is a fiction.
-
HOW: Define the repeatability and quality checks. How does the firm ensure that the Senior Manager is actually exercising their "Duty of Responsibility"? This requires evidence-based routines, not just annual attestations.
-
WHY: Does every step in your decision flow support your current regulatory strategy, or is it a legacy habit? If you are still following processes designed before the Consumer Duty or the latest PRA mandates, you are carrying unnecessary execution risk.
By running these questions through your operational workflows, you quickly find that the "Who" listed on your official SMCR map is often three or four layers removed from the actual decision-making trigger. This distance is where negligence occurs.
The Verdict: Upgrading Your Compliance Framework
To turn regulation into something your firm can actually run, you must move toward a decision-operating model. We frequently advocate for the McKinsey decision rights and accountability framework, which focuses on naming the few decisions that truly drive value and risk in the organization.
This framework requires three specific upgrades to your current approach. First, assign a single point of accountability for each decision, not a committee. Committees are where accountability goes to die. Second, time-box the consultation process. In a fast-moving financial firm, you cannot wait indefinitely for "input" from five different departments. Third, embed these decisions into simple, repeatable routines.
This level of granularity is exactly what we have built into our SMCR Responsibilities Mapping Playbook (https://bit.ly/SMCRPlaybk). While legacy compliance manuals offer a set of rules to follow, this playbook offers a framework for how to lead. It helps you identify the specific triggers that require Senior Manager intervention and provides the tools to evidence that intervention for the FCA.
Clients on our Silver and Gold retainers receive this full playbook (retail value £299) as part of their package. We do this because we know that a firm with clear operational handoffs is a firm that is much easier to defend during a regulatory audit. Whether you are an established investment firm in London or a scaling Fintech, the goal remains the same: ensuring that your paper filings are an accurate reflection of your daily operational truth.
Compliance should not be a weight that slows you down. When accountability is mapped correctly to daily decisions, it becomes a system for faster, more confident growth. You are no longer guessing who has the authority to move forward; you have a documented, evidence-based process that protects your Senior Managers and your firm simultaneously.
Check Out our FREE Compliance Playbook at https://bit.ly/CCCDPlaybook.
Call us on 0800 689 0190 or Int +44 208 243 8620
Email info@complianceconsultant.org
Follow us
- Facebook: https://www.facebook.com/ComplianceConsultant
- Twitter: https://twitter.com/complianceconst
- Instagram: https://www.instagram.com/ukcomplianceconsultant
- LinkedIn: https://www.linkedin.com/company/compliance-consultant-uk
- Pinterest: http://www.pinterest.com/ComplianceConst/
5 Min Webinars - https://bit.ly/CD5MinWeb
Compliance Doctor Podcasts https://bit.ly/UKCDPodcasts