CRO Career Progression: From Risk Manager to SMF4
Chief Risk Officer is one of the most consequential appointments a regulated firm makes, and at most firms it is a controlled function — SMF4, the Chief Risk function under the Senior Managers and Certification Regime. This article sets out the realistic route from risk manager to SMF4: the experience that builds toward it, what the regulator expects, and how to position yourself for the step up.
It is written for risk professionals aiming at the top risk role, and for firms trying to understand what a credible SMF4 candidate looks like. For the role itself in detail, our SMF4 Chief Risk Officer function guide covers the scope and responsibilities in full.
What SMF4 actually carries
The starting point is understanding what you are progressing toward. SMF4 is a senior management function, which means FCA pre-approval before appointment, a Statement of Responsibilities setting out what you own, the Duty of Responsibility under section 66B FSMA, and Conduct Rules accountability. The holder is personally accountable for the firm’s risk framework — not merely responsible for running a team.
The two core obligations are setting and overseeing the firm’s risk exposures, and reporting directly to the governing body on risk management. In Core firms SMF4 typically reports to the CEO; in Enhanced firms it may sit on the board or report to the Chair of the Risk Committee. That reporting line matters, because it shapes how independent the role genuinely is.
The experience that builds toward it
There is no single route, but credible SMF4 candidates almost always bring breadth across the risk disciplines rather than depth in one. The areas that matter most:
- Enterprise risk framework — designing and running a risk framework proportionate to the firm, not just administering one someone else built.
- Operational resilience — now central to the role, covering important business services, impact tolerances and testing.
- Operational and technology risk — including ICT and third-party risk, which have moved from specialist concerns to core SMF4 territory.
- Risk reporting to a board — the ability to give a governing body a clear, honest picture of exposure rather than a data dump.
- Regulatory engagement — direct experience of supervisory dialogue on risk matters.
The SYSC sourcebook sets the core requirements — a risk management function with appropriate authority, resources and access to information, supported by policies and procedures that are genuinely reviewed rather than filed. A candidate who has built that, rather than inherited it, is materially stronger.
The modern SMF4 brief has widened
Candidates approaching SMF4 for the first time need to recognise how the role has changed. It is no longer sufficient to bring traditional financial risk expertise — credit, market, liquidity. Firms now expect an integrated view that combines financial risk with operational, technology and third-party risk, alongside familiarity with operational resilience obligations. A risk manager whose experience is purely financial-risk shaped will find the gap to SMF4 wider than they expect.
Where SMF4 sits against the other functions
Understanding the boundaries is part of being credible in the role, and interviewers probe it. SMF4 owns risk oversight as the second line. SMF24, the Chief Operations function in Enhanced firms, owns operational delivery in the first line — the boundary between the two needs explicit governance and is a common source of confusion. SMF17, the MLRO, owns financial crime risk operationally, though it fits within the broader framework SMF4 oversees. And internal audit, the third line, is independent of SMF4 entirely.
A candidate who can articulate those boundaries clearly — and say how they would govern the overlaps — demonstrates the systemic understanding the role requires.
Building the operational resilience credential
If one area separates candidates who get to SMF4 from those who stall, it is operational resilience. The framework requires firms to identify their important business services, set impact tolerances for each, test whether they can stay within those tolerances through severe but plausible disruption, and remediate where they cannot. SMF4 typically owns this, and it is now a standing item in supervisory dialogue.
A risk manager who has run an important business service mapping exercise, set and defended impact tolerances, or led scenario testing has a concrete credential that is hard to fake in interview. One who has only read about it does not. If you are aiming at SMF4 and lack this exposure, it is the single most valuable gap to close.
Third-party and technology risk
The second gap is third-party risk. Regulated firms depend on outsourced providers and technology vendors, and the regulator expects the risk function to understand and oversee that dependency — including where a provider is critical enough that its failure would threaten the firm’s important business services. Candidates who can talk credibly about vendor due diligence, concentration risk, exit planning and the oversight of critical providers demonstrate the modern breadth of the role.
What interviewers actually probe
Firms and their advisers test SMF4 candidates on a consistent set of themes: how you have set risk appetite and made it operational rather than aspirational; how you have handled a disagreement with the first line or with the executive; how you would report an uncomfortable risk position to a board that does not want to hear it; how you think about your personal accountability under the Duty of Responsibility; and how you would govern the boundary with operations and internal audit.
The strongest answers are specific and slightly uncomfortable — a candidate who can describe a time they held a position against commercial pressure is more convincing than one who describes a frictionless framework rollout.
The fit and proper gate
Because SMF4 requires FCA approval, the fit and proper standard is a genuine gate rather than a formality. The regulator assesses honesty and integrity, competence and capability, and financial soundness. The firm must satisfy itself first and evidence that assessment. In practice this means an aspiring SMF4 needs not just capability but a clean professional and regulatory history, and the ability to demonstrate competence with specifics rather than assertions. The FCA has been explicit that the level of skill and knowledge expected should be in line with the size of the firm and its risk of harm — so the bar rises with the firm.
Positioning yourself for the step
The practical moves are consistent. Broaden deliberately across risk types rather than deepening in one. Get operational resilience and technology risk exposure, because their absence is now the most common gap. Seek board-facing work — presenting to a risk committee is materially different from writing the pack. Build regulatory engagement experience. And understand SM&CR from the inside, ideally holding a certified function that builds toward senior accountability.
Be realistic about firm type, too. A first SMF4 at a smaller or newly-authorised firm often comes sooner and carries broader personal responsibility; at a large firm the role is reached later and is more specialised but sits within deeper support. Many risk leaders make the step at a smaller firm and grow from there.
A note on timelines
SMF4 mandates typically run 16–26 weeks end to end, including notice periods and FCA approval. For candidates, that means a move is a long process rather than a quick switch — worth factoring into career planning. For firms, it means starting the search well before the incumbent leaves.
FD Capital recruits Chief Risk Officers and SMF4 holders into FCA-regulated firms, and advises risk professionals building toward the role.
Making the move: practical advice
For risk professionals actively working toward SMF4, a few practical points recur. Take the broadening move even where it looks lateral — a sideways step into operational or technology risk from a financial risk background is often worth more than a promotion within your existing specialism. Volunteer for the resilience and third-party work that others avoid, because that is where the scarcity is. Ask to present to the risk committee rather than only writing for it.
And treat the Statement of Responsibilities as a career document. Reading the statements attached to SMF4 roles tells you precisely what the regulator expects the holder to own, which is a better guide to preparation than any job advertisement.
Call 020 3287 9501 or email recruitment@fdcapital.co.uk to discuss an SMF4 or risk leadership appointment, or your route toward one.
FD Capital — SMF4 and Risk Leadership Recruitment
Fellow of the ICAEW | Placing Chief Risk Officers and SM&CR function holders into FCA-regulated firms since 2018. 4,600+ network. 160+ placements. Shortlists in 3–7 working days.
Related reading and services
The SMF4 role, scope and responsibilities in full.
The Senior Managers and Certification Regime explained.
The route to the MLRO function and what firms look for.
Senior risk and compliance leaders for regulated firms.
About the author
Adrian Lawrence FCA is the founder and Managing Director of FD Capital. A Fellow of the Institute of Chartered Accountants in England and Wales and a former listed-company Finance Director, he leads every risk and compliance mandate FD Capital accepts personally. Verify his ICAEW membership.
Call 020 3287 9501 or email recruitment@fdcapital.co.uk.
This article is general information about UK financial services regulation and recruitment practice. It is not legal or regulatory advice. Firms and individuals should take their own professional advice on their specific circumstances.
Related posts:
SUP 15: What Firms Must Notify the FCA and When
June 7, 2026DAML requests in practice: how the consent regime actually works
May 18, 2026How Consumer Duty Has Reshaped the SMF16 Compliance Oversight Role
May 5, 2026Career Paths to SMF16: Positioning for Compliance Oversight Roles
May 30, 2026UK MLRO salary 2026: what an MLRO earns by firm type and size
May 16, 2026Head of Internal Audit: Career Path at FCA-Regulated Firms
July 25, 2026
Adrian Lawrence FCA is the founder of FD Capital and a Fellow of the Institute of Chartered Accountants in England and Wales (ICAEW). He holds a BSc from Queen Mary College, University of London, and has over 25 years of experience as a Chartered Accountant and finance leader working with private, PE-backed and owner-managed businesses across the UK. He founded FD Capital to connect growing businesses with the Finance Directors and CFOs they need to scale — and personally interviews candidates for senior finance appointments.




