SMF Personal Liability: What Senior Managers Risk
Every firm authorised by the FCA has to allocate its Senior Management Functions to named individuals. On paper, that looks like an org chart exercise — someone becomes SMF1, someone becomes SMF16, someone becomes SMF17. In practice, it is one of the more consequential decisions a growing financial services firm makes, because it attaches personal regulatory accountability to a specific person, by name, on a public register.
We work with FCA-regulated firms across investment management, payments, consumer credit and wealth every week, placing candidates into exactly these functions. The question we get asked most often — by both firms and candidates — is not “what does the role involve” but “what actually happens if it goes wrong.” This article sets out the honest answer, drawing on real FCA enforcement outcomes rather than theoretical risk.
What the Senior Managers and Certification Regime Actually Changed
Before the Senior Managers and Certification Regime (SM&CR) came into force, regulatory accountability for a firm’s failings sat primarily with the firm itself. Individuals could be swept up in enforcement action, but establishing personal culpability required the regulator to build a case against a specific person’s conduct — often a slow and evidentially difficult process.
SM&CR inverted that dynamic for the most senior roles. Anyone approved to hold a Senior Management Function takes on a statutory Duty of Responsibility. If a regulatory breach occurs within their area of accountability, the burden shifts: the FCA does not need to prove the individual caused the failure. Instead, the individual has to be able to show they took reasonable steps to prevent it, identify it, or stop it continuing. That is a meaningfully different starting position from ordinary employment or even ordinary directorship.
This applies across the full range of Senior Management Functions — not just the compliance-specific ones. SMF1 (Chief Executive), SMF3 (Executive Director), SMF9 (Chairman), SMF16 (Compliance Oversight), SMF17 (Money Laundering Reporting Officer), SMF2 (Chief Finance), and the others each carry their own Statement of Responsibilities, and each holder is personally on the hook for their own area.
The Mechanics of Personal Accountability
A few structural features make SMF liability different from ordinary senior employment:
Personal FCA approval. A firm cannot simply appoint someone to a Senior Management Function. It submits a Form A application, and the individual is vetted and approved by the FCA before they can perform the role. Once approved, their name appears on the FCA’s public register, searchable by clients, counterparties, journalists and future employers alike.
A Statement of Responsibilities. Each SMF holder must have a current, written statement setting out precisely what they are accountable for. This is not internal housekeeping — the FCA can and does request these documents as part of supervisory work, and they form the reference point in any subsequent investigation.
Ongoing certification, not a one-off check. Firms must recertify annually that each SMF holder remains fit and proper. This sits alongside the FCA Conduct Rules, which apply to the individual at all times, not just during a live incident.
Enforcement can outlast the job. The FCA can and does take action against former SMF holders years after they have left a firm, as the cases below show. Moving on does not close the exposure.
What Enforcement Actually Looks Like: Real Cases
The theoretical exposure is significant, but it is worth being precise about how often it actually crystallises, and what it looks like when it does. Individual SMF enforcement cases are genuinely uncommon — but when they happen, the consequences are severe and the reasoning is instructive for anyone stepping into one of these roles.
Steven Smith — MLRO and Compliance Oversight, Sonali Bank (UK). FCA Final Notice, 12 October 2016. The FCA fined Smith £17,900 and prohibited him from ever again performing the MLRO or compliance oversight functions at a regulated firm — a prohibition explicitly extended to cover the equivalent SMF16 and SMF17 functions under the newer regime. What makes this case instructive is what the FCA did, and did not, accept as mitigation. The regulator acknowledged that Smith did not have sufficient senior management support and was overworked. That context reduced the outcome, but did not prevent it: the FCA still found his failings serious in their own right, because he had not taken any of the steps available to an MLRO in that position — escalating concerns to senior management, to the board or relevant committees, to internal audit, through his own annual MLRO report, or directly and confidentially to the FCA itself. Being under-resourced was not, on its own, a defence to failing to escalate. The bank itself was fined £3.25 million separately for the underlying AML systems failings.
David Brian Price — Executive Director and MLRO, CFP Management. FCA Decision Notice, 2023. Price received a financial penalty, a prohibition order, and withdrawal of his approvals. Note this is a decision notice rather than a final notice — procedurally, that means it reflects the FCA’s determination at that stage and can still be referred to the Upper Tribunal, rather than representing a fully concluded matter in the way a final notice does. The FCA’s finding centred on a failure to act with integrity in ensuring a pension transfer model complied with regulatory requirements, with his conduct assessed as reckless rather than merely negligent. Industry commentary at the time noted this was the first individual MLRO enforcement action since the Sonali Bank case nearly a decade earlier, underlining how rare — but how serious — these actions are.
The Trend Line Is Moving in One Direction
Individual cases remain infrequent in absolute terms, but the direction of travel matters more than the historical base rate. In the FCA’s most recent enforcement year, penalties imposed on individuals more than tripled compared to the prior year, and total fines across all enforcement action rose from roughly £38 million to somewhere between £179 million and £186 million. The majority of cases concerned financial crime, deficiencies in anti-money laundering controls, and governance failures — precisely the territory SMF16 and SMF17 holders are personally accountable for.
The FCA has also broadened its toolkit beyond fines: greater use of interventions, authorisation revocations, and other supervisory powers means a firm — and its senior managers — can face serious consequences well before a case reaches formal enforcement and a final notice. Firms under active supervision commonly see voluntary or imposed requirements long before anything becomes public, and named senior managers are the individuals whose conduct and competence come under scrutiny throughout that process.
Why the Fine Is Rarely the Real Penalty
Set against corporate fines running into the tens or hundreds of millions, a £17,900 personal fine can look almost incidental. It is not the number that matters. The prohibition order is the real consequence: a permanent, publicly searchable bar from ever again performing a Senior Management Function at any FCA-regulated firm. For a qualified accountant, compliance professional or executive who has built a career in regulated financial services, that is not a career setback — it is a career ending event in that sector.
This is precisely why candidates who are genuinely qualified to hold SMF16 or SMF17 — people with real, hands-on experience of client money reconciliation, AML frameworks and regulatory reporting — price this risk into what they will accept. A firm advertising one of these functions as a standard management role, without reflecting the personal exposure in the compensation and support structure around it, will struggle to attract someone senior enough to actually carry it well.
Structural Risk Factors Firms Should Address
A handful of structural issues come up repeatedly in FCA findings and in our own conversations with clients building out SMF-holding roles:
Self-review conflicts. Where the same individual prepares financial or compliance information and then signs off on its adequacy in an oversight capacity, that person has a materially harder job demonstrating “reasonable steps” if something goes wrong later. Firms taking on this structure — often unavoidable in smaller regulated businesses — should document how the conflict is managed, for example through an external compliance reviewer or periodic independent audit.
Under-resourcing. In the Sonali Bank case, part of the finding turned on inadequate resourcing and support from senior management. A firm that appoints an SMF16 or SMF17 holder without giving them the budget, headcount or authority to do the job properly is creating exactly the conditions that produced that enforcement outcome.
Handover and transition periods. Where a Senior Management Function is being transferred from one individual to another — common in growing firms bringing regulatory responsibility in-house for the first time — the handover period itself is a point of elevated risk. Responsibilities need to be clearly documented and the incoming holder needs genuine, evidenced readiness before the Form A application goes in, not just proximity to the outgoing holder.
Compensation misaligned with risk. Pricing an SMF-carrying role as though it were a standard operational management position, without reflecting the personal regulatory exposure, tends to either deter genuinely qualified candidates or attract candidates who have not fully understood what they are taking on. Neither outcome serves the firm well.
What This Means in Practice
For firms building out or restructuring their senior management function holders, the practical takeaways are straightforward. Be honest about the scope of accountability in the role from the outset — vague job titles and understated Statements of Responsibilities do not reduce real exposure, they just create confusion later. Resource the function properly, both in terms of budget and organisational authority. Document how any structural conflicts, such as self-review, are managed on an ongoing basis. And compensate the role in line with the personal risk being carried, not simply against a generic finance or compliance manager benchmark.
For individuals considering taking on an SMF16, SMF17 or any other Senior Management Function, the message from the enforcement record is consistent: genuine competence and documented reasonable steps are the best — and largely only — protection available. Enforcement cases turn on whether the individual can show they did what a competent person in that role should have done, with the resources and authority they had. That is worth establishing and evidencing from day one in the role, not after something has already gone wrong.
How FD Capital Helps
We place Senior Management Function holders — SMF16, SMF17, SMF2, SMF18 and related compliance and financial crime roles — into FCA-regulated firms on a permanent, interim and fractional basis. That includes firms taking on regulatory responsibility for the first time, and firms needing experienced cover during a supervisory or enforcement process. Because we work exclusively in this space, we can usually identify candidates with genuine, evidenced hands-on experience of the specific function a firm needs filled, rather than adjacent generalist experience.
If you are building out compliance or financial crime leadership, or need to understand what a role like this should realistically cost given the personal accountability attached, get in touch.
Related Reading
PRACTICE AREA
SMF16: Compliance Oversight Function Guide
A full breakdown of what the SMF16 role covers, how FCA approval works, and current Head of Compliance compensation benchmarks.
PRACTICE AREA
SMF17: The MLRO Function Explained
What the Money Laundering Reporting Officer role actually involves, how it interacts with SMF16, and where MLRO recruitment is tightest.
Adrian Lawrence FCA — Founder, FD Capital
Fellow of the ICAEW | ICAEW Practising Certificate | CFO placements since 2018
Adrian holds a practising certificate from the ICAEW and brings over two decades of experience in finance leadership and executive search. Before founding FD Capital he worked across private, listed, owner-managed and PE-backed organisations, giving him direct experience of the finance challenges and hiring decisions that CFOs and compliance leaders are appointed to solve. He personally leads our most senior CFO and compliance searches, including SMF16, SMF17 and related FCA-regulated appointments, and conducts candidate assessments himself.
FD Capital Recruitment Ltd is registered at Companies House (no. 13329383) and has been providing CFOs and Finance Directors since 2018, operated by an ICAEW-registered practice. Our founder Adrian Lawrence FCA holds an ICAEW practising certificate.
Related posts:
Appropriateness Assessments Under MiFID II: A Practical Guide
July 24, 2026The Financial Promotions Compliance Role: Skills and Career Path
June 16, 2026PEP screening in practice: dealing with false positives at scale
May 16, 2026Debt Collection Compliance Under CONC
July 14, 2026ICT incident reporting under DORA: timelines and templates
May 27, 2026Common Financial Promotions Breaches and How to Avoid Them
June 16, 2026Adrian Lawrence FCA is the founder of FD Capital and a Fellow of the Institute of Chartered Accountants in England and Wales (ICAEW). He holds a BSc from Queen Mary College, University of London, and has over 25 years of experience as a Chartered Accountant and finance leader working with private, PE-backed and owner-managed businesses across the UK. He founded FD Capital to connect growing businesses with the Finance Directors and CFOs they need to scale — and personally interviews candidates for senior finance appointments.