SM&CR was built for banks. Fund managers are paying the price.
the senior managers and certification regime in SYSC 23 to 27 and the duty of responsibility in FSMA s.66A; the conduct rules in COCON; and the FCA's SM&CR review (the joint discussion paper DP23/3, the FCA's consultation, and the first-phase reforms in PS26/6, 2026).
The senior managers and certification regime was designed to fix a banking problem. After 2008, regulators needed a way to trace responsibility inside large, complicated banks, so that when something failed there was a named person to answer for it rather than a committee that could shrug collectively. For that job it works. The trouble starts when the same regime is dropped onto a fund manager, because a fund manager doesn’t look anything like a bank. It looks like a partnership, or a lean firm where the same handful of people wear several hats, where administration and custody are outsourced, and where the big calls are made in committee. SM&CR was designed for banks, so fund-manager individuals can end up personally liable for collective decisions, or for functions they don’t run.
This Deep Dive is about that mismatch and what to do with it. The task is to make the accountability real and evidenced, inside a firm the regime wasn’t built for. Reform is under way, and a fund manager needs to read it accurately, because the personal accountability at the core of the regime isn’t going anywhere. SM&CR can’t be made safe by treating it as paperwork. What works is allocating accountability to the way the firm genuinely decides and operates, then leaving a record that the accountable people took the steps the regime asks of them.
The regulators have been open about where the regime came from. In their joint work on its future they accepted that SM&CR was built to map responsibility inside large, complicated banks, places with clear reporting lines, internal decision-making and a deep hierarchy. A fund manager differs from a bank in three ways that matter for accountability.
It is often a partnership rather than a corporate hierarchy, so the tidy “function reports to board” line the regime assumes doesn’t exist in the same form. It leans heavily on outsourcing and delegation, to fund administrators, transfer agents, depositaries and, very often, to an investment manager in another group entity, so that many of the functions the firm answers for are carried out by people it doesn’t employ. And its decisions get made together, through investment, valuation and risk committees rather than by one accountable executive, so the call the regime wants to pin on a single named person was in fact taken by several.
The result is individual liability for collective decisions. A senior manager who holds a given prescribed responsibility can be accountable, personally, for a decision reached by a committee, argued over by colleagues and shaped by an outsourced provider, none of whom carries the same exposure. The regime asks who is responsible, the firm gives one name because it has to, and that name then carries a liability that doesn’t match the spread-out way the decision was really made. This follows from applying a hierarchical regime to a business that isn’t a hierarchy, and it bites hardest at small firms where one or two people hold most of the senior management functions.
The live obligations are unchanged by the mismatch. The regime sits in SYSC 23 to 27 and catches a fund manager as an SM&CR firm, classified as core, enhanced or limited-scope. Most fund managers are core firms, and that carries a consequence worth understanding. The full management responsibilities map required of enhanced firms under SYSC 25, and the enhanced apparatus generally, only applies above a high threshold, broadly £50bn of assets under management, so a typical manager isn’t obliged to keep the formal map a big bank maintains. Informal allocation is easier but leaves accountability vague. The responsibilities still have to be allocated; done informally, they blur.
There are four substantive obligations. Senior management functions have to be allocated to approved individuals, each holding a statement of responsibilities that spells out what they answer for. Certain prescribed responsibilities, listed at SYSC 24.2.6R, must be handed to senior managers; they cover the running of the senior managers and certification regimes, financial-crime systems, the independence of internal audit, compliance and risk, and the firm’s business model, among others. Each senior manager is subject to the duty of responsibility under FSMA s.66A, which holds them to taking the steps a person in their position could reasonably be expected to take to avoid a regulatory breach in their area, with the burden on the FCA to show those steps weren’t taken. And the certification regime under SYSC 27 requires the firm to certify, at least once a year, that the people performing significant-harm functions are fit and proper. For a fund manager those functions take in client-dealing, material risk-takers and, worth flagging, algorithmic trading.
The bank-shaped regime puts real, individual accountability on the people who run a fund manager, and the awkward fit doesn’t reduce it. If anything it does the reverse. The harder accountability is to map, the more deliberately it has to be allocated.
The mismatch creates four specific exposures worth managing.
The first is individual liability for collective decisions. Where a committee decides and one SMF answers for it, that SMF has to be able to show the steps they personally took: the questions they raised, the information they insisted on, the challenge they put on the record, even though the decision itself was shared. The reasonable-steps defence is personal, so each senior manager needs their own evidence.
The second is accountability for outsourced functions. SYSC 8 is explicit that delegating a function does not delegate the responsibility, so a senior manager stays on the hook for an administrator’s or a delegate’s performance. The exposure covers work done by people the firm doesn’t employ, which means the SMF’s reasonable steps become steps of oversight, and that oversight has to leave a trail.
The third is single-point-of-failure concentration. At small firms one person often holds compliance oversight and the money-laundering function, and frequently more besides, which stacks up not just the workload but the personal liability. A regime designed to spread accountability across a bank’s hierarchy ends up, at a small fund manager, loading it onto one person who then carries the duty of responsibility for everything at once.
The fourth is the reasonable-steps evidence gap. The duty of responsibility turns on whether the senior manager took reasonable steps, and the way you prove reasonable steps is with a contemporaneous record of them. A firm that runs on the personal ability of its senior people, but without the records that show what those people did, leaves them defending the duty of responsibility from memory.
There is a fifth gap, common among newer managers using an appointed-representative or host-AIFM structure. Many smaller managers operate under a host authorised fund manager, or as an appointed representative of a principal, borrowing another firm’s permissions while they build their own. That arrangement splits accountability in a way the bank-shaped regime handles badly. The host or principal carries regulatory responsibility for the activity, with its own senior managers answerable, while the people actually making the investment decisions sit inside the smaller firm. When something goes wrong, working out who took the reasonable steps, the host’s named senior manager who was meant to oversee, or the appointed representative’s people who made the call, is genuinely hard, and both sides can end up exposed for the other’s conduct. The FCA has tightened what it expects of principals overseeing their appointed representatives for that reason, because the split has been a source of harm. A manager working this way should be unusually clear, and unusually well-evidenced, about which decisions and which oversight steps are owned where. Under SMCR a named accountable individual is required on each side; structural ambiguity is not a defence.
The reform should be read accurately, not hopefully. The regulators opened a review through their joint discussion paper, the FCA consulted, and the first phase of reforms has now landed, with a second, legislative phase signalled to follow. Industry asked for the burden to come down a long way, and the reforms move that way. The first phase cuts prescription and process. The proposed second phase would go further still: potentially lifting the certification regime out of primary legislation, including the annual recertification requirement, and removing the statutory statement-of-responsibilities requirement, in favour of something more proportionate.
What the reform leaves alone is the core. The senior management functions, compliance oversight and the money-laundering function among them, stay. The duty of responsibility and the reasonable-steps test stay. The individual accountability that is the whole reason the regime exists stays. The reform trims documentation and prescription, not the personal accountability itself. If anything it makes the substance count for more. The core question stays: did the accountable individual take reasonable steps, and can they show it? That question — whether there are records, not just recollection — runs through the FCA’s current work.
Allocate accountability, and evidence it, in a way that matches how the firm actually works. Five elements.
Allocation that matches reality. The statements of responsibilities and the split of prescribed responsibilities should reflect how the firm genuinely decides and who really owns each area, not a bank template imported wholesale. Where a decision is collective, name who is accountable for the process and the oversight, so the line stays clear even when the call is shared.
Reasonable-steps evidence built into how the firm runs. Each senior manager should leave a contemporaneous trail of what they do, the questions they raise, the information they require, the challenge they put down, so the duty of responsibility can be answered from records rather than recollection.
Oversight of outsourced functions, on the record. For work the firm delegates, the accountable SMF should be able to show the oversight they exercised: the service levels held to, the reporting reviewed, the issues escalated. Oversight has to leave a documented trail to be evidenced.
Deliberate management of concentration. Where one person holds several senior management functions, recognise that both the workload and the personal liability are piling up on them, and do something about it, through real support, independent challenge, or making sure that single named person isn’t the only place every control rests. Accountability shouldn’t concentrate on one person.
Certification done properly. The significant-harm functions, client-dealing and algorithmic trading included, should be identified and certified fit and proper every year, with the assessment written down, because certification is a named obligation that small firms routinely under-do.
An SM&CR maturity model for a fund manager
| Element | Baseline | Mature |
|---|---|---|
| Allocation | Statements of responsibilities exist, on a bank template | Allocation matched to how the firm actually decides, with collective decisions owned for process and oversight |
| Reasonable steps | Senior managers know their responsibilities | A contemporaneous record of what each did, defensible under the duty of responsibility |
| Outsourcing | Functions delegated under contract | The accountable SMF’s oversight of each delegate, recorded |
| Concentration | One person holds several SMFs | The concentration recognised and managed, with support and challenge |
| Certification | A certification policy exists | Significant-harm functions identified and certified fit and proper each year |
This insight is provided for general informational purposes only and doesn’t constitute legal, investment, or regulatory advice.