Accountability that works on paper is not accountability: the PRA's HDI fine, decoded
The PRA's £4.165 million fine against HDI Global SE shows that documented accountability is worthless if it isn't connected to the operational chain that produces the return.

See also: Subscription Market issue 4
What it is
Earlier this month, the PRA fined HDI Global SE £4.165 million over its FSCS levy reporting. The number that got the headlines: in 2023 the firm submitted protected liabilities of £20.39 million when the correct figure was £195.85 million. As Dentons' analysis sets out, the inaccuracies ran for three years and meant the firm significantly underpaid its levy.
But the fine is not really about arithmetic. Read the final notice and the failures it catalogues are architectural. No clear ownership and accountability for the reporting process. No sufficiently robust written methodology for preparing the returns. No adequate management oversight or independent review before submission. And, most damaging of all, remediation that failed after earlier errors had already been identified — meaning the firm found the problem, corrected the number, and then repeated the mistake, because the chain that produced the number was never changed.
These were not isolated calculation errors. They were failures of systems and controls, breaches of the fundamental rules about due skill, care and diligence, and about organising and controlling affairs responsibly.
Why it matters now
The timing is not a coincidence. The SM&CR reform package is moving. Phase 1 is live — FCA PS26/6 and PRA PS12/26 took effect in April, cutting overlapping certifications, easing the 12-week rule and raising enhanced-firm thresholds. The non-financial misconduct alignment changes land on 1 September. Phase 2 — the substantial rewrite — is expected to be consulted on later this year.
The direction of travel across all of it is the same: away from "have you documented the right things?" and toward "can you demonstrate that accountability actually works?" The HDI fine is that second question being asked, with real money attached, of a firm that had every document the first question demanded.
Here is the uncomfortable part for every COO and compliance director reading this: HDI's responsibility maps were presumably complete. Its senior managers were presumably approved. Its reporting process presumably existed. None of it mattered, because none of it was connected to the operational chain that actually produced the return. Accountability that is documented but not operational is not accountability. It is attribution — and the regulator can tell the difference, because the regulator fines the difference.
What firms should do
Three things, none of which can be done by the compliance team alone.
1. Map accountability to the process step, not the job title
A responsibility map says "the CFO is responsible for regulatory reporting." An accountability map traces what that sign-off actually depends on: where the tariff data originates, which system holds it, who prepares it, what checks run between preparation and submission, who reviews before sign-off. If you cannot draw that chain for every material regulatory return, you have a job title and an annual attestation, not accountability. The HDI fine is what the chain looks like when four links fail at once.
2. Treat methodology documents as living artefacts
The PRA criticised the absence of written methodologies that could be followed consistently. In most firms the methodology exists in someone's head, or in a document that has not been opened since it was written. Both fail the same test. A methodology is only a control if it is connected to the process — reviewed when the process changes, versioned, and actually used by the people preparing the return. If the person who knows the process left tomorrow, would the process survive? If the answer is no, the methodology is decoration.
3. Build the feedback loop into the workflow
HDI's most expensive failure was remediation that did not stick: the error was identified, corrected, and then repeated, because the correction did not change the chain that produced it. That is what happens when fixes are applied to outputs rather than processes. Remediation needs to trace back to the originating step — the system configuration, the data source, the review point — and change it. A firm whose operating model is mapped can do that. A firm whose operating model lives in documents cannot, because it does not actually know where the error came from.
The opmodal perspective
We have spent seven years mapping how financial services organisations actually work, and the single most consistent finding across every engagement is this: accountability without traceability is attribution.
When we map a firm's operating model — every process step to its owner, every system to the processes that depend on it, every control to the risk it mitigates, every data flow end to end — we are not just documenting what exists. We are making accountability operational. We are building the chain that connects "the CFO signs off regulatory reporting" to "here is exactly how the return is produced, who owns each step, and what catches the error before it leaves the building."
The firms that treat the SM&CR direction of travel — and enforcement cases like HDI — as a prompt to build that traceability will absorb both Phase 2 and the next decade of regulatory change as configuration, not crisis. The firms that treat it as a paperwork exercise will keep having the same problem, and the fines will keep finding the gaps that documents cannot close.


