Why the SM&CR Overhaul Is an Operating Model Problem, Not a Compliance One
The FCA and PRA's SM&CR consultation shifts the burden from documentation to demonstrable accountability. That only works if your operating model can trace it.

The FCA and PRA's SM&CR consultation was released last week. The headlines are what you'd expect: streamlined certification, reduced prescription around Senior Management Functions, and a shift toward "outcomes-based accountability." The industry has been asking for this for years. The compliance teams are already drafting their response templates.
Although, the real conversation to be had is whether the new regime works. Whether or not it actually improves outcomes, or if it's just going to somewhat reduce paperwork. The answer depends almost entirely on something that isn't in the consultation. It depends on your operating model.
What "outcomes-based accountability" actually requires
The current SM&CR regime is itself prescriptive. Every Senior Management Function is defined. Every responsibility map follows a template. Every certification regime is documented. The system works, bureaucratically, because compliance is a checklist. You can demonstrate compliance by producing documents.
The proposed regime shifts the burden from "have you documented the right things?" to "can you demonstrate that accountability actually works?" The SMFs become fewer and broader. The certification process becomes lighter. Although, the expectation, which is implied in every page of the consultation, is that accountability is embedded in how the organisation operates. This is a very different question, than purely asking how it's documented.
To put that into practice, take a Chief Risk Officer. Under the current regime, the CRO's SMF statement says they're responsible for "the firm's risk management framework". The compliance team maintains a responsibility map showing the CRO at the top of the risk function. The CRO signs off on the annual risk assessment.
Under the new regime, you aren't to ask "does the CRO have a documented responsibility?" Instead, "can the CRO demonstrate — in real time, with evidence — that the risk management framework actually works?" What this means is that the CRO needs to be able to trace any risk from identification through assessment, control assignment, monitoring, and reporting — and show that the chain was intact at every step. Not at the annual review. Now.
Most firms can't do this. This doesn't mean that their CROs aren't competent. It means that the chain — from the risk identified by an underwriter on a Tuesday afternoon to the risk reported to the board three months later — passes through spreadsheets, emails, meeting minutes, and systems that don't talk to each other. The CRO signs off on a framework whose components they can't properly trace.
The accountability cascade
Every Senior Management Function sits atop a cascade of processes, decisions, data flows, and handoffs. The CRO's accountability depends on:
- Underwriters who identify and assess risks in their portfolios
- A risk team that aggregates, challenges, and scores those assessments
- A control framework that maps controls to risks
- Control owners who test and attest to control effectiveness
- Systems that capture risk data, control test results, and incident information
- Reporting processes that synthesise all of this into the information the CRO reviews
If any link in that chain is broken — if the underwriter's risk assessment sits in a spreadsheet the risk team can't access, if the control test results are in a different system from the risk register, if the reporting process aggregates data that's three months old — the CRO's "accountability" is actually attribution. They're attributed with responsibility for something they can't actually see and account for.
The new SM&CR regime doesn't explicitly say "build a traceable operating model", but that's what it requires. Because "outcomes-based accountability" without operational traceability is just a fancier way of saying "we'll hold you responsible for things you can't control."
What firms should do now, not after the consultation closes
The compliance response to SM&CR reform will be well-resourced and well-documented. Law firms will publish templates. Consultants will run gap analyses. By the time the final rules arrive in mid-2027, every firm will have a compliance workstream.
The operating model response is different, as it can't be done by compliance alone. It requires you to:
1. Map accountability, not just responsibility. A responsibility map says "the CRO is responsible for risk management". An accountability map traces every SMF down through the organisation: what processes does the CRO depend on, what data flows into their decisions, what systems generate the information they review, what controls sit at each handoff? If you can't draw that map, then you don't have accountability, you have a job title and an annual attestation.
2. Connect HR, risk, compliance, and operations in a single model. The certification regime requires fitness and propriety assessments. The risk regime requires control effectiveness testing. The compliance regime requires regulatory reporting. If these three things run on separate systems with separate data, then your "streamlined" SM&CR process creates three versions of the truth. If you fail to connect them, then you accept that your accountability framework is only as good as your last reconciliation exercise.
3. Build for regulatory change absorption. The SM&CR rewrite won't be the last regulatory change. Solvency UK, the Consumer Duty evolution, climate risk reporting — the regulatory pipeline is structural, not cyclical. If every regulatory change requires a project to update your accountability framework, then you're building a compliance function, as opposed to an operating model. The firms that build accountability as a living architecture — processes, people, systems, and responsibilities connected in a single model — will absorb regulatory change as configuration.
The opmodal perspective
We've spent seven years helping financial services organisations map how they actually work — the processes, systems, people, and controls that make up their operating reality. And the single most consistent finding across every engagement, from Chaucer's enterprise-wide operating model to an enterprise investment platform provider's client onboarding architecture, is that accountability without traceability is attribution.
When we map a firm's operating model — when we trace every process step to its owner, every system to the processes that depend on it, every control to the risk it mitigates, every SMF to the cascade beneath it — we aren't solely documenting what exists. We're making accountability operational. We're building the chain that connects "the CRO is responsible for risk management" to "here is exactly how risk management works, in real time, with evidence".
The SM&CR consultation is an opportunity disguised as a regulatory burden. The firms that use it to build operational traceability, not just compliance documentation, will emerge with a very effective accountability framework. The firms that treat it as a paperwork exercise will have the same problem in 2028 that they have today; senior managers who are attributed with responsibility for things they can't trace.


