About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

98% of Firms Not Ready for SM&CR, Finds ACA Compliance

Subscribe to our newsletter

Less than 2% of affected firms have completed sufficient preparation for the FCA’s upcoming Senior Managers and Certification Regime (SM&CR) while only 2% of employees have sufficient awareness of the new rules and their implications across the organisation, according to a new survey from ACA Compliance.

The new regulation is due to come into force in December this year, with a submissions deadline of November 24 for conversion from the Approved Persons Regime and a deadline of December 9 for solo-regulated firms (and December 10 for dual-regulated firms) to upload their data. With its shift towards individual responsibility, the regulation is expected to have a substantial impact on data management due to the increased personal data requirements, while it may also correlate with the growing focus on financial crime – the FCA in 2016 specifically highlighted financial crime as an area where senior management functions and prescribed responsibilities were not always assigned to sufficiently senior individuals.

But is the industry taking it seriously enough? From a pool of over 70 respondents including asset managers, hedge funds, private equity firms, broker-dealers and wealth managers, more than a quarter admitted that there is minimal general awareness of SM&CR outside of their compliance teams – and almost 60% are less than a third of the way through their SM&CR projects, despite implementation looming just four months away.

“Without a doubt, solo-regulated firms need to accelerate the pace at which they are preparing for the SM&CR in the UK. It’s a long road ahead for 98% of firms and it’s clear the amount of work required ahead of the deadline is being underestimated. For some, the coming of this new regime will necessitate substantial changes to both governance and culture,” says Adam Palmer, partner at ACA Compliance.

“There are new policies, processes, and documentation that solo-regulated firms must implement. The engagement that must take place with certain individual employees will take time if firms are prepared to make the necessary changes to their overall business culture required by the regulator. In addition, employees across the firm need to be trained on SM&CR individually, as it will in many cases touch on their day-to-day roles. It’s important for firms to start working on SM&CR in earnest today.”

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Are Your Legacy Voice Recordings a Compliance Time Bomb?

Recent enforcement actions underscore the importance of maintaining accurate, secure and up-to-date voice and electronic communication. For some organisations, legacy voice recording systems are not at or beyond end-of-life, posing significant compliance, operational and financial risks. These outdated systems often fail to meet evolving regulatory expectations around data authenticity, retention, and accessibility. Delaying action increases...

BLOG

The Data Backbone of Defence: Powering Next Generation Surveillance

A unified data fabric is fast becoming wholesale finance’s front line of defence. By fusing millions of voice calls, chat messages and trade records into a single analytical view, next generation surveillance promises to detect misconduct in minutes and to satisfy regulators who increasingly ask firms to prove that capability. A-Team Group RegTech Summits in...

EVENT

RegTech Summit New York

Now in its 9th year, the RegTech Summit in New York will bring together the RegTech ecosystem to explore how the North American capital markets financial industry can leverage technology to drive innovation, cut costs and support regulatory change.

GUIDE

The DORA Implementation Playbook: A Practitioner’s Guide to Demonstrating Resilience Beyond the Deadline

The Digital Operational Resilience Act (DORA) has fundamentally reshaped the European Union’s financial regulatory landscape, with its full application beginning on January 17, 2025. This regulation goes beyond traditional risk management, explicitly acknowledging that digital incidents can threaten the stability of the entire financial system. As the deadline has passed, the focus is now shifting...