The FCA and PRA have confirmed a package of changes to the Senior Managers and Certification Regime (SM&CR), reducing the number of certified persons, lengthening approval windows and raising the thresholds at which enhanced standards apply.
According to Karavel, regulators have framed the move as streamlining, and much of the industry has welcomed it as a pragmatic fix to a regime that had, in places, drifted into a paperwork exercise. Yet a harder question lingers: does a smaller certification population mean more risk, or less?
Karavel recently discussed the fact how the FCA cut SM&CR’s certification list by 15%, and the question nobody is asking.
The headline change is a 15% cut to the number of roles subject to certification requirements, a material reduction in the population formally covered by the regime. Firms will also enjoy extended timeframes to push senior manager approvals through, easing bottlenecks that served nobody well.
Meanwhile, higher thresholds for enhanced standards mean fewer firms will need to meet the most demanding tier, on the basis that a mid-size asset manager should not shoulder the same administrative burden as a systemically important bank.
Crucially, the FCA has stressed that stripping a role from the certification list does not strip accountability from the individual holding it. The Consumer Duty continues to apply, individual conduct obligations remain in force, and the regulator’s powers to act against individuals are untouched. What has changed is the formal certification wrapper around a subset of roles.
Firms that treat de-certified roles as low-risk roles are misreading the reform: the accountability framework has been rationalised, not abolished. Compliance teams should be asking whether staff in newly de-certified positions understand that their obligations have not materially shifted.
The more honest concern is cultural rather than administrative. Certification was never solely about paperwork; it signalled that a person had been assessed, their fitness and propriety checked and their responsibilities documented.
Removing that signal risks a gradual organisational drift as visible markers of accountability fade. The most sophisticated firms will respond by strengthening internal accountability frameworks; the least sophisticated will simply bank a 15% cut in compliance overhead and move on.
For compliance teams, the practical burden of demonstrating accountability is shifting from the regulatory wrapper to the firm’s own governance and culture. Three actions stand out. First, map which roles are exiting the certification population and audit what accountability documentation exists for those individuals elsewhere; a thin file is a gap.
Second, revisit training and competency frameworks, since structured oversight must now come from within. Third, document the rationale for every de-certification decision, so that when the FCA comes calling, firms can evidence an active, considered choice rather than a passive response to rule changes.
The SM&CR was always a means to an end: a culture of individual accountability in UK financial services. That end has not changed. The test now is whether firms adjust with the means, or mistake the reduction for the gift it superficially appears to be.
Read the full Karavel post here.
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst





