The Senior Managers & Certification Regime (SM&CR) is a regulatory framework introduced in the United Kingdom to strengthen individual accountability, governance, and conduct within financial services firms.
It places explicit responsibility on senior individuals for specific business functions, requires firms to certify the fitness and propriety of key staff, and applies enforceable conduct rules across the organisation.
Within AML/CFT frameworks, SM&CR plays a critical role by ensuring that responsibility for financial crime controls, compliance failures, and systemic weaknesses is clearly assigned, documented, and enforceable.
SM&CR applies to banks, building societies, insurers, asset managers, investment firms, and certain payment and electronic money institutions regulated by the Financial Conduct Authority and the Prudential Regulation Authority (PRA).
Its core objective is to reduce misconduct, improve risk culture, and prevent the diffusion of responsibility that historically contributed to major regulatory failures, including AML breaches.
SM&CR replaced the former Approved Persons Regime following widespread regulatory concern that senior individuals were able to evade accountability during major financial scandals.
Under the previous model, enforcement actions often failed because responsibility for decision-making and control failures was unclear or poorly documented.
The regime restructures accountability through three integrated pillars:
From an AML/CFT perspective, SM&CR embeds financial crime accountability directly into governance structures.
Senior managers cannot delegate accountability away; they remain responsible for ensuring that AML systems, controls, staffing, and escalation mechanisms are effective, resourced, and proportionate to risk.
SM&CR intersects with AML/CFT obligations by linking regulatory compliance failures directly to individual accountability.
Financial crime is no longer treated solely as an institutional failure but also as a leadership and governance issue.
Key AML/CFT linkages include:
Under SM&CR, inadequate AML frameworks, persistent control weaknesses, or repeated regulatory findings may expose senior managers to personal sanctions, including fines, prohibition orders, or public censure.
The SMR applies to individuals performing Senior Management Functions (SMFs).
These individuals hold ultimate responsibility for specific areas of the firm’s activities.
Core elements include:
For AML/CFT, this structure ensures that accountability for compliance, transaction monitoring, suspicious activity reporting, and regulatory engagement is clearly traceable to named individuals.
The Certification Regime applies to employees whose roles could pose a significant risk of harm to the firm or its customers, but who are not Senior Managers.
Certified roles may include:
Firms must assess and certify these individuals as fit and proper at least annually, considering honesty, integrity, competence, capability, and financial soundness.
Conduct Rules apply to almost all employees within SM&CR firms and establish baseline behavioural standards.
Key rules relevant to AML/CFT include:
Breaches of AML obligations often trigger Conduct Rule breaches, particularly where failures involve negligence, poor oversight, or lack of escalation.
SM&CR significantly increases the regulatory consequences of AML failures by personalising accountability.
Key risk areas include:
Where such failures occur, regulators assess whether Senior Managers took “reasonable steps” to prevent or mitigate the risk.
Documentation, governance evidence, and escalation records become critical.
A bank experiences repeated regulatory findings related to weak transaction monitoring and delayed suspicious activity reporting.
Under SM&CR, the Senior Manager responsible for financial crime controls may be investigated to determine whether reasonable steps were taken to address known weaknesses, allocate sufficient resources, and escalate issues to the board.
A firm certifies an investigations manager without adequate assessment of competence.
Significant AML alerts are mishandled, leading to regulatory breaches.
The firm may face enforcement action for improper certification, while senior management may be questioned on oversight failures.
An executive ignores internal warnings about sanctions screening gaps to prioritise business growth.
This behaviour may constitute a Conduct Rule breach in addition to underlying AML violations, increasing enforcement exposure.
SM&CR materially alters how institutions design and operate AML frameworks.
Key impacts include:
Institutions that fail to align AML programmes with SM&CR expectations often face compounded regulatory risk, including firm-level penalties and individual enforcement.
Despite its benefits, SM&CR presents operational and governance challenges:
In AML contexts, these challenges are amplified by evolving typologies, high transaction volumes, and increasing regulatory scrutiny.
Regulators use SM&CR as both a supervisory and enforcement tool.
Key expectations include:
Failure to meet these expectations can result in enforcement action against both the firm and individuals.
SM&CR strengthens AML/CFT compliance by embedding accountability at the highest levels of governance.
It ensures that financial crime risk is treated as a strategic issue rather than a purely operational concern.
Effective implementation enables institutions to:
As regulatory expectations continue to rise, SM&CR remains a cornerstone framework for ensuring that AML/CFT controls are not only designed but actively owned, enforced, and continuously improved.
Move at crypto speed without losing sight of your regulatory obligations.
With IDYC360, you can scale securely, onboard instantly, and monitor risk in real time—without the friction.