5.3 Additional Oversight: Senior Management, Auditors, Trustees and External Compliance
Key Takeaways
- SMCR personalises accountability: Senior Managers are individually approved as Approved Persons to perform controlled functions, Certification Functions are firm-certified, and the Conduct Rules apply to almost all employees.
- Internal audit provides independent assurance to the board; external audit provides an opinion on the truth and fairness of financial statements.
- Trustees hold and administer trust property for beneficiaries, owe fiduciary duties, and are central to occupational pension scheme governance alongside The Pensions Regulator.
- Non-executive directors (NEDs) provide independent challenge on strategy, risk, and executive performance; the board's audit and risk committees are normally chaired by NEDs.
- External compliance consultants can supplement in-house compliance but cannot substitute for the firm's governing body accountability under SMCR.
Senior Management Oversight and the SMCR
Regulation places personal responsibility for a firm's compliance, culture, and risk-taking on its governing body — typically the board of directors. The Senior Managers and Certification Regime (SMCR) operationalises this by mapping specific responsibilities to named individuals.
The SMCR has three layers:
- Senior Management Functions (SMFs) — individually approved by the FCA (or PRA for dual-regulated SMFs). Each SMF has a Statement of Responsibilities describing the matters they are accountable for. Examples include the Chief Executive (SMF1), Executive Director (SMF3), Chief Finance Function (SMF2), and the new SMF24 (Chief Operations Function) introduced for larger firms.
- Certification Functions — staff who are not SMFs but whose role poses a material risk of harm to the firm or its customers. The firm — not the regulator — certifies their fitness and propriety annually. Examples include material risk takers, portfolio managers, and certain client-facing advisers.
- Conduct Rules — apply to almost all employees (Senior Managers, Certification staff, and other conduct staff). The Individual Conduct Rules require honesty and integrity, due skill, care and diligence, openness and cooperation with regulators, and paying due regard to customers' interests and treating them fairly. Senior Managers are additionally bound by four Senior Manager Conduct Rules including taking reasonable steps to ensure the firm complies with requirements.
The Duty of Responsibility allows the regulator to take enforcement action against an SMF where the firm breaches a requirement in an area the SMF was responsible for and the SMF did not take reasonable steps to prevent or stop the breach.
The Certification Regime removes the regulator from certifying every relevant individual; instead the firm must assess fitness and propriety, supported by training and the Conduct Rules.
Internal Audit vs External Audit
Internal and external audit are distinct functions that provide complementary assurance.
Internal Audit
Internal audit is an in-house, independent function reporting to the audit committee (chaired by a non-executive director). Its purpose is to provide the board with independent assurance that the firm's risk management, internal controls, and governance processes are operating effectively. Internal auditors:
- Evaluate the design and operating effectiveness of controls, including regulatory compliance, conduct risk, and AML.
- Report findings to the audit committee and board, with recommendations for remediation.
- Follow the Three Lines of Defence model: first line = business owns risk; second line = risk and compliance functions oversee and challenge; third line = internal audit independently assures.
The FCA and PRA expect internal audit to be adequately resourced, independent, and have direct access to the board and audit committee.
External Audit
External audit is performed by an independent registered auditor (a firm registered with a recognised supervisory body such as ICAEW, and overseen by the Financial Reporting Council (FRC) for public interest entities). The external auditor's role is to express an opinion on whether the firm's annual financial statements give a true and fair view. External auditors:
- Are appointed by, and report to, shareholders — not management.
- Audit financial statements for
truth and fairnessin line with auditing standards (UK ISA). - Must report certain matters to the FCA/PRA, including qualifying parts of the audit report, significant concerns about the firm's ability to continue as a going concern, and material weaknesses in internal controls over financial reporting.
- Must be independent of the firm — they cannot provide certain non-audit services to public interest entities.
External audit does not opine on regulatory compliance or conduct in the way that internal audit does; it focuses on financial statements. But it is a critical external check, and the FRC sets audit standards and inspects the audits of public interest entities including banks and insurers.
Trustees and Their Role in Pension Schemes and Trusts
A trustee is a person or corporation that holds and administers property (the trust property) on behalf of beneficiaries, in accordance with the terms of a trust. Trustees owe fiduciary duties to the beneficiaries: to act in good faith, exercise reasonable care, avoid conflicts of interest, and not profit from the trust.
In occupational pension schemes, the trustees:
- Hold scheme assets on trust for members and beneficiaries.
- Are responsible for the scheme's governance, administration, funding, and investment strategy (with advice from the scheme actuary and investment consultants).
- Are regulated by The Pensions Regulator (TPR), which sets standards and can take enforcement action (e.g., improvement notices, financial support directions, and trustee appointments).
- Must have regard to the Pensions Regulator's Code of Practice and the Statement of Investment Principles.
Many life and investment products are also structured as trust-based wrappers (e.g., offshore bonds, ISAs held in trust). The trustee may be the product provider's corporate trustee or, for certain trusts used in estate planning, an independent trustee. Trustees of financial product trusts are usually approved by the FCA as SMFs where they sit within an authorised firm's governance.
Non-Executive Directors and Board Governance
Non-executive directors (NEDs) are directors who do not hold executive management positions. Their role is to:
- Provide independent challenge and constructive scrutiny of executive proposals.
- Contribute to strategy, risk appetite, and governance.
- Sit on, and usually chair, the audit committee, risk committee, remuneration committee, and nominations committee.
- Review the performance of executive management and the design of incentive structures (the FCA/PRA require remuneration policies to be aligned with risk).
The UK Corporate Governance Code (issued by the FRC) expects boards of premium-listed companies to have at least half their members (excluding the chair) as independent NEDs, with a separate chair and CEO. The FCA's SYSC rules require authorised firms' governing bodies to include independent non-executive directors where appropriate to the firm's size and complexity.
Approved Persons and External Compliance Consultants
Approved Persons
Under the SMCR, Senior Manager Functions are Approved Persons — individuals approved by the FCA (or PRA for dual-regulated SMFs) before they perform the function. Approval requires the firm to submit a Form A certifying the individual is fit and proper (honesty, integrity, reputation, capability, competence, financial soundness). Approved Persons are subject to the Conduct Rules and to personal enforcement action including prohibition orders and financial penalties.
For firms still transitioning or where SMCR does not apply in full (e.g., some limited permission firms), the Approved Persons Regime pre-SMCR applies.
External Compliance Consultants
An external compliance consultant is a specialist third party engaged to provide advice on regulatory compliance, conduct risk, training, or to perform compliance health-checks. They may be used by:
- Smaller firms without a dedicated in-house compliance team.
- Larger firms for specialist projects (e.g., a new product launch, Consumer Duty implementation, or SMCR readiness).
- Boards seeking independent assurance beyond internal audit.
External consultants can supplement but cannot substitute for the firm's governing body and Senior Managers, who remain personally accountable under the SMCR for the matters within their Statements of Responsibilities. The governing body must take ownership of the compliance framework; outsourcing tasks does not outsource accountability.
Firms using external consultants should:
- Conduct due diligence on the consultant's competence, independence, and conflicts.
- Document the scope and reporting lines.
- Ensure the board reviews and challenges the consultant's findings.
Summary — Layers of Oversight
| Layer | Provided by | Reports to | Focus |
|---|---|---|---|
| Senior Manager accountability | SMCR — named SMFs | Board / regulator | Personal responsibility for compliance, conduct, and risk |
| Internal audit | In-house independent function | Audit committee (NED-chaired) | Effectiveness of controls and governance |
| External audit | Independent registered auditor | Shareholders / FRC | Truth and fairness of financial statements |
| Trustees | Pension/product trustees | Beneficiaries / TPR | Fiduciary stewardship of trust property |
| Non-executive directors | Independent board members | Shareholders | Independent challenge on strategy and risk |
| External compliance consultants | Third-party specialists | Board / Senior Managers | Specialist advice and assurance |
These layers reinforce the regulatory framework: regulators set the rules, but firms — through their governance, audit, trusteeship, and advisory arrangements — deliver the outcomes the rules require.
Under the SMCR, who is responsible for certifying that staff performing Certification Functions are fit and proper?
What is the primary purpose of internal audit in an authorised firm?
Which statement best describes the relationship between an external compliance consultant and SMCR accountability?
Who regulates the trustees of UK occupational pension schemes for governance, funding, and administration?