Governance, Risk & SMCR in 2026: The Regime Got Lighter. Your Accountability Did Not.
Making Compliance Work | Compliance Consultant
The short answer
2026 is the year the Senior Managers and Certification Regime started shrinking and expanding at the same time. Phase 1 reforms took effect on 24 April and 10 July 2026, easing administrative burden, and HM Treasury has confirmed it will remove the Certification Regime from primary legislation altogether. Meanwhile, from 1 September 2026 the Conduct Rules expand to cover bullying, harassment and violence at around 37,000 non-bank firms that were previously outside that scope. Fewer forms, wider liability. If your governance framework was built to satisfy paperwork rather than to evidence judgement, the simplification is not good news for you.
1. The deadline that is four weeks away
On 1 September 2026 a new rule, COCON 1.1.7FR, takes effect. It extends the scope of the Conduct Rules in non-banking firms to cover bullying, harassment or violence against colleagues where the behaviour relates to an individual’s role. Alongside it, the Handbook guidance finalised in FCA PS25/23 comes into force, covering four areas firms have consistently struggled with:
- the boundary between work and private life;
- how non-financial misconduct (NFM) can breach the Conduct Rules;
- reasonable steps for managers; and
- fitness and propriety assessments โ including private life, social media and unproven allegations.
The population affected is large. The rule change brings roughly 37,000 non-bank firms into line with the position that has applied to banks โ meaning IFAs, mortgage and insurance brokers, wealth managers, asset managers, insurers and payment firms are all in scope.
What the FCA is not asking for is as important as what it is, because over-reaction here creates employment law exposure of its own. Firms are not required to monitor employees’ private social media proactively, are not required to investigate trivial or implausible allegations, and should not assume private-life conduct will automatically be repeated at work. The rule is not retrospective.
What you should have done before 1 September, per the FCA’s own readiness guidance: reviewed staff policies, conduct breach reporting, fit and proper assessments and regulatory references; made sure staff and managers understand how the changes apply to them; and carried out retrospective analysis to check whether past conduct rule breaches were correctly determined.
If that list makes you uncomfortable in early August, the honest sequence for the next four weeks is: policies and reporting route first, training second, historical analysis third. Get the pipe built before you pour anything down it.
The judgement problem. Only serious misconduct amounts to a breach, and conduct can be work-related even when it occurs outside the office. The guidance deliberately leaves room for firms to exercise judgement โ which means the defensibility of your decision rests on how you documented the assessment, not on the outcome you reached. And these are not purely regulatory decisions: they collide with unfair dismissal risk, discrimination, whistleblowing protections and regulatory reference obligations. Firms that handle NFM cases through the compliance function alone, without employment law input, are building a different kind of liability.
2. What already changed: Phase 1
On 22 April 2026 the FCA and PRA published PS26/6 and PS12/26, confirming the first phase of SMCR reform largely as consulted on. Most changes took effect on 24 April 2026, with reporting and process improvements following on 10 July 2026, and the NFM-related changes on 1 September 2026.
The practical wins for firms:
- The 12-week rule is more workable. Previously firms had 12 weeks for a senior manager application to be submitted and approved. Now it is only necessary to submit within the 12-week period. The candidate may perform the role pending determination, subject to Senior Manager Conduct Rules during that time.
- Conduct Rule breach reporting for those interim candidates must be made as soon as practicable, rather than waiting for the annual return.
- Certification duplication removed. Separate certification for certain overlapping roles goes, with the FCA removing the duplicate entries from the Directory itself.
- Streamlined annual reporting and additional guidance, including on SMF7.
None of this significantly lightens the overall burden โ the commentary is near-unanimous on that point. It removes friction, not obligation.
3. What is coming: Phase 2, and the end of certification as we know it
HM Treasury’s April 2026 consultation response confirmed the direction of travel, and it is more radical than Phase 1:
- The Certification Regime will be removed from FSMA, allowing the regulators to build a more proportionate and flexible replacement in their rulebooks.
- Certain Senior Management Functions may become notification-only, rather than requiring pre-approval.
- Statutory determination deadlines for senior manager applications are proposed to shorten from three months to two โ a timescale the regulators are already meeting voluntarily.
- Legislation is intended as soon as parliamentary time allows, with the FCA expecting to consult on Phase 2 later in 2026.
The stated ambition, running back to the Financial Services Growth and Competitiveness strategy, is to halve the regulatory burden of the regime.
Read that carefully. Removing the Certification Regime from statute does not remove your obligation to ensure that people who deal with clients or manage risk are competent and fit to do so. It moves the requirement from a legislative instruction into a regulator-set framework โ and, in the interim, into your own governance judgement. Firms that treated annual certification as a form-filling exercise have been running an assessment process with no substance underneath it. When the form goes away, the absence becomes visible.
4. The pattern across everything in 2026
Look at the three pillars together and the same shape appears in each:
| Area | What was removed | What replaced it |
|---|---|---|
| AML (MLRs 2026, in force 30 June) | Prescriptive EDD triggers; euro thresholds | Your Business-Wide Risk Assessment, carrying the judgement |
| SMCR (PS26/6; Phase 2 to follow) | Certification in statute; pre-approval friction | Your fitness, competence and governance evidence |
| Consumer Duty | Prescriptive conduct rules | Your outcomes monitoring and board challenge |
This is the defining regulatory movement of the decade: prescription out, evidenced judgement in. Every simplification transfers the burden of proof from the rulebook to the firm. For a well-governed business, that is genuine relief. For a firm whose compliance rested on doing what the rules literally said, it is the removal of the only thing that was holding it up.
Related reading: our companion pieces on the 2026 AML changes and compliance audits and monitoring trace the same pattern through financial crime and assurance.
5. “Reasonable steps”: what the evidence pack actually looks like
Every Senior Manager must be able to show they took the steps a reasonable person in their position would take. In practice, when we test this in governance reviews, most Senior Managers in SME firms can describe their reasonable steps and almost none can evidence them.
A defensible reasonable steps file for each SMF contains:
- A current Statement of Responsibilities that matches what the person actually does โ not what the template said when the firm was half its present size.
- A delegation record. Who you delegated to, what you delegated, how you satisfied yourself they were capable, and how you oversee them. Delegation without oversight is the classic finding.
- Management information you actually received, with evidence that you interrogated it. A dashboard nobody questioned is not oversight.
- Decisions taken, with the reasoning and the date. Including decisions not to act โ those need the same documentation as decisions to act.
- Escalations made and received, and what happened to them.
- Challenge you raised, minuted. If board minutes record only outcomes and never disagreement, they are not evidence of governance.
- Competence and training, yours and your direct reports’.
Build this as a live file per Senior Manager, updated quarterly. Assembling it retrospectively during an FCA investigation โ when memory, motive and hindsight are all working against you โ is a very different exercise.
6. The risk framework that connects it all
Governance without a functioning risk framework is theatre. The three artefacts that carry the weight:
The risk register. Live, owned, and specific to your business model. Generic risks (“regulatory change”, “cyber”) with no owner, no control mapping and no movement over eighteen months tell a supervisor that nobody is actually running risk management. Each material risk should trace to a named control and to a monitoring test that verifies the control works.
Board MI. Trends rather than snapshots; exceptions rather than volumes; forward indicators rather than lagging counts. The recurring supervisory criticism of board reporting is that it documents oversight without demonstrating impact.
Minuted challenge. The single cheapest governance improvement available to a small firm is a minute-taking discipline that records the questions asked, the answers given, the dissent expressed and the actions arising with owners and dates. It costs nothing and it is the first document a skilled person reads.
7. If you are a firm of twelve people
Everything above sounds like it was written for a bank. It was not โ but the proportionality point needs saying plainly.
In a small firm, the “three lines of defence” collapses. The person doing the business writes the procedure, checks the file and reports to the board they sit on. That does not exempt you; it means your independence has to come from somewhere else. Practical options:
- Buy the independence. An outsourced second-line review, or an annual independent governance audit, supplies the challenge your structure cannot generate internally.
- Separate the roles you can. Even in a firm of twelve, the person who advises should not be the person who signs off the file review of their own advice.
- Use a Non-Executive. One properly briefed NED who reads the pack and asks awkward questions changes board dynamics more than any policy rewrite.
- Document the constraint. Where you cannot achieve separation, record that, record the compensating controls, and record the board’s acceptance. A documented, mitigated limitation is defensible. An undocumented one is a finding.
8. Your 60-day plan
Days 1โ14 โ Close the 1 September gap.
Update the staff handbook, disciplinary policy and conduct rules policy to reflect COCON 1.1.7FR. Define your NFM escalation route and who assesses. Agree with your employment law adviser where the regulatory and employment processes intersect. Confirm your regulatory reference process captures NFM outcomes.
Days 15โ30 โ Train and communicate.
Conduct Rules training for all conduct rules staff covering the September change, with a competence check rather than an attendance sheet. Separate, deeper briefing for Senior Managers on reasonable steps in an NFM context โ they carry a different obligation.
Days 31โ45 โ Rebuild the accountability evidence.
Refresh Statements of Responsibilities against reality. Open a reasonable steps file for each SMF using the seven-item structure above. Re-run this year’s certification assessments and ask, honestly, whether the evidence would satisfy an outsider.
Days 46โ60 โ Test and report.
Retrospective review of past conduct rule breach determinations, as the FCA has asked. Refresh the risk register with named owners. Take a single governance paper to the board covering the September changes, the reasonable steps position, and the Phase 2 horizon โ minuted, with challenge recorded.
Frequently asked questions
What changes for SMCR firms on 1 September 2026?
A new rule, COCON 1.1.7FR, extends the Conduct Rules in non-bank firms to cover bullying, harassment and violence towards colleagues where there is a sufficient work-related link. New Handbook guidance from PS25/23 takes effect at the same time, covering work/private life boundaries, reasonable steps and fitness and propriety assessments.
Is the Certification Regime being abolished?
HM Treasury has confirmed it will remove the Certification Regime from primary legislation, allowing the FCA and PRA to build a more proportionate replacement in their rules. Legislation is expected when parliamentary time allows, with FCA consultation on Phase 2 anticipated later in 2026. Until then, the existing certification obligations continue to apply in full โ do not stop certifying.
Does non-financial misconduct really apply to a small mortgage broker?
Yes. The rule applies to SMCR firms broadly, and the expansion was specifically aimed at the roughly 37,000 non-bank firms previously outside the wider scope. A three-adviser brokerage is in scope, proportionately.
Do we have to monitor employees’ social media?
No. The FCA has been explicit that firms are not required to monitor private social media proactively, nor to investigate trivial or implausible allegations. What you do need is a proportionate, documented route for escalating and assessing relevant conduct when it comes to your attention.
What is the biggest SMCR weakness the FCA finds in small firms?
Statements of Responsibilities that no longer describe what people actually do, and Senior Managers who cannot evidence oversight of what they have delegated. Both are cheap to fix in advance and very expensive to explain afterwards.
How Compliance Consultant helps
25 years of building governance frameworks that survive contact with a supervisor โ for FCA-regulated firms across mortgage broking, payment services, investment management, claims management, fintech and cryptoasset businesses.
- Governance and SMCR Reviews โ Statements of Responsibilities, responsibilities maps, reasonable steps evidencing and board effectiveness.
- SMCR annual certification support โ including our attestation guide and fitness and propriety assessment framework.
- Conduct Rules and NFM readiness โ policy, escalation route, training and record-keeping, aligned with employment law input.
- Regulatory risk management โ risk register design, board MI and Compliance Monitoring Programmes for FSMA and PSR firms.
- FCA Authorisation โ governance arrangements that have to work on day one, not just read well in the application.
Book a Discovery Call: https://bit.ly/CCDiscovr
Prefer to answer a few preliminary questions first? Use our voice agents:
Sources and further reading
- FCA, PS25/23: Tackling non-financial misconduct in financial services (December 2025); FCA firm readiness guidance, March 2026
- FCA Handbook: COCON 1.1.7FR and COCON guidance; FIT; SYSC
- FCA, PS26/6: Senior Managers & Certification Regime Review (22 April 2026)
- PRA, PS12/26: Review of the Senior Managers and Certification Regime โ Phase 1 (April 2026)
- HM Treasury, Reforming the Senior Managers & Certification Regime: Consultation Response (April 2026)
- FCA, CP25/21: Senior Managers and Certification Regime Review (July 2025)
- HM Treasury, Financial Services Growth and Competitiveness Strategy
- The Money Laundering and Terrorist Financing (Amendment) Regulations 2026, SI 2026/621
Follow us:
Facebook | Twitter | Instagram | LinkedIn | Pinterest
Compliance Consultant | https://complianceconsultant.org | UK 0800 689 0190 | Int’l 020 8243 8620 | Discovery call: https://bit.ly/CCDiscovr
Compliance Consultant and Compliance Doctor are trading styles of UK Compliance Consultant Limited, Companies House number 14805896.
This article is general guidance current at the date of publication and does not constitute legal, employment or regulatory advice for any specific firm.



