FCA Releases SM&CR Banking Stocktake Report
11 September 2019: In early August the UK Financial Conduct Authority issued a report on initial findings related to the start of the implementation of the Senior Managers and Certification Regime which has been effective for banks and dual-regulated firms since March 2016.
FCA interviewed 45 people at 15 banking sector firms as well as trade associations, the Banking Standards Board, the FCA and the PRA. The key element was interviews with individuals in firms who have worked with SM&CR. The firms selected for this review included large and small wholesale and retail banks and building societies.
The review covered a wide range of themes, including: senior manager accountability; certification; regulatory references; conduct rules; impact on culture; unintended consequences; embedding and overcoming initial implementation issues.
FCA found that the industry has made a concerted effort to implement the regime. Most firms are taking actions to move away from basic rules-based compliance towards embedding the regime in the organisation.
Senior Manager Accountability: senior managers across all firms were clear on what accountability means in the context of their jobs and day-to-day activities. They could explain how they were accountable for their own actions and their responsibilities as leaders in their organisations.
Some non-executive directors were concerned the regime expected too much from the Board. There was a perceived risk that the line between a non-executive and executive could become blurred as Board members become more involved in operations of the business. FCA commented that SM&CR is not seeking to re-define the roles of non-execs, or raise expectations they act more like executives. FCA stressed the safeguard value to a firm’s stakeholders of non-exec oversight and effective challenge. It did confirm that the responsibilities of non-execs in larger firms will be considerable.
Some firms are placing a lot of importance on the Management Responsibilities Map (MRM) and are using it beyond what it was originally created for. Many senior managers expressed concern around understanding the meaning of ‘reasonable steps’ in the context of their business. They were reluctant to state what they believe ‘good’ looks like, and were inclined to look to the regulators’ expectations, often seeing the answer as being further guidance from the FCA.
FCA commented that the concept of reasonable steps is part of the Duty of Responsibility introduced in the legislation that established SM&CR. There is guidance in the Decision Procedure and Penalties manual that sets out some of the factors that FCA would expect senior managers to have regard to in considering whether they have taken reasonable steps to avoid a contravention from occurring or continuing. It is not possible or helpful to provide an exhaustive list that would cover every situation. FCA expects senior managers to do what they reasonably can to prevent misconduct. Appropriate controls and processes are an important part of this but senior managers must think more broadly and create an environment where the risk of misconduct is minimised, for example through nurturing healthy cultures.
Certification: the evidence indicates that firms have implemented processes to oversee the certification population. They have taken steps to ensure their frameworks are robust with several checks and balances in place to support the competence assessment and provision of training.
Firms have broadened their approach to assessment of staff beyond solely technical skills, and managers are in a better position to assess the behaviours of their certified staff. However, most firms could not demonstrate the effectiveness of their assessment approach, use of subjective judgement or how they ensure consistency across the population.
FCA did not see evidence in general that firms had made significant changes to their performance assessment processes other than incorporating expected behaviours. For instance, it is not clear that firms are using the Certification Regime to evaluate if managers of certification staff (who are themselves certified) are competent managers.
Regulatory references: all firms were positive about the concept of regulatory references and its intention to address the potential issue of ‘rolling bad apples’ (where people with poor conduct records are able to move to new employers). However, the majority felt that the industry had some way to go to improve the quality and timeliness of references. Another challenge for firms is that other firms are not always consistent in recording breaches of the Conduct Rules. Some firms were more inclined to rely on references than others. This depended on their size, risk appetite and from where they recruit senior managers and certification staff.
Conduct Rules: those interviewed believed that staff generally understand the conduct rules. However, FCA evidence suggests that firms have not always sufficiently tailored their conduct rules training to staff’s job roles. Firms are often using their own values to articulate how they bring the conduct rules to life. However, there was insufficient evidence to be confident that firms have clearly mapped the conduct rules to their values. Many firms were often unable to explain what a conduct breach looked like in the context of their business.
FCA commented that the conduct rules are a critical foundation for firms’ culture and the conduct of individuals. It is essential that staff understand the rules and how they apply to them. Under FSMA, firms must: a) notify all relevant persons of the conduct rules that apply in relation to them; b) take all reasonable steps to secure that those persons understand how those rules apply in relation to them. This must include the provision of suitable training.
Impact on culture: most firms said that they had embarked on culture change work before the implementation of the regime. These initiatives were prompted by a number of factors, including past conduct issues, the impact of ring-fencing and the remuneration code.
Many described a stronger tone and ownership from the top. They told FCA that there was now a change in the level of detail, clarity and quality of conversations on culture and expected behaviours. All the firms talked about the work they had done to create a culture of challenge, escalation and providing a safe environment for staff to speak up.
Firms have found it challenging to find appropriate ways of measuring culture and the effort to do so is continuing. Firms told FCA that the regime is having an impact on the mindset of senior managers. However, SM&CR is primarily enabling firms to improve their controls environment, which they expect to lead to improved behaviours. It is not clear to what extent the regime has been linked to culture.
Unintended consequences: for most firms, SM&CR did not lead to significant unintended consequences. The unintended consequences that arose for a few firms were specific to their respective businesses. Some firms told FCA that there was a culture of fear during the early days of the regime. However, this has now largely dissipated. Two reasons were given for this: firms worked to develop an environment of healthy challenge and openness; they are seeing the regulators work collaboratively with them to achieve positive outcomes.
There is evidence that processes and controls on approvals of new products and businesses have been tightened. This has potentially contributed to firms being more risk averse and considered around innovation initiatives. However, if firms get the balance right, FCA does not see this as a negative outcome.
There is some evidence of recruitment challenges, particularly for candidates from outside the financial services industry considering certification or SMF roles but this was not universal. Most firms mentioned the additional staff and work required to administer the regime. However, this was seen by many as part of creating a robust governance environment within their firm.
Embedding and overcoming initial implementation issues: most firms are continuing to embed the regime, particularly below the senior manager level, with a focus on the spirit of the regime and ensuring their approach is proportionate. The different levels of maturity across firms are driven by several factors. This includes size, resources, their cultural baseline and their interactions with regulators. Generally, the larger banks, with more resources and exposure to the regulators, are more mature in their approach.
FCA believes that initial implementation issues that firms faced have now been overcome. Firms described the initial stages of implementation as challenging but came to see clear definition of accountability as beneficial. Some firms seem to have been less successful in embedding the regime below the senior manager level. There is some room for further progress at the certification level and potentially more significant weaknesses in the implementation of the conduct rules for other staff.
FCA’s next steps and actions: FCA will increase its supervisory focus on the conduct rules. It expects all SM&CR firms to ensure that they are embedding the conduct rules in their businesses to meet their obligations under the regime. FCA will continue to build on the links between the SM&CR and firm culture. The Senior Managers and Certification Regime is an important way to establish a culture of accountability for conduct and aligns with FCA’s cross-sector business priority to continue to work on firm culture and governance.