What SMF16 and SMF17 actually are
SMF16, Compliance Oversight, and SMF17, the Money Laundering Reporting Officer, are two Senior Management Functions central to a firm's financial crime defence, though not every regulated firm requires both. All dual-regulated firms require SMF16; for solo-regulated firms, whether SMF16 applies depends on the firm's regulatory status, type, and permissions, and the Senior Managers and Certification Regime applies differently across its Enhanced, Core, and Limited Scope tiers. SMF16 holds personal accountability under the Duty of Responsibility, conditional on a firm contravention in an area the individual was responsible for and a failure to take reasonably expected steps, not blanket liability for every FCA rule. SMF17 carries individual responsibility for the firm's anti-money laundering controls specifically; under MLR 2017 regulation 21, the firm must notify the relevant supervisory authority of the nominated officer's identity within 14 days of appointment, a narrower requirement than a general expectation that the FCA or the NCA can reach the holder directly.
Both are Senior Management Functions under the Senior Managers and Certification Regime. Holding one means FCA approval before you start the role, and a Statement of Responsibilities that names exactly what you're accountable for. The personal Duty of Responsibility, under section 66A of the Financial Services and Markets Act 2000, is not a standalone duty that exists independently of the employer, it applies where there has been a contravention by the firm, the individual was responsible for the relevant area, and the individual failed to take the steps a person in that position could reasonably be expected to take to prevent it. No FCA source publishes a specific "first question" it asks after an AML control failure, the statutory test above is what actually governs individual liability.
Whether SMF16 and SMF17 can be combined in one person, rather than requiring separate individuals, depends on the firm's SMCR categorisation and its specific regulatory permissions, not a fixed revenue threshold. Enhanced-firm categorisation is set by six separate tests (for example ยฃ65bn in assets under management, ยฃ45m in intermediary regulated business revenue, ยฃ130m in regulated consumer credit lending revenue, or 10,000 regulated mortgages), and SMF16 applicability depends on regulatory status, firm type, and permissions rather than a single figure. Larger or more complex firms more often split the two roles, driven by workload rather than a specific revenue rule.
Combining SMF16 and SMF17 in one person is permitted; whether it's realistic for a given firm turns on its actual SMCR categorisation and regulatory permissions, not a fixed revenue figure. The practical focus is realistic time allocation across both remits, training that's proportionate to the firm's actual risk profile rather than generic, and being genuinely present and knowledgeable, rather than leaning on external advisers to cover for a thin internal picture.
The FCA still expects the same personal accountability either way, combining the roles doesn't lower the bar, it just concentrates it in one person.
Who can actually become one
There's a persistent myth in compliance circles that you need to have already been an MLRO to become one. The FCA has explicitly said otherwise. Applicants do not need prior head of compliance or MLRO experience, a background in a more junior compliance role, compliance manager, deputy MLRO, or equivalent, is one legitimate route in, the FCA says that kind of experience can help, without describing how common it is as a route.
What the FCA is actually screening for is whether the individual can demonstrate, in their own right, sufficient knowledge and experience to make real compliance decisions for that specific business. That's a functional test, not a credentials checklist. It means:
- Diverse professional backgrounds are acceptable. The FCA specifically names compliance teams, legal teams, lawyers, accountants, and consultants as accepted backgrounds; relevant experience from other sectors, including internal audit, can also be taken into account, provided the person's actual experience maps onto what the role demands at that firm.
- Front-line experience alone is usually not enough. Someone whose entire career has been sales or operations, with no compliance, risk, or legal grounding, tends to struggle to satisfy the FCA that they understand the regulatory environment they'd be accountable for.
- Seniority and independence are also relevant factors, alongside technical knowledge, the FCA doesn't publish a specific weighting between them. The role needs to sit close enough to real decision making to be effective, and free enough from conflicting duties to exercise independent judgement.
What it actually takes: the FCA's real bar
The FCA published explicit guidance on what separates a strong SMF16/17 application from a weak one, drawn from patterns across the applications it reviews. Four things come up consistently: training, experience, third-party support, and capacity, with the individual's physical location assessed as one factor within capacity, not a separate category of its own.
Depth of training, not breadth of certificates
Short introductory courses, on their own, do not provide sufficient coverage for either role, even at the smallest firms. The FCA has said that training containing an assessment or examination component is better at demonstrating that relevant knowledge has actually been gained than attendance alone, that's a narrower claim than saying it demonstrates retained knowledge better over time. What matters is whether the training is current, relevant to the firm's actual business type, and substantive enough to hold up under questioning.
Relevant experience, not necessarily prior MLRO experience
Experience is assessed on its own terms too, separately from training, and it doesn't need to be prior head of compliance or MLRO experience specifically, see the section above for what backgrounds the FCA actually accepts and what the functional competence test looks for in practice.
Genuine, proportionate time commitment, including location
Part-time SMF16/17 roles are accepted, particularly at smaller firms, but the time allocated has to be real, candidates proposing only a handful of hours a week tend to be unsuccessful, though the FCA doesn't describe this as an automatic or outright rejection. If the individual holds another role internally or externally, the FCA will look directly at whether that creates a conflict of interest with the objectivity the role requires. Where the candidate is actually based feeds into this same capacity picture rather than standing as a separate bar: current FCA guidance expressly welcomes overseas candidates, takes overseas experience into account, and states that processing an application takes no longer than for a UK-based candidate, with some activities permitted from overseas provided the individual's actual presence stays consistent with their responsibilities. No comparative approval rate between UK-based and overseas candidates is published anywhere.
Internal competence, not outsourced competence
External compliance consultants and law firms are not a required part of running a compliance function, the FCA describes external advice as optional. It has been clear, though, that an application will probably be refused if external support is the firm's only compliance resource. The named individual, not the firm's advisers, has to be able to demonstrate sufficient personal knowledge to make compliance calls, know when to seek advice, and know how to implement it.
The approval process, step by step
Click any stage below to see the specific documents or common failure points that apply at that step.
The combination question every smaller firm faces
Many smaller and lower-complexity firms face a genuine, non-trivial decision: one person holding both SMF16 and SMF17, or two. Whether combination is even available depends on the firm's regulatory status, firm type, and permissions, not a single Enhanced-tier threshold, Enhanced categorisation is itself set by six separate tests, not one figure, and doesn't on its own determine whether the functions can be combined. There's no single correct answer to the combination question itself, but there is a wrong way to reach it, drifting into it by default because the firm hasn't actively decided either way. The FCA requires ongoing fitness and propriety assessment of SMF holders at least annually, which necessarily touches on capacity and conflicts, though no FCA source specifically calls out periodic reconsideration of the combination decision itself as a distinct expectation beyond that general review.
Where the roles are combined, the practical risk isn't competence, it's capacity and independence, one person now concentrates both general regulatory compliance and AML-specific accountability, with no internal separation of duties if either area comes under scrutiny at the same time. That concentration doesn't displace the firm's own obligations, senior management or board-level responsibilities, or the independent audit arrangements required under MLR 2017 regulation 21 where applicable, the combined role holder isn't the sole point of accountability for the firm's entire AML framework.