Section 1

What SMF16 and SMF17 actually are

Two functions sit at the centre of every regulated firm's defence against financial crime. SMF16, Compliance Oversight, is the senior individual personally accountable for the firm's compliance with FCA rules. SMF17, the Money Laundering Reporting Officer, carries personal accountability for the firm's anti-money laundering controls specifically, the person the FCA and the National Crime Agency expect to be able to name and reach directly.

Both are Senior Management Functions under the Senior Managers and Certification Regime. Holding one means FCA approval before you start the role, a Statement of Responsibilities that names exactly what you're accountable for, and a personal Duty of Responsibility under the Financial Services and Markets Act that survives independently of your employer. If the firm gets its AML controls wrong, the question the FCA asks first is not "what did the firm do", it's "what did the SMF17 holder know, and what did they do about it."

"What did the SMF17 holder know, and what did they do about it?"

In firms below roughly ยฃ20 million in revenue, SMF16 and SMF17 are routinely held by the same person. That's permitted, and it's standard practice, not a compromise. In larger or more complex firms, the workload typically forces a split between the two.

Small firm, roughly under ยฃ20m revenue

One person holding both SMF16 and SMF17 is standard practice here, not a compromise or a workaround. The practical focus is realistic time allocation across both remits, training that's proportionate to the firm's actual risk profile rather than generic, and being genuinely present and knowledgeable, rather than leaning on external advisers to cover for a thin internal picture.

The FCA still expects the same personal accountability either way, combining the roles doesn't lower the bar, it just concentrates it in one person.

Section 2

Who can actually become one

There's a persistent myth in compliance circles that you need to have already been an MLRO to become one. The FCA has explicitly said otherwise. Applicants do not need prior head of compliance or MLRO experience, a background in a more junior compliance role, compliance manager, deputy MLRO, or equivalent, is a legitimate and common route in.

What the FCA is actually screening for is whether the individual can demonstrate, in their own right, sufficient knowledge and experience to make real compliance decisions for that specific business. That's a functional test, not a credentials checklist. It means:

  • Diverse professional backgrounds are acceptable. Legal, accountancy, consultancy, and internal audit backgrounds are all considered, provided the person's actual experience maps onto what the role demands at that firm.
  • Front-line experience alone is usually not enough. Someone whose entire career has been sales or operations, with no compliance, risk, or legal grounding, tends to struggle to satisfy the FCA that they understand the regulatory environment they'd be accountable for.
  • Seniority and independence matter as much as technical knowledge. The role needs to sit close enough to real decision making to be effective, and free enough from conflicting duties to exercise independent judgement.
๐Ÿงญ Self-check ยท Educational only
Could you be put forward as SMF16/17? Answer all six questions for a directional read out. This is educational only, it is not a formal fitness and propriety determination.
1. Which best describes your professional background?
2. Would you have genuine authority to challenge business decisions and reach senior management or the board directly?
3. Realistically, how many hours a week could you dedicate to this role?
4. Would this role sit alongside another role that could create a conflict of interest, for example sales or client relationship management?
5. Would you be working from the firm's actual UK place of business?
6. Has your compliance or AML training included an assessed or examined component, not just attendance at short introductory courses?
Educational self-check only, based on the factors the FCA has said it looks for. This is not a formal fitness and propriety determination. Only your firm's own internal assessment, and ultimately FCA approval, determines whether you meet the fit and proper standard.
Section 3

What it actually takes: the FCA's real bar

The FCA published explicit guidance on what separates a strong SMF16/17 application from a weak one, drawn from patterns across the applications it reviews. Four things come up consistently.

Depth of training, not breadth of certificates

Short introductory courses, on their own, do not provide sufficient coverage for either role, even at the smallest firms. Training with an assessment or examination component demonstrates retained knowledge far better than attendance alone, and the FCA has said as much directly. What matters is whether the training is current, relevant to the firm's actual business type, and substantive enough to hold up under questioning.

Genuine, proportionate time commitment

Part-time SMF16/17 roles are accepted, particularly at smaller firms, but the time allocated has to be real. Applications proposing a handful of hours a week have a track record of being rejected outright. If the individual holds another role internally or externally, the FCA will look directly at whether that creates a conflict of interest with the objectivity the role requires.

Internal competence, not outsourced competence

External compliance consultants and law firms are a normal and often necessary part of running a compliance function, but the FCA has been clear that reliance on external support alone does not satisfy the requirement. The named individual, not the firm's advisers, has to be able to demonstrate sufficient personal knowledge to make compliance calls. Applications where a firm leans entirely on outside advisers, with no genuinely competent internal person behind the title, have tended not to succeed.

Physical and operational presence

Applicants working from the firm's actual UK place of business have a stronger track record of approval than those operating remotely or from overseas, a detail that surprises some fintech and early stage applicants used to fully distributed teams.

Section 4

The approval process, step by step

Click any stage below to see the specific documents or common failure points that apply at that step.

1
Internal fit and proper assessment
+
The firm identifies a candidate and satisfies itself internally, before ever contacting the FCA, that the person meets the fit and proper standard: honesty and integrity, competence and capability, and financial soundness.
2
Form A and Statement of Responsibilities submitted via Connect
+
A Form A is submitted through the FCA's Connect system, the formal application for approval, alongside a Statement of Responsibilities setting out precisely what the individual will be accountable for. For a new firm going through authorisation, both are submitted as part of the wider application. Common failure point: a missing or thin CV, or a vaguely defined responsibility map, is a common cause of an application being marked incomplete before it's even substantively reviewed.
3
FCA review, and possibly an interview
+
The FCA reviews the application and, in a meaningful proportion of cases, does not stop there. This is not a self-certification process. If the FCA has questions about competency, time commitment, independence, or the depth of the candidate's training, it can and does request a formal interview. Expect: firms and candidates should be ready to explain, in specific and practical terms, how the AML framework works for that business, not recite policy from memory.
4
Approval, or further questions
+
Approval is granted, or the FCA raises further questions. Recurring rejection patterns: insufficient time committed to the role, training that's too shallow or generic for the firm's actual risk profile, unresolved conflicts of interest, or a firm that clearly cannot function without its external advisers standing in for the named individual's own judgement.
5
Ongoing responsibility begins
+
Ongoing responsibility begins immediately on approval. The Statement of Responsibilities and the Duty of Responsibility aren't paperwork exercises, they're the standard the FCA will hold the individual to if something goes wrong later, including in supervisory action or enforcement.
Section 5

The combination question every smaller firm faces

Firms under the Enhanced tier threshold face a genuine, non-trivial decision: one person holding both SMF16 and SMF17, or two. There's no single correct answer, but there is a wrong way to reach it, which is drifting into the combination by default because the firm hasn't actively decided either way. The FCA expects firms to have consciously assessed whether combination is appropriate given the firm's size, complexity, and risk profile, and to revisit that assessment periodically rather than setting it once and forgetting it.

Where the roles are combined, the practical risk isn't competence, it's capacity and independence. One person is now the sole point of accountability for both general regulatory compliance and the firm's entire AML defence, with no internal separation of duties if either area comes under scrutiny at the same time.

๐Ÿ“˜
Coming in Part 2
This section covers eligibility, requirements, and the formal approval route. The next section in this handbook covers what the role looks like day to day once approved, the SAR process, board reporting lines, and where SMF16/17 liability has actually been tested in enforcement action.
Quick Reference
MLRO / SMF16-17 at a glance, cheat sheet summary Summary card covering who can apply, what it takes, the five step approval process, and the combination question, for the MLRO Handbook Part 1 guide. MLRO / SMF16-17 AT A GLANCE โ€” CHEAT SHEET WHO CAN APPLY No prior MLRO experience required, just proven compliance-adjacent judgement Legal ยท accountancy ยท consultancy backgrounds all considered WHAT IT TAKES Depth of training, not breadth of certificates Genuine, proportionate time commitment Internal competence, UK-based COMBINE SMF16/17? Standard below ~ยฃ20m revenue, active decision not a default Risk shifts from competence to capacity and independence THE FIVE STEP APPROVAL PROCESS 1 Firm assesses fit and proper 2 Form A + Statement of Resp. 3 FCA reviews, may interview 4 Approved or challenged 5 Personal duty begins immediately A summary aid, not a substitute for the full guide or professional advice. fincrimeradar.org