Section 1

What SMF16 and SMF17 actually are

SMF16, Compliance Oversight, and SMF17, the Money Laundering Reporting Officer, are two Senior Management Functions central to a firm's financial crime defence, though not every regulated firm requires both. All dual-regulated firms require SMF16; for solo-regulated firms, whether SMF16 applies depends on the firm's regulatory status, type, and permissions, and the Senior Managers and Certification Regime applies differently across its Enhanced, Core, and Limited Scope tiers. SMF16 holds personal accountability under the Duty of Responsibility, conditional on a firm contravention in an area the individual was responsible for and a failure to take reasonably expected steps, not blanket liability for every FCA rule. SMF17 carries individual responsibility for the firm's anti-money laundering controls specifically; under MLR 2017 regulation 21, the firm must notify the relevant supervisory authority of the nominated officer's identity within 14 days of appointment, a narrower requirement than a general expectation that the FCA or the NCA can reach the holder directly.

Both are Senior Management Functions under the Senior Managers and Certification Regime. Holding one means FCA approval before you start the role, and a Statement of Responsibilities that names exactly what you're accountable for. The personal Duty of Responsibility, under section 66A of the Financial Services and Markets Act 2000, is not a standalone duty that exists independently of the employer, it applies where there has been a contravention by the firm, the individual was responsible for the relevant area, and the individual failed to take the steps a person in that position could reasonably be expected to take to prevent it. No FCA source publishes a specific "first question" it asks after an AML control failure, the statutory test above is what actually governs individual liability.

Whether SMF16 and SMF17 can be combined in one person, rather than requiring separate individuals, depends on the firm's SMCR categorisation and its specific regulatory permissions, not a fixed revenue threshold. Enhanced-firm categorisation is set by six separate tests (for example ยฃ65bn in assets under management, ยฃ45m in intermediary regulated business revenue, ยฃ130m in regulated consumer credit lending revenue, or 10,000 regulated mortgages), and SMF16 applicability depends on regulatory status, firm type, and permissions rather than a single figure. Larger or more complex firms more often split the two roles, driven by workload rather than a specific revenue rule.

Small or lower-complexity firm

Combining SMF16 and SMF17 in one person is permitted; whether it's realistic for a given firm turns on its actual SMCR categorisation and regulatory permissions, not a fixed revenue figure. The practical focus is realistic time allocation across both remits, training that's proportionate to the firm's actual risk profile rather than generic, and being genuinely present and knowledgeable, rather than leaning on external advisers to cover for a thin internal picture.

The FCA still expects the same personal accountability either way, combining the roles doesn't lower the bar, it just concentrates it in one person.

Section 2

Who can actually become one

There's a persistent myth in compliance circles that you need to have already been an MLRO to become one. The FCA has explicitly said otherwise. Applicants do not need prior head of compliance or MLRO experience, a background in a more junior compliance role, compliance manager, deputy MLRO, or equivalent, is one legitimate route in, the FCA says that kind of experience can help, without describing how common it is as a route.

What the FCA is actually screening for is whether the individual can demonstrate, in their own right, sufficient knowledge and experience to make real compliance decisions for that specific business. That's a functional test, not a credentials checklist. It means:

  • Diverse professional backgrounds are acceptable. The FCA specifically names compliance teams, legal teams, lawyers, accountants, and consultants as accepted backgrounds; relevant experience from other sectors, including internal audit, can also be taken into account, provided the person's actual experience maps onto what the role demands at that firm.
  • Front-line experience alone is usually not enough. Someone whose entire career has been sales or operations, with no compliance, risk, or legal grounding, tends to struggle to satisfy the FCA that they understand the regulatory environment they'd be accountable for.
  • Seniority and independence are also relevant factors, alongside technical knowledge, the FCA doesn't publish a specific weighting between them. The role needs to sit close enough to real decision making to be effective, and free enough from conflicting duties to exercise independent judgement.
๐Ÿงญ Self-check ยท Educational only
Could you be put forward as SMF16/17? Answer all six questions for a directional read out. This is educational only, it is not a formal fitness and propriety determination.
1. Which best describes your professional background?
2. Would you have genuine authority to challenge business decisions and reach senior management or the board directly?
3. Realistically, how many hours a week could you dedicate to this role?
4. Would this role sit alongside another role that could create a conflict of interest, for example sales or client relationship management?
5. Would where you're actually based stay consistent with the role's responsibilities, including reachability and oversight?
6. Has your compliance or AML training included an assessed or examined component, not just attendance at short introductory courses?
Educational self-check only, based on the factors the FCA has said it looks for. This is not a formal fitness and propriety determination. Only your firm's own internal assessment, and ultimately FCA approval, determines whether you meet the fit and proper standard.
Section 3

What it actually takes: the FCA's real bar

The FCA published explicit guidance on what separates a strong SMF16/17 application from a weak one, drawn from patterns across the applications it reviews. Four things come up consistently: training, experience, third-party support, and capacity, with the individual's physical location assessed as one factor within capacity, not a separate category of its own.

Depth of training, not breadth of certificates

Short introductory courses, on their own, do not provide sufficient coverage for either role, even at the smallest firms. The FCA has said that training containing an assessment or examination component is better at demonstrating that relevant knowledge has actually been gained than attendance alone, that's a narrower claim than saying it demonstrates retained knowledge better over time. What matters is whether the training is current, relevant to the firm's actual business type, and substantive enough to hold up under questioning.

Relevant experience, not necessarily prior MLRO experience

Experience is assessed on its own terms too, separately from training, and it doesn't need to be prior head of compliance or MLRO experience specifically, see the section above for what backgrounds the FCA actually accepts and what the functional competence test looks for in practice.

Genuine, proportionate time commitment, including location

Part-time SMF16/17 roles are accepted, particularly at smaller firms, but the time allocated has to be real, candidates proposing only a handful of hours a week tend to be unsuccessful, though the FCA doesn't describe this as an automatic or outright rejection. If the individual holds another role internally or externally, the FCA will look directly at whether that creates a conflict of interest with the objectivity the role requires. Where the candidate is actually based feeds into this same capacity picture rather than standing as a separate bar: current FCA guidance expressly welcomes overseas candidates, takes overseas experience into account, and states that processing an application takes no longer than for a UK-based candidate, with some activities permitted from overseas provided the individual's actual presence stays consistent with their responsibilities. No comparative approval rate between UK-based and overseas candidates is published anywhere.

Internal competence, not outsourced competence

External compliance consultants and law firms are not a required part of running a compliance function, the FCA describes external advice as optional. It has been clear, though, that an application will probably be refused if external support is the firm's only compliance resource. The named individual, not the firm's advisers, has to be able to demonstrate sufficient personal knowledge to make compliance calls, know when to seek advice, and know how to implement it.

Section 4

The approval process, step by step

Click any stage below to see the specific documents or common failure points that apply at that step.

1
Internal fit and proper assessment
+
The firm identifies a candidate and satisfies itself internally, before ever contacting the FCA, that the person meets the fit and proper standard: honesty, integrity and reputation, competence and capability, and financial soundness.
2
Form A, supporting evidence, and Statement of Responsibilities via Connect
+
A Form A is submitted through the FCA's Connect system, the formal application for approval, together with the required supporting evidence (Form A itself calls for ten years of employment history) and a Statement of Responsibilities setting out precisely what the individual will be accountable for. For a new firm going through authorisation, these are submitted as part of the wider application, and application fees apply where the relevant activity requires one. Common failure point: the FCA does not require a CV, so a missing CV isn't itself a cause of an incomplete application, the recurring issues are an incomplete application form or an inadequate explanation of how responsibilities are actually allocated; for Enhanced firms specifically, an out-of-date management responsibilities map is also a live issue.
3
FCA review, and possibly an interview
+
The FCA reviews the application, and this is not a self-certification process. Whether it goes further than a paper review is risk-based: the FCA may request a formal interview where there are fitness concerns, the firm itself has been challenged, or the role carries significant potential impact, no fixed proportion of applications going to interview is published. Expect: firms and candidates should be ready to explain, in specific and practical terms, how the AML framework works for that business, not recite policy from memory.
4
Approval, conditional approval, or refusal
+
Outcomes include approval, conditional or time-limited approval, and refusal, not simply approval versus further questions. Recurring patterns behind a difficult outcome: insufficient time committed to the role, training that's too shallow or generic for the firm's actual risk profile, unresolved conflicts of interest, or a firm that clearly cannot function without its external advisers standing in for the named individual's own judgement, the FCA doesn't publish these as a formally measured list of rejection categories, but they recur across its own published guidance on what goes wrong.
5
Approval must precede starting the role
+
Approval has to be obtained before the person actually starts performing the function, the two are distinct events, not the same moment. Once in the role, personal liability under the Duty of Responsibility isn't triggered simply by the fact of approval, it depends on the statutory test: a contravention by the firm, in an area the individual was responsible for, where the individual failed to take the steps a person in that position could reasonably be expected to take. The Statement of Responsibilities and the Duty of Responsibility matter because they define what that test is actually measured against if something later goes wrong, not because a problem alone is enough to trigger liability.
Section 5

The combination question every smaller firm faces

Many smaller and lower-complexity firms face a genuine, non-trivial decision: one person holding both SMF16 and SMF17, or two. Whether combination is even available depends on the firm's regulatory status, firm type, and permissions, not a single Enhanced-tier threshold, Enhanced categorisation is itself set by six separate tests, not one figure, and doesn't on its own determine whether the functions can be combined. There's no single correct answer to the combination question itself, but there is a wrong way to reach it, drifting into it by default because the firm hasn't actively decided either way. The FCA requires ongoing fitness and propriety assessment of SMF holders at least annually, which necessarily touches on capacity and conflicts, though no FCA source specifically calls out periodic reconsideration of the combination decision itself as a distinct expectation beyond that general review.

Where the roles are combined, the practical risk isn't competence, it's capacity and independence, one person now concentrates both general regulatory compliance and AML-specific accountability, with no internal separation of duties if either area comes under scrutiny at the same time. That concentration doesn't displace the firm's own obligations, senior management or board-level responsibilities, or the independent audit arrangements required under MLR 2017 regulation 21 where applicable, the combined role holder isn't the sole point of accountability for the firm's entire AML framework.

๐Ÿ“˜
Coming in Part 2
This section covers eligibility, requirements, and the formal approval route. The next section in this handbook covers what the role looks like day to day once approved, the SAR process, board reporting lines, and where SMF16/17 liability has actually been tested in enforcement action.
Quick Reference
MLRO / SMF16-17 at a glance, cheat sheet summary Summary card covering who can apply, what it takes, the five step approval process, and the combination question, for the MLRO Handbook Part 1 guide. MLRO / SMF16-17 AT A GLANCE: CHEAT SHEET WHO CAN APPLY No prior MLRO experience required, just proven compliance-adjacent judgement Legal ยท accountancy ยท consultancy backgrounds all considered WHAT IT TAKES Depth of training, not breadth of certificates Genuine, proportionate time commitment Internal competence, not outsourced COMBINE SMF16/17? Depends on categorisation and permissions, active decision not a default Risk shifts from competence to capacity and independence THE FIVE STEP APPROVAL PROCESS 1 Firm assesses fit and proper 2 Form A + Statement of Resp. 3 FCA reviews, may interview 4 Approved or challenged 5 Approval before role starts A summary aid, not a substitute for the full guide or professional advice. fincrimeradar.org