What SMF16 and SMF17 actually are
Two functions sit at the centre of every regulated firm's defence against financial crime. SMF16, Compliance Oversight, is the senior individual personally accountable for the firm's compliance with FCA rules. SMF17, the Money Laundering Reporting Officer, carries personal accountability for the firm's anti-money laundering controls specifically, the person the FCA and the National Crime Agency expect to be able to name and reach directly.
Both are Senior Management Functions under the Senior Managers and Certification Regime. Holding one means FCA approval before you start the role, a Statement of Responsibilities that names exactly what you're accountable for, and a personal Duty of Responsibility under the Financial Services and Markets Act that survives independently of your employer. If the firm gets its AML controls wrong, the question the FCA asks first is not "what did the firm do", it's "what did the SMF17 holder know, and what did they do about it."
In firms below roughly ยฃ20 million in revenue, SMF16 and SMF17 are routinely held by the same person. That's permitted, and it's standard practice, not a compromise. In larger or more complex firms, the workload typically forces a split between the two.
One person holding both SMF16 and SMF17 is standard practice here, not a compromise or a workaround. The practical focus is realistic time allocation across both remits, training that's proportionate to the firm's actual risk profile rather than generic, and being genuinely present and knowledgeable, rather than leaning on external advisers to cover for a thin internal picture.
The FCA still expects the same personal accountability either way, combining the roles doesn't lower the bar, it just concentrates it in one person.
Who can actually become one
There's a persistent myth in compliance circles that you need to have already been an MLRO to become one. The FCA has explicitly said otherwise. Applicants do not need prior head of compliance or MLRO experience, a background in a more junior compliance role, compliance manager, deputy MLRO, or equivalent, is a legitimate and common route in.
What the FCA is actually screening for is whether the individual can demonstrate, in their own right, sufficient knowledge and experience to make real compliance decisions for that specific business. That's a functional test, not a credentials checklist. It means:
- Diverse professional backgrounds are acceptable. Legal, accountancy, consultancy, and internal audit backgrounds are all considered, provided the person's actual experience maps onto what the role demands at that firm.
- Front-line experience alone is usually not enough. Someone whose entire career has been sales or operations, with no compliance, risk, or legal grounding, tends to struggle to satisfy the FCA that they understand the regulatory environment they'd be accountable for.
- Seniority and independence matter as much as technical knowledge. The role needs to sit close enough to real decision making to be effective, and free enough from conflicting duties to exercise independent judgement.
What it actually takes: the FCA's real bar
The FCA published explicit guidance on what separates a strong SMF16/17 application from a weak one, drawn from patterns across the applications it reviews. Four things come up consistently.
Depth of training, not breadth of certificates
Short introductory courses, on their own, do not provide sufficient coverage for either role, even at the smallest firms. Training with an assessment or examination component demonstrates retained knowledge far better than attendance alone, and the FCA has said as much directly. What matters is whether the training is current, relevant to the firm's actual business type, and substantive enough to hold up under questioning.
Genuine, proportionate time commitment
Part-time SMF16/17 roles are accepted, particularly at smaller firms, but the time allocated has to be real. Applications proposing a handful of hours a week have a track record of being rejected outright. If the individual holds another role internally or externally, the FCA will look directly at whether that creates a conflict of interest with the objectivity the role requires.
Internal competence, not outsourced competence
External compliance consultants and law firms are a normal and often necessary part of running a compliance function, but the FCA has been clear that reliance on external support alone does not satisfy the requirement. The named individual, not the firm's advisers, has to be able to demonstrate sufficient personal knowledge to make compliance calls. Applications where a firm leans entirely on outside advisers, with no genuinely competent internal person behind the title, have tended not to succeed.
Physical and operational presence
Applicants working from the firm's actual UK place of business have a stronger track record of approval than those operating remotely or from overseas, a detail that surprises some fintech and early stage applicants used to fully distributed teams.
The approval process, step by step
Click any stage below to see the specific documents or common failure points that apply at that step.
The combination question every smaller firm faces
Firms under the Enhanced tier threshold face a genuine, non-trivial decision: one person holding both SMF16 and SMF17, or two. There's no single correct answer, but there is a wrong way to reach it, which is drifting into the combination by default because the firm hasn't actively decided either way. The FCA expects firms to have consciously assessed whether combination is appropriate given the firm's size, complexity, and risk profile, and to revisit that assessment periodically rather than setting it once and forgetting it.
Where the roles are combined, the practical risk isn't competence, it's capacity and independence. One person is now the sole point of accountability for both general regulatory compliance and the firm's entire AML defence, with no internal separation of duties if either area comes under scrutiny at the same time.