How to Prepare a Credible SM&CR Statement of Responsibilities
This guide sets out how senior managers and governance teams should draft, test and maintain a Statement of Responsibilities that stands up to regulatory challenge and successor review. After reading it, you will know what to include, what to cut, and how to evidence the judgements behind every line.
A Statement of Responsibilities (SoR) is read twice: once when it is filed, and again when something has gone wrong. The second reading is the one that matters. Regulators, internal investigators and your successor will treat the document as the authoritative map of what you owned, when you owned it, and what you did about it. A thin, generic or stale SoR is a governance problem long before it is a regulatory one.
Key Executive Takeaways
- An SoR must describe real accountability as it operates day to day, not a tidied version of the org chart or a restatement of the Prescribed Responsibilities.
- The document only holds up under scrutiny if it is anchored to evidence: committee terms of reference, delegations, MI flows and reporting lines that match what it claims.
- Treat the SoR as a living record. Every material change in scope, structure or shared responsibility should trigger a prompt revision, not an annual tidy-up.
Start from what you actually do, not the template
Most weak SoRs are weak because they begin with the FCA template and work backwards. Start instead with a blank page and write, in plain English, what you are accountable for in this role: which businesses, legal entities, functions, products, geographies and risk types. Then map each item to the relevant Prescribed Responsibility, Overall Responsibility or Senior Management Function. If something you do in practice does not map cleanly, that is the interesting question. Either the mapping needs rethinking, or the firm's responsibilities map does.
What good looks like: a reader who has never met you can describe, within five minutes, the perimeter of your role, where it touches other SMFs, and where the hand-offs sit.
Be specific about shared and divided responsibilities
Shared responsibilities are where SoRs most often fail under scrutiny. If two SMFs share accountability for, say, operational resilience of a critical business service, the SoR must say who leads, who contributes, how disagreements are resolved, and where the decision rights sit. Vague phrasing like "jointly responsible with the COO" invites a regulator to ask who was actually in the chair when the issue arose. If you cannot answer that in the document, you will have to answer it in an interview.
The same applies to divided responsibilities across legal entities, matrix reporting lines, or group versus solo arrangements. Name the entity. Name the committee. Name the escalation route.
Anchor every claim to evidence
For each responsibility, you should be able to point to: the committee or forum where it is discharged, the MI you receive, the delegations you have made and to whom, and the frequency of review. You do not need to put all of this in the SoR itself, but the Management Responsibilities Map, committee ToRs and delegation letters must be consistent with it. Inconsistencies between these documents are the single most common finding in enforcement cases involving senior manager conduct.
Run a line-by-line reconciliation before filing. If the SoR says you chair a committee that no longer meets, fix it before a regulator does.
Write for your successor
The best test of an SoR is whether someone taking over your role in six months could use it as a working handover document. That means describing not just what you are responsible for, but the known issues, remediation programmes, regulatory commitments and open supervisory matters that sit within your perimeter at the point of signing. A successor-ready SoR protects both of you: it establishes what you handed over and what they inherited.
Keep it current
Trigger a review whenever: your scope changes, a new product or entity enters your perimeter, a shared responsibility is renegotiated, an SMF around you changes, or a significant regulatory matter opens or closes. Annual reviews are a floor, not a ceiling. A dated SoR that no longer reflects reality is worse than no SoR at all, because it evidences that governance was not keeping pace.
The next decision
Pull your current SoR today and read it as if you were the successor, the internal investigator and the supervisor. If any of the three would struggle to understand what you own and how you discharge it, start the rewrite this week.
Frequently Asked Questions
How detailed should the SoR be?
Detailed enough that a reader can understand scope, boundaries and hand-offs without needing a conversation. Short enough that it is readable in one sitting. Most credible SoRs run to two or three pages of substantive content, supported by a clear link to the Management Responsibilities Map.
What should we do about responsibilities that are genuinely shared?
Name the sharing arrangement explicitly, identify the lead SMF, and describe how decisions are made and recorded. Shared accountability is permitted and sometimes unavoidable, but it must be legible. Ambiguity is the risk, not the sharing itself.
Who should review the SoR before it is filed?
At minimum: the SMF holder, the Chair or line manager, the Head of Compliance, and the company secretary or governance team responsible for the Responsibilities Map. For material roles, legal review is sensible, particularly where group structures or outsourcing arrangements are involved.
How do we handle interim or acting arrangements?
File an updated SoR for the acting holder, even if the arrangement is short. Supervisors expect to see the paper trail. Relying on informal cover without documentation is a common and avoidable finding.
What is the single most common weakness regulators flag?
Disconnection between the SoR and operational reality: committees that have been restructured, delegations that have moved, or responsibilities that have shifted following a reorganisation. The document on file no longer describes how the firm actually runs.
Frequently asked questions
How detailed should the SoR be?
Detailed enough that a reader can understand scope, boundaries and hand-offs without needing a conversation. Short enough that it is readable in one sitting. Most credible SoRs run to two or three pages of substantive content, supported by a clear link to the Management Responsibilities Map.
What should we do about responsibilities that are genuinely shared?
Name the sharing arrangement explicitly, identify the lead SMF, and describe how decisions are made and recorded. Shared accountability is permitted and sometimes unavoidable, but it must be legible. Ambiguity is the risk, not the sharing itself.
Who should review the SoR before it is filed?
At minimum: the SMF holder, the Chair or line manager, the Head of Compliance, and the company secretary or governance team responsible for the Responsibilities Map. For material roles, legal review is sensible, particularly where group structures or outsourcing arrangements are involved.
How do we handle interim or acting arrangements?
File an updated SoR for the acting holder, even if the arrangement is short. Supervisors expect to see the paper trail. Relying on informal cover without documentation is a common and avoidable finding.
What is the single most common weakness regulators flag?
Disconnection between the SoR and operational reality: committees that have been restructured, delegations that have moved, or responsibilities that have shifted following a reorganisation. The document on file no longer describes how the firm actually runs.
Related guides
How to Prepare a Credible Response to a PRA Capital Add-On Proposal
This guide sets out how to respond substantively to a PRA proposal for a Pillar 2A or 2B capital add-on, from first read through to final representations. It helps senior leaders structure the technical rebuttal, govern the process properly, and engage the supervisor in a way that improves the quality of the outcome.
How to Prepare a Credible Response to an FCA Consumer Duty Finding
This guide sets out how senior leaders should respond to an FCA supervisory finding on consumer duty outcomes, from first read to remediation plan. After reading, you will know how to structure a response that demonstrates genuine engagement, credible evidence, and a realistic path to better customer outcomes.
How to Build a Credible Operational Resilience Self-Assessment
This guide sets out how to produce an operational resilience self-assessment that stands up to board challenge and supervisory review. After reading it, senior leaders will know how to structure the document, where the evidence typically falls short, and how to demonstrate genuine capability rather than paper compliance.
Structuring a Threshold Conditions Self-Assessment That Evidences Ongoing Compliance
This guide sets out how to structure a Threshold Conditions self-assessment that credibly evidences continued satisfaction of FSMA Schedule 6 and COND, while surfacing resource or business model pressures honestly and with a clear remediation path. Readers will finish able to commission, review, and sign off a document that stands up to supervisory scrutiny and supports genuine board oversight.
How to Prepare a Credible Response to a Section 165 Request
This guide explains how to respond to an FCA or PRA Section 165 information request with the rigour, accuracy and timeliness regulators expect. After reading it, you will know how to mobilise the right people, control the production process, and engage credibly with the supervisor throughout.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity