How to Structure a Senior Manager Handover Certificate That Protects Incoming SMF Holders
This guide sets out how to construct a Senior Manager handover certificate that discharges the outgoing SMF's SYSC 25.9 obligations while giving the incoming holder documented protection against inherited accountability. Readers will learn what to demand in the handover pack, how to record known issues, and how to sequence sign-off to preserve evidential value if the FCA later challenges conduct that predates the transition.
A handover certificate is not a formality. It is the primary document the FCA will read when deciding whether an incoming Senior Manager took reasonable steps during the critical first months in role. Done well, it draws a clean line between legacy exposure and forward accountability. Done badly, it silently transfers historic problems onto the new holder's Statement of Responsibilities.
Key Executive Takeaways
- The handover certificate must name specific unresolved issues, remediation status, and known regulatory attention, not offer bland assurance that everything is in order.
- The incoming SMF should sign an acknowledgement of receipt only, never a countersignature endorsing the accuracy of the outgoing SMF's account.
- Legal privilege, board minute cross-references, and dated evidence packs are what turn a handover note into a defensible record if the FCA later challenges conduct that straddles the transition.
Start with what the rule actually requires
SYSC 25.9 requires that a Senior Manager taking on a new role receives all information and materials they could reasonably expect to do their job. The obligation sits on the firm, but in practice it is discharged through the outgoing SMF. The certificate is the artefact that proves discharge occurred. It is also, inevitably, the document that gets forensically examined when something goes wrong twelve months later.
The drafting problem is this: the outgoing SMF wants a document that closes their exposure. The incoming SMF wants a document that opens a protected window. The firm wants a document that satisfies the regulator. These three objectives are not aligned, and pretending they are is where most handover certificates fail.
What the certificate must contain
Structure the document in four parts.
Part one: scope of role and permissions. Reference the current Statement of Responsibilities, the relevant Prescribed Responsibilities, and any shared or divided responsibilities. Attach the current governance map. This anchors the handover to the formal accountability perimeter.
Part two: known issues register. This is the section that does the protective work. List, individually and by date, every open regulatory matter, internal audit finding, risk acceptance, skilled persons review, past business review, customer remediation programme, and material control weakness. For each, record: date identified, current status, remediation owner, expected closure date, and whether the FCA or PRA has been notified. Vague summaries destroy the protection. Specificity creates it.
Part three: matters under regulatory attention. Correspondence with supervisors, live s.166 work, ongoing information requests, any Early Warning Notice or draft Warning Notice, whistleblowing matters under investigation, and any Principle 11 notifications made in the preceding 24 months. Include copies or clear references to the evidence pack.
Part four: judgement calls and risk acceptances. Decisions the outgoing SMF made where reasonable people could have decided differently. This is the section outgoing SMFs resist most. It is also the section that most reduces the incoming SMF's inherited exposure, because it forces contested judgements into the light rather than allowing them to be reframed later as failures the successor should have detected.
Sequencing the sign-off
The incoming SMF should never countersign the outgoing SMF's certificate as accurate. They cannot verify it on day one. Instead, use a two-document structure: the outgoing SMF signs an attestation of completeness, and the incoming SMF signs a separate acknowledgement of receipt, dated the same day but explicitly reserving position pending their own reasonable steps review.
Book a 90-day review point into the acknowledgement. This creates a defined window in which the incoming SMF conducts independent verification and either adopts, qualifies, or challenges the inherited position. That window is what the FCA will look for when assessing whether reasonable steps were taken.
What good looks like
A strong handover pack runs to hundreds of pages. It includes the certificate, the evidence bundle, board and committee minutes for the preceding 18 months, the risk appetite statement, MI packs actually received by the outgoing SMF, and a documented walkthrough with the Chair of the relevant committee. Weak handovers are ten pages of narrative and a signature block.
The decision point
Before accepting the role, the incoming SMF should ask to see the draft certificate and evidence pack. If it is not ready, or if the outgoing SMF resists including the judgement calls section, that is the signal. Negotiate the document before the appointment takes effect, not after. Once the regulatory approval lands, the leverage disappears.
Frequently Asked Questions
Can the firm compel the outgoing SMF to complete a full certificate?
Yes, through the employment contract and SYSC 25.9 obligations, but enforcement is difficult if the outgoing SMF has already left. Build handover completion into notice period obligations and, where possible, defer a portion of variable remuneration against certification quality.
What if the outgoing SMF refuses to document contested judgements?
Escalate to the Chair and record the refusal. The incoming SMF should then document their own understanding of the contested areas in their 90-day review, with reference to the refusal. This preserves the protective effect even without cooperation.
Should the certificate be privileged?
Parts of the evidence pack may attract legal advice privilege. The certificate itself will not, and should be drafted on the assumption the FCA will read it. Route sensitive legal analysis through separate privileged advice, referenced but not reproduced in the certificate.
How long should records be retained?
Retain the full handover pack for at least six years, aligned with the SM&CR record-keeping requirement, and longer where matters remain open. Storage should be independent of the outgoing SMF's personal or departmental drives.
Frequently asked questions
Can the firm compel the outgoing SMF to complete a full certificate?
Yes, through the employment contract and SYSC 25.9 obligations, but enforcement is difficult if the outgoing SMF has already left. Build handover completion into notice period obligations and, where possible, defer a portion of variable remuneration against certification quality.
What if the outgoing SMF refuses to document contested judgements?
Escalate to the Chair and record the refusal. The incoming SMF should then document their own understanding of the contested areas in their 90-day review, with reference to the refusal. This preserves the protective effect even without cooperation.
Should the certificate be privileged?
Parts of the evidence pack may attract legal advice privilege. The certificate itself will not, and should be drafted on the assumption the FCA will read it. Route sensitive legal analysis through separate privileged advice, referenced but not reproduced in the certificate.
How long should records be retained?
Retain the full handover pack for at least six years, aligned with the SM&CR record-keeping requirement, and longer where matters remain open. Storage should be independent of the outgoing SMF's personal or departmental drives.
Related guides
Handing Over an SMR Role Mid-Remediation: A Practical Guide
This guide sets out how to structure a Senior Managers Regime handover when a key function holder departs partway through a remediation programme. After reading, you will know how to sequence the transition, protect regulatory continuity, and defend the handover if challenged.
How to Structure an SM&CR Statement of Responsibilities to Avoid Accountability Gaps
This guide sets out how to draft a Statement of Responsibilities that stands up to FCA and PRA scrutiny without creating unintended liability. Readers will learn how to allocate prescribed responsibilities cleanly, close overlap and gap risks, and produce a document that supports rather than undermines the SMF holder.
How to Structure a Whistleblowing Annual Report to the Board Under SYSC 18
This guide sets out how to build a board-level whistleblowing report that meets FCA SYSC 18.6 expectations while protecting reporter identity and case confidentiality. After reading, you will know what to include, what to leave out, and how to frame themes so the board can discharge oversight without becoming a de facto investigations committee.
How to Structure a Section 166 Scoping Response That Limits Reviewer Overreach
This guide sets out how to respond to an FCA or PRA Section 166 scoping notice in a way that constrains the skilled person's remit without antagonising the regulator. After reading, you will know how to shape the scope, methodology, and reporting terms before the skilled person is appointed.
Regulated Industry Governance Best Practice: A Practical Guide
This guide sets out what governance best practice actually looks like in regulated financial services, from board composition to evidencing challenge. After reading it, senior leaders will know where their governance is likely to fail regulatory scrutiny and what to fix first.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity