Structuring a PRA Senior Manager Attestation on Risk Framework Effectiveness
This guide sets out how to structure a Senior Manager attestation on the effectiveness of a firm's risk framework in a way that meets PRA supervisory expectations and stands up to later challenge. Readers will finish with a clear method for scoping, evidencing, qualifying, and signing an attestation that reflects the true state of the framework.
An attestation is a personal statement of fact by a Senior Manager. The PRA reads it as such, and so does the Enforcement Division if things later unravel. The task is not to soften the statement or hedge it into meaninglessness. It is to make an accurate, evidenced, appropriately scoped assertion that you can defend in two years, under different market conditions, in front of a supervisor who has your prior year's version open on the desk.
Key Executive Takeaways
- An attestation is only defensible if its scope, evidence base, and known limitations are explicit on the face of the document, not buried in supporting papers.
- Personal exposure comes from overstating certainty or omitting known weaknesses, not from disclosing issues honestly alongside credible remediation.
- The strongest attestations are built from a documented assurance chain that already exists in first, second, and third line reporting, not assembled bespoke at year end.
Start with what you are actually attesting to
Read the supervisory letter or rule reference carefully. "Effectiveness of the risk management framework" is not a single concept. It typically covers governance, risk appetite operation, identification and measurement, controls, reporting to the board, and remediation of known gaps. Break the statement into its component assertions and treat each as a separate evidential question. If the request letter is ambiguous, write to your supervisor and ask. A clarifying exchange before signature is worth more than a caveat afterwards.
Build the assurance chain before you draft
Good attestations are the visible tip of an assurance record that already exists. Before drafting, map each assertion to:
- First line control testing and self assessment output for the period.
- Second line risk opinions, including any qualified opinions from the CRO function.
- Internal Audit coverage and ratings, with attention to any "unsatisfactory" or repeat findings.
- Board and Board Risk Committee minutes recording challenge and management responses.
- External review, skilled person reports, or thematic feedback from the PRA.
If a component of the framework has not been independently tested in the attestation period, say so. A statement of effectiveness that rests on untested self assessment is fragile.
Write the scope section as if a supervisor will test every word
The scope paragraph is where most attestations go wrong. Common errors: describing the framework in aspirational terms, using group level language when the entity is UK regulated, or dating the assertion to a point that predates known incidents. Be precise about the legal entity, the risk types covered, the period, and any material carve outs (for example, a newly acquired portfolio still being integrated).
Handle known weaknesses on the face of the document
The instinct to move issues into an appendix is the single biggest source of personal exposure. If a control has failed, if a risk appetite metric has been breached repeatedly, or if a remediation programme is behind schedule, state it in the body of the attestation, describe the mitigation, and identify the accountable owner and target date. An attestation that reads "effective, subject to the matters set out below" is defensible. One that reads "effective" while material issues sit in a separate risk report is not.
Calibrate the language
Avoid absolutes. "Effective in all material respects, based on the assurance sources listed in Annex A, as at 31 December" is a defensible formulation. "Fully effective" is not, and neither is "broadly effective" without definition. If you are relying on the work of others, say so and name the sources. Reliance is legitimate; concealed reliance is not.
Sequence the sign off
Circulate the draft to the CRO, General Counsel, Chief Internal Auditor, and the Chair of the Board Risk Committee before signature. Their comments should be logged. If any of them disagrees materially with the assertion, that disagreement needs to be resolved on the record, not smoothed over. The Board Risk Committee should see the final version before it goes to the PRA.
What good looks like
A good attestation is short, specific, and unsurprising to anyone who has read the year's risk reporting. It contains no new information for the board. It survives a change of Senior Manager because the evidence base is documented, not held in the outgoing holder's head.
Your next decision: if you cannot currently point to the assurance sources behind each assertion in your draft, do not sign yet. Fix the evidence chain first.
Frequently Asked Questions
Should I take personal legal advice before signing?
Yes, if the attestation covers a period in which material incidents, breaches, or supervisory concerns have arisen, or if you are new in role. Advice should be taken early enough to influence drafting, not on the day of signature.
How do I handle disagreement with the CRO or Internal Audit?
Document it. If Internal Audit rates a control area unsatisfactory and you consider the framework effective overall, the attestation should acknowledge the finding and explain the basis for your judgement. Silent disagreement is the worst outcome.
What if the framework was effective for most of the year but degraded recently?
Attest to the position as at the effective date, note the deterioration, and describe the response. A point in time statement that ignores a known late period issue is misleading.
Can I rely on group level assurance?
Only to the extent it addresses the UK regulated entity's risks and controls. State the reliance explicitly and identify any UK specific gaps that group assurance does not cover.
How long should the attestation be?
The assertion itself is usually one to two pages. The supporting annex, mapping each assertion to evidence, is typically longer. Brevity in the assertion, depth in the annex.
Frequently asked questions
Should I take personal legal advice before signing?
Yes, if the attestation covers a period in which material incidents, breaches, or supervisory concerns have arisen, or if you are new in role. Advice should be taken early enough to influence drafting, not on the day of signature.
How do I handle disagreement with the CRO or Internal Audit?
Document it. If Internal Audit rates a control area unsatisfactory and you consider the framework effective overall, the attestation should acknowledge the finding and explain the basis for your judgement. Silent disagreement is the worst outcome.
What if the framework was effective for most of the year but degraded recently?
Attest to the position as at the effective date, note the deterioration, and describe the response. A point in time statement that ignores a known late period issue is misleading.
Can I rely on group level assurance?
Only to the extent it addresses the UK regulated entity's risks and controls. State the reliance explicitly and identify any UK specific gaps that group assurance does not cover.
How long should the attestation be?
The assertion itself is usually one to two pages. The supporting annex, mapping each assertion to evidence, is typically longer. Brevity in the assertion, depth in the annex.
Related guides
Regulated Industry Governance Best Practice: A Working Guide for Boards
This guide sets out what genuinely strong governance looks like in regulated financial services, from board composition through to escalation culture. After reading, senior leaders will know what to strengthen, what to test, and what regulators and other stakeholders actually expect to see.
How to Build a Credible Operational Resilience Self-Assessment
This guide sets out how to produce an operational resilience self-assessment that stands up to board challenge and supervisory review. After reading it, senior leaders will know how to structure the document, where the evidence typically falls short, and how to demonstrate genuine capability rather than paper compliance.
How to Prepare a Credible SM&CR Statement of Responsibilities Update After a Senior Hire
A practical guide to producing an accurate, defensible Statement of Responsibilities update when a Senior Manager joins or changes role. Readers will finish knowing how to sequence the drafting, capture handovers cleanly, and submit something that stands up to FCA scrutiny.
How to Build a Regulator-Ready Wind-Down Plan That Demonstrates Operational Credibility
This guide sets out how to build a wind-down plan that stands up to regulatory challenge and reflects genuine operational capability. Readers will finish with a clear view of what makes a plan credible, where firms typically fall short, and what to fix first.
How to Structure a Section 166 Skilled Person Review Response
This guide sets out how senior leaders in regulated firms should structure their response to a Section 166 skilled person review, from the moment the requirement notice arrives to the remediation phase. It covers governance, evidence, stakeholder handling, and the judgement calls that determine whether the firm emerges credibly or damaged.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity