Structuring a PRA Senior Manager Attestation on Risk Framework Effectiveness
This guide sets out how to structure a Senior Manager attestation on the effectiveness of a firm's risk framework in a way that meets PRA supervisory expectations and stands up to later challenge. Readers will finish with a clear method for scoping, evidencing, qualifying, and signing an attestation that reflects the true state of the framework.
An attestation is a personal statement of fact by a Senior Manager. The PRA reads it as such, and so does the Enforcement Division if things later unravel. The task is not to soften the statement or hedge it into meaninglessness. It is to make an accurate, evidenced, appropriately scoped assertion that you can defend in two years, under different market conditions, in front of a supervisor who has your prior year's version open on the desk.
Key Executive Takeaways
- An attestation is only defensible if its scope, evidence base, and known limitations are explicit on the face of the document, not buried in supporting papers.
- Personal exposure comes from overstating certainty or omitting known weaknesses, not from disclosing issues honestly alongside credible remediation.
- The strongest attestations are built from a documented assurance chain that already exists in first, second, and third line reporting, not assembled bespoke at year end.
Start with what you are actually attesting to
Read the supervisory letter or rule reference carefully. "Effectiveness of the risk management framework" is not a single concept. It typically covers governance, risk appetite operation, identification and measurement, controls, reporting to the board, and remediation of known gaps. Break the statement into its component assertions and treat each as a separate evidential question. If the request letter is ambiguous, write to your supervisor and ask. A clarifying exchange before signature is worth more than a caveat afterwards.
Build the assurance chain before you draft
Good attestations are the visible tip of an assurance record that already exists. Before drafting, map each assertion to:
- First line control testing and self assessment output for the period.
- Second line risk opinions, including any qualified opinions from the CRO function.
- Internal Audit coverage and ratings, with attention to any "unsatisfactory" or repeat findings.
- Board and Board Risk Committee minutes recording challenge and management responses.
- External review, skilled person reports, or thematic feedback from the PRA.
If a component of the framework has not been independently tested in the attestation period, say so. A statement of effectiveness that rests on untested self assessment is fragile.
Write the scope section as if a supervisor will test every word
The scope paragraph is where most attestations go wrong. Common errors: describing the framework in aspirational terms, using group level language when the entity is UK regulated, or dating the assertion to a point that predates known incidents. Be precise about the legal entity, the risk types covered, the period, and any material carve outs (for example, a newly acquired portfolio still being integrated).
Handle known weaknesses on the face of the document
The instinct to move issues into an appendix is the single biggest source of personal exposure. If a control has failed, if a risk appetite metric has been breached repeatedly, or if a remediation programme is behind schedule, state it in the body of the attestation, describe the mitigation, and identify the accountable owner and target date. An attestation that reads "effective, subject to the matters set out below" is defensible. One that reads "effective" while material issues sit in a separate risk report is not.
Calibrate the language
Avoid absolutes. "Effective in all material respects, based on the assurance sources listed in Annex A, as at 31 December" is a defensible formulation. "Fully effective" is not, and neither is "broadly effective" without definition. If you are relying on the work of others, say so and name the sources. Reliance is legitimate; concealed reliance is not.
Sequence the sign off
Circulate the draft to the CRO, General Counsel, Chief Internal Auditor, and the Chair of the Board Risk Committee before signature. Their comments should be logged. If any of them disagrees materially with the assertion, that disagreement needs to be resolved on the record, not smoothed over. The Board Risk Committee should see the final version before it goes to the PRA.
What good looks like
A good attestation is short, specific, and unsurprising to anyone who has read the year's risk reporting. It contains no new information for the board. It survives a change of Senior Manager because the evidence base is documented, not held in the outgoing holder's head.
Your next decision: if you cannot currently point to the assurance sources behind each assertion in your draft, do not sign yet. Fix the evidence chain first.
Frequently Asked Questions
Should I take personal legal advice before signing?
Yes, if the attestation covers a period in which material incidents, breaches, or supervisory concerns have arisen, or if you are new in role. Advice should be taken early enough to influence drafting, not on the day of signature.
How do I handle disagreement with the CRO or Internal Audit?
Document it. If Internal Audit rates a control area unsatisfactory and you consider the framework effective overall, the attestation should acknowledge the finding and explain the basis for your judgement. Silent disagreement is the worst outcome.
What if the framework was effective for most of the year but degraded recently?
Attest to the position as at the effective date, note the deterioration, and describe the response. A point in time statement that ignores a known late period issue is misleading.
Can I rely on group level assurance?
Only to the extent it addresses the UK regulated entity's risks and controls. State the reliance explicitly and identify any UK specific gaps that group assurance does not cover.
How long should the attestation be?
The assertion itself is usually one to two pages. The supporting annex, mapping each assertion to evidence, is typically longer. Brevity in the assertion, depth in the annex.
Frequently asked questions
Should I take personal legal advice before signing?
Yes, if the attestation covers a period in which material incidents, breaches, or supervisory concerns have arisen, or if you are new in role. Advice should be taken early enough to influence drafting, not on the day of signature.
How do I handle disagreement with the CRO or Internal Audit?
Document it. If Internal Audit rates a control area unsatisfactory and you consider the framework effective overall, the attestation should acknowledge the finding and explain the basis for your judgement. Silent disagreement is the worst outcome.
What if the framework was effective for most of the year but degraded recently?
Attest to the position as at the effective date, note the deterioration, and describe the response. A point in time statement that ignores a known late period issue is misleading.
Can I rely on group level assurance?
Only to the extent it addresses the UK regulated entity's risks and controls. State the reliance explicitly and identify any UK specific gaps that group assurance does not cover.
How long should the attestation be?
The assertion itself is usually one to two pages. The supporting annex, mapping each assertion to evidence, is typically longer. Brevity in the assertion, depth in the annex.
Related guides
How to Structure a Recovery Plan Regulators Will Accept as Executable
A practical guide to building a Recovery Plan that supervisors treat as a credible operational document rather than a compliance artefact. Readers will learn how to sequence stress calibration, option design, governance triggers, and management actions so the plan holds up under both desktop review and live stress.
How to Write an ICAAP Narrative That Shows Real Capital Judgement
This guide sets out how to construct an ICAAP document that evidences genuine board-level thinking about capital adequacy, not formulaic compliance. After reading, you will know how to sequence the narrative, where to place judgement, and how to make the document defensible under supervisory challenge.
How to Prepare a Credible Response to a Section 165 Request
This guide explains how to respond to an FCA or PRA Section 165 information request with the rigour, accuracy and timeliness regulators expect. After reading it, you will know how to mobilise the right people, control the production process, and engage credibly with the supervisor throughout.
How to Prepare a Credible Response to a PRA Capital Add-On Proposal
This guide sets out how to respond substantively to a PRA proposal for a Pillar 2A or 2B capital add-on, from first read through to final representations. It helps senior leaders structure the technical rebuttal, govern the process properly, and engage the supervisor in a way that improves the quality of the outcome.
How to Prepare a Credible Response to an FCA Consumer Duty Finding
This guide sets out how senior leaders should respond to an FCA supervisory finding on consumer duty outcomes, from first read to remediation plan. After reading, you will know how to structure a response that demonstrates genuine engagement, credible evidence, and a realistic path to better customer outcomes.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity