Skip to main content

Structuring a PRA Senior Manager Attestation on Risk Framework Effectiveness

This guide sets out how to structure a Senior Manager attestation on the effectiveness of a firm's risk framework in a way that meets PRA supervisory expectations and stands up to later challenge. Readers will finish with a clear method for scoping, evidencing, qualifying, and signing an attestation that reflects the true state of the framework.

An attestation is a personal statement of fact by a Senior Manager. The PRA reads it as such, and so does the Enforcement Division if things later unravel. The task is not to soften the statement or hedge it into meaninglessness. It is to make an accurate, evidenced, appropriately scoped assertion that you can defend in two years, under different market conditions, in front of a supervisor who has your prior year's version open on the desk.

Key Executive Takeaways

  • An attestation is only defensible if its scope, evidence base, and known limitations are explicit on the face of the document, not buried in supporting papers.
  • Personal exposure comes from overstating certainty or omitting known weaknesses, not from disclosing issues honestly alongside credible remediation.
  • The strongest attestations are built from a documented assurance chain that already exists in first, second, and third line reporting, not assembled bespoke at year end.

Start with what you are actually attesting to

Read the supervisory letter or rule reference carefully. "Effectiveness of the risk management framework" is not a single concept. It typically covers governance, risk appetite operation, identification and measurement, controls, reporting to the board, and remediation of known gaps. Break the statement into its component assertions and treat each as a separate evidential question. If the request letter is ambiguous, write to your supervisor and ask. A clarifying exchange before signature is worth more than a caveat afterwards.

Build the assurance chain before you draft

Good attestations are the visible tip of an assurance record that already exists. Before drafting, map each assertion to:

  • First line control testing and self assessment output for the period.
  • Second line risk opinions, including any qualified opinions from the CRO function.
  • Internal Audit coverage and ratings, with attention to any "unsatisfactory" or repeat findings.
  • Board and Board Risk Committee minutes recording challenge and management responses.
  • External review, skilled person reports, or thematic feedback from the PRA.

If a component of the framework has not been independently tested in the attestation period, say so. A statement of effectiveness that rests on untested self assessment is fragile.

Write the scope section as if a supervisor will test every word

The scope paragraph is where most attestations go wrong. Common errors: describing the framework in aspirational terms, using group level language when the entity is UK regulated, or dating the assertion to a point that predates known incidents. Be precise about the legal entity, the risk types covered, the period, and any material carve outs (for example, a newly acquired portfolio still being integrated).

Handle known weaknesses on the face of the document

The instinct to move issues into an appendix is the single biggest source of personal exposure. If a control has failed, if a risk appetite metric has been breached repeatedly, or if a remediation programme is behind schedule, state it in the body of the attestation, describe the mitigation, and identify the accountable owner and target date. An attestation that reads "effective, subject to the matters set out below" is defensible. One that reads "effective" while material issues sit in a separate risk report is not.

Calibrate the language

Avoid absolutes. "Effective in all material respects, based on the assurance sources listed in Annex A, as at 31 December" is a defensible formulation. "Fully effective" is not, and neither is "broadly effective" without definition. If you are relying on the work of others, say so and name the sources. Reliance is legitimate; concealed reliance is not.

Sequence the sign off

Circulate the draft to the CRO, General Counsel, Chief Internal Auditor, and the Chair of the Board Risk Committee before signature. Their comments should be logged. If any of them disagrees materially with the assertion, that disagreement needs to be resolved on the record, not smoothed over. The Board Risk Committee should see the final version before it goes to the PRA.

What good looks like

A good attestation is short, specific, and unsurprising to anyone who has read the year's risk reporting. It contains no new information for the board. It survives a change of Senior Manager because the evidence base is documented, not held in the outgoing holder's head.

Your next decision: if you cannot currently point to the assurance sources behind each assertion in your draft, do not sign yet. Fix the evidence chain first.

Frequently Asked Questions

Should I take personal legal advice before signing?

Yes, if the attestation covers a period in which material incidents, breaches, or supervisory concerns have arisen, or if you are new in role. Advice should be taken early enough to influence drafting, not on the day of signature.

How do I handle disagreement with the CRO or Internal Audit?

Document it. If Internal Audit rates a control area unsatisfactory and you consider the framework effective overall, the attestation should acknowledge the finding and explain the basis for your judgement. Silent disagreement is the worst outcome.

What if the framework was effective for most of the year but degraded recently?

Attest to the position as at the effective date, note the deterioration, and describe the response. A point in time statement that ignores a known late period issue is misleading.

Can I rely on group level assurance?

Only to the extent it addresses the UK regulated entity's risks and controls. State the reliance explicitly and identify any UK specific gaps that group assurance does not cover.

How long should the attestation be?

The assertion itself is usually one to two pages. The supporting annex, mapping each assertion to evidence, is typically longer. Brevity in the assertion, depth in the annex.

Frequently asked questions

Should I take personal legal advice before signing?

Yes, if the attestation covers a period in which material incidents, breaches, or supervisory concerns have arisen, or if you are new in role. Advice should be taken early enough to influence drafting, not on the day of signature.

How do I handle disagreement with the CRO or Internal Audit?

Document it. If Internal Audit rates a control area unsatisfactory and you consider the framework effective overall, the attestation should acknowledge the finding and explain the basis for your judgement. Silent disagreement is the worst outcome.

What if the framework was effective for most of the year but degraded recently?

Attest to the position as at the effective date, note the deterioration, and describe the response. A point in time statement that ignores a known late period issue is misleading.

Can I rely on group level assurance?

Only to the extent it addresses the UK regulated entity's risks and controls. State the reliance explicitly and identify any UK specific gaps that group assurance does not cover.

How long should the attestation be?

The assertion itself is usually one to two pages. The supporting annex, mapping each assertion to evidence, is typically longer. Brevity in the assertion, depth in the annex.

Related guides

Regulation & Regulatory Change

Structuring a Threshold Conditions Self-Assessment That Evidences Ongoing Compliance

This guide sets out how to structure a Threshold Conditions self-assessment that credibly evidences continued satisfaction of FSMA Schedule 6 and COND, while surfacing resource or business model pressures honestly and with a clear remediation path. Readers will finish able to commission, review, and sign off a document that stands up to supervisory scrutiny and supports genuine board oversight.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

Structuring an MLRO Annual Report That Satisfies SYSC 6 Without Triggering FCA Intervention

This guide sets out how to structure and write the MLRO annual report so it meets SYSC 6.3.9G expectations and gives the board a defensible record of financial crime oversight. After reading it, senior decision-makers will know what to include, what to leave out, and how to frame weaknesses without inviting supervisory follow-up.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Recovery Plan Playbook That Passes PRA Credibility Tests

This guide sets out how to build a Recovery Plan playbook that meets the PRA's credibility, usability and timeliness expectations without creating documents that could damage confidence if they surface externally. After reading, you will know how to sequence indicators, options and governance triggers so the plan works as a live management tool rather than a compliance artefact.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure an Operational Resilience Self-Assessment That Withstands Regulator Challenge

This guide sets out how to build an operational resilience self-assessment that holds up to FCA and PRA impact tolerance scrutiny. After reading, senior leaders will know how to sequence evidence, frame judgements, and pre-empt the challenges supervisors are most likely to raise.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Board Diversity Disclosure That Satisfies the FCA Without Inviting Activist Scrutiny

This guide sets out how to draft a Listing Rule 6.6.6R(9) and (10) diversity disclosure that meets FCA expectations while managing exposure to activist investors, proxy advisers, and campaign groups. After reading, you will know how to sequence the numerical disclosure, contextual narrative, and forward statements to satisfy regulators without creating avoidable hostages to fortune.

Regulatory submissionRegulatorsInvestors
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity