Financial services firms operating under the Senior Managers & Certification Regime (SM&CR), FCA Conduct Rules, and SYSC requirements accumulate compliance obligations faster than manual systems can track them. Statements of Responsibilities are incomplete. Certification records are missing. Breach registers are populated retrospectively. When the FCA investigates, the evidence deficit is catastrophic.
Under SM&CR, each Senior Manager shall have a current, accurate Statement of Responsibilities. Most firms maintain these as Word documents on shared drives — without version control, approval audit trails, or structured review cycles. When the FCA requests current SoRs, firms cannot demonstrate that documents reflect actual responsibilities.
Firms shall assess and certify Certified Persons as fit and proper at least annually. Evidence of T&C completion, competency assessments, and certification decisions is stored across disparate systems. When an enforcement team requests certification records for a specific individual, retrieval takes days — if the records exist at all.
FCA SYSC requirements mandate systematic breach identification, recording, and escalation. Most firms operate breach registers in Excel, populated days or weeks after incidents occur. There is no automated alerting, no escalation workflow, and no immutable record of when a breach was first identified — all of which the FCA will scrutinise.
Client-facing regulatory documents — terms of business, risk warnings, key information documents — are updated without structured version control or distribution audit trails. There is no system confirming which version was presented to which client, creating significant conduct risk exposure under COBS requirements.
Compliance Officers produce attestations and board reports based on information provided by business lines — not drawn from an independent, auditable data source. The FCA's supervisory approach increasingly focuses on the quality of evidence firms produce, not the policies they write. Assertion-based compliance fails this scrutiny.
Financial services firms handle significant volumes of personal and financial data. Without ISO/IEC 27001-aligned information security governance — documented controls, risk registers, audit trails of access and changes — firms accumulate information security risk that intersects directly with FCA data protection expectations.
FCA enforcement is increasingly individual-focused under SM&CR. Senior Managers are personally accountable for areas under their statement of responsibilities. Where evidence of adequate oversight is absent, personal liability follows.
The 72-hour breach notification window is unachievable for firms that record breaches retrospectively. Missing a notification deadline — or notifying with incomplete information — is treated as a separate, aggravated compliance failure by the FCA.
Under ISO 9001:2015 Clause 9.1.3, organisations shall analyse and evaluate data to assess the effectiveness of the quality management system. A firm that cannot produce a structured compliance evidence trail on demand cannot satisfy this requirement — or the FCA's equivalent.
UNUS London builds compliance systems where SM&CR documentation, certification records, and breach notifications are enforced at the PostgreSQL schema level with immutable audit trails. Compliance Officers access real-time, evidence-grade data — not attested summaries. Senior Managers can demonstrate their oversight obligations are met, structurally.
Statements of Responsibilities are maintained in a structured database with version control, approval workflows, and change audit trails. Every update is timestamped and attributable. The FCA can request any version of any SoR at any point in its history — and receive it within 30 seconds.
Annual certification records, T&C completion evidence, and competency assessments are stored in a structured register with automated renewal alerts. Evidence is retrievable by individual, by certification period, or by regulatory requirement — in a format directly presentable to the FCA.
Breach identification triggers an automated workflow: timestamped recording, severity classification, escalation routing, and notification tracking. The 72-hour FCA notification window is monitored structurally. No breach may proceed without a compliant record — enforced at the database level.
Each mini solution is independently deployable and production-ready. All systems share the UNUS London database-first architecture and connect to provide a consolidated compliance evidence trail for FCA supervisory review.
Structured annual certification register for Certified Persons. Tracks fit and proper assessments, T&C completion, and certification decisions with automated renewal alerts. Produces FCA-presentable evidence records on demand, eliminating manual retrieval delays.
View SolutionVersioned regulatory document management system for client-facing FCA documentation. Enforces approval workflows before distribution. Maintains a complete distribution audit trail — which version, to which client, on which date — satisfying COBS requirements structurally.
View SolutionStructured SM&CR Statement of Responsibilities register with full version history, approval workflow, and change audit trail. Every SoR update is timestamped and attributable. Retrieval of any historical version is achievable within 30 seconds — directly presentable to the FCA.
View SolutionAutomated breach capture and management system with timestamp enforcement, severity classification, and escalation routing. The 72-hour FCA notification window is monitored structurally. Immutable breach records are maintained with a complete regulatory audit trail from first identification to resolution.
View SolutionDeploying a compliance system is one thing. Keeping it aligned with the FCA's evolving expectations — Consumer Duty, SMCR, operational resilience — is another. UNUS Govern is the operational wrapper that turns a one-time build into a continuously-evidenced system. For financial services firms, the relevant Govern add-on module provides FCA-specific continuous evidence tracking, SMCR / Certification monitoring, and a live Consumer Duty readiness score.
Book a 30-minute discovery call. We will assess your SM&CR documentation posture, certification evidence gaps, and breach management capability — and specify the production-ready systems that address them in 14 days.