UNUS London  —  Compliance Architecture Division  |  UNCLASSIFIED // REGULATED INDUSTRIES
Home Solutions Legal & Professional Financial Services Manufacturing Healthcare Academy Blogs Ebooks About Book Discovery Call UNUS Govern
🏦 Financial Services

FCA-Regulated Firms Face a Documentation Crisis They Cannot See Coming

Financial services firms operating under the Senior Managers & Certification Regime (SM&CR), FCA Conduct Rules, and SYSC requirements accumulate compliance obligations faster than manual systems can track them. Statements of Responsibilities are incomplete. Certification records are missing. Breach registers are populated retrospectively. When the FCA investigates, the evidence deficit is catastrophic.

£568M
FCA financial penalties issued in 2023 alone
SM&CR
Applies to all FCA-authorised firms — documentation shall be maintained continuously
72 hrs
FCA breach notification window — most firms cannot locate records within this period

The Structural Problems FCA-Regulated Firms Face

🧑‍💼
SM&CR — Senior Managers Regime

Statements of Responsibilities Maintained in Word Documents

Under SM&CR, each Senior Manager shall have a current, accurate Statement of Responsibilities. Most firms maintain these as Word documents on shared drives — without version control, approval audit trails, or structured review cycles. When the FCA requests current SoRs, firms cannot demonstrate that documents reflect actual responsibilities.

📜
SM&CR — Certification Regime

Certification Evidence Cannot Be Retrieved on Demand

Firms shall assess and certify Certified Persons as fit and proper at least annually. Evidence of T&C completion, competency assessments, and certification decisions is stored across disparate systems. When an enforcement team requests certification records for a specific individual, retrieval takes days — if the records exist at all.

⚠️
SYSC 10.1 — Breach Management

Breach Registers Populated Retrospectively

FCA SYSC requirements mandate systematic breach identification, recording, and escalation. Most firms operate breach registers in Excel, populated days or weeks after incidents occur. There is no automated alerting, no escalation workflow, and no immutable record of when a breach was first identified — all of which the FCA will scrutinise.

📁
FCA COBS — Document Integrity

Regulatory Document Packs Without Version Integrity

Client-facing regulatory documents — terms of business, risk warnings, key information documents — are updated without structured version control or distribution audit trails. There is no system confirming which version was presented to which client, creating significant conduct risk exposure under COBS requirements.

🔍
FCA Supervisory Focus — Evidence

Compliance Assurance Is Assertion-Based

Compliance Officers produce attestations and board reports based on information provided by business lines — not drawn from an independent, auditable data source. The FCA's supervisory approach increasingly focuses on the quality of evidence firms produce, not the policies they write. Assertion-based compliance fails this scrutiny.

📊
ISO/IEC 27001 — Information Security

No Structured Information Security Governance

Financial services firms handle significant volumes of personal and financial data. Without ISO/IEC 27001-aligned information security governance — documented controls, risk registers, audit trails of access and changes — firms accumulate information security risk that intersects directly with FCA data protection expectations.

The Financial and Regulatory Cost of Compliance Gaps

FCA enforcement is increasingly individual-focused under SM&CR. Senior Managers are personally accountable for areas under their statement of responsibilities. Where evidence of adequate oversight is absent, personal liability follows.

The 72-hour breach notification window is unachievable for firms that record breaches retrospectively. Missing a notification deadline — or notifying with incomplete information — is treated as a separate, aggravated compliance failure by the FCA.

Under ISO 9001:2015 Clause 9.1.3, organisations shall analyse and evaluate data to assess the effectiveness of the quality management system. A firm that cannot produce a structured compliance evidence trail on demand cannot satisfy this requirement — or the FCA's equivalent.

SM&CR FCA SYSC FCA COBS ISO/IEC 27001
💸
Average FCA Fine Per Enforcement Action
£12.8M (2023 average)
👤
SM&CR Individual Accountability Actions
Rising 34% year-on-year
FCA Breach Notification Window
72 hours — missed by most firms
📉
Certification Record Retrieval Time (Manual)
3–7 Business Days Average
🔒
Consequence of SoR Documentation Failure
Senior Manager personal liability

Database-First Governance Infrastructure for FCA-Regulated Firms

UNUS London builds compliance systems where SM&CR documentation, certification records, and breach notifications are enforced at the PostgreSQL schema level with immutable audit trails. Compliance Officers access real-time, evidence-grade data — not attested summaries. Senior Managers can demonstrate their oversight obligations are met, structurally.

01 — Personal Accountability Documentation

Statements of Responsibilities with Full Version History

Statements of Responsibilities are maintained in a structured database with version control, approval workflows, and change audit trails. Every update is timestamped and attributable. The FCA can request any version of any SoR at any point in its history — and receive it within 30 seconds.

SM&CRITIL 4 SACM
02 — Certification Evidence Architecture

Fit & Proper Certification with Immutable Records

Annual certification records, T&C completion evidence, and competency assessments are stored in a structured register with automated renewal alerts. Evidence is retrievable by individual, by certification period, or by regulatory requirement — in a format directly presentable to the FCA.

SM&CR Cert RegimeISO 9001
03 — Breach Management Infrastructure

Automated Breach Capture with Escalation Gating

Breach identification triggers an automated workflow: timestamped recording, severity classification, escalation routing, and notification tracking. The 72-hour FCA notification window is monitored structurally. No breach may proceed without a compliant record — enforced at the database level.

FCA SYSC 10.1ISO/IEC 27001

Production-Ready Financial Compliance Systems

Each mini solution is independently deployable and production-ready. All systems share the UNUS London database-first architecture and connect to provide a consolidated compliance evidence trail for FCA supervisory review.

📜
SM&CR — Certification Regime

Finance Certification Tracker

Structured annual certification register for Certified Persons. Tracks fit and proper assessments, T&C completion, and certification decisions with automated renewal alerts. Produces FCA-presentable evidence records on demand, eliminating manual retrieval delays.

View Solution
📁
FCA COBS — Document Integrity

Finance FCA Document Pack

Versioned regulatory document management system for client-facing FCA documentation. Enforces approval workflows before distribution. Maintains a complete distribution audit trail — which version, to which client, on which date — satisfying COBS requirements structurally.

View Solution
🧑‍💼
SM&CR — Senior Managers Regime

Finance Statement of Responsibilities

Structured SM&CR Statement of Responsibilities register with full version history, approval workflow, and change audit trail. Every SoR update is timestamped and attributable. Retrieval of any historical version is achievable within 30 seconds — directly presentable to the FCA.

View Solution
⚠️
FCA SYSC 10.1 — Breach Management

Finance Breach Register

Automated breach capture and management system with timestamp enforcement, severity classification, and escalation routing. The 72-hour FCA notification window is monitored structurally. Immutable breach records are maintained with a complete regulatory audit trail from first identification to resolution.

View Solution

Keep Your Firm Running
SMCR-Ready & Consumer-Duty-Aligned

Deploying a compliance system is one thing. Keeping it aligned with the FCA's evolving expectations — Consumer Duty, SMCR, operational resilience — is another. UNUS Govern is the operational wrapper that turns a one-time build into a continuously-evidenced system. For financial services firms, the relevant Govern add-on module provides FCA-specific continuous evidence tracking, SMCR / Certification monitoring, and a live Consumer Duty readiness score.

UNUS Govern Industry Add-On Module

  • FCA Consumer Duty evidence tracking (live)
  • SMCR / Certification regime monitoring
  • Operational resilience readiness scoring
  • Annual SMCR fit & proper evidence pack
  • Quarterly regulatory change alerts (FCA / PRA)
Explore Industry Add-On → UNUS Govern Overview →

Deploy → Hand to Govern → Stay Live

  1. STEP 01  ·  DEPLOY
    Build or buy a UNUS compliance system. Your infrastructure, your data, your code.
  2. STEP 02  ·  GOVERN
    Activate the industry add-on. UNUS Govern tracks drift, configuration, and regulatory mapping.
  3. STEP 03  ·  EVIDENCE
    Regulator visits, surveillance audits, file reviews — you have a live evidence layer to present.

Your Firm's Compliance Infrastructure Shall Be FCA-Evidence-Grade

Book a 30-minute discovery call. We will assess your SM&CR documentation posture, certification evidence gaps, and breach management capability — and specify the production-ready systems that address them in 14 days.