The Senior Managers and Certification Regime attaches personal accountability to a named individual for specific prescribed responsibilities, regardless of where that individual is physically based day to day. A remote technology leadership arrangement at a UK-regulated firm has to be built around this fact explicitly, not treated as a detail to sort out once the arrangement is already running.
UK-regulated firms — particularly smaller and mid-sized ones without the scale to justify a full-time, on-site CTO — increasingly use fractional or remote technology leadership arrangements, and there’s no inherent regulatory objection to remote engagement itself. What matters to the FCA and PRA is whether the individual holding the relevant Senior Management Function genuinely exercises the accountability the role carries, and can evidence that they do, regardless of their physical location.
Who this is for
- The board of a UK-regulated firm structuring a remote technology leadership arrangement that will hold an SMCR-relevant function.
- The compliance function confirming an existing remote arrangement genuinely satisfies SMCR expectations.
SMCR doesn’t require physical presence, but it does require evidenced ownership
Under SMCR, a Senior Manager holding a Prescribed Responsibility for technology or operational resilience needs to be able to demonstrate genuine, active ownership of that responsibility — decisions made, risks assessed, escalations handled — not simply hold the title while substantive decisions are actually made by someone else. A remote arrangement satisfies this perfectly well when the remote individual is genuinely doing the work the SMF requires; it fails when the SMF is held by someone remote in name while an on-site but more junior team member is, in practice, making the real decisions without the accountability that should follow that authority.
Free · 4 minutes
Is your engineering team shipping safely, or quietly accumulating risk?
Fourteen questions on how work gets from idea to production — cadence, testing, rollback, and the key-person risk in your delivery. Banded finding on screen, full sheet by email.
The Statement of Responsibilities has to reflect the actual working pattern
Every SMF holder’s Statement of Responsibilities should accurately describe how the role is actually discharged — including that it’s a remote or fractional arrangement, the specific cadence of engagement, and the escalation structure for matters arising outside that cadence. A Statement of Responsibilities that reads as though the SMF holder is on-site and fully engaged day to day, when the reality is a fractional remote arrangement, creates a documentation gap that becomes a genuine problem if a regulator ever scrutinises how the responsibility was actually being discharged during a specific incident.
Certification Regime staff underneath the SMF need clear delegated authority
Where day-to-day technical decisions are made by Certification Regime staff operating under the remote SMF holder’s oversight, the delegation of authority from the SMF to those individuals needs to be explicit and documented — what they can decide independently, what needs the SMF holder’s sign-off, and how quickly that sign-off can realistically be obtained given the remote arrangement’s cadence. Undocumented, informal delegation is a common gap that surfaces only when something goes wrong and the actual decision-making chain needs to be reconstructed after the fact.
Incident response timing needs to be realistic, not aspirational
A remote SMF holder’s incident response commitments — to the board, to the regulator, to customers — need to be set at a timeline the remote arrangement can genuinely deliver, accounting honestly for availability, time zone if relevant, and the realistic time to assess and respond to a genuinely urgent technology incident. Committing to response times that assume an on-site, always-available presence, when the actual arrangement is fractional and remote, creates a gap that becomes visible and damaging at exactly the worst moment — during a live incident, not during a calm policy review.
What a defensible remote SMF arrangement includes
- Documented evidence of genuine, active ownership of the Prescribed Responsibility by the actual SMF holder, not a title held while someone else decides.
- A Statement of Responsibilities that accurately reflects the remote or fractional nature of the engagement and its actual cadence.
- Explicit, documented delegation of authority to any Certification Regime staff operating under the SMF holder’s oversight.
- Incident response commitments set at a timeline the actual remote arrangement can realistically deliver.
How we engage with this
We provide Fractional CTO engagements for UK-regulated firms structured explicitly to satisfy SMCR’s genuine accountability expectations, with Statements of Responsibilities and escalation structures built to match the arrangement’s real working pattern.
Pricing is published at /pricing/. If your firm is structuring or reviewing a remote technology leadership arrangement holding an SMCR function, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Need strategic technology leadership?
Technology decisions do not stop because there is no CTO. Bring experienced technical leadership into the business without a full-time executive hire.