SM&CR – Why technology is the only workable solution
For firms of a certain size, the complexity and scale of managing SM&CR means technology is the only workable solution. The risk to the firm, and individually to senior managers, of personal fines and sanctions, is too significant to rely on manual solutions.
Compounding this complexity is the fact that many firms consist of multiple legal entities and the SM&CR applies at legal entity level. Therefore, requiring multiple Responsibility Maps and Statement of Responsibilities for Senior Managers with roles in several firms within the Group. This imposes more emphasis on consistency, change management, version control and interactions between entities.
Our clients have selected a technology solution to help them manage Risk and Compliance, and specifically SM&CR, in a better, faster, cheaper and far safer way than is possible with manual solutions. Our solution offers an opportunity for firms to apply more stringent controls that mitigate the risk of human oversight or inefficiency by automating compliance and implementing a system that places transparency at the heart of business operations, minimising the risks of malpractice across front, middle and back-offices.
The cost and pace of regulatory change is cited by many Chief Risk Officers and Chief Compliance Officers as one of the biggest and highest priority risks in the industry and there are no signs of it reducing. The degree of regulatory change, if anything is set to increase.
Typical real-life examples
Within a typical, medium-sized firm, it is easy to identify 100+ existing or new policies and processes impacted by SM&CR. In addition, over 40 new ‘Regulatory Artefacts’ must be maintained, kept in sync and retained as evidence (e.g. Responsibility Maps, SoRs, Reasonable Steps Policy, Handover Policy, etc).
A particular bank updated their Management Responsibilities Maps (which have to be submitted to the Regulator) 12 times in the first 24 months, including more than 200 updates to their Statements of Responsibilities (across approx. 20 Senior Managers).
In another case, a bank performed manual updates to 6 SoRs which required approx. 80 man hours of effort. Using our solution the same task would take 90 minutes, with a guaranteed and consistent result. Furthermore, the Certification element of the regime imposes critical dependence on existing Performance Management (HR and Training & Competency). These functions are typically inadequately equipped or resourced to provide the significantly increased rigour that the regime demands.
One of our clients originally implemented SM&CR based on a combination of existing HR systems, spreadsheets and manual processes. Whilst it was sufficient to meet the regime’s requirements, it resulted in the following issues:
Inefficiency – data needed to be collated and checked manually, often being re-keyed from multiple sources
Risk of inaccuracies – mitigating inaccuracies meant that HR, Compliance and senior managers needed to manually check data and records
Poor audit trail – there was no central data store or efficient reporting function or rigorous evidence record
Poor user experience – resulting in HR and Compliance teams having to help end-users
Senior manager confidence – given their personal responsibility, the firm needed to give their senior managers greater protection and confidence in the accuracy of records and audit trail
To address these issues, our client chose our SM&CR solution. The contrasting outcomes were as follows:
Process automation – the Certification process being automatically scheduled, communicated and actioned, requiring no manual intervention whatsoever
Greater protection and reduced risk – mitigating any non-compliance and breaches
Accurate data – reports, data and Certificates stored centrally, providing a full audit trail
Improved user experience – the interface is intuitive therefore removed the need for any end-user training
Senior managers confidence – SMs now have complete confidence in the consistent application of controls
For further details of how our technology can help your firm manage and comply with the Accountability Regime, Senior Managers & Certification Regime, contact us today.