SMF10 and SMF11: The Risk and Audit Committee Chairs Under the SMCR
Of all the Senior Manager Functions available to non-executives, SMF10 and SMF11 are the two most likely to be recruited together — and the two most frequently confused with each other by boards who haven’t run one of these searches before. This post separates the two designations, explains what each actually carries in terms of regulatory accountability, and sets out what a search process should be testing.
Two Designations, One Refresh Cycle
SMF10 covers the Chair of the Risk Committee. SMF11 covers the Chair of the Audit Committee. In practice, many regulated boards review both roles at the same time, because the two committees frequently draw from an overlapping candidate pool — finance-qualified, governance-experienced non-executives with regulated firm exposure — and a single refresh cycle is more efficient than running two separate processes months apart. That efficiency only works, though, if the search distinguishes clearly between what each designation actually requires, rather than treating “committee chair experience” as a single, interchangeable qualification.
SMF10 — Chair of the Risk Committee
For PRA-regulated firms, a standalone board risk committee chaired by an independent non-executive is a governance requirement, not an option. Smaller FCA solo-regulated firms sometimes combine risk oversight into the audit committee’s remit, in which case the SMF10 designation can sit with the audit committee chair covering both functions — but where a genuinely separate risk committee exists, its chair carries a distinct and demanding brief.
The SMF10 holder’s accountability runs across the firm’s entire risk management framework: challenging the risk appetite statement and the limits that sit underneath it, monitoring whether the business is actually operating within that appetite rather than simply reporting that it is, overseeing stress testing and scenario analysis, and governing the firm’s approach to model risk wherever models feed into risk assessment or business decisions.
The CRO relationship is the job
If there is one relationship that defines whether an SMF10 chair is doing the job properly, it is the relationship with the Chief Risk Officer. The risk committee — and specifically its chair — is the primary governance line of accountability for the CRO. That means making sure the CRO has genuine organisational independence from the business lines they oversee, adequate resourcing, and direct, unfiltered access to the board. Where that independence is compromised and nobody on the board notices, the regulatory failure sits with the SMF10 holder.
What a strong SMF10 candidate looks like
Board-level risk governance experience at a comparable regulated firm; a genuine, hands-on understanding of enterprise risk frameworks and stress-testing methodology rather than a passing familiarity; sector-specific risk knowledge that matches the firm’s actual exposures — credit risk for a lender, insurance risk for an insurer, market risk for an investment firm; and, critically, the ability to engage with risk professionals as a governance peer rather than simply receiving their presentations.
SMF11 — Chair of the Audit Committee
SMF11 covers the integrity of financial reporting, the external audit relationship, internal audit, and the internal controls framework. For a regulated firm, this goes well beyond the standard audit committee chair brief at a non-regulated company — regulatory capital reporting adds a layer that many otherwise well-qualified audit committee chairs have never actually dealt with.
Recent and relevant financial experience — but relevant to what?
The FCA and PRA both expect SMF11 holders to have “recent and relevant financial experience,” mirroring the language of the wider corporate governance code but applying it inside a specific regulatory context. The word doing the real work here is “relevant.” A highly qualified CFO from outside financial services, with no prior exposure to a financial services audit committee, may simply not be relevant to a bank or insurer’s SMF11 role — however strong their general accounting background. The test is whether the candidate’s financial experience actually applies to this type of regulated firm’s reporting and capital framework, and whether it’s current rather than a decade out of date.
Regulatory capital and financial reporting
For banks and insurers specifically, concepts like Common Equity Tier 1 capital reporting and, for insurers, IFRS 17, sit inside the SMF11 chair’s remit. Errors in regulatory capital reporting — where the numbers misrepresent the firm’s actual capital position — are a specific and serious enforcement concern for both the FCA and PRA, and the audit committee chair’s governance is the first line of defence against them.
Internal audit governance
Regulatory expectations for internal audit functions at regulated firms are more prescriptive than standard governance code requirements — covering the function’s organisational independence, its risk-based audit planning, and its direct reporting line into the audit committee. The SMF11 chair is responsible for satisfying themselves the head of internal audit is both qualified and genuinely independent, not simply reviewing a report once a quarter.
What a strong SMF11 candidate looks like
A professional accountancy qualification currently being applied in a relevant context — ACA/FCA, ACCA, CIMA or an international equivalent; direct prior audit committee experience at a comparable regulated firm; specific familiarity with the reporting framework relevant to the firm’s sector; and real experience managing both the external audit relationship and internal audit oversight in a financial services setting. Former Big Four audit partners with financial services clients, former CFOs of regulated firms, and experienced financial services audit committee chairs consistently make the strongest shortlists.
Form A and the Notification Process
Both SMF10 and SMF11 require Form A notification to the FCA before the individual takes up the role, with a parallel PRA notification for dual-regulated firms. The submission has to demonstrate — with evidence, not assertion — that the candidate is fit and proper against all three assessment pillars: honesty, integrity and reputation; competence and capability; and financial soundness. Where a candidate’s background includes anything requiring specific explanation — prior regulatory history, an overseas regulatory background, or unusual career circumstances — bringing in specialist regulatory counsel before submission, rather than after a query comes back from the regulator, saves weeks.
| Firm type | Typical combined fee range |
|---|---|
| Major banks and insurers | £115,000 – £175,000 |
| Mid-tier regulated firms | £70,000 – £110,000 |
| Smaller FCA-authorised firms | £45,000 – £85,000 |
These figures include the base non-executive fee plus the committee chair supplement, and reflect the regulatory accountability of the designation rather than a simple time commitment.
Related SMF Appointments
Boards refreshing risk and audit leadership are often reviewing the wider board composition at the same time.
SMF9
What the Chair of the Governing Body function actually requires, and why it differs from a standard chair role.
SMF14
The SID’s regulatory escalation function, and how it’s often combined with a committee chair role.
NED Capital
Our sister practice for board-level non-executive and committee chair appointments across regulated firms.
Adrian Lawrence FCA — Founder, SMF Capital
Adrian is a Fellow of the ICAEW and holds an ICAEW practising certificate in his own name. His own ICAEW credentials mean he applies the same professional standard for “recent and relevant financial experience” to SMF11 candidates that the FCA and PRA actually expect — not a softer reading of the governance code. Every SMF10 and SMF11 search is led personally by Adrian Lawrence FCA. View Adrian’s ICAEW profile.
Refreshing Your Risk or Audit Committee Leadership?
Call 0203 137 2496 or email recruitment@smfcapital.co.uk. Tell us which designation — or both — you need, and any regulatory context. Shortlists are typically ready within two to three weeks.