SMF24 Explained: What the FCA Expects From a Chief Operations Function
SMF24 — the Chief Operations function — has moved from a relatively minor designation to one of the more actively scrutinised executive SMFs, driven almost entirely by the FCA and PRA’s operational resilience requirements. A COO holding SMF24 today is accountable for a materially larger and more regulator-visible remit than the role carried a few years ago, and firms recruiting into it need to recognise how much the job has changed.
What SMF24 Covers
The Chief Operations function carries responsibility for the internal operations and technology of the firm — the systems, processes and infrastructure that keep the business actually running day to day. Historically this sat somewhat in the shadow of the more visible executive functions like SMF1 and SMF2, treated as an important but largely internally-facing role. That’s changed substantially with the introduction of the FCA and PRA’s operational resilience framework, which has made SMF24 one of the executive functions most directly exposed to formal regulatory reporting obligations and supervisory attention.
Operational Resilience Has Changed the Job
Under the operational resilience rules, firms must identify their important business services — the services whose disruption could cause harm to consumers or market integrity — set impact tolerances for how much disruption to each service is acceptable, and demonstrate through testing that they can actually stay within those tolerances during a severe but plausible disruption scenario. The SMF24 holder typically carries direct, personal accountability for this framework, which means the role now involves formal regulatory reporting and testing obligations that didn’t exist in anything like the same form a decade ago.
This is not a paperwork exercise the COO can delegate and simply sign off. The FCA and PRA expect genuine scenario testing — cyber attack, critical third-party outage, major system failure — with real evidence that the firm can identify a breach of impact tolerance and respond to it, not a tabletop exercise that concludes everything would probably be fine. An SMF24 holder without direct, hands-on experience of building and running this kind of resilience testing programme is starting from a significant disadvantage in a firm where operational resilience maturity now genuinely matters to supervisors.
Third-Party and Outsourcing Oversight
Modern regulated firms depend heavily on third-party providers — cloud infrastructure, payment processing, core banking platforms, outsourced technology development — and the SMF24 holder typically carries direct accountability for overseeing those relationships from an operational risk perspective. This includes understanding concentration risk where multiple critical functions depend on the same provider, having credible exit and contingency plans for critical third-party relationships, and making sure due diligence on new providers actually assesses operational resilience rather than simply cost and functionality.
Technology and Change Management
Beyond steady-state operations, SMF24 typically carries accountability for the firm’s approach to technology change — system migrations, platform upgrades, and the operational risk that major change programmes introduce. A firm undergoing significant technology transformation while its SMF24 holder lacks direct experience of managing change risk at that scale is taking on a specific, identifiable risk that a properly scoped search should catch before the appointment is made, not after a migration goes wrong.
What a Strong SMF24 Candidate Looks Like
Direct prior experience holding a COO or senior operations leadership role at a comparable regulated firm, ideally one that has actually run an operational resilience programme through to a genuine regulatory reporting cycle rather than only building the initial framework; hands-on experience overseeing critical third-party and outsourcing relationships, including having managed an actual third-party incident or exit; genuine technology fluency sufficient to hold real conversations with the firm’s technology leadership, even where SMF24 doesn’t personally run the technology function; and enough operational and personal credibility to drive genuine change management discipline across a business that may resist it.
Where SMF24 Sits Relative to Other Executive Functions
SMF24 sits alongside SMF1, SMF2 and SMF4 as one of the core executive functions at larger regulated firms, and the operational resilience obligation increasingly means it needs to be recruited with the same rigour as those better-established designations rather than treated as a secondary appointment. Boards building out a full executive team at a scaling Enhanced-tier firm should think about SMF24 as a genuinely strategic hire, not simply “the person who keeps the lights on.”
Related SMF Appointments
SMF24 sits alongside the wider executive team and its regulatory accountability structure.
SMF1
The Chief Executive function, and how the executive team’s accountabilities fit together.
SMF4
How operational risk accountability under SMF24 relates to the wider risk function.
Exec Capital
Our sister practice for COO and wider C-suite recruitment across regulated and unregulated firms.
Adrian Lawrence FCA — Founder, SMF Capital
Adrian is a Fellow of the ICAEW and holds an ICAEW practising certificate in his own name. He founded FD Capital in 2018 and has since built out Exec Capital, NED Capital and Accountancy Capital alongside SMF Capital, giving FCA-regulated firms specialist recruitment coverage across the full executive team. Every SMF24 search is led personally by Adrian Lawrence FCA. View Adrian’s ICAEW profile.
Recruiting an SMF24 Chief Operations Officer?
Call 0203 137 2496 or email recruitment@smfcapital.co.uk. Tell us the firm type and current operational resilience maturity — we build the fit and proper assessment into the search from day one.