SMF5 Explained: What the FCA Expects From a Head of Internal Audit
Internal audit is the third line of defence in any regulated firm’s governance model — the function that checks whether the first line (the business) and the second line (risk and compliance) are actually doing what they claim to be doing. SMF5, the Head of Internal Audit function, exists because that checking function is only worth anything if the person running it is genuinely independent, genuinely resourced, and personally accountable for saying so when they aren’t.
Why Internal Audit Gets Its Own SMF
SMF5 applies at Enhanced tier firms, reflecting the FCA and PRA’s view that at sufficient scale, internal audit needs to be led by someone with the same personal, evidenced regulatory accountability as the functions it’s auditing — not simply a senior manager reporting into the CFO or COO as one function among many. The logic is straightforward: if internal audit’s findings can be softened, delayed or deprioritised by whoever it reports to commercially, the whole third line of defence becomes theatre. Giving the role its own SMF designation, with its own Statement of Responsibilities and its own Duty of Responsibility, is the regulatory answer to that risk.
What the Role Actually Involves
The SMF5 holder is accountable for the design and execution of the firm’s internal audit plan — a risk-based programme of reviews covering the business’s key processes, controls and governance arrangements, prioritised according to where the greatest risk of failure sits rather than according to what’s administratively convenient to review. Beyond running the plan itself, SMF5 carries responsibility for the quality and independence of the audit function’s findings, for escalating serious issues directly to the audit committee rather than allowing them to be resolved quietly at management level, and for tracking whether management actually remediates findings rather than simply acknowledging them.
Reporting line is the test that matters most
As with the CRO function, the single structural feature that determines whether an internal audit function is credible is its reporting line. Internal audit needs to report functionally to the audit committee — chaired by the SMF11 holder — rather than solely through an executive management chain that has a commercial interest in how audit findings land. Where a firm’s internal audit function reports primarily to the CFO or COO, with only a nominal dotted line to the audit committee, both the FCA and PRA treat that as a governance weakness worth probing directly, regardless of how technically competent the SMF5 holder personally is.
Resourcing and scope
A well-designed internal audit function needs genuine authority to access any part of the business, sufficient headcount and technical expertise to actually cover the firm’s risk profile rather than a token annual review cycle, and a mandate broad enough to include IT and operational resilience audits alongside traditional financial controls testing. An SMF5 holder without the resourcing to deliver against that scope is set up to fail regardless of personal capability — a point boards should resolve before recruiting, not something a strong candidate can simply work around.
The Audit Committee Relationship
SMF5 and SMF11 — the Chair of the Audit Committee — need a working relationship built on the same principle that governs the CRO and risk committee chair relationship: genuine, informed challenge, not a one-way reporting line the committee simply receives and files. A strong audit committee chair pushes the Head of Internal Audit on scope, methodology and independence; a strong Head of Internal Audit brings forward findings the business genuinely doesn’t want to hear, and expects the committee to back that escalation rather than quietly smooth it over. Boards recruiting both roles around the same time should think about how the two people will actually work together, not just whether each clears the bar individually.
What a Strong SMF5 Candidate Looks Like
Direct prior experience leading an internal audit function at a comparable regulated firm — ideally one that has actually delivered an uncomfortable finding and seen it through to remediation, not just run a compliant-looking audit cycle; a professional audit qualification held and actively applied, such as the IIA’s Chartered Internal Auditor designation, ACA or an equivalent; genuine technical range across financial, operational and increasingly technology and cyber risk auditing, since internal audit’s scope has broadened well beyond traditional financial controls; and, as with every senior regulatory appointment, enough personal seniority and standing to make independence real in practice, not just on an organisation chart.
Where This Sits in the Wider SMF Landscape
SMF5 completes the third-line-of-defence picture alongside SMF4’s second-line risk ownership and SMF16’s compliance function — the three functions that, between them, are meant to catch what the first line misses. A board reviewing its overall governance architecture is often looking at all three at once, and the same underlying question applies to each: is this function structurally independent enough to actually do its job, or does it exist mainly to satisfy a regulatory checklist?
Related SMF Appointments
Internal audit sits alongside the wider committee and risk governance structure.
SMF10 & SMF11
The risk and audit committee chairs, and how they interact with the executive risk and audit functions.
SMF4
The Chief Risk Officer function, and how it complements internal audit’s third-line role.
All SMF Roles
A plain-English guide to the SMCR, the fit and proper test, and how executive and non-executive designations differ.
Adrian Lawrence FCA — Founder, SMF Capital
Adrian is a Fellow of the ICAEW and holds an ICAEW practising certificate in his own name. He founded FD Capital in 2018 and has since built out Exec Capital, NED Capital and Accountancy Capital alongside SMF Capital, giving FCA-regulated firms specialist recruitment coverage across every line of defence. Every SMF5 search is led personally by Adrian Lawrence FCA. View Adrian’s ICAEW profile.
Recruiting an SMF5 Head of Internal Audit?
Call 0203 137 2496 or email recruitment@smfcapital.co.uk. Tell us the firm type and current reporting line — we build the fit and proper assessment into the search from day one.