Nine roles, three tiers: mandatory, proportionate, or outsourceable.

Every role below exists because a specific obligation makes it accountable, but "accountable" doesn't always mean "mandatory, in-house, full-time." This page replaces a flat minimum-viable org chart with a three-tier control architecture: what the law and supervisors treat as an absolute floor, what's strongly expected but can flex at the smallest scale, and what's a required function that doesn't have to be an employee.

Last reviewed: 2026-07-24

Why three tiers, not one flat list.

This isn't a bank's typical executive committee: it's the accountable control architecture the FCA and PRA specifically require, under the Senior Managers & Certification Regime (SM&CR)[12], classified into three tiers:

Mandatory

A named individual. No exceptions.

The MLRO is the clearest example: a hard legal floor, not a proportionate judgement call.

Proportionate

Strongly expected, but can flex at the smallest scale.

The CRO and COO can be combined or part-time in a small firm. Dedicated leadership becomes harder to avoid only as the bank grows.

Outsourceable function

Required, but not necessarily in-house.

Internal Audit and the DPO are both required as functions, and both can legitimately be external service arrangements rather than employees.

A role appears here only if a cited regulatory obligation makes it accountable. Anything not listed is, provisionally, a candidate for full automation under this investigation's Minimum Viable Human Oversight model. See the regulatory floor matrix for the full set of obligations this roster is drawn from. This page covers the roles and tiers those obligations imply, not the obligations themselves.

Nine functions, three tiers, one control architecture.

The chart below shows how the nine relate; the table beneath it has the full reasoning per role, tier included. Click through to a role's own page for the full perspective: what it's accountable for, what evidence it signs, and how far AI runs everything else in its remit. Roles marked "deep-dive coming soon" aren't yet built.

NEDsSMF9 – SMF14CEOSMF1Head of Internal AuditSMF5 · may be outsourcedCFOSMF2COOSMF24 · if applicableCROSMF4MLROSMF17Compliance OversightSMF16DPOGDPR Art. 37

Borders: solid: mandatory, no exceptions. Dashed: strongly expected but proportionate, can be combined or part-time at the smallest scale. Dotted: a required function that doesn't have to be in-house. Lines: solid, formal accountability. Dashed, administrative reporting only: Internal Audit's real accountability runs to the NEDs, not the CEO, so its independence isn't compromised by reporting to the function it exists to check.

RoleTierSM&CR functionWhy
CEO (deep-dive coming soon)MandatorySMF1: Chief ExecutiveOverall responsibility for the firm's conduct; the FCA/PRA require one identifiable, individually accountable person at the top, non-delegable to a model or vendor.
CFO →MandatorySMF2: Chief FinanceBank of England new-bank guidance expects a CEO, Board Chair, and another executive (usually a CFO) before authorisation, and a functioning executive team including finance at full authorisation. Owns prudential reporting, capital and liquidity planning, and the accounts.
CRO (deep-dive coming soon)ProportionateSMF4: Chief RiskOwns the risk framework and risk-appetite sign-off. At the smallest scale this can be a proportionate, even part-time, function. Dedicated risk leadership becomes much harder to avoid only once the bank grows. Where the PRA's model risk management standard SS1/23 applies (firms with PRA-approved internal models specifically), it adds personal accountability for model risk decisions.
COO (deep-dive coming soon)ProportionateSMF24: Chief OperationsOperational resilience obligations (SS1/21, SS2/21) require someone accountable for the resilience of important business services, including the AI infrastructure itself. The source research treats the SMF24 designation itself as "if applicable": at the smallest scale this accountability can sit with another executive rather than a dedicated COO.
MLRO →MandatorySMF17: Money Laundering Reporting OfficerA named, individually accountable human is a hard legal requirement under the Money Laundering Regulations 2017, closer to an absolute floor than any other role here.
Compliance Oversight (deep-dive coming soon)MandatorySMF16Owns regulatory compliance sign-off, including the advice-boundary escalations described under the blockers below.
DPO / Privacy Lead →Outsourceable functionNot an SM&CR function: UK GDPR Art. 37Not a Senior Management Function at all: a separate UK GDPR requirement, triggered wherever core activities involve large-scale, regular and systematic monitoring or large-scale special-category processing. For a digital-only retail bank running continuous transaction monitoring, a DPO is highly likely in practice even though the precise legal trigger depends on the processing design. Article 37(6) explicitly permits the role to be fulfilled on a service-contract basis, not necessarily in-house.
Head of Internal Audit (deep-dive coming soon)Outsourceable functionSMF5Independent assurance over the whole control environment is a required function, but in a non-significant firm it doesn't need to be a fully in-house SMF5. It can be outsourced to an external internal-audit provider, so long as oversight responsibility for that provider is allocated to another existing SMF.
NEDs (Chair, Chair of Risk, Chair of Audit, Senior Independent Director) (deep-dive coming soon)MandatorySMF9 / SMF10 / SMF11 / SMF14Independent challenge of the executive is the entire point of a NED. At minimum, at least two independent minds must participate in major policy and strategy decisions. The specific four-way split shown here can be proportionate at the smallest scale, but independent challenge itself cannot disappear or be automated.

This mapping is a proposed starting point, not yet checked against the FCA/PRA's current Prescribed Responsibilities allocation. See the Thought Experiment hub's What's Still Open section. "CIA," as raised in the original research brief, is read here as Chief Internal Auditor / Head of Internal Audit (SMF5): an assumption, not a confirmed reading. This roster is the "named-accountability floor" the scenario model builds its FTE estimates on top of.

Sources

[12] Senior Managers and Certification Regime, FCA. [13] The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, legislation.gov.uk. [23] Data protection officers: accountability and governance guidance, ICO. None of these citations have been independently re-confirmed by Axiom Verity this session. Treat as pending verification, consistent with every other source in this investigation.

Three roles built, six to go.

MLRO, CFO, and DPO are built, covering all three tiers. Each remaining role will follow the same shape: the Prescribed Responsibility it owns, how far AI runs the rest of its domain, the evidence it personally signs, and which blocker it's most exposed to.