The floor isn't a feeling: it's ten specific obligations.
"A handful of humans must retain effective governance" only means something if it's traceable to specific obligations. This page is that trace: ten obligation areas, each tagged against the legal/supervisory frame the hub introduces, each with a named source. Every source here still needs the independent verification pass this site applies to everything else. See "What's Still Open" below.
Last reviewed: 2026-07-24
Legal floor vs. supervisory floor, row by row.
Legal floor rows cite a binding requirement: legislation, the PRA Rulebook, or the FCA Handbook. Supervisory floor rows cite a regulator's stated proportionate expectation, which is real and consequential but isn't the same as a hard legal minimum. Several rows carry both: a binding rule underneath, with supervisory guidance shaping how firms are expected to meet it. Those get a short note explaining the split rather than being forced into one box.
What creates the floor, and where each one comes from.
Drawn from deep-research-report.md's regulatory floor analysis. This is the raw material the minimum accountable control architecture and the forthcoming scenario model are built from, not yet converted into headcount here.
| Obligation area | Practical consequence | Layer | Source |
|---|---|---|---|
| Authorisation governance | A new bank must have a CEO, Board Chair, and another executive at mobilisation, usually a CFO. Full authorisation requires a functioning executive team and board. | Supervisory floor Authorisation itself is a legal gateway (FSMA Part 4A permission); this specific staffing composition is Bank of England new-bank guidance, not primary legislation. | [15] Bank of England(opens in a new tab) |
| Independent direction | At least two independent minds must participate in the formulation and implementation of firm policy and major strategy decisions: the "four eyes" principle. | Legal floor | [16] legislation.gov.uk(opens in a new tab) |
| SM&CR accountabilities | Dual-regulated firms require SMF16 and SMF17; responsibilities must be allocated to named SMF managers and maintained in statements of responsibilities and the management responsibilities map. | Legal floor | [12] FCA(opens in a new tab) |
| AML/CTF internal controls | The firm must maintain AML policies, controls and procedures; appoint a board-level individual responsible for AML compliance; screen relevant employees; appoint a nominated officer; provide training; and, where appropriate, maintain an independent audit function. | Legal floor | [13] legislation.gov.uk(opens in a new tab) |
| Operational resilience | The firm must identify important business services, set impact tolerances, map dependencies, run severe-but-plausible scenario testing, and maintain a board-approved self-assessment. Where SMF24 exists, the PRA expects it to hold overall implementation responsibility. | Legal floor PRA Rulebook-anchored, though the specific scenario-testing expectations sit in a Supervisory Statement (SS1/21), not the Rulebook text itself. | [17] Bank of England / PRA(opens in a new tab) |
| Outsourcing and third-party risk | Accountability cannot be outsourced. The firm must retain sufficient non-financial resources to oversee providers, maintain governance, assess materiality, plan exits, and communicate effectively in disruptions. Internal audit specifically may be outsourced in a non-significant firm. | Legal floor The PRA Rulebook Outsourcing Part sets the binding requirement; SS2/21 is supervisory guidance on how to meet it. | [18] Bank of England / PRA(opens in a new tab) |
| Consumer support and vulnerability | The bank must support good outcomes under the Consumer Duty, provide customer service that responds flexibly to vulnerable consumers, and design digital journeys that do not leave vulnerable customers unsupported. | Legal floor | [19] FCA(opens in a new tab) |
| Automated decisions and data protection | Significant decisions cannot be treated as ungoverned black boxes. Meaningful human involvement and safeguards matter: the ICO treats a decision as "solely automated" only where there is no meaningful human involvement at all. | Legal floor UK GDPR Article 22 is the legal floor; the ICO guidance cited is supervisory-level interpretation. | [20] ICO(opens in a new tab) |
| Resolution and depositor protection | Deposit takers must be able to provide a Single Customer View to the FSCS within 24 hours. New banks are also expected to prepare recovery, solvent-exit, and resolution information as they move through authorisation and mobilisation. | Legal floor | [21] legislation.gov.uk(opens in a new tab) |
| Audit and control environment | Firms should have audit committee arrangements proportionate to scale, effective segregation of duties, and no single individual with unrestricted authority to initiate, bind, pay, and account for the same transaction set. | Legal floor | [22] FCA(opens in a new tab) |
None of these ten citations have been independently checked.
- Every source above is named to the correct real instrument as best as this pass can determine, but no one has yet opened each one and confirmed the specific section, current wording, or that the link still resolves to the right place.
- The "usually a CFO" authorisation-governance consequence and the SM&CR/AML/CTF rows are the most load-bearing for the org-structure work, worth verifying first if this pass is prioritised.
- This page doesn't yet say how many humans each obligation actually requires at different scales: that conversion is the scenario model's job, not this page's.
This feeds the control architecture and the scenario model.
The minimum accountable control architecture and the small/medium/large scenario model both build directly on the ten rows above.