Why Your Compliance Department is Making Your Bank Less Safe

Why Your Compliance Department is Making Your Bank Less Safe

The financial press is currently weeping over the supposed "dilution" of the UK’s Senior Managers and Certification Regime (SMCR). They see a rollback of "fit and proper" rules as a white flag to greed. They think we are inviting 2008 back for a second date.

They are dead wrong.

The assumption that rigid, bureaucratic vetting makes a financial system "safe" is one of the most expensive delusions in the City. For years, we have prioritized paper trails over actual character, and process over performance. By relaxing the administrative stranglehold of the SMCR, the UK isn't becoming "soft on crime." It is finally acknowledging that a checklist is a terrible substitute for a conscience.

The Compliance Paradox

Safety is not the same thing as compliance. In fact, they are often in direct opposition.

When you create a massive, multi-layered "fit and proper" apparatus, you create a culture of defensive box-ticking. I have seen banks spend seven figures on background checks for mid-level managers that focus on whether a candidate forgot to disclose a dormant credit card ten years ago. Meanwhile, the actual systemic risks—the cultural rot, the "groupthink" in the risk committee, the aggressive mispricing of assets—go unnoticed because everyone is too busy filling out Form 4.

We have built a system that filters for people who are good at following rules, not people who are good at managing risk. Those are not the same skill sets. A rule-follower will walk a bank off a cliff if the manual says the path is clear. A risk-manager will stop before the edge, even if it means breaking protocol. By "diluting" these rules, the UK is opening the door for the latter.

The Myth of the "Paper-Trail" Executive

The current obsession with "fitness and propriety" assumes that bad actors are simply people with bad resumes. It assumes that if we look deep enough into a person’s past, we can predict their future integrity.

This is a fundamental misunderstanding of how financial scandals happen. Most "rogue" traders and disgraced CEOs didn't start their careers as villains. They were "fit and proper" by every metric the regulator had. They passed the exams. They had the right references. They were vetted within an inch of their lives.

The rot happens inside the institution. It is a product of the environment, the incentives, and the silence of peers. No amount of pre-employment vetting can prevent a "good" person from making "bad" decisions when the quarterly bonus depends on it.

The SMCR, in its most bloated form, gave boards a false sense of security. They figured that if the regulator signed off on an appointment, their job was done. "The FCA said he’s fit and proper, so why are you questioning his ethics?" That is a dangerous mindset. It offloads the board’s primary responsibility—oversight—to a government agency that isn't in the room when the trades are being made.

Why "Streamlining" is a Strategic Necessity

The UK is currently in a fight for its life as a global financial hub. Post-Brexit, the City cannot afford to be a museum of 2009-era regulatory trauma.

When a New York or Singapore-based firm looks at London and sees a six-month waiting period just to get a C-suite executive approved, they don't see "safety." They see a sclerotic market.

  • The Talent Drain: High-caliber leaders are increasingly avoiding the UK because the personal liability and administrative burden are disproportionate to the rewards.
  • The Cost of Entry: Small, innovative fintech firms are being crushed by the sheer weight of compliance overhead. They can’t afford the legal teams required to navigate the SMCR's labyrinth.
  • The Illusion of Accountability: The SMCR was designed to make it easier to "jail the bankers." How many senior managers have actually been prosecuted under these rules since 2016? The answer is a rounding error.

We have traded agility for an accountability mechanism that doesn't actually hold anyone accountable. It is all cost and no benefit.

The Risk of the "Clean" Resume

There is a hidden danger in overly strict vetting: it favors the status quo.

If you want to hire a disruptor—someone who has failed, someone who has taken risks, someone who doesn't fit the standard corporate mold—the "fit and proper" rules act as a barrier. The easiest person to get through a regulatory vetting process is a mediocre lifer who has never done anything controversial enough to leave a mark.

We are filtering for the beige. We are ensuring that the leadership of our financial institutions is composed of people who are masters of optics rather than masters of markets. If you want a bank to survive a black swan event, you don't want a "fit and proper" bureaucrat at the helm. You want someone who knows how to navigate chaos.

Moving Toward Radical Responsibility

The critics of this "dilution" argue that without these rules, banks will return to the Wild West. This is a classic "false binary."

The alternative to a heavy-handed, process-driven regime is not "no regime." It is a regime based on outcomes rather than inputs.

Instead of the FCA spending months reviewing a candidate's history, the burden should shift entirely to the firm's board. If a bank hires a disaster, the board should be the first to lose their seats. Not because they failed to follow a vetting process, but because they failed in their duty of care.

We need to stop treating regulators like HR departments. Their job is to monitor systemic stability and market integrity. It is not their job to decide if John Smith is a "nice guy."

The Truth About Regulatory Capture

The dirty secret of the financial services industry is that the biggest banks actually love complex regulation. It acts as a moat.

Goldman Sachs and HSBC can afford 500-person compliance departments. A startup with ten employees cannot. By advocating for "robust" (one of those words I despise, but here it fits the enemy's vocabulary) and "comprehensive" vetting, the incumbents are effectively legislating their competition out of existence.

When the government "dilutes" these rules, they are actually lowering the barrier to entry for new players. They are making the market more competitive, which—as any basic economics textbook will tell you—actually makes the system more resilient. Monopolies are fragile. Diverse ecosystems are hardy.

The Cost of Being "Right"

I realize this view is unpopular. It is much easier to tweet about "bankers getting away with it" than it is to understand the nuances of regulatory friction.

But I have seen the inside of these institutions. I have seen the "Fit and Proper" interviews that turn into theater. I have seen the millions of hours wasted on paperwork that no one ever reads.

If we keep going down this path of hyper-regulation, we will eventually have the safest, most "proper," and most compliant financial sector in the world. It will also be completely irrelevant, devoid of talent, and incapable of generating the capital that the real economy needs to grow.

Safety is not found in a filing cabinet in Canary Wharf. It is found in transparency, in skin in the game, and in the courage to fire people who prioritize their own bonus over the bank's survival.

The UK isn't "diluting" its standards. It is finally admitting that the current standards were a performance, not a protection.

Burn the checklists. Start hiring for character again. Give the responsibility back to the boards and hold them to a standard of results, not a standard of paperwork. That is how you actually protect a financial system. Anything else is just expensive wallpaper.

Stop asking if a manager is "fit and proper" according to a government handbook. Ask if they have the guts to say "no" when everyone else is saying "yes."

The regulator can't tell you that. Only a culture of genuine accountability can.

KM

Kenji Mitchell

Kenji Mitchell has built a reputation for clear, engaging writing that transforms complex subjects into stories readers can connect with and understand.