CRO & Compliance Leadership

Who Actually Owns the Model? Professional Roles and Accountability in UK and US Financial Services

Ask five professionals who is accountable when a model fails and you get five incompatible answers. A role-by-role map of model accountability across UK SM&CR and the US collective-responsibility model.

By Jonas Osman AbdelghafourPublished 4 August 2026

Ask a room of financial services professionals who is accountable when a pricing model produces systematically unfair outcomes, and you will get five confident, mutually incompatible answers. The actuary who built it. The CRO who owns the risk. The compliance officer who signed the policy. The senior manager whose function it sits under. The board.

In the UK, that question now has a legally specific answer. In the US, it has a structurally different one. And in both jurisdictions, the answer is changing as AI systems take on functions that were previously exercised by identifiable humans.

*This article discusses professional and regulatory roles in general terms and is not legal advice.*

The UK: Accountability Attaches to a Named Person

The Senior Managers and Certification Regime, in force for banks since March 2016 and for dual-regulated insurers since December 2018, does something no US framework does. It requires firms to allocate specified responsibilities to named individuals who are personally accountable to the regulator for the reasonable steps they took.

That phrase — reasonable steps — is the whole regime. A senior manager is not liable because something went wrong. They are exposed because they cannot evidence that they took reasonable steps to prevent it. This inverts the documentation logic of the entire function: the record exists to demonstrate the manager's diligence, not merely to describe the model.

The regime is currently in reform. On 22 April 2026 the FCA and PRA confirmed changes to streamline senior manager accountability, described as the first phase of a multi-stage package. Firms get more time to submit senior manager applications where there has been an unexpected or temporary change. The Government's consultation response proposed removing the Certification Regime — which covers less senior roles — from legislation, and giving regulators more flexibility to reduce the number of senior management functions requiring pre-approval. The regulators intend to consult on wider changes later in 2026 as part of reforms aimed at substantially reducing the regime's burden.

Read the direction carefully. The core principle of individual senior accountability is being retained. What is being reduced is the administrative apparatus around it — pre-approval volume, certification bureaucracy, application timing. For anyone whose responsibilities include model governance, the personal exposure is not going away.

The US: Accountability Attaches to a Function

The US framework distributes accountability differently, and across more regulators.

Under SR 26-2, model risk management responsibility sits with the board and senior management collectively. The board is expected to establish a framework and oversee its execution; senior management is expected to implement it. There is no equivalent of a regulator-approved individual holding a defined statement of responsibilities.

In insurance, the picture is different again, because there is no federal prudential insurance regulator. Accountability runs through the domiciliary state and every state in which the insurer writes. Two roles carry unusually specific personal weight:

The Appointed Actuary, who signs the Statement of Actuarial Opinion on reserves. This is a named individual, with defined qualification requirements, whose opinion is filed with regulators and whose professional standing is directly at stake.

The signing actuary under NAIC AI governance expectations. The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers requires a written AI Systems Program with senior management and board accountability — pushing named responsibility into AI governance in a way federal banking guidance has not.

The professional layer sits alongside this. The Actuarial Standards Board sets Actuarial Standards of Practice; the US Qualification Standards administered through the American Academy of Actuaries govern who may issue statements of actuarial opinion; and the Actuarial Board for Counseling and Discipline handles professional discipline across the US-based actuarial organisations. These are professional instruments enforced through professional consequence, operating in parallel with — not as part of — state insurance regulation.

Role by Role: What Each Professional Actually Owns

Here is the mapping that most firms have never written down explicitly.

The modelling actuary or quantitative analyst. Owns technical correctness, methodological appropriateness and documentation quality. In the UK, bound by TAS 100 and the relevant sector standard, plus the Actuaries' Code. In the US, bound by applicable ASOPs and the Code of Professional Conduct. Critically, this professional obligation exists independently of the employer's instructions — a point that becomes uncomfortable precisely when it matters.

The independent validator. Owns effective challenge. Note that SR 26-2 explicitly decoupled validation quality from organisational reporting lines: what matters is accuracy, expertise and the authority to drive change, not where the validator sits. The UK expectation via SS1/23 remains closer to structural independence. A dual-jurisdiction firm should not read the US relaxation as permission to fold validation into the first line.

The Chief Risk Officer. Owns the aggregate risk position and the adequacy of the framework. In the UK this is typically an approved senior management function with a personal statement of responsibilities. In the US it is a senior management role without individual regulatory approval, though not without exposure.

The compliance function. Owns the mapping between regulatory obligation and firm process — not the model's correctness. This distinction is routinely blurred, and the blurring is dangerous in both directions: compliance officers sign off on things they cannot assess, and modellers assume compliance sign-off covers technical risk. It does not.

Internal audit. Owns assurance over whether the framework operates as designed. Third line. Should be testing whether validation actually challenged anything, not re-performing validation.

The general counsel. Owns legal risk, contract terms with model vendors, and — increasingly the pressure point — privilege strategy. This differs meaningfully between jurisdictions. US legal privilege doctrine and UK legal professional privilege are not coextensive, and a validation report commissioned in a way that attracts privilege in one jurisdiction may not in the other. Groups running cross-border remediation should get this right before the work starts, not after.

The board. Owns the risk appetite and the adequacy of the control environment. In both jurisdictions the board's realistic contribution is asking whether the framework is producing genuine challenge — not reviewing model documentation it cannot meaningfully assess.

The Gap AI Is Opening

The interesting problem is what happens when an AI system performs a function that previously required a human exercising judgement.

The FCA has raised this directly, questioning how SM&CR would operate where AI systems perform functions traditionally subject to direct human oversight. It launched a long-term review in January 2026 into how AI could reshape retail financial services, having reiterated that it does not currently plan to introduce AI-specific rules. The House of Commons Treasury Committee, in its January 2026 report on AI in financial services, recommended the FCA publish practical guidance by the end of 2026 on what level of assurance is expected from senior managers under SM&CR for harm caused through AI.

That recommendation names the gap precisely. If a senior manager's defence is "reasonable steps," what are reasonable steps in relation to a system whose behaviour cannot be fully specified in advance? Nobody has published an answer. Firms are constructing one every day by deciding what to document.

My working position, which I offer as a practitioner view rather than a legal one: reasonable steps in relation to an AI-mediated decision should include a documented understanding of the system's failure modes, evidence of pre-deployment testing proportionate to the harm available, ongoing monitoring with defined escalation thresholds, and a named individual who can and does exercise the authority to switch it off. If those four things exist and are evidenced, a senior manager has a defensible position. If they do not, the absence of an AI-specific rulebook will provide no protection whatsoever.

Three Practical Recommendations

Write the accountability map down. One page, per material model: builder, validator, approver, accountable senior manager or executive, professional standards engaged. Most firms have never produced this, and the exercise of producing it typically reveals at least one material model with no clear owner.

Distinguish professional obligation from firm policy explicitly. Where an actuary's professional standard requires something the firm's policy does not, the professional standard governs the actuary. Make sure both the actuary and their manager understand this before a disagreement, not during one.

Allocate AI governance under SM&CR explicitly, in the UK, now. Not as a general responsibility swept into an existing function description, but as a named allocation with a stated scope. Where regulatory guidance is pending, having already made a considered allocation is the strongest possible position.

The Point

Accountability frameworks are not paperwork. They determine who has the standing to say no.

A validator without authority to force change is not a control. A senior manager without visibility of the models under their function has personal exposure without personal knowledge — the worst combination available. And an AI system operating without a human who can switch it off has no owner at all, whatever the org chart says.

Key Takeaways

  • SM&CR allocates model governance accountability to a named individual assessed on "reasonable steps" — a standard that shapes how documentation should be written.
  • April 2026 reforms streamline SM&CR administration while explicitly retaining the core principle of individual senior accountability.
  • US accountability sits with the board and senior management collectively under SR 26-2, with sharper individual exposure in insurance through the Appointed Actuary and NAIC AI Systems Program expectations.
  • SR 26-2 decoupled validation quality from reporting lines; UK expectations remain closer to structural independence, so dual-jurisdiction firms should not relax the second line.
  • Professional actuarial obligations under TASs or ASOPs exist independently of employer instruction — a distinction that must be understood before a disagreement arises.

Frequently Asked Questions

Who is accountable under SM&CR for a model that causes customer harm? The senior manager to whom the relevant responsibility has been allocated, assessed against whether they took reasonable steps to prevent the harm. Accountability follows the allocation recorded in the statement of responsibilities and management responsibilities map, which is why explicit allocation of model and AI governance matters.

Is the Certification Regime being abolished in the UK? The Government's April 2026 consultation response proposed removing the Certification Regime from legislation as part of a multi-stage reform package, with regulators expected to consult on wider changes later in 2026. The core Senior Managers Regime and the principle of individual senior accountability are being retained.

How does US accountability for model risk differ from the UK? US banking guidance places responsibility with the board and senior management collectively, without regulator-approved individual functions. Individual accountability is sharper in US insurance, through the Appointed Actuary's signed opinion and through the senior management and board accountability required by the NAIC AI Systems Program in adopting states.

Related reading

See also Corporate Governance and Model Risk, or review qualifications.

About the author

Jonas Osman Abdelghafour is an actuary and risk expert advising insurers, banks and pension funds on model risk, regulatory compliance, financial crime and enterprise risk management across UK, EU and US regimes. He writes on where quantitative actuarial practice meets the governance, risk and compliance frameworks regulators expect boards to evidence. See qualifications and services, or get in touch to discuss an engagement.

Frequently asked questions

What should risk leaders know about the UK: Accountability Attaches to a Named Person?

The Senior Managers and Certification Regime, in force for banks since March 2016 and for dual-regulated insurers since December 2018, does something no US framework does. It requires firms to allocate specified responsibilities to named individuals who are personally accountable to the regulator for the reasonable steps they took.

What should risk leaders know about the US: Accountability Attaches to a Function?

The US framework distributes accountability differently, and across more regulators.

What should risk leaders know about role by Role: What Each Professional Actually Owns?

Here is the mapping that most firms have never written down explicitly.

What should risk leaders know about the Gap AI Is Opening?

The interesting problem is what happens when an AI system performs a function that previously required a human exercising judgement.

What should risk leaders know about three Practical Recommendations?

**Write the accountability map down.** One page, per material model: builder, validator, approver, accountable senior manager or executive, professional standards engaged. Most firms have never produced this, and the exercise of producing it typically reveals at least one material model with no clear owner.