Compliance FAQ
Questions on authorisation, SMCR, trade surveillance, reporting and ODD — answered from 15 years of in-house experience at hedge funds and prop trading firms.
These answers are general guidance only. Compliance obligations are fact-dependent and the position will vary by firm, structure and regulatory context. Nothing here constitutes legal or regulatory advice — you should seek specific professional advice for your situation.
AI and compliance
AI is most immediately useful in compliance for three things: building, monitoring and synthesising.
Building. Policy libraries, surveillance specifications, risk and control frameworks, SMCR mapping, regulatory horizon trackers and ICARA templates can all be built with AI in days rather than months — and at a fraction of the cost of licensing vendor software or engaging a Big Four firm. The output is yours, hosted in your systems, with no ongoing licensing cost. This is the most underused application in financial services right now.
Monitoring. AI can automate repetitive compliance tasks that currently consume analyst time — drafting trade surveillance alerts for review, summarising regulatory publications, checking policy documents against updated FCA handbook rules, or pre-screening communications. These workflows are buildable today with off-the-shelf tools like Claude and don't require a development team.
Synthesising. AI is exceptionally good at reading large volumes of regulatory text, case law, FCA thematic reviews and enforcement notices and distilling the practical implications for a specific firm type. A CCO can use it to stay current with regulatory change more efficiently than any manual process.
The constraints are real: AI should not be making compliance judgements unsupervised, outputs should be reviewed by someone with regulatory expertise, and firms should consider their data governance position before feeding client or trade data into external models. But for firms that get this right, the efficiency gain is material — and the firms that figure it out first will have a significant competitive advantage in how they run their compliance function.
FCA Authorisation & Structure
The Appointed Representative model allows a firm to operate under the regulatory umbrella of a fully authorised principal firm without holding its own FCA Part 4A authorisation. The principal takes regulatory responsibility for the AR's activities. It makes sense at launch — you can be operational in six to eight weeks rather than waiting for direct authorisation — but it has limitations: the principal controls your permissions, takes a hosting fee, and can terminate the arrangement. Most firms transition to direct authorisation within twelve to twenty-four months. This is a fact-dependent area and the right structure depends on the nature of your business.
An AR never requires or holds its own SMF 16/17 — that function is only required for directly authorised firms and FCA principals. The principal firm's own SMF 16/17 is responsible for compliance oversight across the AR relationship. That said, ARs will typically need a designated compliance responsible person internally to act as the day-to-day compliance contact; the skills, expertise and oversight provided by the principal should ensure FCA requirements are met in practice. If your firm is growing as an AR, the key question is whether you have outgrown the model and should seek direct Part 4A authorisation — at which point appointing an SMF 16/17 becomes mandatory. Specific advice should be sought as the position is fact-dependent.
SMF 16 is the Compliance Oversight function under SMCR — the person responsible for the firm's compliance with FCA rules. SMF 17 is the Money Laundering Reporting Officer (MLRO). Both are controlled functions requiring FCA approval. For most small investment managers one person holds both, but the FCA expects them to be genuinely separate roles in larger or higher-risk firms. Whether one person can hold both depends on the firm's size, complexity and risk profile.
CPMI stands for Collective Portfolio Management Investment firm — an FCA authorisation category introduced under MiFID II that covers firms managing AIFs or UCITS funds and also providing MiFID services such as discretionary portfolio management or investment advice. You need CPMI authorisation if you manage a fund and also provide investment services to third-party clients. A pure AIFM managing only its own funds does not need CPMI. The position depends on the structure of your business and the services you provide — specific advice should be sought.
The FCA has a statutory maximum of twelve months from submission to approve or reject an application. The six-month determination window only starts once the FCA deems the application complete — a separate and important distinction. After submission the FCA reviews the pack within a few weeks to a few months depending on complexity, then issues qualifying questions to establish completeness. Several rounds of Q&A over the first two to three months are normal. Once complete, a further two to three months of review follows — the applications team conducts a four-eyes peer review to assess readiness, willingness and ability. The applicant is then notified of conditional approval (the FCA will say "minded to authorise"), conditions are typically met within two weeks (commonly CET1 capital in place), and authorisation is granted. A well-prepared, complete application typically achieves authorisation in six to eight months total. Incomplete or poorly prepared submissions are viewed poorly by the FCA and extend the timeline considerably.
Trade and position monitoring
The core requirements depend on your regulatory regime — the position is fact-dependent and specific advice should be sought. A MiFID investment manager typically needs: trade surveillance (spoofing, layering, ramping, wash trading, OTR/message rate monitoring), communications recording and sampling under SYSC 10A, short selling position monitoring under UK SSR if you hold listed equity, best execution monitoring, and PA dealing controls. An AIFM that delegates execution is not subject to the same execution-layer surveillance but remains responsible for position-level monitoring including short selling and market abuse at the portfolio level.
RTS 6 is the MiFID II regulatory technical standard on organisational requirements for investment firms engaged in algorithmic trading. It applies to any firm that uses a computer algorithm to determine the parameters of an order — timing, speed, price, quantity, routing — without human intervention in each order. If your firm is systematic or uses an EMS with any algorithmic routing or execution logic, RTS 6 likely applies — though this is fact-dependent and the specific nature of your trading should be assessed. Where it applies, it requires annual self-assessment, kill-switch controls, conformance testing and robust change management. Advice should be sought to assess your specific position.
Reporting & Capital
The obligation applies to MiFID investment firms — CPMI firms are excluded — that execute transactions or perform discretionary portfolio management in financial instruments admitted to trading on a trading venue. Reports must reach the FCA by close of the following working day. Technically firms can report directly to the FCA, but in practice over 95% of reports are submitted via an Approved Reporting Mechanism (ARM). ARMs are not mandatory but are the standard and recommended approach — they handle validation, formatting and submission. Increasingly tech-capable firms are building equivalent pre-report testing and validation logic in-house, which is viable but requires meaningful engineering investment and ongoing regulatory maintenance. Pure AIFMs that delegate execution do not report — the obligation sits with the executing counterparty.
ICARA stands for Internal Capital Adequacy and Risk Assessment — a document required under MiFIDPRU as part of the Investment Firms Prudential Regime (IFPR), introduced in the UK in January 2022. IFPR replaced the CRD IV capital framework for MiFID investment firms and brought with it the ICARA as a replacement for the old ICAAP. You need an ICARA if you are a MiFID investment firm holding a Part 4A authorisation. The document must assess your capital and liquid asset requirements under stress, identify the potential harms your business could cause, and set out your wind-down plan. SNI (small and non-interconnected) firms face lighter requirements than non-SNI firms, but the obligation to produce and maintain an ICARA applies to both.
Investor Relations & Operations
ODD stands for Operational Due Diligence — the process institutional investors use to assess an investment manager's operational infrastructure before allocating. Key areas include: governance and legal structure, regulatory status, key person risk, technology and cybersecurity, valuation independence, prime brokerage and counterparty arrangements, compliance framework (policies, monitoring, training), disaster recovery, and AIFMD/UCITS fund documentation. Most institutional allocators conduct ODD before a first allocation and on an ongoing basis thereafter. A well-prepared manager should be able to respond to a standard ODD questionnaire within five working days.
Most compliance questions have a firm-specific dimension. A short conversation usually gets to the answer faster than a longer article.
Request a call → Try the AI Compliance Workbench →