Who holds it, what shape it takes, and how the hiring works
senior figures mapped
senior roles tracked
firms & regulators
documented role moves
This is a commentary on compliance leadership in UK financial services — who holds the compliance chair across the country’s banks and insurers, how those seats are configured, and where the talent comes from. It draws on Brown Strategic Search Partners’ market map of senior compliance leadership across the Tier-1 institutions, the mid-market and the London specialty insurance market. What follows is a read of the market as it stands in mid-2026 — and of the direction it is travelling.
Ask who runs compliance at a UK financial services firm and there is no single answer. Across the 62 senior seats in our map the role is configured several different ways — a standalone chair at some institutions, a combined mandate at others, folded into risk, or, at many payments and e-money firms, placed outside the Senior Managers and Certification Regime (SM&CR) altogether. Where the chair sits, who it answers to, and what else it carries vary firm to firm, and that variation says more about how an organisation treats conduct than the title on the door.
No shape is standard, but two currently stand out. The most common is the combined compliance and financial crime seat — one person holding both SMF16 (Compliance Oversight) and SMF17 (MLRO), so conduct and financial crime answer to a single owner — in place at eighteen firms. Just behind it is the standalone compliance chair, an SMF16 whose whole remit is compliance with its own line to the board, at seventeen firms. Between them they account for roughly three-quarters of the seats in our map that fall within the Senior Managers Regime. Beneath them the numbers thin fast: six hold compliance within the risk function, under the chief risk officer; five combine it with risk under a single second-line chief; and one places it under non-financial risk. A further fifteen firms — 24% of the map — fall outside the Senior Managers Regime altogether, chiefly payments and e-money businesses alongside the regulators. At the payments firms, compliance and financial crime are usually run as a single combined function.
The reporting line is the signal to read first — whether a firm treats compliance as an independent authority or as one input into the risk function — and it is the first question in a search: not who runs compliance, but how high the seat sits and who it answers to.
The combined seat’s dominance is really an indication of scale. It concentrates in the mid-market — challenger banks and smaller insurers, where tighter headcount and less complexity make a single owner for conduct and financial crime the natural choice — while the largest, most complex organisations keep the two mandates apart, typically opting for the standalone compliance chair.
By sector the contrast is softer: among banks the split is even, eleven standalone chairs to ten combined, while insurers lean to the combined seat.
For a hiring board the point is practical: a ‘Head of Compliance and MLRO’ may be one accountable person or two. Combining the mandates concentrates conduct and financial-crime accountability — and its risk — on one approved individual; splitting them spreads both. Scale explains much of the pattern, but the shape a firm settles on still says something about how independently it governs conduct — and that remains its call, not the market’s.
The people in these seats come from a different place than their risk counterparts. Where insurer chief risk officers are actuaries, compliance leaders almost never are. They come from the law, from long compliance careers, from the Big Four, and — more than in any risk seat — from the regulator itself. The revolving door between the FCA, the PRA and the firms they supervise runs through compliance: an ex-regulator is a recognised route into the chair, not an exception. One group compliance chief in the specialty insurance market came to the seat from the Financial Services Authority before a compliance career in insurance; in banking, another runs compliance and the MLRO mandate together, having arrived from internal audit and financial-crime investigation. The unifying thread is law, regulation, audit and compliance — not the actuarial training that defines the chief risk officer’s chair next door.
The sourcing split runs along the same line it does for risk. The largest firms promote from within — five of the eight Tier-1 seats are internal, the compliance chief raised through the bank’s own second line. The mid-market does the opposite, hiring externally by almost two to one. The difference is bench depth: a Tier-1 bank has a layered compliance function to grow a leader from; a challenger or a mid-tier insurer does not, and goes to the market when the seat turns.
There is a vertical layer, too. At the biggest banks a group compliance officer often sits above entity-level SMF16 holders — at one Tier-1 bank, for instance, a Group Chief Compliance Officer sits over the SMF16 holder for the bank entity. The difference is one of scope, not discipline: the entity SMF16 owns regulatory accountability for one authorised firm, while the group role leads the function across the whole — and relies as much on group-level sponsorship and navigating that landscape as on technical depth. A strong entity CCO can grow into the group seat; the point for a board is to be clear which one it is filling.
All of which makes the configuration the first question in any compliance search, before a single name is considered. A board that signs off a ‘Head of Compliance’ mandate without deciding whether it wants a standalone SMF16, a combined compliance and financial crime seat, a compliance lead under the CRO, or a role folded into a combined risk-and-compliance chief will interview four different kinds of candidate for one seat, and is certain to waste time and potentially mis-hire. Three of the ten Tier-1 seats are also in transition as this is written, one of them as a thirty-year compliance veteran steps away.
The strongest force now reshaping the compliance chair is technology. Monitoring, surveillance, transaction screening and much of regulatory reporting are being automated, and the use of AI in anti-money-laundering and know-your-customer work has moved from experiment to baseline. The leader’s job does not shrink as a result; its emphasis shifts — less running of manual controls, more governing of automated ones, and, increasingly, governing the firm’s own use of AI.
That last duty is the one to watch, because of how the UK regulates it. Rather than write new rules for AI, the FCA and PRA apply the frameworks already in place — the Senior Managers Regime, the Consumer Duty, operational resilience — so a named senior manager must own the firm’s AI and be able to show it produces good outcomes. Where that accountability sits is, for now, unsettled: with the chief data or information officer at some firms, with risk or compliance at others. The likeliest resolution is consolidation — the combined and converged shapes, where one accountable leader can hold conduct, control and the governance of the technology together.
For the next hire, the technical bar rises with it. The compliance leader firms increasingly want is fluent in data and in the systems the function now runs on, not in regulation alone — and the ex-regulator, who can read where supervision is heading on AI and outcomes before it hardens into a rule, is the more valuable for it. None of this displaces the shapes in this report; it raises the premium on the leaders who pair one of them with technical range.
Compliance leadership is not one market but several, layered by sector and scale, so the job specification has to start one step earlier than usual — with the shape of the seat, not the seniority of the person. Firms that decide the shape first run a cleaner search and recognise the right candidate when they see them; those that do not keep asking why a strong compliance leader did not work out, when the real mismatch was structural — the wrong shape for the seat they had.
Watch whether the standalone SMF16 cedes ground to combined configurations — risk-and-compliance, or compliance alongside the governance of data and AI — as one leader is asked to hold more together.
Under the Senior Managers Regime someone must own the firm’s AI; where it lands — data, risk or compliance — is unsettled, and the firms that resolve it cleanly will define the next version of the chair.
Three of the ten Tier-1 seats are in transition, unusual churn for a chair that usually changes hands quietly.
Ex-FCA and PRA leaders stay prized — they read where supervision is heading before it is written into rules.
Demand is shifting toward leaders fluent in data and the function’s systems, not in regulation alone.
Drawn from Brown Strategic Search Partners’ UK FS compliance-leadership market map: 62 senior compliance seats across Tier-1, mid-market and London specialty insurance firms, verified June 2026 across company, regulatory and industry sources. Named individuals and firms are omitted from this public version.
Brown Strategic Search Partners is a boutique senior executive search firm focused on data, AI, governance and senior risk mandates at MD and ED level in UK financial services. The mapping behind this work is a working asset we maintain continuously and use to advise on senior seat design, candidate selection, and architectural decisions. We welcome a conversation on any of these findings or a specific senior question on your bench.
Insight-first: Every mandate begins with a structured view of the market, capability trends and leadership patterns.
Integrated lens: We surface cross-domain leaders who operate across technology, data, regulation and strategy.
Pricing philosophy: A flat-fee structure shaped by in-house executive hiring experience — typically 40–60% below traditional search pricing — designed for clarity, predictability and senior delivery.
Senior appointments across Governance, Data & Transformation with specialist FS firms — banks, payments providers, insurers, fintechs and regulated infrastructure.
Example Hires:
Governance – Director of Compliance & NF Risk · Head of Operational Risk for Tech, Cyber & Data · Chief Risk Officer, Channel Islands · Head of Financial Crime, Corporate Bank
Data & Emerging Technology – Head of AI Strategy · Head of AI Data Engineering · Head of Data Governance · Chief Architect