SMCR & Accountability Regime Software

Accountability regimes ask you to prove who was responsible for what, and that they were fit to hold it, years after the fact. Dreamix build the systems that hold that evidence: fit and proper, responsibilities mapping, approvals and CPD tracking. For firms under SMCR, SEAR, FAR and EU fit and proper rules.

300+
engineers across regulated industries
20+ years
in financial services and insurance
Synechron
Part of the Synechron group · EU-jurisdiction nearshore delivery from Bulgaria

Same obligation, different rulebook

Most firms come to us for one regime. If you operate across borders you are dealing with two or three, each asking for the same evidence in a different format, on a different deadline, to a different regulator.

Thanks to our years of experience with RegTech leaders around the world, we build for all of them:

SMCR

UK, FCA and PRA

Who is in scope

Banks since 2016, insurers since 2018, nearly all other regulated firms since December 2019

What it asks for

Senior Management Functions, statements of responsibilities, annual certification, conduct rules, regulatory references

IAF and SEAR

Ireland, Central Bank of Ireland

Who is in scope

Credit institutions, insurers and certain investment firms, phased from 2024

What it asks for

Fitness and probity, statements of responsibilities, management responsibility maps, common conduct standards

FAR

Australia, APRA and ASIC

Who is in scope

Banking from 2024, insurance and superannuation from 2025

What it asks for

Accountable persons, accountability statements and maps, deferred remuneration obligations

Manager-In-Charge

Hong Kong, SFC

Who is in scope

Licensed corporations

What it asks for

Eight core functions mapped to named managers, management structure filings

IAC guidelines

Singapore, MAS

Who is in scope

Financial institutions above the headcount threshold

What it asks for

Identified senior managers, fitness and propriety, conduct outcomes

Fit and proper

EU, via CRD, MiCA and DORA

Who is in scope

Banks, crypto-asset service providers and other financial entities

What it asks for

Suitability of the management body, documented governance, named accountability for ICT risk

What accountability regimes actually ask of your systems

Writing the policy is the straightforward part. Technology needs to hold the evidence, keep it current, and be able to rebuild any date in the past and show who was responsible for what.

Fit and proper assessments that hold up

Honesty, competence and financial soundness, checked before someone starts and then re-checked every year. In practice that means criminal record checks, credit checks, qualifications, references, directorship searches and conflicts declarations, each with an expiry date and a decision attached. Firms usually manage the first assessment well. The annual cycle is where it slips, because nothing prompts anyone until an audit does.

Responsibilities you can map, version and hand over

Every significant duty allocated to one named person, with no gaps and no orphans. Statements of responsibilities, responsibilities maps and prescribed responsibilities all have to stay accurate as people move, and every version has to survive. When a senior manager leaves, the successor is entitled to a handover that shows what they are inheriting. A document sitting in a shared drive does not give you that.

Approvals, certification and public registers

Senior roles need regulator approval before they start. The tier below is certified by the firm itself and published on a public register, which then has to be corrected when anything changes. Applications, withdrawals, role changes and register updates each have their own form, their own deadline and their own evidence pack, and they arrive constantly once you are past a few hundred staff.

Conduct rules and breach reporting

Conduct rules reach almost everyone in the firm, so the training has to reach almost everyone too, be tailored to the role, and be evidenced. Then there is the harder half: spotting a possible breach, investigating it, recording the outcome and reporting it to the regulator on time. Most firms run that on email, and most firms know it.

Continuing education and competence

Certification is a statement that someone is still competent, which means competence has to be evidenced continuously rather than at the point of hire. CPD hours, structured and unstructured, training completions, supervision records and role-specific competence assessments, all tied back to the individual and the function they hold. The data usually lives in a learning platform that has no idea the regime exists.

An audit trail that reconstructs any date

The question a supervisor asks is rarely about today. It is about a date two years ago, and it is usually asked after something has already gone wrong. Who held that responsibility then, what were they assessed against, what training had they done, and who signed it off. Answering that needs versioned records with proper lineage, not a current-state view with a change log bolted on.

Any one of these is manageable on its own. Together, across a few hundred people and more than one jurisdiction, they turn into a data problem that spreadsheets and a shared drive cannot hold.

Where the spreadsheet stops working

Most firms start with a workbook, a folder and a calendar reminder, and that genuinely works for a while. The signs that it has stopped tend to look like this.

  • Nobody can say with confidence how many certified staff you have this morning.
  • An assessment lapsed and the first anyone knew of it was during an internal audit.
  • A reorganisation moved twenty people and the responsibilities map is still being redrafted six weeks later.
  • You are running the same evidence twice because a UK entity and an Irish entity ask for it differently.
  • Someone left, and reconstructing what they were responsible for takes days.
  • The evidence for one person sits in HR, the learning platform, a shared drive and three inboxes.

None of these are compliance failures yet. They are the conditions that produce one.

Executive reviewing data dashboards on a laptop in a modern office

Can off-the-shelf SMCR software get you there?

Often, yes. But it gets harder in a few situations.

When you are under two or three regimes at once and the product only really models one of them.

When your group structure, matrix reporting or secondment arrangements do not fit the shape the product expects, and configuration turns into workaround.

When the regime data needs to live inside your existing HR, identity and learning stack rather than beside it in another portal.

And when you are the software vendor, and your own customers keep asking for the accountability module you do not have yet.

That is the work we do. We build the pieces that are missing, connect the tools you already pay for, and modernise the systems you use, rather than adding one more product for your compliance team to keep in sync.

What we build

Fit and proper assessment workflows

Pre-hire and annual assessments with the checks built in: criminal record and credit checks, qualifications, directorship searches, conflicts and outside interests. Automatic re-assessment scheduling, escalation when something lapses, and a decision record for every outcome.

Responsibilities mapping and statements

Responsibilities allocated to named individuals and functions, with generated statements of responsibilities and responsibilities maps, full version history, gap and overlap detection, and structured handover packs when a role changes hands.

Approvals, certification and register reporting

Application and approval workflows for senior roles, annual certification cycles, and the reporting pipelines that keep public registers accurate when someone joins, moves or leaves.

Conduct rules, training and attestations

Role-based conduct rules training with completion evidence, attestation campaigns, and case management for suspected breaches from first report through investigation to regulatory notification.

CPD and competence tracking

CPD hours captured against each individual and role, structured and unstructured activity, supervision and competence records, and dashboards that show a shortfall while there is still time to fix it.

Integrations and legacy modernisation

One accountability data layer drawing from your HR system, learning platform, screening providers and identity stack, with lineage and audit trails throughout. Where an existing system cannot be extended to meet current requirements, we rebuild or re-platform it without stopping your roadmap.

Banks and credit institutions
The highest obligations, the largest certified populations, and the most integration work, because the regime data has to reach across core systems that were never built to share it.

Insurers and asset managers
Long approval chains, appointed representatives and delegated authority arrangements that make responsibility harder to map than an org chart suggests.

Payment, e-money and crypto-asset firms
Growing quickly, adding jurisdictions, and often meeting a formal accountability regime for the first time while the team is still small.

Multi-jurisdiction groups
Firms holding the same evidence for two or more regulators, who want one source of truth underneath rather than three parallel processes.

RegTech and compliance software vendors
Product companies building accountability, certification or competence modules who need engineering capacity and domain knowledge alongside their own team.

How we work with you

Four ways to engage, matched to where your systems are today.

Accountability readiness review

An engineering-led review of how you currently hold fit and proper evidence, responsibilities and competence records, what a supervisor could and could not be shown, and what it would take to close the gaps. You get a remediation plan, and a team to deliver it if you want one.

Specialist engineering pods

A time-boxed team for one piece of work: a responsibilities mapping module, a certification cycle rebuild, CPD tracking, or the data layer underneath all of it.

Product engineering partner

Full ownership from architecture through build, release and support, for firms and vendors who want the system delivered rather than staffed.

Dedicated engineering teams

A long-running embedded team for multi-year compliance modernisation, working as part of your organisation.

Our success stories

dreamix home image scaled e1718004077682 - SMCR and Accountability Regime Software Development
our success stories bg mobile - SMCR and Accountability Regime Software Development
  • Building an AI Platform for the Compliance Industry

    Our client is a leader in compliance technology solutions for regulated financial firms. As the volume of data compliance teams must monitor keeps growing, they saw an opportunity to use AI to get ahead of it. They partnered with Dreamix to build Encore: a production-grade AI platform that today gives compliance teams access to 100+ […]

  • Streamlining compliance with a comprehensive ARL management tool 

    Navigating regulation has always been a core challenge for companies. For nearly two decades, MCO has been at the forefront of creating solutions to help overcome this hurdle. In the currently growing complexity of the regulatory landscape, the US-based platform recognized a rare opportunity to make compliance more straightforward for their clients.  After joining forces […]

  • Automating Workforce Management for Transatlantic Aviation Leader  

    When managing thousands of ground operations employees across multiple airports, keeping licenses, permissions, and shift planning synchronized is critical and incredibly time-consuming. Icelandair partnered with Dreamix to automate its workforce management processes. The result? Over 1,200 hours saved annually, zero human error in permission assignments, and streamlined operations that give management real-time visibility into employee […]

Regulated-industry engineering
Over two decades building software for financial services, insurance and fintech, under real regulatory scrutiny rather than adjacent to it.

Part of the Synechron group
A global financial services consultancy with regulatory expertise across 21 countries, which matters when your obligations do not stop at one border.

EU nearshore delivery
Delivery inside EU jurisdiction, full time-zone overlap with UK and European teams, and same-day overlap with the US.

Compliance-aware engineering
Security, audit and traceability built into how we work. GDPR-aligned handling of personal data, which matters more here than on most projects, because fit and proper evidence is some of the most sensitive data your firm holds.

Low-turnover teams
95% employee retention, so the people who learned your regime and your systems are still there when the rules change.

The technology we build on

We work mainly in Java and Spring Boot with Angular or React on the front end, microservices where they earn their place, and cloud deployment on AWS or Azure. For the audit and lineage work underneath an accountability system, event-driven architecture and proper data modelling do most of the heavy lifting.

Java

Spring Boot

Angular

React

Node.js

Microservices

Kafka

PostgreSQL

Python

Elasticsearch

How a build comes together

01

Discovery

We map your obligations regime by regime, the systems holding the evidence today, and where the gaps actually are rather than where they are assumed to be.

02

Architecture

Data model, versioning and audit design, integration points, security architecture and technology choices. On these systems the data model is the product, so it gets the time it needs.

03

Build

Focused Agile sprints with regular touchpoints, so your compliance team sees the workflows early enough to change them.

04

Integrate and test

Functional, integration, security and performance testing, including the scenario that matters most: reconstructing a past date and proving the trail holds.

05

Deploy and support

We stay involved after launch, because the regimes keep moving and the system has to move with them.

Frequently asked questions about SMCR and accountability regime software

Software that holds the evidence the Senior Managers and Certification Regime requires: who holds each Senior Management Function, what each person has been assessed against, their certification status, conduct rules training and any breaches. Good systems handle the ongoing cycle rather than the initial setup, because that is where firms fall behind.

SMCR is the UK’s version of one. Ireland has SEAR, Australia has FAR, Hong Kong has the Manager-In-Charge regime and Singapore has the MAS accountability guidelines, while the EU spreads similar duties across CRD, MiCA and DORA. They share the same four mechanics: fit and proper, allocated responsibilities, approvals and registration, and continuing competence.

Yes, and it is normally the point of building rather than buying. The underlying record is the same: a person, a role, a set of responsibilities and a body of evidence. What changes between regimes is the terminology, the forms and the reporting deadlines, which sit on top of that record rather than inside it.

Fit and proper files hold criminal record results, credit history and references, so they need tighter handling than most HR data. We design for least-privilege access, field-level encryption, defined retention and full access logging, aligned with GDPR and the UK equivalent.

Yes. Most of the value in these builds comes from integration rather than new screens. We connect HR systems, learning platforms, screening and background check providers and identity systems so the same person is not maintained in four places.

They will. SMCR has been under review, other jurisdictions keep adopting their own versions, and EU governance requirements continue to expand. We build the regime-specific parts as configuration rather than hard-coded logic, so a change in forms, thresholds or deadlines does not become a rebuild.

A focused module such as certification cycles or CPD tracking usually takes a few months. A full accountability platform with integrations depends mostly on how clean your existing people data is, which is worth finding out during discovery rather than after.

Pick a date eighteen months ago and try to show who was responsible for what, and what they had been assessed against. If that takes more than an afternoon, tell us how your systems are set up today and we will put you in front of the right engineering lead.