Head of Compliance Recruitment in London
Hiring a Head of Compliance in London means appointing the person personally accountable to the FCA for your firm's compliance arrangements. SMF16 approval runs 4-12 weeks, time-to-hire at smaller firms has stretched to 14 weeks, and 35% of recent hires came from unsolicited approaches rather than active search.
Key takeaways
- The SMF16 Compliance Oversight function carries personal regulatory accountability under SMCR; getting the appointment wrong exposes both the firm and the postholder to FCA enforcement action.
- Average Head of Compliance salary in London in 2026 sits at £120,000-£150,000, with combined SMF16 + SMF17 roles and cryptoasset specialists commanding a 15-25% premium (FD Capital 2026).
- 35% of compliance and risk hires in the past 12 months came from unsolicited approaches the candidate found compelling, not active job search (FD Capital placement data, 2026).
- Time-to-hire at smaller FCA-regulated firms now runs 8-14 weeks, plus a 4-12 week FCA approval window before the candidate can take up the function.
- Morgan Spencer pre-screens FCA Register history, Regulatory References and Fit & Proper indicators before introducing any candidate, cutting shortlist time to 2-3 weeks.
The hard skills a Head of Compliance must bring to your firm
Five technical disciplines define a credible Head of Compliance candidate in London: FCA Handbook fluency on the sourcebooks that apply to your firm, SMCR expertise at the firm's regulatory tier, Consumer Duty outcome monitoring across the four cross-cutting rules, financial crime and AML programme ownership, and compliance monitoring programme design with Section 166 readiness. Any one of these missing in the shortlist is a signal the search has been run too generically.
FCA Handbook fluency across the sourcebooks that apply to your firm
Working interpretation of the specific Handbook sourcebooks applicable to your firm's regulated activities is what the FCA assesses at SMF16 approval, not generic compliance theory. COBS and SYSC for asset managers and MiFID investment firms. MIFIDPRU for prudential standards post-IFPR. CONC for consumer credit and high-cost short-term credit lenders. PRIN and SUP across every regulated firm type. A candidate with twenty years of retail bank compliance experience moving into a MIFIDPRU investment firm role will be tested on the investment firm Handbook stack at FCA interview regardless of seniority, and the FCA can refuse approval if the firm-specific knowledge gap is material (FD Capital, June 2026).
SMCR expertise at your firm's regulatory tier
SMCR expertise covers SMF16, SMF17 and SMF24 designation routes, Statement of Responsibilities drafting against SUP 10C, Prescribed Responsibilities allocation across the senior management team, Fit and Proper assessments under the certification regime, and Conduct Rules monitoring across both Tier 1 (Senior Manager) and Tier 2 (Individual) populations. Depth required varies by SMCR tier: Core, Enhanced, or Limited Scope. An SMF16 candidate from an Enhanced firm has materially different obligations to one from a Core firm, and the FCA assesses each appointment against the firm's actual tier rather than the candidate's previous one (Comply.com, October 2025; FD Capital SMCR Interview Guide, May 2026).
Consumer Duty outcome monitoring across the four cross-cutting rules
Outcome monitoring against the FCA's Consumer Duty cross-cutting rules is the 2026 differentiator for any retail-facing or distribution-chain compliance hire. Products and services. Price and value. Consumer understanding. Consumer support. Since the FCA moved Consumer Duty from implementation to evidence phase in 2026, multi-firm reviews and targeted data requests have turned the annual Consumer Duty Board Report into a CCO-owned artefact, not a policy refresh. Candidates who can describe specific data sources, vulnerability monitoring, and fair value assessment methodology by product earn a 12-18% premium over policy-led peers (Middlesex Partnership, February 2026; FD Capital, March 2026).
Financial crime and AML programme ownership
Financial crime ownership runs from Enterprise-Wide Risk Assessment design through transaction monitoring rule logic, SAR and STR reporting via the NCA portal, sanctions screening, PEP screening and adverse media monitoring. At smaller FCA-regulated firms the SMF16 holder usually also carries SMF17 (MLRO), which combines compliance oversight with personal AML accountability. The Economic Crime and Corporate Transparency Act 2023 failure-to-prevent fraud offence (in force from 2025) has lifted board attention on financial crime resourcing, and combined SMF16 + SMF17 holders now command a 15-25% premium over single-function SMF16 candidates (FD Capital 2026 Salary Guide, March 2026).
Compliance monitoring programme design and Section 166 readiness
Compliance monitoring programme design is the audit-style framework that proves to the FCA your firm is actually doing what its Handbook obligations require. RegData and GABRIEL returns. REP-CRIM submissions. Risk-based monitoring plan delivery against the Annual Compliance Plan. Thematic review preparation. Section 166 skilled person review activity has increased through 2025-2026 and is now a recognised trigger for senior compliance hiring, with remediation programmes creating substantial interim demand at premium day rates (Barclay Simpson 2026 Compliance Salary Survey, April 2026).
The soft skills that separate effective Heads of Compliance from technically capable ones
Five behavioural attributes separate a credible SMF16 candidate from a technically capable Compliance Manager: second-line independence under commercial pressure, board-level regulatory communication, FCA supervisory relationship management, cross-functional influence without direct authority, and personal regulatory accountability composure. Defining the essential KPIs a Head of Compliance must be accountable for sits at the intersection of these soft skills and the firm's quarterly governance cycle, with the essential KPIs a Head of Compliance must be accountable for shaping how the Board holds the postholder to account.
Second-line independence under commercial pressure
Holding a regulatory line against a CEO or front-office head who wants to take on risk you cannot defend is the single hardest behavioural test the role applies. SMF16 holders are personally accountable to the FCA for compliance oversight, and capitulating to commercial pressure exposes the postholder to personal enforcement action and the firm to FCA censure. The candidates who pass this test maintain the working relationship without yielding the technical point, document their challenge in writing, and escalate cleanly when the business does not adjust (Exec Capital CCO Job Description, 2024).
Board-level regulatory communication
Translating Handbook obligations and outcome data into Board and Audit Committee language that supports decisions rather than just feeding information is the second-line skill most often missed at shortlist stage. The Board owns regulatory risk strategically; the Head of Compliance only succeeds if the Board can act on the risk picture, which requires structured Risk Committee reporting and concise Audit Committee narrative rather than 60-slide compliance decks (Exec Capital CCO Job Description, 2024).
FCA supervisory relationship management
Handling routine FCA supervision contacts, thematic data requests, multi-firm reviews and Section 166 engagements without escalating tone or triggering supervisory concern is a learned skill, not a textbook one. The FCA forms a continuous view of senior management calibre across every interaction, and an SMF16 candidate who has handled a difficult supervision moment well is materially more valuable than one with theoretical knowledge alone (FD Capital SMCR Interview Guide, May 2026).
Cross-functional influence without direct authority
The compliance function depends on first-line ownership of controls across sales, distribution, product, operations and finance. An SMF16 who micromanages first-line controls weakens the three-lines model and loses business credibility, which then weakens regulatory oversight. The credible candidates influence without owning, frame controls in commercial language, and hold the first line accountable through structured second-line monitoring rather than through direct intervention (Exec Capital CCO Job Description, 2024).
Personal regulatory accountability composure
Operating under personal SMF liability without becoming risk-averse to the point of obstructing the business is the maturity test for senior compliance candidates in 2026. Recent FCA enforcement against individual SMFs for Conduct Rule breaches has changed how candidates view SMF appointment, with some declining SMF roles at higher pay rather than accept the personal liability. The candidates who continue to take SMF mandates hold personal accountability with calibrated, not defensive, judgement (Exec Capital, May 2026).
Interview questions for a Head of Compliance: what to ask and what good looks like
Five competency-based questions test the technical depth, regulatory currency, behavioural independence and AML horizon-scanning a credible SMF16 candidate must demonstrate. Each question maps to a specific skill from the hard and soft skills sets above. Each answer is assessed against what a strong candidate would say, what the interviewer is actually testing, and the red flag patterns that mark a weak response.
Q1: Walk us through how you would draft your Statement of Responsibilities in your first 60 days as SMF16 at this firm, including the Prescribed Responsibilities the firm has allocated to you and any expected overlaps with other SMFs.
Signal: Tests SMCR depth, understanding of SoR construction, awareness of the Prescribed Responsibilities allocation process, and ability to identify and close governance gaps with other SMFs (especially SMF17, SMF4, SMF24).
Good answer framework: References SUP 10C of the FCA Handbook, names the firm's SMCR tier (Core, Enhanced, Limited Scope), lists the Prescribed Responsibilities the SMF16 typically holds (Conduct Rules training and monitoring, Consumer Duty outcomes oversight at smaller firms), describes the Board sign-off route, and explicitly addresses overlap risk with SMF17 (MLRO) and SMF24 (Operations) where relevant. Strong candidates name the SoR review cycle (annual minimum, on material change).
Red flags: Generic "owning compliance" language, inability to name specific Prescribed Responsibilities, no mention of SoR review cycle, no awareness of overlap risk with other SMFs.
Q2: Describe the most challenging FCA supervisory interaction you have personally led and what the documented outcome was.
Signal: Direct regulator-facing experience, named touchpoints (Section 166, thematic review, multi-firm review, supervisory visit, RegData query), composure under regulatory pressure.
Good answer framework: STAR structure with a specific named interaction, the candidate's role versus the firm's wider response, evidence of the outcome (no enforcement, lifted limitation, satisfactory close-out letter, accepted remediation plan), and reflection on what they would do differently.
Red flags: Generic answers with no named FCA touchpoint, takes credit for outcomes they did not personally lead, blames the firm for the supervisory issue, no evidence of post-event learning.
Q3: How have you evidenced positive consumer outcomes against the four Consumer Duty cross-cutting rules in your current role, and what data sources have you used to defend that evidence at Board level?
Signal: Recent regulatory currency (Consumer Duty in force July 2023, supervisory phase 2026), outcome-led monitoring versus policy-led documentation, ability to defend the annual Consumer Duty Board Report.
Good answer framework: Names all four outcomes (Products & Services, Price & Value, Consumer Understanding, Consumer Support), references specific data sources (complaints data with root-cause analysis, customer journey testing, fair value assessments by product, vulnerability data), and describes Board Consumer Duty Champion liaison.
Red flags: Treats Consumer Duty as a policy refresh, cannot name the four outcomes, no outcome metrics offered, no mention of the annual Board report.
Q4: Tell me about a time you challenged the CEO or Board on a commercial decision that carried material regulatory risk, what happened, and what your documented escalation route looked like.
Signal: Tests second-line independence required for SMF16, willingness to hold a line against commercial pressure, knowledge of the firm's escalation route (CEO, NED, Board, Audit Committee, FCA self-report).
Good answer framework: STAR structure, names the specific risk (product launch, fee structure, distribution chain, third-party arrangement), the escalation pathway followed, documented evidence preserved, outcome that protected the firm, and the candidate's tone (firm without being adversarial).
Red flags: No example offered, an example where the candidate yielded without escalation, generic "regulators are partners not obstacles" framing without specifics, no documentation reference.
Q5: Walk me through your firm's current Enterprise-Wide Financial Crime Risk Assessment methodology and the top three emerging financial crime threats you would prioritise for the next 12 months.
Signal: AML technical depth, awareness of the Economic Crime and Corporate Transparency Act 2023 (failure-to-prevent fraud offence in force 2025), forward-thinking horizon scanning, ability to rank by firm-specific business model not generic threat list.
Good answer framework: Names a documented EWRA methodology (e.g., 5x5 inherent risk matrix with control rating), ranks emerging threats with firm-specific rationale (synthetic identity fraud, cryptoasset exposure, sanctions exposure post-Ukraine and Russia, AI-generated falsified documents per HireRight April 2026 survey), ties prioritisation to the firm's customer book and product set.
Red flags: Generic answers about "watching the FATF list", no firm-specific context, no awareness of ECCTA or the 2025-2026 failure-to-prevent fraud offence, no methodology referenced.
The three recruitment obstacles that derail London Head of Compliance hires
Three obstacles cause the majority of failed Head of Compliance searches in London: SMF16-eligible candidate scarcity at boutique and mid-market firms, counter-offer aggression at offer-accept stage, and FCA approval timeline risk with no bridging strategy in place.
Obstacle 1: SMF16-eligible candidate scarcity
The pool of SMF16-eligible candidates willing to move is materially below open vacancies in 2026. FD Capital reports 35% of compliance and risk hires in the past 12 months came from unsolicited approaches the candidate found compelling, not active job search. Time-to-hire for SMF16 roles at smaller firms now sits at 8-14 weeks before factoring in the FCA approval window. The choice between recruitment agencies and direct applications becomes acute at SMF16 level because direct adverts do not reach the candidates the firm actually needs.
Morgan Spencer manages this by maintaining a confidential pre-mapped SMF16 talent pool by firm-type vertical: asset manager, payments, consumer credit, insurance, fintech. FCA Register history, Regulatory References and basic Fit & Proper screening are completed before any candidate is introduced. The outcome: time-to-shortlist drops from 6-8 weeks (market average) to 2-3 weeks, with candidates engaged at quality stage rather than active-search stage.
Obstacle 2: Counter-offer aggression at offer-accept stage
Counter-offers at resignation are now standard practice at SMF16 level. FD Capital placement data shows more than 35% of senior compliance hires were driven by an unsolicited offer the candidate found compelling, which signals incumbent firms are now aggressive in retention. Firms losing an SMF16 holder face a 6-12 month FCA approval window for the replacement, which sharpens that counter-offer aggression further.
Morgan Spencer builds counter-offer pre-emption into the interview process from first meeting. The candidate's actual motivators (financial, scope, regulatory comfort with the new firm, board-relationship dynamics) are tested at every stage, with the resignation conversation scripted in advance to anticipate the incumbent firm's response. Counter-offer accept rate runs materially below industry norm, and where a counter-offer happens, the client has already pre-considered the terms.
Obstacle 3: FCA approval timeline and SMF gap-cover risk
SMF16 appointments require FCA approval before the candidate can take up the function. Standard approval runs 4-12 weeks; contested or complex cases can extend to 6+ months. A firm appointing without a bridging strategy sits in regulatory limbo, with the outgoing SMF16 retaining personal accountability until handover is FCA-approved.
Morgan Spencer briefs both client and candidate on the FCA approval timeline at offer stage. Interim and contract SMF16 candidates are held in a pre-vetted bridging pool; the candidate's FCA Register history and Regulatory References are reviewed before introduction to surface approval risk early. Bridging risk gets managed before the offer is signed, not after.
Alternative job titles a Head of Compliance might use
The same role appears under different titles across UK financial services, and the candidate pool you reach depends on which titles your search covers. The nine titles that materially overlap with Head of Compliance in 2026 are:
- Chief Compliance Officer (CCO) - financial services C-suite, interchangeable with Head of Compliance at smaller FCA-regulated firms
- Director of Compliance - banking, mid-large firms
- Compliance Director - asset management, wealth management
- Head of Regulatory Compliance - insurance, retail banking
- Head of Compliance and MLRO - smaller FCA-regulated firms with combined SMF16 + SMF17
- Head of Conduct, Regulatory and Financial Crime - banking, complex compliance functions
- VP Compliance / Senior Vice President Compliance - US-headquartered banks and investment banks operating in London
- Group Head of Compliance - multi-entity, holding company structures
- Head of Compliance Oversight - SMF16 designation used as job title at smaller firms
A search that filters on "Head of Compliance" alone misses around half the relevant CV population. Morgan Spencer runs every Head of Compliance search across all nine title variants to surface the full candidate pool.
How Morgan Spencer recruits a Head of Compliance
Our seven-step process structures every Head of Compliance search around the SMCR tier, the FCA-regulated activity perimeter, and the firm's specific governance environment. The process compresses time-to-shortlist while protecting the firm against FCA approval risk and counter-offer breakage.
Step 1: We define the SMCR tier and SMF mapping before drafting the spec
We identify your firm's SMCR tier (Core, Enhanced, Limited Scope), confirm whether the role is SMF16-designated, and clarify whether SMF17 (MLRO) sits with the same postholder or a separate appointment. Without this clarity, the spec describes the wrong job and the wrong candidate pool.
Step 2: We map the firm-specific regulatory perimeter to the right Handbook sourcebooks
We translate the firm's regulated activities into the Handbook sourcebooks the role must cover: COBS, SYSC, MIFIDPRU for investment firms; CONC for consumer credit; PRIN and SUP for everyone; EMRs and PSRs for payments and e-money firms. Generalist compliance candidates filter out at this stage and the shortlist becomes tier-specific.
Step 3: We run a confidential direct-approach search across all nine title variants
We approach pre-mapped candidates directly across the title variants set out above. SMF16-eligible candidates rarely apply through advertised vacancies and almost never engage with public job boards while in role, so confidential direct-approach searches produce a materially stronger shortlist than passive advert-and-respond.
Step 4: We pre-screen FCA Register history, Regulatory References and Fit & Proper indicators
We complete the SMCR Regulatory Reference workflow from previous regulated employers (5-year window), check FCA Register history for any open enforcement, conduct breach or fit and proper findings, and confirm credit history and criminal record clearance where relevant. The pre-screen compresses the formal post-offer reference window from 4-6 weeks down to a final confirmation step.
Step 5: We support a two-stage interview structure with technical and board-fit components
Stage 1: Head of Risk, CRO or General Counsel tests technical regulatory depth using the scenario questions set out earlier in this guide. Stage 2: CEO and one Non-Executive Director (typically Audit Committee Chair) tests board-level communication, second-line independence and Conduct Rules-tested behavioural fit. We provide structured interview frameworks and scoring rubrics on request.
Step 6: We run formal SMCR references and final FCA Register checks in parallel with final interviews
We run the formal SMCR Regulatory References from all regulated employers in the previous five years in parallel with the final-stage interviews, not after offer. Running them post-offer adds 4-6 weeks to the start date and creates the risk of late-stage breakage on a reference finding the firm could have surfaced earlier.
Step 7: We plan FCA approval and bridging cover at offer stage, not after
We build the 4-12 week FCA approval window into the agreed start date. Where the outgoing SMF16's notice expires before the incoming appointment can be FCA-approved, we pre-line up an interim SMF16 candidate from our bridging pool to hold the function under a regulated firm-side appointment until the substantive appointee can take over.
The 2026 London Head of Compliance market
The 2026 compliance market in London is candidate-driven at SMF16 level. Demand outpaces supply across boutique investment firms, payments and e-money businesses, cryptoasset firms, and any FCA-regulated business preparing for a Section 166 review or a Consumer Duty multi-firm review. The London talent pipeline shows where the gaps in 2025 sit most acutely at senior regulatory level, with boutique asset managers and payments firms reporting the longest time-to-hire.
Salary inflation for Head of Compliance roles in London projects at 6-10% in 2026, materially above general professional services salary growth of 2-3%. Three drivers shape the forecast. The FCA Consumer Duty supervisory phase intensifies outcome-evidence requirements, driving hiring at firms preparing for multi-firm reviews. Ongoing AML enforcement and the FATF mutual evaluation follow-up applies pressure on MLRO and combined SMF16 + SMF17 resourcing. The FCA's announced "rebalancing" toward growth has lifted some regulatory volume, but Consumer Duty and financial crime supervision remain active.
Counter-offer activity at offer-accept stage has risen, particularly at boutique asset managers, payments firms and cryptoasset businesses where combined SMF16 + SMF17 designations command a 15-25% premium. Interim demand at £700-£1,200 per day outside IR35 has grown sharply, driven by Section 166 remediation programmes and Consumer Duty implementation support. Expect time-to-hire to extend further through 2026 unless firms address salary benchmarks at the brief stage rather than at offer (FD Capital 2026 Salary Guide, March 2026; Barclay Simpson 2026 Compliance Salary Survey, April 2026).
Frequently asked questions
How long does it take to hire a Head of Compliance in London?
Time-to-shortlist at smaller FCA-regulated firms runs 8-14 weeks through general search, or 2-3 weeks with a pre-mapped specialist recruiter. Add 4-12 weeks for FCA SMF16 approval before the appointee can take up the function. The full timeline from instruction to working start typically sits at 12-26 weeks in 2026 (FD Capital 2026; Barclay Simpson 2026).
What salary should we offer a Head of Compliance in 2026?
London Head of Compliance salaries in 2026 sit at £120,000-£150,000 on average, ranging from £95,000 at smaller boutique investment firms to £250,000+ at investment banks. Combined SMF16 + SMF17 designations add 15-25% premium. Cryptoasset and FCA-authorised payments firms pay at the upper end of the boutique band (Morgan McKinley 2026; FD Capital 2026).
Can a Head of Compliance work remotely under SMCR?
Full remote SMF16 appointments are rare. The FCA expects SMF16 holders to be based at the firm's principal place of business in the UK, and most FCA-regulated firms expect on-site presence for 3-4 days a week minimum. Hybrid arrangements are common for days that do not require Board, committee or regulator interaction (Compliance Consultant London SMF16/17 FAQs, January 2025).
What is the difference between Head of Compliance and Chief Compliance Officer?
At smaller FCA-regulated firms the two titles are interchangeable: both typically hold SMF16 and the most senior compliance accountability. At larger or multi-entity firms the Chief Compliance Officer is the group-level or executive-tier postholder, with one or more Heads of Compliance running individual business lines or regulated entities reporting in (Exec Capital, May 2026; FD Capital, April 2026).
Should we use an interim SMF16 to bridge an FCA approval gap?
Yes, where the outgoing SMF16's notice expires before the incoming substantive appointee can be FCA-approved. Interim SMF16 candidates at £700-£1,200 per day cover the regulatory gap under a separate FCA-approved appointment. Morgan Spencer maintains a pre-vetted bridging pool to manage this risk before the substantive offer is signed (FD Capital 2026 Salary Guide, March 2026).
Speak to Morgan Spencer's compliance recruitment team
Morgan Spencer's legal and compliance recruitment team places Head of Compliance, MLRO, AMLRO and Compliance Manager professionals at FCA-regulated firms across London, Canary Wharf and the City of London. We deliver a pre-screened SMF16 shortlist within 10-15 working days, operate a counter-offer pre-emption protocol on every placement, and pre-vet FCA Register history before any candidate reaches the client. Speak to our team to scope your next compliance leadership hire.
