Please verify you’re human to continue.
Director Personal Liability 2026: The Complete NED Guide
SMCR | Companies Act | ICO | Crime and Policing Act 2026 | NEDs | Senior Managers
Every UK NED and Senior Manager is personally exposed to multiple concurrent liability regimes in 2026. This pack consolidates them all in one place — so directors understand exactly where they stand.
What This Pack Contains
- Complete guide to every personal liability regime applicable to UK NEDs and Senior Managers in 2026
- SMCR duty of responsibility — what it means in practice for NEDs
- Companies Act director duties under ss.171-177 CA 2006
- ICO individual enforcement — how the ICO can pursue directors personally for data breaches
- DORA board accountability requirements for firms in scope
- Crime and Policing Act 2026 — the new criminal liability framework for senior managers
- Board-level risk assessment tool
- 10 board questions every NED should ask
The Liability Landscape in 2026
UK Non-Executive Directors and Senior Managers face personal regulatory liability under at least five distinct legal frameworks in 2026. These regimes operate independently — a single incident can trigger exposure under multiple frameworks simultaneously.
| Regime | Regulator / Enforcer | Key Risk for NEDs |
|---|---|---|
| SMCR Duty of Responsibility | FCA / PRA | Personal enforcement action where NED failed to take reasonable steps to prevent regulatory breach in their area |
| Companies Act Director Duties (ss.171-177) | Courts / BEIS | Personal liability for breach of fiduciary duties, including conflicts of interest and duty of care |
| ICO Individual Enforcement | ICO | Fines and enforcement notices against directors personally for organisational data protection failures |
| DORA Board Accountability | FCA / PRA (for UK firms) | Board members accountable for ICT risk management failures under Digital Operational Resilience Act |
| Crime and Policing Act 2026 | SFO / FCA / CPS | New criminal liability for senior managers who fail to prevent certain financial crimes |
SMCR: The Duty of Responsibility
The Senior Managers and Certification Regime imposes a duty of responsibility on every Senior Manager Function (SMF) holder. This means that where a regulatory breach occurs in an area for which an SMF holder is responsible, the FCA or PRA can take enforcement action against them personally — unless they can demonstrate they took reasonable steps to prevent the breach.
What Reasonable Steps Looks Like
- Active engagement with management information on issues in your area of responsibility
- Documented challenge to management proposals that carry regulatory risk
- Escalation of concerns when assurances are not sufficient
- Ensuring adequate resources for compliance and risk management
- Reviewing and approving the Statement of Responsibilities and Responsibilities Map
Crime and Policing Act 2026
The Crime and Policing Act 2026 introduces a new ‘failure to prevent’ offence that creates criminal liability for senior managers at organisations that facilitate certain financial crimes.
- The offence applies where a firm fails to prevent an associate from facilitating fraud, money laundering, or tax evasion
- Senior managers can be personally criminally liable where they had awareness of the risk and failed to act
- The defence is to demonstrate that adequate prevention procedures were in place
- Maximum penalties include unlimited fines and, for individuals, imprisonment
10 Board Questions Every NED Should Ask
- Have I reviewed and approved my Statement of Responsibilities, and does it accurately reflect my actual responsibilities?
- Am I receiving adequate management information to discharge my duty of responsibility for my SMF role?
- Have I documented my challenge and escalation actions in board and committee minutes?
- Does the firm’s D&O insurance cover personal regulatory enforcement action under SMCR?
- Have I received a briefing on the Crime and Policing Act 2026 ‘failure to prevent’ offence?
- What is the firm’s process for ensuring adequate prevention procedures against financial crime facilitation?
- Has the board received an ICO briefing on individual director enforcement risk?
- Are there any current or anticipated regulatory investigations where my personal liability may be engaged?
- Do I understand which of my fellow board members hold SMF roles and what their responsibilities are?
- When did I last review the firm’s Responsibilities Map to ensure it accurately reflects accountability allocations?
This pack is included in the INFORMD Executive Team plan (£299/month) and available as a standalone download. Contact us for enterprise or multi-firm access.
