Director Personal Liability 2026: Complete NED Guide | INFORMD

Informd

Please verify you’re human to continue.

Director Personal Liability 2026: The Complete NED Guide
SMCR | Companies Act | ICO | Crime and Policing Act 2026 | NEDs | Senior Managers

← Back to all Board Packs

Every UK NED and Senior Manager is personally exposed to multiple concurrent liability regimes in 2026. This pack consolidates them all in one place — so directors understand exactly where they stand.

What This Pack Contains

  • Complete guide to every personal liability regime applicable to UK NEDs and Senior Managers in 2026
  • SMCR duty of responsibility — what it means in practice for NEDs
  • Companies Act director duties under ss.171-177 CA 2006
  • ICO individual enforcement — how the ICO can pursue directors personally for data breaches
  • DORA board accountability requirements for firms in scope
  • Crime and Policing Act 2026 — the new criminal liability framework for senior managers
  • Board-level risk assessment tool
  • 10 board questions every NED should ask

The Liability Landscape in 2026

UK Non-Executive Directors and Senior Managers face personal regulatory liability under at least five distinct legal frameworks in 2026. These regimes operate independently — a single incident can trigger exposure under multiple frameworks simultaneously.

RegimeRegulator / EnforcerKey Risk for NEDs
SMCR Duty of ResponsibilityFCA / PRAPersonal enforcement action where NED failed to take reasonable steps to prevent regulatory breach in their area
Companies Act Director Duties (ss.171-177)Courts / BEISPersonal liability for breach of fiduciary duties, including conflicts of interest and duty of care
ICO Individual EnforcementICOFines and enforcement notices against directors personally for organisational data protection failures
DORA Board AccountabilityFCA / PRA (for UK firms)Board members accountable for ICT risk management failures under Digital Operational Resilience Act
Crime and Policing Act 2026SFO / FCA / CPSNew criminal liability for senior managers who fail to prevent certain financial crimes

SMCR: The Duty of Responsibility

The Senior Managers and Certification Regime imposes a duty of responsibility on every Senior Manager Function (SMF) holder. This means that where a regulatory breach occurs in an area for which an SMF holder is responsible, the FCA or PRA can take enforcement action against them personally — unless they can demonstrate they took reasonable steps to prevent the breach.

What Reasonable Steps Looks Like

  • Active engagement with management information on issues in your area of responsibility
  • Documented challenge to management proposals that carry regulatory risk
  • Escalation of concerns when assurances are not sufficient
  • Ensuring adequate resources for compliance and risk management
  • Reviewing and approving the Statement of Responsibilities and Responsibilities Map

Crime and Policing Act 2026

The Crime and Policing Act 2026 introduces a new ‘failure to prevent’ offence that creates criminal liability for senior managers at organisations that facilitate certain financial crimes.

  • The offence applies where a firm fails to prevent an associate from facilitating fraud, money laundering, or tax evasion
  • Senior managers can be personally criminally liable where they had awareness of the risk and failed to act
  • The defence is to demonstrate that adequate prevention procedures were in place
  • Maximum penalties include unlimited fines and, for individuals, imprisonment

10 Board Questions Every NED Should Ask

  • Have I reviewed and approved my Statement of Responsibilities, and does it accurately reflect my actual responsibilities?
  • Am I receiving adequate management information to discharge my duty of responsibility for my SMF role?
  • Have I documented my challenge and escalation actions in board and committee minutes?
  • Does the firm’s D&O insurance cover personal regulatory enforcement action under SMCR?
  • Have I received a briefing on the Crime and Policing Act 2026 ‘failure to prevent’ offence?
  • What is the firm’s process for ensuring adequate prevention procedures against financial crime facilitation?
  • Has the board received an ICO briefing on individual director enforcement risk?
  • Are there any current or anticipated regulatory investigations where my personal liability may be engaged?
  • Do I understand which of my fellow board members hold SMF roles and what their responsibilities are?
  • When did I last review the firm’s Responsibilities Map to ensure it accurately reflects accountability allocations?

This pack is included in the INFORMD Executive Team plan (£299/month) and available as a standalone download. Contact us for enterprise or multi-firm access.

← Back to all Board Packs