{
  "code": "FCA-SYSC",
  "name": "FCA Senior Management Arrangements, Systems and Controls (SYSC)",
  "version": "2023",
  "issuing_body": "Financial Conduct Authority",
  "description": "FCA requirements for senior management arrangements, systems and controls for UK financial firms",
  "regions": ["uk"],
  "industries": ["Financial Services"],
  "effective_date": "2023-07-31",
  "is_global": false,
  "requirements": [
    {
      "reference_code": "SYSC.1",
      "title": "Application and Purpose",
      "requirement_type": "mandatory",
      "category": "General Requirements"
    },
    {
      "reference_code": "SYSC.4",
      "title": "General Organisational Requirements",
      "requirement_type": "mandatory",
      "category": "Governance",
      "children": [
        { "reference_code": "SYSC.4.1", "title": "Systems and controls", "description": "Implement appropriate systems and controls to manage risks to its business, customers and market integrity.", "requirement_type": "mandatory" },
        { "reference_code": "SYSC.4.2", "title": "Compliance oversight", "description": "Establish, implement and maintain compliance policies and procedures.", "requirement_type": "mandatory" },
        { "reference_code": "SYSC.4.3", "title": "Risk management", "description": "Implement risk management policies and procedures, and consider risks from operations and potential obligation.", "requirement_type": "mandatory" },
        { "reference_code": "SYSC.4.4", "title": "Internal audit", "description": "Maintain an internal audit function to establish, implement and maintain an audit plan.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "SYSC.5",
      "title": "Employees, agents and other relevant persons",
      "requirement_type": "mandatory",
      "category": "Human Resources",
      "children": [
        { "reference_code": "SYSC.5.1", "title": "Apportionment and oversight", "description": "Ensure oversight of relevant persons engaged in any activity on behalf of the firm.", "requirement_type": "mandatory" },
        { "reference_code": "SYSC.5.2", "title": "Competence", "description": "Ensure that relevant persons are competent for the functions they perform on behalf of the firm.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "SYSC.6",
      "title": "Compliance, internal audit and financial crime",
      "requirement_type": "mandatory",
      "category": "Compliance",
      "children": [
        { "reference_code": "SYSC.6.1", "title": "Compliance function", "description": "Establish, implement and maintain adequate policies and procedures designed to detect risk of failure to comply with obligations.", "requirement_type": "mandatory" },
        { "reference_code": "SYSC.6.2", "title": "Internal audit function", "description": "Establish and maintain an internal audit function which is separate and independent.", "requirement_type": "mandatory" },
        { "reference_code": "SYSC.6.3", "title": "Financial crime", "description": "Establish and maintain effective systems and controls for countering the risk that the firm might be used to further financial crime.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "SYSC.7",
      "title": "Risk control",
      "requirement_type": "mandatory",
      "category": "Risk Management",
      "children": [
        { "reference_code": "SYSC.7.1", "title": "Risk management systems", "description": "Establish, implement and maintain adequate risk management policies and procedures that identify the risks relating to the firm's activities.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "SYSC.8",
      "title": "Outsourcing",
      "requirement_type": "mandatory",
      "category": "Third-party Management",
      "children": [
        { "reference_code": "SYSC.8.1", "title": "Outsourcing requirements", "description": "Conduct due diligence on third-party service providers and maintain oversight of outsourced functions.", "requirement_type": "mandatory" },
        { "reference_code": "SYSC.8.2", "title": "Contingency plans", "description": "Ensure business continuity exists in case service provision from third parties is disrupted.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "SYSC.13",
      "title": "Operational risk",
      "requirement_type": "mandatory",
      "category": "Operational Risk",
      "children": [
        { "reference_code": "SYSC.13.1", "title": "Identification and assessment", "description": "Take reasonable steps to identify and assess all operational risks.", "requirement_type": "mandatory" },
        { "reference_code": "SYSC.13.2", "title": "Business continuity planning", "description": "Establish and maintain contingency arrangements and business continuity plans.", "requirement_type": "mandatory" }
      ]
    }
  ]
}
