Contadores e assessores de IA habilitados, integrados ao ESG e globalmente conectados. Auditoria, impostos, consultoria, finanças corporativas e 16 pilares de serviços especializados.Contadores e assessores de IA habilitados, integrados ao ESG e globalmente conectados. Auditoria, impostos, consultoria, finanças corporativas e 16 pilares de serviços especializados.Contadores e assessores de IA habilitados, integrados ao ESG e globalmente conectados. Auditoria, impostos, consultoria, finanças corporativas e 16 pilares de serviços especializados.Contadores e assessores de IA habilitados, integrados ao ESG e globalmente conectados. Auditoria, impostos, consultoria, finanças corporativas e 16 pilares de serviços especializados.
All insights

Operational Resilience Framework UK: A Practical Guide

Build an FCA-aligned operational resilience framework in the UK, from important business services and impact tolerances to mapping and testing.

17 September 2026

Operational Resilience Framework UK: A Practical Guide

Building an operational resilience framework in the UK is not a matter of producing another policy document. For firms within the FCA or PRA perimeter, the programme must show how important business services will continue through severe but plausible disruption, how quickly harm can be contained, and how the firm will learn from testing and incidents. The strongest programmes connect regulatory obligations to accountable owners, evidence, investment decisions and board oversight.

Read Aureliant Global's regulatory compliance advisory guide for UK financial services

What is operational resilience and why does the FCA require it?

The FCA defines operational resilience as the ability of firms, financial market infrastructures and the financial sector to prevent, adapt to, respond to, recover from and learn from operational disruption. The focus is therefore on maintaining services that matter to customers and markets, rather than protecting every internal process equally.

The FCA's operational resilience rules came into force on 31 March 2022. Firms in scope were expected to identify important business services, set impact tolerances, map dependencies, test their ability to remain within those tolerances and remediate vulnerabilities. The transitional deadline of 31 March 2025 has passed, but the obligation is not finished. Resilience must be kept under review as products, systems, suppliers, customers and risks change.

The regulatory rationale is practical. An outage affecting a non-critical internal tool may be inconvenient. A disruption that prevents customers from accessing accounts, making payments, receiving insurance services or completing a market transaction can cause intolerable harm, damage market integrity or undermine confidence in the financial system. A framework should help management make that distinction and demonstrate that it has acted on it.

Scope depends on the firm's permissions and regulatory status. FCA rules cover a range of firms, including banks, building societies, insurers, recognised investment exchanges, payment and e-money firms, certain cryptoasset firms and other regulated entities. PRA expectations also apply to relevant banks, building societies, PRA-designated investment firms and insurers. A firm should confirm its precise obligations rather than assume that a generic operational risk policy is sufficient.

Operational resilience framework UK: the core building blocks

A compliant programme is best treated as a connected management system. The following elements should work together, with clear ownership and an evidence trail.

  • Important business services: identify the services where disruption could cause intolerable harm to consumers, firms or markets.
  • Impact tolerances: set the maximum tolerable level of disruption for each important business service.
  • Mapping: document the people, processes, technology, facilities and information needed to deliver each service.
  • Scenario testing: test severe but plausible disruption and assess whether the firm remains within tolerance.
  • Vulnerability remediation: prioritise weaknesses, fund improvements and track actions to closure.
  • Governance and self-assessment: ensure senior management and the board can challenge the programme and evidence decisions.
  • Incident response and lessons learned: connect operational resilience to communications, recovery and continuous improvement.

These elements should not sit in separate files owned by separate teams. For example, a map that identifies a single cloud provider as a concentration risk should inform testing, the impact tolerance, the investment case and the board's risk discussion.

Important business services: how to identify and map them

Important business services are external-facing services whose disruption could cause intolerable harm. They are not simply departments, applications or legal entities. A firm should describe the service from the customer's or market's perspective, then assess the potential harm if it becomes unavailable, materially degraded or unreliable.

Start with service outcomes, not systems

Useful descriptions are outcome-led. Examples might include receiving retail payments, executing a customer trade, administering an insurance claim or providing access to a regulated investment service. The exact list must reflect the firm's business model and regulatory perimeter. Avoid grouping distinct services together merely because they share a platform or operating team.

For each candidate service, assess factors such as customer harm, market impact, the number and vulnerability of affected users, time sensitivity, legal or regulatory consequences, and dependencies on other services. Document the rationale for inclusion or exclusion. This helps the board challenge whether the inventory reflects the firm's actual risk profile.

Map the end-to-end delivery chain

FCA SYSC 15A.4 requires firms to identify and document the people, processes, technology, facilities and information necessary to deliver each important business service. The map should be detailed enough to identify vulnerabilities, not so broad that every process appears equally critical.

A practical map can connect:

  • Customer journeys and service activities.
  • Front-line and back-office processes.
  • Key roles, skills, locations and decision rights.
  • Applications, infrastructure, data stores and network connections.
  • Facilities, work locations and recovery arrangements.
  • Internal and external suppliers, including outsourced and cloud services.
  • Information assets, manual workarounds and communication channels.

Mapping should be refreshed after material change and at least within the firm's review cycle. A map that was accurate at implementation can become misleading after a platform migration, acquisition, outsourcing decision, new product launch or major change in customer volumes.

Impact tolerances: setting and testing your limits

An impact tolerance is the maximum tolerable level of disruption to an important business service, including the maximum tolerable duration where a time-based measure is relevant. It is not the same as a recovery time objective, service-level agreement or internal target, although those measures may support the analysis.

Set the tolerance by considering the harm that customers, markets and the firm could experience as disruption continues. Depending on the service, relevant measures may include:

  • Maximum duration of unavailability or material degradation.
  • Number or proportion of customers affected.
  • Transaction volume or value that cannot be processed.
  • Data integrity, confidentiality or accuracy thresholds.
  • Time-sensitive regulatory or market obligations.
  • Consequences for vulnerable customers or critical counterparties.

Record the reasoning, assumptions and metric for every tolerance. A statement such as "restore service quickly" is not testable. A defined tolerance gives the firm a basis for scenario design, escalation and investment decisions. It also allows the board to ask whether the tolerance is realistic given the current architecture and supplier arrangements.

The PRA's guidance for relevant firms emphasises that impact tolerances should support the firm's safety and soundness, policyholder protection and, where applicable, financial stability. Dual-regulated firms should consider both FCA and PRA objectives when setting tolerances. The two perspectives may lead to the same measure, but the rationale should be clear.

Discuss an FCA-aligned resilience and regulatory compliance programme with Aureliant Global

Mapping people, processes and technology dependencies

The purpose of mapping is to expose vulnerabilities that ordinary process documentation can hide. A service may appear resilient until a firm asks which role approves a manual workaround, which supplier provides a critical data feed, or whether the recovery environment can handle the required transaction volume.

Use dependency mapping to examine concentration and single points of failure, including:

  • Reliance on one supplier, cloud region, data centre or network route.
  • Key-person dependencies and access to specialist skills.
  • Shared platforms supporting several important business services.
  • Identity, authentication and privileged-access dependencies.
  • Data lineage, backups, recovery points and data restoration quality.
  • Manual workarounds that have not been rehearsed at realistic scale.
  • Third-party incident notification, service credits and exit arrangements.

Third-party reliance does not transfer accountability. The firm needs enough understanding of the people, processes, technology, facilities and information supporting a service delivered by a supplier to meet its own obligations. Supplier assurance is useful, but it should not replace the firm's own view of service impact, tolerance and recovery capability.

Scenario testing: proving the framework works

Scenario testing should provide evidence, not a reassuring exercise that confirms the plan. The FCA expects firms to carry out scenario testing for each important business service against severe but plausible disruption. Scenarios should be credible enough to reveal weaknesses and demanding enough to test whether the impact tolerance is achievable.

Useful scenarios may include a cyber incident, a prolonged cloud or data-centre outage, loss of a critical supplier, a major technology release failure, loss of a key location, a severe staffing constraint or a compound event involving several services. The right scenario depends on the firm's threat profile and dependencies.

Each test should define:

  1. The service, tolerance and assumptions being tested.
  2. The disruption scenario, scope and points of escalation.
  3. Participants, decision rights and evidence to be collected.
  4. How performance will be measured against the tolerance.
  5. Known limitations, observed vulnerabilities and corrective actions.
  6. The owner, priority and deadline for each remediation.

Testing should increase in sophistication over time. Begin with structured walkthroughs where necessary, then progress to simulations, technical recovery tests and controlled exercises that include key third parties. A failed test is not evidence that the programme is useless. It is evidence that the firm has found a vulnerability, provided the issue is assessed, prioritised, funded and tracked to closure.

Self-assessment and board reporting under FCA rules

Senior management and the board need a clear view of whether the firm can remain within impact tolerances and what prevents it from doing so. Reporting should be decision-ready rather than a catalogue of policies and completed workshops.

A useful board pack can show:

  • The current list of important business services and accountable executives.
  • Impact tolerances, testing status and the latest test result for each service.
  • Material vulnerabilities, concentration risks and overdue remediation.
  • Changes in products, systems, suppliers or operating locations.
  • Incident trends, lessons learned and recurring control weaknesses.
  • Investment decisions required to improve resilience.
  • Management's assessment of residual risk and any accepted limitations.

The self-assessment should explain the firm's methodology, evidence and conclusions. It should distinguish between a control that exists on paper, a control that has been implemented and a capability that has been demonstrated under a realistic test. This distinction gives the board and regulators a more credible view of readiness.

How to build an operational resilience programme from scratch

Firms starting from a blank page can use a staged approach. The sequence below is not a substitute for the firm's regulatory analysis, but it creates a practical route from scope to evidence.

Stage

Primary output

Key question

1. Establish scope

Regulatory perimeter, governance and programme plan

Which rules, services and entities are in scope?

2. Identify services

Approved important business service inventory

Which disruptions could cause intolerable harm?

3. Set tolerances

Documented metrics and rationale

How much disruption can each service tolerate?

4. Map dependencies

End-to-end maps and vulnerability register

What must work for the service to continue?

5. Test and learn

Scenario evidence and remediation plan

Can the firm stay within tolerance during severe disruption?

6. Embed governance

Board reporting and recurring review cycle

How will management detect and fund improvement?

Keep an evidence register from the beginning. Link each conclusion to the service assessment, tolerance rationale, map, test result, incident record or remediation decision that supports it. This avoids a late scramble to reconstruct why a decision was made.

How an external advisor supports a resilience programme

External support can add value when it improves the quality of decisions and evidence, rather than producing a generic policy pack. An advisor may help a firm define its regulatory perimeter, facilitate service identification workshops, challenge tolerances, assess mapping quality, design scenario tests, review third-party dependencies and prepare board-level reporting.

The right model remains proportionate to the firm's size, complexity and risk profile. A smaller regulated firm may need a focused framework with clear ownership and disciplined evidence. A larger group may need service taxonomy, entity alignment, critical supplier analysis and a multi-year remediation portfolio. In both cases, the output should be usable by the people who operate the service and credible to senior management.

Aureliant Global combines partner-led advisory with regulatory, risk and controls expertise. Its approach is designed to connect compliance, operational risk, internal audit and implementation planning, so resilience improvements can be prioritised rather than left as disconnected observations.

Frequently asked questions

What is an operational resilience framework in the UK?

It is the governance, assessment, mapping, testing and remediation structure a firm uses to keep important business services within defined impact tolerances during severe but plausible disruption. For regulated firms, it should align with the applicable FCA and, where relevant, PRA rules and expectations.

What are the three core elements of FCA operational resilience?

The programme is commonly organised around identifying important business services, setting impact tolerances and mapping and testing the resources and dependencies needed to deliver those services. Governance, communications, remediation and lessons learned make those elements effective in practice.

What is the FCA deadline for operational resilience?

The FCA's operational resilience rules came into force on 31 March 2022, and firms in scope were expected to be able to remain within their impact tolerances by 31 March 2025. The work continues after that date through testing, review, remediation and reassessment when the business or its dependencies materially change.

Does DORA replace the UK's operational resilience requirements?

No. DORA is an EU regulation with its own scope and requirements. A UK firm may need to consider DORA because of its EU entities, customers or group structure, but DORA does not remove applicable FCA or PRA obligations. The firm should assess the interaction between the regimes rather than assume that one framework covers both.

How often should operational resilience mapping be updated?

Mapping should be updated when there is a material change to the business, an important business service or its impact tolerance, and within the firm's defined review cycle. FCA SYSC 15A also requires firms to keep compliance under review, with relevant assessments reviewed no later than one year after the previous assessment.

Book a confidential consultation with Aureliant Global about your operational resilience framework

This article is general information, not legal or regulatory advice. A firm's obligations depend on its permissions, business model, entities and regulatory perimeter. Obtain advice tailored to your circumstances before relying on it.

Sources