From Compliance to Confidence: Why UK Financial Services Firms Are Still Struggling with Operational Resilience
On March 31, 2025, the transition period for the UK’s operational resilience framework ended.
Financial institutions regulated by the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) were expected to have identified their Important Business Services, established impact tolerances, mapped critical dependencies, and tested their ability to remain within those tolerances during disruption. [fca.org.uk], [sidley.com]
For many firms, this milestone represented years of planning, investment, and internal coordination. Yet an important reality has emerged across the sector: compliance does not automatically equal resilience.
As regulators increasingly focus on evidence rather than documentation, financial services organizations are discovering that some of the most challenging aspects of operational resilience are not creating policies or completing templates. The challenge is demonstrating, under realistic conditions, that the organization can continue delivering critical services when disruptions occur.
This shift presents both a challenge and an opportunity for financial institutions. It also highlights why exercising, validation, and crisis preparedness have become essential components of modern resilience programs.
The Evolution of Operational Resilience
The UK operational resilience framework was designed to address a fundamental question:
Can a financial institution continue to deliver its most important business services during severe disruption? [fca.org.uk], [fca.org.uk]
Unlike traditional business continuity programs that often focused on recovering systems or facilities, operational resilience centers on customer outcomes and market stability. Organizations are expected to understand which services matter most, determine how much disruption they can tolerate, and demonstrate they can operate within those limits under significant operational stress. [fca.org.uk], [sidley.com]
The framework requires firms to:
- Identify Important Business Services (IBS)
- Establish impact tolerances
- Map supporting dependencies
- Conduct scenario testing
- Maintain board-level oversight
- Continuously improve resilience capabilities [fca.org.uk], [sidley.com]
While these requirements appear straightforward, implementation has proven challenging for many organizations.
Challenge #1: Identifying Important Business Services
One of the most common areas of difficulty begins at the foundation of the framework itself.
The FCA has observed significant variation in how firms identify Important Business Services. Some organizations have focused too heavily on internal processes, while others have excluded services because they believed customers could use alternative providers during disruption. Regulators have noted that firms should not exclude Important Business Services based on a single factor and should be able to justify their decisions with clear rationale. [fca.org.uk]
In practice, many organizations struggle to separate critical customer-facing outcomes from the thousands of supporting activities performed daily across the enterprise.
The challenge is not merely identifying services. It is developing a shared understanding among business leaders, technology teams, risk professionals, and executives regarding what truly constitutes an important business service and why.
Challenge #2: Defining Meaningful Impact Tolerances
Once firms identify important business services, they must determine how much disruption they can tolerate before unacceptable harm occurs.
While most institutions have established impact tolerances, the FCA has reported that firms often struggle to explain why a particular tolerance represents the threshold of intolerable harm. Regulators have frequently required additional clarification regarding the rationale used to establish these limits. [fca.org.uk]
This challenge reflects the complexity of balancing customer expectations, regulatory obligations, operational realities, and market considerations.
Questions such as:
- How long can customers be unable to access their accounts?
- How much disruption to payment processing is acceptable?
- At what point does a service outage create market integrity concerns?
are often more difficult to answer than anticipated.
The issue becomes even more complex when organizations attempt to validate those assumptions through testing.
Challenge #3: Understanding Critical Dependencies
Many firms discover that they do not fully understand the web of dependencies supporting their critical services until they begin detailed resilience assessments.
The UK framework requires organizations to map and understand the people, technology, facilities, information, and third-party providers that support important business services. This mapping must be sufficiently detailed to identify vulnerabilities and points of failure. [sidley.com], [thepayment…iation.org]
What frequently surprises organizations is the level of interconnectivity in modern operations.
Single applications may support multiple business services. Cloud providers may underpin dozens of critical processes. Key operational knowledge may reside with only a few individuals. Third-party vendors may represent hidden dependencies that have never been exercised.
Resilience mapping exercises often reveal vulnerabilities that were not visible through traditional risk assessments.
Challenge #4: Third-Party and Cloud Risk
No area has received more regulatory attention in recent years than third-party risk.
Financial institutions increasingly rely on cloud providers, outsourced service partners, managed security vendors, and external technology suppliers. As a result, many resilience programs extend well beyond the organization’s direct control.
The PRA has highlighted growing concerns regarding operational incidents and third-party dependencies, introducing enhanced reporting measures designed to strengthen visibility into these risks. [bankofengland.co.uk]
Organizations frequently struggle with questions such as:
- What happens if a cloud provider experiences a regional outage?
- How resilient are critical outsourcing partners?
- What contingency options exist if a vendor experiences a cyberattack?
- How quickly can operations be restored using alternate providers?
While contracts may address some of these concerns, exercising and validating response strategies often reveal gaps that policies alone cannot identify.
Challenge #5: Testing That Truly Challenges the Organization
One of the most significant gaps across the industry is the difference between reviewing plans and validating capabilities.
Regulators expect organizations to test their resilience against severe but plausible disruption scenarios. This includes cyber incidents, technology failures, third-party disruptions, data loss events, and operational crises. [fca.org.uk], [sidley.com]
However, many organizations continue to rely heavily on document reviews, tabletop discussions, or narrowly focused technical tests.
Effective operational resilience testing should challenge:
- Executive decision-making
- Crisis management structures
- Internal communications
- Customer communications
- Regulatory engagement
- Recovery strategies
- Cross-functional coordination
When organizations move beyond theoretical discussions and simulate realistic disruptions, they often discover that planning assumptions do not always hold up under pressure.
Challenge #6: Executive and Board Readiness
The UK framework places significant emphasis on governance.
Boards and senior executives are expected to oversee operational resilience programs and understand the risks, tolerances, and remediation activities associated with important business services. [fca.org.uk], [fca.org.uk]
Yet many organizations find that resilience discussions remain concentrated within risk, compliance, cybersecurity, or business continuity teams.
During real disruptions, executives must make high-consequence decisions with incomplete information, competing priorities, and intense stakeholder scrutiny. Those skills are difficult to develop without realistic practice.
This is why regulators increasingly look for evidence that leadership teams have been challenged through meaningful exercises rather than briefed on resilience concepts.
Challenge #7: Demonstrating Continuous Improvement
Ultimately, operational resilience is not a one-time compliance project.
Regulators expect firms to identify vulnerabilities, conduct testing, remediate weaknesses, and continuously improve their capabilities over time. [fca.org.uk], [fca.org.uk]
The ability to demonstrate:
- Lessons learned
- Corrective actions
- Program enhancements
- Repeat testing
- Management oversight
has become just as important as the original resilience framework itself.
Organizations that treat operational resilience as a compliance exercise may struggle to produce the evidence regulators increasingly expect.
Organizations that view resilience as a capability, however, are often better positioned to demonstrate both preparedness and continuous improvement.
Moving Beyond Compliance
The financial services industry has entered a new phase of operational resilience maturity.
The question regulators are asking is no longer:
“Do you have a resilience framework?”
Instead, the question is:
“Can you prove it works?” [fca.org.uk], [fca.org.uk]
This shift creates a significant opportunity for organizations to strengthen resilience through realistic validation and exercising.
At PreparedEx, we believe operational resilience is best demonstrated through action. Our resilience validation programs help financial institutions challenge assumptions, test capabilities, evaluate decision-making, and generate evidence that supports continuous improvement.
Whether organizations are seeking to validate Important Business Services, test impact tolerances, evaluate third-party dependencies, exercise executive leadership, or strengthen crisis management capabilities, the goal remains the same:
Transform operational resilience from a compliance requirement into a demonstrated organizational capability.
Because when disruption occurs, resilience is no longer measured by the quality of a plan. It is measured by an organization’s ability to continue delivering the services that matter most.
Sources & Further Reading
The insights in this article are informed by guidance and publications from:
- UK Financial Conduct Authority (FCA) – Building Operational Resilience
- FCA – Operational Resilience: Insights and Observations for Firms (2024)
- Prudential Regulation Authority (PRA) – SS1/21 Operational Resilience
- Bank of England Operational Resilience Framework
- Digital Operational Resilience Act (DORA), European Union

Add your first comment to this post