| Link(s): |
| Operational resilience: insights and observations one year on | FCA Operational resilience | FCA Operational resilience: insights and observations for firms | FCA (May 2024) |
Context
To help firms review and evolve their approach to being resilient, and to make sure they are continuing to comply with the FCA’s operational resilience rules, the FCA has published observations and insights from a review of firms’ self-assessments on how they are continuing to strengthen operational resilience under FCA rules and guidance. The FCA has seen strong engagement and good progress across all areas of the operational resilience requirements.
Key points to note and next actions
The FCA has seen examples of good practice as well as areas where further improvement is needed, and it is engaging directly with firms in scope of its rules on these findings. However, there is information in the observations that all firms could benefit from considering, even those not in scope of these rules.
- High-profile incidents and outages in have reinforced the need for strong resilience and its role in maintaining trust and stability in the sector.
- Boards play an important role in strengthening firms’ operational resilience; the self-assessment gives them the information they need to understand their firm’s approach, who is responsible for it, and the organisation’s ability to recover important business services within impact tolerance.
- The FCA encourages firms to continue to remediate individual firm-specific vulnerabilities and working collaboratively with industry groups. The FCA published examples of effective practice we have observed in these areas with the PRA and Bank of England in 2025.
- Many firms demonstrate maturity in governance, but all firms should continue to focus on Board / most senior management engagement, robust frameworks, and evidence-based self-assessment for sector-wide improvement.
- The FCA sets out its good practice and areas for improvement findings under six headings:
- Important business services and impact tolerances
- Mapping resources
- Scenario testing
- Vulnerability management
- Communications plans and strategy
- Governance
