Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Business Continuity

FCA Operational Resilience: Six Evidence Checks From Its One-Year Observations

The FCA's March 2026 publication gives good-practice examples and improvement areas—not an enforcement verdict. Use these six evidence checks.

By Rebecca Leung · August 16, 2026 ·
Table of Contents

On March 27, 2026, the FCA published Operational resilience: insights and observations one year on. The status matters: this was not an enforcement verdict and it did not declare four universal deficiencies.

The FCA reviewed firms’ annual self-assessments and published examples of good practice and areas for improvement. It organized the feedback around six topics. Those observations sit alongside the operative rules and guidance in SYSC 15A, rather than replacing them.

TL;DR

  • The March 2026 FCA page is supervisory feedback, not a final finding against every firm.
  • It covers six topics: services and tolerances, mapping, scenario testing, vulnerability management, communications, and governance.
  • The transition period ended March 31, 2025, but operational resilience remains a continuing management and evidence obligation.
  • The FCA highlights both good practice and improvement areas; do not turn an example into a new universal rule.
  • A useful response is to test six evidence artifacts against the exact FCA observations and record any gap as an owned remediation item.

The status of the publication

The FCA says that, by March 31, 2025, in-scope firms were required to have completed mapping and testing so they could remain within impact tolerances for each important business service. In its 2026 review, the regulator reported strong engagement and good progress while also identifying areas where some firms could improve.

That wording should govern how compliance teams use the page:

  • Rules and guidance remain binding according to their terms in the FCA Handbook.
  • Good-practice examples show approaches the FCA observed and regarded positively.
  • Areas for improvement are supervisory signals that firms should compare with their own facts.
  • The page is not proof that a named firm violated a rule, and it does not convert every positive example into a prescribed control design.

The safest use is an evidence review: map each observation to the firm’s current artifact, test whether the artifact supports the board’s conclusion, and log any deficiency with an owner and target date.

1. Important business services and impact tolerances

The FCA says firms must identify important business services, set impact tolerances, and review both regularly. People who define, deliver, and review those services should share a clear understanding of the service and the point at which disruption could create intolerable consumer harm or threaten market integrity.

The observed good practices include:

  • a clear methodology and rationale;
  • documented assumptions and harm thresholds;
  • quantitative non-time metrics, such as transaction or financial thresholds, alongside time;
  • annual and material-change reviews; and
  • recalibration using scenario tests and actual incidents.

The improvement area is specific: some firms had not established distinct tolerances for consumer harm and market integrity.

Evidence check: For one important business service, trace the approved definition, customer and market-harm analysis, time and non-time metrics, assumptions, review date, and latest test result. Confirm that the tolerance is not merely a copy of an internal system recovery target.

2. Resource and dependency mapping

The FCA says mapping should identify the people, processes, technology, facilities, information, and relevant third-party relationships needed to deliver each important business service.

Good-practice examples include documented methodology, multiple data sources, clear ownership of mapping data, use of mapping outputs in vulnerability analysis and testing, and detail about planned improvements.

The improvement signal is narrower than the original draft claimed. The FCA observed that some mapping was focused mainly on technology and said firms should also include facilities, people, processes, information, and third-party resilience or testing outcomes. It also said more work was needed on identifying, assessing, and remediating third-party vulnerabilities.

Evidence check: Select one service and reconcile its dependency map against the application inventory, process map, staffing and location data, facilities record, information assets, contracts, and provider testing evidence. Record the source and owner for every mapped dependency.

For infrastructure and subcontractor depth, pair this with the fourth-party concentration and subcontractor risk map. Treat that as a risk-analysis aid, not as a claim that the FCA always requires unlimited mapping through every supplier tier.

3. Scenario testing

The FCA says firms must maintain testing plans showing they can remain within impact tolerances through severe but plausible disruptions. Scenarios should vary in nature, severity, and duration and align with the firm’s risks and vulnerabilities.

Observed good practices include:

  • broader cyber and alternative scenarios;
  • consideration of third-party failures and operational outages;
  • scenarios that would breach tolerance without recovery action;
  • documented mitigation and longer-term remediation;
  • clear methodology, assumptions, workarounds, recovery times, and affected services;
  • testing outcomes linked to remediation and governance reporting; and
  • confidence ratings that help explain the maturity of recovery options.

The improvement area is also precise: some self-assessments said there was no scenario from which the firm could not recover but did not provide evidence from sufficiently severe tests.

Evidence check: Take the strongest resilience claim in the self-assessment and identify the scenario that tested it. Preserve the scenario assumptions, participants, time-stamped decisions, recovery evidence, tolerance result, confidence rating, exceptions, and remediation links.

When internal teams conflate impact tolerance with a technology recovery target, use the impact-tolerance versus RTO comparison to separate the consumer-harm or market-integrity threshold from the recovery plan’s objective.

4. Vulnerability management

Mapping and testing should identify vulnerabilities that could prevent a firm from remaining within tolerance. The self-assessment should contain enough detail for the board to understand and prioritize remediation.

The FCA’s good-practice examples include a defined process, acknowledged gaps, links from mapping and testing to vulnerabilities, tracked remediation, clear ownership, and ongoing monitoring.

Areas for improvement include missing detail on the end-to-end framework, unclear second- and third-line involvement, and claims of few or no vulnerabilities without enough mapping, testing, or management evidence to support that result.

Evidence check: Reconcile vulnerabilities from scenario tests, live incidents, dependency maps, audit, risk assessments, and provider reviews into one inventory. For each item, retain the affected service, root cause, risk, interim control, owner, due date, validation method, and governing-body visibility.

5. Communications plans and strategy

The FCA says firms must maintain internal and external communication strategies that can deliver clear, timely, relevant messages during disruption. Plans should cover roles, responsibilities, thresholds, escalation, activation, and the loss of normal communication channels.

Good-practice examples include embedding communications in frameworks and playbooks, testing internal and external audiences, defining escalation protocols, and feeding lessons from live incidents back into resilience planning.

The improvement areas are limited testing and insufficiently detailed alternatives when usual channels are unavailable.

Evidence check: Run a scenario in which the primary email, collaboration, or customer-notification channel is unavailable. Verify the alternate channel, audience list, approval path, regulatory escalation, accessibility, message ownership, and evidence retention.

6. Governance

The governing body must review and approve the self-assessment. The FCA says the document should be transparent enough for the board to understand and challenge how the firm defines services, sets tolerances, maps dependencies, manages vulnerabilities, and oversees testing.

The FCA also says firms do not normally need to place every item of supporting evidence inside the self-assessment, provided the information is clear enough for informed board decisions.

Observed good practices include defined reporting channels, senior-management accountability, second- and third-line involvement, effective challenge, lessons learned, and dashboards. Improvement areas include unclear board engagement or approval trails, uncertain remediation ownership, missing owners or target dates, and little evidence of independent-line input.

Evidence check: Reconstruct the latest approval from draft through challenge and sign-off. Retain the paper, referenced evidence index, questions, changes made, decision, action owners, deadlines, and follow-up reporting.

A six-artifact review pack

The observations can be converted into a compact review pack:

  1. Service and tolerance record — definition, harm analysis, metrics, assumptions, and review trigger.
  2. Dependency map — all resource classes, data sources, ownership, and provider evidence.
  3. Scenario file — severe-but-plausible basis, execution record, outcomes, confidence, and actions.
  4. Vulnerability register — sources, affected services, root cause, owner, validation, and closure.
  5. Communications test — audience, alternate channel, activation, approvals, and lessons.
  6. Governance trail — self-assessment version, evidence index, challenge, approval, and open actions.

Use the FCA page as a benchmark, then test each artifact against the binding rule or guidance that applies to the firm. That distinction prevents two opposite errors: dismissing useful supervisory feedback as optional commentary, or misreporting every observed practice as a new mandatory formula.

Keep this self-assessment review separate from the PS26/2 incident and third-party reporting implementation. The workstreams overlap operationally, but the March 2026 observations did not themselves create the PS26/2 reporting duties.

The Business Continuity & Disaster Recovery Kit includes mapping, impact, exercise, recovery, and evidence templates that can support this review. FCA rules and firm-specific legal advice control where they differ.


Primary sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Did the FCA issue an operational-resilience enforcement verdict in March 2026?
No. On March 27, 2026, the FCA published observations from firms' annual self-assessments. The page gives examples of good practice and areas for improvement and says the FCA is engaging directly with in-scope firms. It is supervisory guidance and feedback, not a final adjudication that every firm has one of four violations.
What were the six topics in the FCA's observations?
The FCA organized its observations around important business services and impact tolerances, resource mapping, scenario testing, vulnerability management, communications plans and strategy, and governance. Each topic includes existing rule or guidance context plus observed good practice and areas for improvement.
What was required by March 31, 2025?
By the end of the transition period, in-scope firms were required to have completed mapping and testing so they could remain within impact tolerances for each important business service. The continuing rules and guidance are in SYSC 15A of the FCA Handbook; firms must keep reviewing, testing, remediating, and obtaining governing-body approval rather than treating March 2025 as a one-time filing date.
Does an impact tolerance have to equal an RTO?
No such equality appears in the FCA definition. An impact tolerance is the maximum tolerable disruption to an important business service before further disruption could cause intolerable client harm or threaten UK market resilience. An RTO is an internal recovery target. A firm should document the harm and market-integrity basis for its tolerance and then test whether its recovery capability stays within it.
What evidence should the board receive?
The self-assessment should give the governing body enough clear information to understand and challenge the firm's approach: important-service and tolerance methodology, mapping coverage, scenario assumptions and outcomes, vulnerabilities and remediation, communications testing, accountable owners, second- and third-line input, and the approval or review trail. The FCA says every underlying exhibit need not sit in the self-assessment itself if the document remains clear enough for informed decisions.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Business Continuity & Disaster Recovery (BCP/DR) Kit

BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.