Feature Business Continuity
FCA Operational Resilience: Six Evidence Checks From Its One-Year Observations
The FCA's March 2026 publication gives good-practice examples and improvement areas—not an enforcement verdict. Use these six evidence checks.
Table of Contents
On March 27, 2026, the FCA published Operational resilience: insights and observations one year on. The status matters: this was not an enforcement verdict and it did not declare four universal deficiencies.
The FCA reviewed firms’ annual self-assessments and published examples of good practice and areas for improvement. It organized the feedback around six topics. Those observations sit alongside the operative rules and guidance in SYSC 15A, rather than replacing them.
TL;DR
- The March 2026 FCA page is supervisory feedback, not a final finding against every firm.
- It covers six topics: services and tolerances, mapping, scenario testing, vulnerability management, communications, and governance.
- The transition period ended March 31, 2025, but operational resilience remains a continuing management and evidence obligation.
- The FCA highlights both good practice and improvement areas; do not turn an example into a new universal rule.
- A useful response is to test six evidence artifacts against the exact FCA observations and record any gap as an owned remediation item.
The status of the publication
The FCA says that, by March 31, 2025, in-scope firms were required to have completed mapping and testing so they could remain within impact tolerances for each important business service. In its 2026 review, the regulator reported strong engagement and good progress while also identifying areas where some firms could improve.
That wording should govern how compliance teams use the page:
- Rules and guidance remain binding according to their terms in the FCA Handbook.
- Good-practice examples show approaches the FCA observed and regarded positively.
- Areas for improvement are supervisory signals that firms should compare with their own facts.
- The page is not proof that a named firm violated a rule, and it does not convert every positive example into a prescribed control design.
The safest use is an evidence review: map each observation to the firm’s current artifact, test whether the artifact supports the board’s conclusion, and log any deficiency with an owner and target date.
1. Important business services and impact tolerances
The FCA says firms must identify important business services, set impact tolerances, and review both regularly. People who define, deliver, and review those services should share a clear understanding of the service and the point at which disruption could create intolerable consumer harm or threaten market integrity.
The observed good practices include:
- a clear methodology and rationale;
- documented assumptions and harm thresholds;
- quantitative non-time metrics, such as transaction or financial thresholds, alongside time;
- annual and material-change reviews; and
- recalibration using scenario tests and actual incidents.
The improvement area is specific: some firms had not established distinct tolerances for consumer harm and market integrity.
Evidence check: For one important business service, trace the approved definition, customer and market-harm analysis, time and non-time metrics, assumptions, review date, and latest test result. Confirm that the tolerance is not merely a copy of an internal system recovery target.
2. Resource and dependency mapping
The FCA says mapping should identify the people, processes, technology, facilities, information, and relevant third-party relationships needed to deliver each important business service.
Good-practice examples include documented methodology, multiple data sources, clear ownership of mapping data, use of mapping outputs in vulnerability analysis and testing, and detail about planned improvements.
The improvement signal is narrower than the original draft claimed. The FCA observed that some mapping was focused mainly on technology and said firms should also include facilities, people, processes, information, and third-party resilience or testing outcomes. It also said more work was needed on identifying, assessing, and remediating third-party vulnerabilities.
Evidence check: Select one service and reconcile its dependency map against the application inventory, process map, staffing and location data, facilities record, information assets, contracts, and provider testing evidence. Record the source and owner for every mapped dependency.
For infrastructure and subcontractor depth, pair this with the fourth-party concentration and subcontractor risk map. Treat that as a risk-analysis aid, not as a claim that the FCA always requires unlimited mapping through every supplier tier.
3. Scenario testing
The FCA says firms must maintain testing plans showing they can remain within impact tolerances through severe but plausible disruptions. Scenarios should vary in nature, severity, and duration and align with the firm’s risks and vulnerabilities.
Observed good practices include:
- broader cyber and alternative scenarios;
- consideration of third-party failures and operational outages;
- scenarios that would breach tolerance without recovery action;
- documented mitigation and longer-term remediation;
- clear methodology, assumptions, workarounds, recovery times, and affected services;
- testing outcomes linked to remediation and governance reporting; and
- confidence ratings that help explain the maturity of recovery options.
The improvement area is also precise: some self-assessments said there was no scenario from which the firm could not recover but did not provide evidence from sufficiently severe tests.
Evidence check: Take the strongest resilience claim in the self-assessment and identify the scenario that tested it. Preserve the scenario assumptions, participants, time-stamped decisions, recovery evidence, tolerance result, confidence rating, exceptions, and remediation links.
When internal teams conflate impact tolerance with a technology recovery target, use the impact-tolerance versus RTO comparison to separate the consumer-harm or market-integrity threshold from the recovery plan’s objective.
4. Vulnerability management
Mapping and testing should identify vulnerabilities that could prevent a firm from remaining within tolerance. The self-assessment should contain enough detail for the board to understand and prioritize remediation.
The FCA’s good-practice examples include a defined process, acknowledged gaps, links from mapping and testing to vulnerabilities, tracked remediation, clear ownership, and ongoing monitoring.
Areas for improvement include missing detail on the end-to-end framework, unclear second- and third-line involvement, and claims of few or no vulnerabilities without enough mapping, testing, or management evidence to support that result.
Evidence check: Reconcile vulnerabilities from scenario tests, live incidents, dependency maps, audit, risk assessments, and provider reviews into one inventory. For each item, retain the affected service, root cause, risk, interim control, owner, due date, validation method, and governing-body visibility.
5. Communications plans and strategy
The FCA says firms must maintain internal and external communication strategies that can deliver clear, timely, relevant messages during disruption. Plans should cover roles, responsibilities, thresholds, escalation, activation, and the loss of normal communication channels.
Good-practice examples include embedding communications in frameworks and playbooks, testing internal and external audiences, defining escalation protocols, and feeding lessons from live incidents back into resilience planning.
The improvement areas are limited testing and insufficiently detailed alternatives when usual channels are unavailable.
Evidence check: Run a scenario in which the primary email, collaboration, or customer-notification channel is unavailable. Verify the alternate channel, audience list, approval path, regulatory escalation, accessibility, message ownership, and evidence retention.
6. Governance
The governing body must review and approve the self-assessment. The FCA says the document should be transparent enough for the board to understand and challenge how the firm defines services, sets tolerances, maps dependencies, manages vulnerabilities, and oversees testing.
The FCA also says firms do not normally need to place every item of supporting evidence inside the self-assessment, provided the information is clear enough for informed board decisions.
Observed good practices include defined reporting channels, senior-management accountability, second- and third-line involvement, effective challenge, lessons learned, and dashboards. Improvement areas include unclear board engagement or approval trails, uncertain remediation ownership, missing owners or target dates, and little evidence of independent-line input.
Evidence check: Reconstruct the latest approval from draft through challenge and sign-off. Retain the paper, referenced evidence index, questions, changes made, decision, action owners, deadlines, and follow-up reporting.
A six-artifact review pack
The observations can be converted into a compact review pack:
- Service and tolerance record — definition, harm analysis, metrics, assumptions, and review trigger.
- Dependency map — all resource classes, data sources, ownership, and provider evidence.
- Scenario file — severe-but-plausible basis, execution record, outcomes, confidence, and actions.
- Vulnerability register — sources, affected services, root cause, owner, validation, and closure.
- Communications test — audience, alternate channel, activation, approvals, and lessons.
- Governance trail — self-assessment version, evidence index, challenge, approval, and open actions.
Use the FCA page as a benchmark, then test each artifact against the binding rule or guidance that applies to the firm. That distinction prevents two opposite errors: dismissing useful supervisory feedback as optional commentary, or misreporting every observed practice as a new mandatory formula.
Keep this self-assessment review separate from the PS26/2 incident and third-party reporting implementation. The workstreams overlap operationally, but the March 2026 observations did not themselves create the PS26/2 reporting duties.
The Business Continuity & Disaster Recovery Kit includes mapping, impact, exercise, recovery, and evidence templates that can support this review. FCA rules and firm-specific legal advice control where they differ.
Primary sources:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Did the FCA issue an operational-resilience enforcement verdict in March 2026?
What were the six topics in the FCA's observations?
What was required by March 31, 2025?
Does an impact tolerance have to equal an RTO?
What evidence should the board receive?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Keep reading
Related posts.
Business Continuity
Tabletop Exercise Injects: Build an MSEL That Tests Decisions
A Master Scenario Events List (MSEL) is an exercise controller's run sheet—not a general bank or fintech regulatory requirement. Here's how to build one.
Aug 17, 2026
Business Continuity
The ECB Just Ran 110 Banks Through a Geopolitical Reverse Stress Test. Here's What US Banks' BCPs Are Missing.
On July 31, 2026, the ECB published results of its thematic geopolitical risk reverse stress test covering 110 directly supervised euro area banks—and urged the sector to improve. The OCC's Spring 2026 Semiannual Risk Perspective added geopolitical risk as a prominent new concern for the first time. Most US bank business continuity programs are built for IT failures and natural disasters. They are not built for this class of scenario.
Aug 1, 2026
Business Continuity
DORA's 4-Hour Incident Reporting Clock: What US Banks with EU Operations Are Missing in Their Playbooks
DORA's ICT incident reporting timeline is the strictest in the world — 4 hours to initial notification, 72 hours to the intermediate report, one month to final. US banks with EU branches are subject to it and most have a gap between their US playbook and what Brussels actually requires.
Jul 30, 2026