Support your FCA resilience programme with tested, documented IT
For firms within SYSC 15A, we help map technology dependencies, test recovery and produce the evidence behind important business services.
Meet the requirements you will be assessed against
Identify important business services
You must identify and document the services your firm provides that, if disrupted, could cause harm to consumers, market integrity, or the firm's safety and soundness. IT systems underpinning these services become critical dependencies.
Impact tolerances
For each important business service, you must define the maximum tolerable level of disruption. This is expressed as a time limit — for example, a trading platform must be restored within two hours. Your IT infrastructure must be designed to meet these tolerances.
Scenario testing
Firms must conduct regular scenario testing to verify they can remain within impact tolerances during severe but plausible disruptions. Tests must cover technology failures, cyber attacks, third-party provider outages, and data integrity events.
Mapping dependencies
Every resource that supports an important business service must be mapped, including IT systems, data assets, third-party providers, facilities, and key personnel. The mapping must be detailed enough to identify single points of failure.
Continuous self-assessment
Operational resilience is not a one-off project. The FCA expects firms to continuously review and improve their resilience capabilities, updating impact tolerances, dependency maps, and testing programmes as the business and threat landscape evolve.
Board and senior management accountability
The board must own the firm's operational resilience strategy. Senior managers under the SM&CR regime are individually accountable for ensuring important business services remain within impact tolerances.
Where the March 2025 deadline leaves you
The FCA’s operational resilience framework sits in policy statement PS21/3 and the SYSC 15A rules. The transition ended on 31 March 2025 for firms within scope. SYSC 15A does not apply to every FCA-authorised firm, so confirm your category and permissions before treating the framework as a direct obligation.
The three-year transition that opened in March 2022 has closed. If you identified services and set tolerances on paper, but left the underlying technology alone, you are exposed. The FCA asks you to demonstrate resilience, not describe it.
The next deadline is already set. Under PS26/2, operational incident and material third-party reporting becomes mandatory on 18 March 2027 — we set out what that means and the work to do now.
For an in-scope firm, technology is usually a significant dependency underneath important business services. Understanding that dependency is the starting point for useful testing and recovery planning.
What the FCA actually expects
The framework runs as a chain of five steps.
Identify the services that matter most. These are the services whose disruption would harm consumers, threaten market integrity or undermine your firm’s safety and soundness. For a wealth manager that is usually portfolio access and trade execution. For a payment firm it is transaction processing. For an advisory firm it may be regulatory reporting and client communication.
Set an impact tolerance for each one. An impact tolerance is the longest disruption you can absorb before the harm becomes intolerable. It is not a recovery time objective buried in an IT plan. It is a board-level commitment to a number.
Map every dependency underneath. Document the IT systems, data stores, cloud platforms, network links, third parties, buildings and people. Map at a level that exposes single points of failure and concentration risk.
Test whether you can hold the tolerance. Cover technology failure, cyber attack, third-party outage and data corruption. Keep the scenarios realistic, write up the results, and repeat them on a schedule.
Keep improving. The FCA does not expect perfection. It expects a credible programme driven by your own testing, incidents and business change.
Your IT provider as a regulated dependency
Your important business services sit on a chain of technology: servers, networks, cloud platforms, applications, backups and the controls protecting all of it. When the FCA asks whether you can restore a service inside your tolerance, it is asking how fast that chain recovers.
That makes a managed IT provider one of the dependencies your resilience programme may need to map and test.
Monitoring that spots a failure in minutes rather than hours cuts your recovery time directly. Backup and disaster recovery that restores data to a known good state decides whether you recover at all. Structured incident management gives your compliance team the evidence trail when the FCA asks questions.
Support processes, recovery tests and change records should therefore produce evidence the firm can review and retain.
A resilience programme on IT we test and document
We work with FCA-regulated firms across London, including hedge funds, private equity firms and wealth managers. Where SYSC 15A applies, we support the technology layer of the firm’s wider resilience programme.
We begin with dependency mapping. We record every system, application and third-party service behind your important business services. We show you the single points of failure and the concentration risks, then plan the remediation.
We align monitoring and alerting to your tolerances. If your tolerance on a client-facing platform is four hours, we escalate within minutes rather than hours. Our incident process classifies a disruption against your stated tolerance and triggers the matching response.
We build and maintain recovery capability against your own scenarios. Tabletop exercises, failover tests and full recovery simulations are scheduled and written up. When your compliance team needs proof that recovery works, the results are current.
We can produce technology reporting for boards and senior managers, covering incident trends, test outcomes, dependency changes and improvement actions. Your firm and its advisers determine the governance and regulatory conclusions.
This framework and DORA overlap heavily. Build the capability once, designed for both, and you avoid paying twice. We build that foundation with our managed IT support, cybersecurity and penetration testing services.
Last updated:
FAQ
Frequently asked questions
When did FCA operational resilience rules become fully enforceable?
The FCA's operational resilience framework became fully enforceable on 31 March 2025. Firms were given a three-year transition period from March 2022 to identify important business services, set impact tolerances, and build the capability to remain within them. There is no further transition period — firms must now demonstrate compliance on an ongoing basis.
How does FCA operational resilience relate to DORA?
The FCA's framework and DORA share the same underlying principle: financial firms must be able to withstand, respond to, and recover from operational disruptions. DORA is more prescriptive about ICT-specific requirements including incident reporting timeframes, third-party contract clauses, and resilience testing methodologies. Firms subject to both must align their programmes.
What counts as an important business service?
An important business service is one whose disruption could cause intolerable harm to consumers, market integrity, or firm safety and soundness. Examples include client order execution, payment processing, client reporting, custody and safeguarding of assets, and regulatory reporting. The firm determines which services qualify, but the FCA expects rigorous justification.
What scenario tests does the FCA expect?
Scenario tests must cover severe but plausible disruptions including major IT system failures, successful cyber attacks, critical third-party provider outages, loss of key facilities, and data corruption events. Tests should be conducted regularly, with results documented and used to drive improvement.
How does managed IT support our operational resilience programme?
Your managed IT provider controls the technology layer that underpins most important business services. Proactive monitoring, documented recovery procedures, tested backup and disaster recovery capabilities, and structured incident management directly support your ability to remain within impact tolerances.
What happens if we cannot stay within our impact tolerances?
If a disruption exceeds your stated impact tolerances, the FCA will examine whether the firm had taken reasonable steps to build resilience. Failures to identify important business services, inadequate testing, or insufficient investment in technology resilience can result in supervisory action, including enforcement proceedings under the SM&CR.
Talk to our team about this standard
Tell us where you are with this standard. A London-based engineer replies within 2 hours during business hours.
Message sent
Thanks for getting in touch. We will reply within 2 hours on a business day.
Contact details
0330 043 7414
Mon-Fri 8am-6pm
[email protected]
We reply within 2 hours
71-75 Shelton Street
Covent Garden, London WC2H 9JQ
IT assessment
A review of your IT, your security posture and your compliance readiness, free of charge.
- 30-minute consultation call
- Infrastructure & security review
- Compliance gap analysis
- Custom recommendations report
Related compliance services
Find out where you stand today
Book a compliance review. We assess your readiness against the current requirements and give you a priority order for closing the gaps.
- No callout fees
- No-obligation assessment