Home  ›  Insights  ›  Operational resilience: learning from the FCA observations
Regulatory27 Aug 2026 · 2 min read

Operational resilience: learning from the FCA observations

One year after the initial deadlines for operational resilience, the Financial Conduct Authority has provided critical feedback on how firms are documenting their important business services. For investment managers and insurers, this is a prompt to move beyond initial compliance exercises and ensure their frameworks are robust, evidence-based, and genuinely reflective of how work happens.

Moving beyond the initial self-assessment

The recent report from the FCA regarding operational resilience serves as a diagnostic tool for firms. Many organisations initially approached these requirements as a documentation exercise to meet immediate regulatory deadlines. However, the supervisor is now looking for deeper evidence that firms truly understand their critical dependencies. If your organisation cannot demonstrate a granular, evidenced record of the processes underpinning your important business services, you remain exposed to regulatory scrutiny and operational instability.

The importance of evidenced workflow

A recurring theme in the FCA findings is the lack of precision in identifying dependencies. It is not enough to maintain a high-level map of an IT system. Firms must understand the specific people, manual processes, and third-party relationships that ensure a service remains within its impact tolerance. We advocate for process mapping without event logs to ensure your records reflect the actual experience of your employees rather than what is captured in IT system logs.

The FCA has made it clear that understanding your dependencies is not a static requirement. It is an active obligation that requires constant review of the people and processes that support your important business services.

Aligning resilience with your AI strategy

Many firms struggle to reconcile the need for stable operational resilience with the desire to deploy new technologies. Before automating any step, you must verify that the process is resilient. We assist firms in this transition through our AI opportunity assessment, which identifies where automation can be safely introduced without compromising your ability to meet impact tolerances. Understanding where AI belongs within your firm is a prerequisite for long-term operational success.

Third-party oversight

The regulator is increasingly focused on how third-party relationships could threaten your resilience. Whether you are dealing with cloud service providers or outsourced fund administrators, your DORA operational resilience process mapping must extend to these external entities. If you cannot identify the human elements of your third-party workflows, you cannot effectively test your impact tolerance during a failure.

Building a foundation for the future

Operational resilience is a measure of your firm's AI readiness. If you cannot describe your processes clearly, you are not ready to automate them. To discuss how your firm can align its current operational documentation with these updated supervisory expectations, you can book a consultation or reach out to us at hello@pinpointproof.com.

FAQ

Questions this article raises.

What is the primary focus of the recent FCA report on operational resilience?

The FCA report details both good and poor practices observed in firms' self-assessments regarding operational resilience. It is intended to help firms review and refine their frameworks to better comply with SYSC 15A rules.

Why is granular process mapping essential for regulatory compliance?

Regulators require firms to document the exact people, manual steps, and third-party relationships that support each important business service. Detailed mapping ensures you can accurately identify dependencies that could threaten your ability to stay within impact tolerances during a failure.

How does operational resilience relate to an AI strategy?

Operational resilience acts as a foundation for AI readiness. Before a firm can safely automate a process, it must have an evidenced record of how that work currently functions. Without this understanding, automation risks introducing new vulnerabilities into your resilient business services.

Know where to start.
Prove it worked.

Book a thirty-minute walkthrough. Bring one process; we will show you what its map, scores and opportunity register look like.

Pick a time that suits you. No form to fill in first.