Back to Resources

Operational Resilience: The FCA Self-Assessment Every Fintech Now Owes

FCA & Regulatory

Share
Executive summary: The FCA's operational resilience regime requires in-scope firms to identify their important business services, set impact tolerances for each, map and test their ability to stay within those tolerances, and maintain a board-approved self-assessment document. Many scaling fintechs are in scope and treat the self-assessment as a compliance artefact rather than a genuine resilience exercise. This piece covers who is in scope, the core concepts, the self-assessment, and the CFO's specific role — including the financial dimension of resilience.

The Regime and Who It Covers

The FCA's operational resilience rules, in SYSC 15A, require in-scope firms to be able to prevent, adapt to, respond to, recover from, and learn from operational disruptions. The regime applies to a range of FCA-authorised firms — banks, insurers, and specified investment and payment firms — and many scaling fintechs fall within it, particularly those providing payment services, e-money, or investment services at scale. The first step for any authorised fintech is to confirm whether it is in scope, because the obligations are substantial and the FCA expects them to be met, not aspired to.

The regime is built around a specific idea: rather than trying to prevent every possible disruption, a firm should identify the services whose disruption would cause the most harm, decide how much disruption to each is tolerable, and ensure it can stay within those limits even in severe scenarios. That reframing — from preventing all failure to bounding the harm from the failures that matter — is the core of the regime.

Important Business Services

The foundational concept is the important business service: a service the firm provides to an external end user whose disruption could cause intolerable harm to customers or risk to market integrity. Not every service is important in this sense — the regime is deliberately focused on the services that matter most. A payments fintech's important business services might include processing payments and providing access to funds; an investment platform's might include executing trades and enabling withdrawals.

The discipline is to identify these services precisely and from the customer's perspective — what service, if it failed, would genuinely harm customers — rather than listing every internal system. A firm that identifies too many "important" services dilutes the exercise; one that identifies too few misses the point. The identification should be deliberate, documented, and reviewed as the business changes.

Impact Tolerances

For each important business service, the firm sets an impact tolerance: the maximum tolerable level of disruption, expressed in a measurable way — typically a maximum duration of outage, but potentially other metrics. The impact tolerance is the firm's own statement of how much disruption to that service is acceptable before intolerable harm occurs, and it becomes the standard the firm must be able to stay within.

Core artefact
Self-assessmentBoard-approved, at least annual
Foundational unit
IBSImportant business service
The standard
Impact toleranceMax tolerable disruption, measurable
The test
Severe-but-plausible scenarios

Setting the tolerance is a judgement about customer harm, not a technical target — it should reflect the point at which disruption to the service genuinely harms customers, and it needs board-level agreement because it is a statement of the firm's risk appetite for that service.

Mapping and Testing

Having identified the important business services and set impact tolerances, the firm must map the resources — people, processes, technology, facilities, and third parties — that each service depends on, and test its ability to stay within the impact tolerance under severe-but-plausible disruption scenarios. The mapping reveals the dependencies and vulnerabilities; the testing demonstrates whether the firm can actually remain within tolerance when something goes wrong.

The third-party dimension is critical for fintechs, which typically depend heavily on cloud providers, banking partners, and other outsourced services. An important business service that depends on a single cloud provider or a single banking partner has a concentration vulnerability that the mapping should surface and the firm should address. Testing against severe-but-plausible scenarios — a cloud outage, a key third-party failure — is where the firm learns whether its resilience is real or theoretical.

The Board Self-Assessment

The regime requires a self-assessment document, approved by the board, that sets out the firm's important business services, impact tolerances, mapping, testing, and any vulnerabilities identified together with the plan to address them. This document is the artefact the FCA can request, and it must be kept current — reviewed and re-approved at least annually and when the business changes materially.

The self-assessment is where firms most often fall short by treating it as a document to produce rather than a genuine assessment. A strong self-assessment is honest about vulnerabilities and specific about remediation; a weak one asserts resilience without evidence. As with the Consumer Duty report, the FCA values a clear statement of where the firm is not yet resilient enough, with a plan, over an unsupported assertion of full resilience.

"Operational resilience is not about preventing every failure — it is about knowing which services matter most, deciding how much disruption to each is tolerable, and being able to prove you can stay within that even when something breaks. The self-assessment that names the vulnerabilities honestly and plans to fix them is worth far more than one that asserts resilience the firm cannot demonstrate."

The CFO's Role

Operational resilience is typically owned by operations or risk, but the CFO has a specific role in two dimensions. First, resilience investment is a budget question: the mapping and testing surface vulnerabilities — a concentrated third party, an under-resilient system — and remediating them costs money that has to be funded. The CFO owns the trade-off between resilience investment and other priorities, and the funding of the remediation plan in the self-assessment.

Second, there is a financial dimension to resilience itself. The firm's ability to withstand disruption depends partly on financial resilience — the liquidity and capital to keep operating through a severe scenario. Where an important business service depends on the firm's own financial soundness (the ability to keep making payments, to keep client money safe), the CFO owns that dimension of the resilience assessment. The two regimes — operational resilience and prudential soundness — meet in the finance function.

The genuine-resilience dividend: A firm that treats the self-assessment as a real exercise gets more than compliance — it gets a genuine understanding of its most critical vulnerabilities and a funded plan to address them, which is valuable operational insight regardless of the regulation. A firm that treats it as a document gets a file that satisfies no-one under scrutiny and leaves the real vulnerabilities unaddressed until they cause the disruption the regime was designed to bound.

Key Takeaways

  • The FCA's operational resilience regime (SYSC 15A) applies to many scaling fintechs, especially payment, e-money and investment firms — confirm scope first.
  • The regime reframes resilience: not preventing all failure, but bounding the harm from the failures that matter most.
  • Identify important business services precisely, from the customer-harm perspective — the services whose disruption would cause intolerable harm.
  • Set a measurable impact tolerance for each — a board-level statement of how much disruption is acceptable before intolerable harm.
  • Map the dependencies (especially third parties like cloud and banking partners) and test against severe-but-plausible scenarios.
  • Maintain a board-approved self-assessment that names vulnerabilities honestly with a funded remediation plan — the CFO owns the resilience-investment funding and the financial dimension of resilience.

Work Together

Need this applied to
your business?

Operational resilience mapping, impact tolerances and self-assessment preparation for FCA-authorised firms. We bring CFO-level rigour without the full-time cost.

Book a Free Discovery Call →