Skip to content
All Blogs

One year on: The FCA's operational resilience verdict

Published
One year on: The FCA's operational resilience verdict
One year on: The FCA's operational resilience verdict
2:35

 

 


TL;DR

 

On 27 March 2026, the FCA published its review of firms' operational resilience one year after the transition period ended. The recurring weakness? Third-party dependency mapping. The FCA expects firms to map through their providers, run severe-but-plausible scenario tests with full records, and give boards enough evidence to challenge. Even out-of-scope firms should treat it as a benchmark.

A year into the UK's operational resilience regime, the regulator has graded the homework. The FCA's insights and observations one year on, published on 27 March 2026, review firms' annual self-assessments following the 31 March 2025 end of the transition period. It's a rare, concrete "good versus poor practice" resource, and the findings are pointed.

 

The standout weakness is third-party dependency mapping. The FCA found that firms mapped their internal technology but treated external providers as "endpoints" rather than mapping through them to the underlying services they support. The regulator's expectation is broader: mapping should cover people, processes, facilities, information, and third parties, not just technology. If you can't see through a critical provider to what actually delivers your important business service, your resilience picture has a hole in it.

 

Two more themes stand out for GRC teams. Scenario testing must use severe-but-plausible scenarios, ransomware, loss of a key site, critical third-party failure, and be backed by full records covering scenario design, participants, timings, gaps, and remediation; a one-page summary is explicitly not sufficient evidence. And governance matters: firms must clearly distinguish consumer harm from market-integrity impact when setting impact tolerances, and boards must be given enough evidence to genuinely challenge resilience decisions. Notably, the FCA said even out-of-scope firms can use these findings as a benchmark.

 

Meeting that evidentiary bar, especially the "full records" expectation, is where many firms struggle, and where 6clicks helps. The platform lets you map important business services through to the people, processes, and third parties they depend on, document scenario tests with the detail the FCA now expects, and give boards a clear, current view to inform genuine challenge. On Sovereign GRC Infrastructure, that mapping and evidence stay UK-resident and reach the restricted environments that resilience testing often has to cover.

Frequently asked questions

That third-party dependency mapping is a consistent weakness, with firms mapping internal technology but treating external providers as endpoints. 

Testing against severe-but-plausible scenarios with full records of design, participants, timings, gaps, and remediation; a one-page summary is not sufficient. 

That boards receive enough evidence to genuinely challenge resilience decisions, and that firms distinguish consumer harm from market-integrity impact. 

The FCA said even out-of-scope firms can use the findings as a benchmark for their own resilience practices.

 

 

Benchmark your resilience against the FCA's verdict. Meet the 6clicks team in person at our UK roadshow to compare your operational resilience approach with peers. Book your place. 

Ready to transform GRC with 6clicks?

Let’s show you how it works for your team.

awards-mobile-v3