Asked and answered

Frequently asked questions

The questions UK financial services firms bring to us before commissioning resilience work, answered plainly by the people who then deliver it. Anything else belongs on the scoping call.

Frequently asked operational resilience questions
What is operational resilience, in one sentence?

The ability of a firm to keep its important business services running through disruption, within tolerances its board has set, evidenced well enough that a supervisor believes it. Everything else in the regime, mapping, testing, self-assessment, exists to make that one sentence true and provable.

The full definition and framework

How is it different from business continuity?

Business continuity plans for getting sites, systems and people back; operational resilience starts from the customer-facing service and asks how much disruption is tolerable at all. A firm can hold an excellent ISO 22301 certificate and still fail supervision, because plans are not outcomes and recovery time objectives are not impact tolerances.

The comparison, properly made

Who do the FCA and PRA operational resilience rules apply to?

Banks, building societies, PRA-designated investment firms and insurers, plus enhanced-scope SM&CR firms, payment and e-money institutions and recognised investment exchanges on the FCA side. Dual-regulated firms answer to both regulators, which in practice means one set of work evidenced two ways.

The FCA regime, from rules to evidence

The transition ended in March 2025. What are firms expected to have now?

A current self-assessment the board has approved, impact tolerances for every important business service, mapping that reaches your third parties, scenario testing that is genuinely severe, and evidence that vulnerabilities found along the way are being fixed. The regime stopped being a project and became business as usual; supervision now reads it that way.

What did the FCA's 2026 review criticise?

The published findings from March 2026 land on four themes: third-party mapping that stops at the contract, scenario testing that is not severe enough to break anything, self-assessments frozen since the compliance deadline, and recovery claims asserted rather than evidenced. Each of our services exists because one of those findings keeps appearing.

What is an impact tolerance, and how many should we have?

The maximum tolerable disruption to an important business service, set by the board as a hard line rather than an ambition, usually as time plus other measures that capture real harm. You need one per important business service; most firms genuinely run a handful of those, not dozens, and inflating the list dilutes everything downstream.

Setting tolerances that survive supervision

How often should the self-assessment be updated?

Whenever something material changes, and reviewed at least annually with board approval either way. A self-assessment dated March 2025 says its own quiet part out loud: the FCA's review specifically called out documents that have not moved since the deadline.

What good looks like

Does DORA apply to UK firms?

Not automatically, but three routes pull UK firms in: entities incorporated in the EU, EU clients served as a financial entity, and sitting in the ICT supply chain of an EU financial entity. The decision-tree page settles it for your structure in a couple of minutes.

Work it out in two minutes

Who are the designated Critical Third Parties, and what does it mean for us?

HM Treasury made the first designations on 10 July 2026: AWS, Google Cloud, Microsoft and Oracle, with regulator oversight running from 13 July. The obligations land on those providers, not on you, but your own mapping, exit planning and scenario testing around them remain yours, and supervisors will expect your programme to notice the regime exists.

The CTP regime, explained

Do we need CBEST, STAR-FS or neither?

CBEST is the Bank of England's scheme for systemic firms and arrives by invitation; STAR-FS is the lighter, self-initiatable alternative the Bank now points non-systemic firms toward; DORA adds its own threat-led testing cycle for in-scope entities. Which applies depends on your regulatory position, and the three-regime comparison page walks it through.

The three regimes, compared

Does SWIFT CSP require an independent assessment in 2026?

Yes. Under CSCF v2026, attesting on self-assessment alone is no longer accepted: every attestation in the July to 31 December 2026 window needs an independent assessment behind it, and Control 2.4 has moved from advisory to mandatory. We deliver that assessment from the UK at a published fixed fee.

The UK assessment, priced

What does a resilience review cost?

The prices are on the pricing page, which makes this the only firm in the market you do not have to ask. The services run from a scored Rapid Resilience Review at £1,995, through the Resilience Gap Analysis, Resilience Framework and Scenario Testing Exercise, to the SWIFT CSP assessment, each a fixed published fee; only full programmes are quoted, and we say so plainly.

Every fee, published

How long does the self-assessment review take?

It is a bounded desk exercise: we read your self-assessment and its supporting evidence, then return a gap letter and board summary. The schedule is agreed at scoping and depends mostly on how quickly documents arrive; the work itself is the definition of a well-contained engagement.

Can you run our whole resilience programme?

Yes, from £24,950, quoted following scoping, because programme scope genuinely varies by regulatory footprint and the number of important business services. The quote follows the same logic as our published fees, so you can see how it was built, and an ongoing retainer is available where a firm wants standing senior cover rather than a one-off build.

Rocket above the Operational Resilience UK call to action

A question we missed?

Bring it to the scoping call

The free 45 minutes exist for precisely this: your regulatory position, the state of your programme and which service fits, discussed with a practitioner whether or not you buy anything.