Prove the tolerance holds

Scenario testing: severe, plausible and evidenced

Impact tolerances are claims until they are tested. Scenario testing is where a firm finds out whether an important business service really stays within tolerance when a supplier fails, a cyber incident lands or a payment rail goes quiet, and it is the part of the regime the FCA's 2026 review found wanting. This page covers what a credible exercise looks like, the themes worth testing, and the fixed-fee exercise we design and run.

First principles

What scenario testing is, and what severe but plausible means

A severe but plausible scenario is a disruption serious enough to genuinely threaten an important business service's impact tolerance, while remaining realistic for the firm's actual operations, technology and third parties. Scenario testing is the discipline of running such scenarios and recording whether the tolerance held.

Every credible scenario begins from your own important business services and impact tolerances, because the tolerance is what calibrates severity. A scenario that could not plausibly breach the tolerance is not a test; it is a rehearsal of a good day.

That calibration is exactly where firms are falling short. When the FCA published its observations on the regime in March 2026, a year after the transition ended, testing that was not severe enough stood out among the findings. An exercise designed to be passed produces reassurance and no information, and supervisors have learned to tell the difference.

Anatomy of a real test

What a credible exercise looks like

Six elements separate an exercise that produces evidence from a meeting that produced minutes. Remove any one of them and the value of the rest falls sharply.

1

Scenario design from your IBS and tolerances

The scenario starts from your own important business services and the tolerances you set for them, with severity calibrated so a tolerance breach is genuinely in play. The assumptions are written down before anyone enters the room: what has failed, for how long, what is known and what is not.

2

Tabletop facilitation

The people who would actually own the decisions work the disruption in real time, with a facilitator holding the pace and refusing to let the room retreat into describing the plan instead of executing it.

3

Injects

New information arrives mid-exercise: the restore is failing, the vendor's estimate has doubled, a journalist is asking questions. Injects test decision-making under changing facts, which is what a real disruption serves up, rather than memory of a document.

4

Timed decisions

A decision log with clock times set against the tolerance metrics: who decided what, when, and on what information. Without the clock there is no way to say whether the service would have stayed within tolerance, which is the question the whole exercise exists to answer.

5

The evidence pack

Scenario documents, attendance, the decision log, the tolerance outcome and the vulnerabilities surfaced, assembled so the test can be shown to a supervisor rather than described to one.

6

Lessons into the self-assessment

Findings land as entries in the vulnerability and remediation register, and the test itself becomes the newest evidence in the self-assessment's testing section. An exercise that changes nothing in that document probably was not severe enough.

The final element is why testing and the self-assessment rise and fall together: each test should leave that document measurably more truthful than it found it.

Where to point the severity

Scenario themes worth testing

Themes, not scripts: each becomes a scenario only once it is grounded in your services, your tolerances and your mapping. Six recur for good reason.

Third-party failure

A critical supplier's outage becomes your outage. With the first critical third parties designated in July 2026, an outage at a designated CTP is a scenario supervisors will expect to see considered, especially where your mapping shows concentration on one provider.

Cyber incident

Systems unavailable and untrusted at the same time. Recovery competes with containment, and every restore decision carries the question of whether the environment being restored into is clean.

Data corruption

The failure that replicates into your backups before anyone notices. The decisions under test are which point in time to recover to, what is lost by choosing it, and who is told what about the gap.

Loss of workplace

A site is inaccessible, whether through damage, denial of access or utilities failure. The test is whether the service continues, not whether the building reopens: the two questions have different owners and different clocks.

Key-person unavailability

The process that lives in one person's head, unavailable without notice. Uncomfortable to run and consistently revealing, because mapping tends to record teams while reality depends on individuals.

Payment-rail outage

A scheme or agent bank stops mid-day with cut-offs approaching. Time and value metrics come under pressure together, which makes this theme a natural first test for any firm whose important business services move money.

The third-party theme has its own regulatory layer now the first designations have landed; the critical third parties guide covers what the regime means for firms. And if a cyber scenario ever stops being hypothetical, incident response is delivered by CyPro directly.

The scenario library, free

Worked scenario outlines across the six themes, each with severity parameters and starter injects to adapt to your own services. No details demanded in exchange.

Download the scenario library

Designed, run and evidenced for you

The fixed-fee Scenario Testing Exercise

We design the scenario from your important business services and tolerances, facilitate the tabletop with live injects and a timed decision log, and assemble the evidence pack afterwards. Severity is calibrated to threaten the tolerance, because an exercise that cannot fail teaches nothing and persuades nobody.

You receive the scenario documents and injects, the decision log from the session, the tolerance outcome, and a findings letter setting out the vulnerabilities surfaced with recommended remediation, ready to enter your self-assessment and your remediation register.

Who should attend: the owners of the services in scope, the operations and technology leads who would run the recovery, whoever faces customers and the regulator when things break, and at least one member of the governing body, because the hardest calls in a real disruption are theirs.

The exercise carries a fixed fee of £8,550 to £13,200 by scope, published on the pricing page alongside all our other services, so the cost is on the table before the conversation starts.

Quick answers

Scenario testing questions, answered

What are severe but plausible scenarios?

Disruption scenarios that are serious enough to genuinely threaten an important business service's impact tolerance, while remaining realistic for the firm's actual operations, technology and third parties. Both words carry weight: a scenario the firm would comfortably absorb is not severe, and a scenario disconnected from how the firm really runs is not plausible. The tolerance is the calibration point for both.

How often should we run scenario testing?

The rules require testing to be carried out regularly rather than on a prescribed timetable. A defensible programme covers each important business service on a rolling cycle, retests after material change to a service, its tolerance or its dependencies, and increases severity over time rather than repeating a passed scenario. What convinces a supervisor is a programme with a rationale, not a one-off exercise however well run.

Does a tabletop count as testing?

Yes, provided it is severe, plausible and evidenced: a calibrated scenario, timed decisions and a documented tolerance outcome. What does not count is a walkthrough of the plan with no clock and no possibility of failure. Technical elements such as recovery or failover exercises strengthen the picture where a tolerance rests on a technical claim, and the two formats work best feeding the same evidence pack.

Rocket above the Operational Resilience UK call to action

Test before you are tested

Run an exercise that proves something

Take the free scenario library and run your own tabletop, or book the fixed-fee exercise and have the design, facilitation and evidence pack handled end to end at a published price.