Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Finance > New FCA rules and guidance on operational resilience is an opportunity for financial sector to add real robustness into business functions
    Finance

    New FCA rules and guidance on operational resilience is an opportunity for financial sector to add real robustness into business functions

    New FCA rules and guidance on operational resilience is an opportunity for financial sector to add real robustness into business functions

    Published by Jessica Weisman-Pitts

    Posted on April 1, 2022

    Featured image for article about Finance

    New rules mean financial organisations will have to ensure business critical functions continue operate even during periods of huge disruption

    Tom Richards, Systems and Storage Practice lead, Northdoor plc

    New FCA guidance has come into force which will see organisations across the financial sector have to identify important areas of their business and ensure that they can continue functioning during any disruption.

    With the pandemic and the fact that cyberattacks are becoming increasingly sophisticated and numerous, the FCA is looking to ensure that organisations across the sector are as well prepared as possible. This guidance started as a discussion paper in 2018 and organisations now have until March 2025 to ensure adherence.

    Although there is a three-year onboarding process, companies should have already identified their important business services, set impact tolerances for the maximum tolerant disruption and carried out mapping and testing to a level of sophistication necessary to do so.

    Which financial sectors must adhere to new rules and guidance?

    The FCA operational resilience rules and guidance is a joint venture between the FCA, Bank of England and Prudential Regulation Authority (PRA) and as such much of the financial sector is covered including:

    • Banks
    • Building societies
    • PRA-designated investment firms
    • Insurers
    • Recognised Investment Exchanges
    • Enhanced scope Senior Managers & Certification Regime (SM&CR) firms
    • Entities authorised and registered under the Payment Services Regulations 2017 or Electronic Money Regulations 2011.

    A handful of the bigger financial organisations have worked alongside the three regulatory bodies in putting this regulation in place and so are already ahead of the game. However, most other companies will be only just be starting to think about what they need to put into place.

    What do organisations need to do and how long have they got?

    To ensure that you are adhering to these new guidelines, companies will have to look at a broad range of activities connected to governance, risk management and compliance. The key to success though is service discovery and classification, as well as having the people, processes and technology in place.

    The deadline for adherence is March 2025, but there are incentives in place for those that achieve this sooner as it will help to build stability and trust in the UK financial sector. Therefore, businesses will have to quickly work out what critical systems serve clients and what impact there would be if they lost these systems, or they couldn’t deliver services to their customers.

    They will need to determine the maximum outage they could suffer without causing undue harm to the business. This will be a business-led conversation at board level to establish what services they could run without and for how long. Financial services institutions will need to put measures in place to check that they never go beyond the threshold set.

    The last two years have shown why these steps are so incredibly important. The impact of the pandemic itself as well as the resulting changes to the workplace have made the financial sector a more tempting target for cybercriminals. Ensuring that the critical services can be continued no matter the crisis will help not just the company, but the sector as a whole.

    Discovery, people and processes to play a key role

    The FCA’s operational resilience is in many ways similar to GDPR as discovery, people and processes will play a key role. The guidance is designed to help financial organisations ensure that they resilient for consumers, firms and financial markets.

    As we have seen over the course of the past five years, cyberattacks on financial sector organisations are not just having a huge impact on the specific business but also on customers and the wider market. The aim of the guidance is to ensure that organisations implement operational resilient systems that can absorb shocks rather than compound them.

    In order to achieve this they need to ensure that they build resilience in right the way. Organisations need to consider how the whole architecture can be made more resilient with a mission statement that outlines this as a goal that the organisation subsequently designs back from.

    Initial task checklist

    With so many firms likely to be behind schedule or indeed not even begun the initial processes, there are some key tasks that need to be implemented urgently.

    If you’re one of these firms, you will need to immediately:

    • Identify your important business services that, if disrupted, could cause intolerable harm to consumers of your firm or risk to market integrity, threaten your firm’s viability or cause instability in the financial system.
    • Set impact tolerances for the maximum tolerable disruption to these services.
    • Carryout mapping and testing to a level of sophistication necessary to identify important business services, set impact tolerances and identify any vulnerabilities in your operational resilience.
    • Conduct lessons learnt exercises to identify, prioritise, and invest in your ability to respond and recover from disruptions as effectively as possible.
    • Develop internal and external communications plans for when important business services are disrupted.
    • Prepare self-assessment documentation.

    Like the introduction of many regulations, most notably GDPR, the process of adherence can on the face of it look a daunting task. Many are turning to independent consultancies to help them through the processes, identify the key functions and add layers of resilience to help ensure business continuity.

    Far from being a daunting task this should be seen as an opportunity. Cyberattacks are only likely to get more numerous and sophisticated over the coming months and years. Therefore, ensuring that you can continue to service customers even during the greatest disruption is not only good for business, it enhances reputation amongst customers and potential customers and thwarts the growing menace of cybercriminals.

    Related Posts
    Russian ban on Roblox gaming platform sparks rare protest
    Russian ban on Roblox gaming platform sparks rare protest
    UK's Starmer and EU's von der Leyen discuss Ukraine peace plan, frozen Russian assets
    UK's Starmer and EU's von der Leyen discuss Ukraine peace plan, frozen Russian assets
    Thousands march in Hungary in protest over child abuse scandal
    Thousands march in Hungary in protest over child abuse scandal
    US says Belarus agreed to stop balloon flyovers into Lithuania
    US says Belarus agreed to stop balloon flyovers into Lithuania
    Ukraine says Russian drone attack hit civilian Turkish vessel
    Ukraine says Russian drone attack hit civilian Turkish vessel
    Who are the most prominent prisoners released by Belarusian president Lukashenko?
    Who are the most prominent prisoners released by Belarusian president Lukashenko?
    Spanish police bust gang that used helicopters to fly drugs from Morocco
    Spanish police bust gang that used helicopters to fly drugs from Morocco
    Lukashenko frees Nobel winner Bialiatski and key Belarus opposition figures in deal with US
    Lukashenko frees Nobel winner Bialiatski and key Belarus opposition figures in deal with US
    EU countries agree 2026 fishing quotas, avoid tighter Mediterranean curbs
    EU countries agree 2026 fishing quotas, avoid tighter Mediterranean curbs
    New Czech prime minister rejects guarantees for Ukraine loan
    New Czech prime minister rejects guarantees for Ukraine loan
    Ukraine's Odesa suffers major blackouts after Russian attack
    Ukraine's Odesa suffers major blackouts after Russian attack
    Bitcoin hoarding company Strategy remains in Nasdaq 100
    Bitcoin hoarding company Strategy remains in Nasdaq 100

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Finance

    Explore more articles in the Finance category

    North Korean leader Kim hails troops returning from Russia mission, state media says

    North Korean leader Kim hails troops returning from Russia mission, state media says

    Spain urges EU not to weaken 2035 combustion engine ban, letter shows

    Spain urges EU not to weaken 2035 combustion engine ban, letter shows

    EU vote on Mercosur trade deal set for next week, Denmark says

    EU vote on Mercosur trade deal set for next week, Denmark says

    King Charles says his treatment for cancer can be reduced in the new year

    King Charles says his treatment for cancer can be reduced in the new year

    Juventus 'not for sale' say Agnellis, rejecting crypto giant Tether's bid

    Juventus 'not for sale' say Agnellis, rejecting crypto giant Tether's bid

    Ukraine hits Russian oil infrastructure in Caspian for second time

    Ukraine hits Russian oil infrastructure in Caspian for second time

    EU, India unlikely to finalize trade agreement by end of year, Bloomberg News reports

    EU, India unlikely to finalize trade agreement by end of year, Bloomberg News reports

    Explainer-What are the legal risks of EU's 'reparations loan' for Ukraine?

    Explainer-What are the legal risks of EU's 'reparations loan' for Ukraine?

    Ice-cream spin-off turns up heat on Unilever to deliver on growth, margins

    Ice-cream spin-off turns up heat on Unilever to deliver on growth, margins

    Google faces $129 million French asset freeze after Russian ruling, documents show

    Google faces $129 million French asset freeze after Russian ruling, documents show

    Hundreds of storks found dead near Madrid amid wider bird flu surge

    Hundreds of storks found dead near Madrid amid wider bird flu surge

    EIB to boost lending for EU defence projects in 2026

    EIB to boost lending for EU defence projects in 2026

    View All Finance Posts
    Previous Finance PostImprove Your Home and Car Security to Cut Your Insurance Rates
    Next Finance PostThe Fintech Road to Carbon Neutrality