Operational Resilience: Where Supervisory Expectations Actually Stand Now

The FCA and PRA’s operational resilience framework had a defined transition period, and firms are now well past the point where “we’re still building toward compliance” is an acceptable answer to a supervisor’s questions. What’s changed since the original deadline isn’t the rules themselves — it’s how seriously, and how specifically, supervisors now test whether a firm’s resilience framework actually works, rather than simply exists. This matters directly to how firms should be recruiting into SMF24 and briefing their wider executive team.

From “Do You Have a Framework” to “Prove It Actually Works”

In the early period after the operational resilience rules came into force, supervisory engagement understandably focused on whether firms had done the foundational work — identified their important business services, set impact tolerances, mapped the resources supporting each service. That foundational question has largely been answered across the regulated population. Supervisory attention has moved on to a harder question: when a severe but plausible disruption scenario is actually tested, does the firm demonstrably stay within its stated impact tolerances, or does the testing reveal that the tolerances themselves were unrealistic, or that the firm’s actual capability doesn’t match what its framework claims?

This shift matters because it changes what “good” looks like in a way that’s easy to underestimate. A firm with a well-documented framework and untested, optimistic assumptions about its own resilience is now more exposed to supervisory criticism than a firm with a less polished framework that has genuinely stress-tested itself and found, and started fixing, real gaps.

Third-Party Concentration Risk Has Become a Specific Supervisory Focus

As firms across the sector have converged on a relatively small number of critical infrastructure providers — cloud hosting, core banking platforms, payment processing — supervisors have become increasingly focused on concentration risk that sits above any individual firm’s control: what happens if a provider serving a large share of the regulated sector fails simultaneously. Individual firms are now expected to demonstrate genuine understanding of this system-wide risk, not just their own direct third-party relationships, and to have credible contingency plans that don’t simply assume an alternative provider will be readily available in a genuine sector-wide disruption.

Testing Maturity Varies Enormously Across the Sector

In our experience working with SMF24 candidates and the firms recruiting them, testing maturity varies far more across the sector than firms often assume when benchmarking themselves informally against competitors. Some firms have moved to genuinely adversarial testing — bringing in external specialists to attempt to find gaps the internal team hasn’t considered — while others are still running tabletop exercises that tend, by their nature, to confirm the existing framework rather than genuinely challenge it. A firm’s actual position on this spectrum should be a specific, explicit part of any SMF24 brief, because the skill set needed to take a firm from tabletop exercises to genuine adversarial testing is meaningfully different from the skill set needed to maintain an already-mature programme.

What This Means for SMF24 Recruitment

Firms recruiting a Chief Operations function holder today should test candidates specifically for experience running genuine, adversarial resilience testing through to a real regulatory reporting cycle — not simply having built the initial framework several years ago and maintained it since. The operational resilience landscape has moved meaningfully since the framework was new, and a candidate whose direct experience predates that shift may need real support to bring their skill set current, which is a fair and useful thing for a firm to plan for explicitly rather than discover after the appointment is made.

It’s also worth testing candidates on their experience of the third-party concentration risk question specifically, since this has become one of the more sophisticated and less commonly well-handled parts of the framework. A candidate who can speak fluently about their own firm’s direct third-party arrangements but hasn’t thought through sector-wide concentration risk is demonstrating a real, if common, gap.

The Board’s Role Hasn’t Changed, But Its Engagement Should

Boards, and specifically the SMF9 chair, retain ultimate accountability for satisfying themselves that the firm’s operational resilience framework is genuinely fit for purpose. Given how much the supervisory bar has moved from “does a framework exist” to “does it actually work under genuine stress,” boards should be asking their SMF24 holder increasingly pointed questions about the last real test — what it actually found, not just whether it was completed on schedule.

Related Reading

The designations most directly connected to operational resilience accountability.

Executive Function

SMF24

The Chief Operations function, and how the resilience obligation has changed the role.

→ Read the guide

Board Chair

SMF9

The chair’s ultimate accountability for the board’s oversight of resilience.

→ Read the guide

Risk Oversight

SMF4

How operational risk ownership under SMF24 relates to the wider risk function.

→ Read the guide

Adrian Lawrence FCA — Founder, SMF Capital

Adrian is a Fellow of the ICAEW and holds an ICAEW practising certificate in his own name. He founded FD Capital in 2018 and has since built out Exec Capital, NED Capital and Accountancy Capital alongside SMF Capital, tracking how supervisory expectations evolve across every SMF designation. View Adrian’s ICAEW profile.

Recruiting Into SMF24 or Reviewing Your Resilience Testing?

Call 0203 137 2496 or email recruitment@smfcapital.co.uk. Tell us your firm’s current testing maturity — it directly shapes what your search brief should look like.