In an article in the FCA website, Suman Ziaullah, the FCA’s Head of technology, resilience, and cyber, has outlined what UK regulated firms can expect now that the operational resilience policy implementation deadline has passed.
As of 31st March 2025 regulated firms in the UK have to have operational resilience processes in place; and rules about the mapping of important business services, setting impact tolerances, completing scenario testing, and addressing identified vulnerabilities need to be complied with.
In Suman Ziaullah’s article he explains what businesses can expect next:
- Operational resilience is a key part of the FCA’s five-year strategy being one of the measures that will deepen trust in the financial sector, which will in turn support growth and improve lives.
- The FCA will be looking at how regulated firms strengthen their resilience culture by learning from incidents and ongoing scenario testing to remediate any newly discovered vulnerabilities.
- The FCA wants to help the financial sector improve its operational resilience through shared insights and a collaborative approach.
- Where the FCA sees ‘failings that put customers or markets at risk’, it will use its powers to ‘drive necessary change’.






