Resilience Testing Requirements Under FCA and PRA Regulations
A practical guide to meeting FCA and PRA operational resilience testing requirements, including scenario development and evidence documentation.
Financial services firms in the UK now face binding requirements to demonstrate their operational resilience through comprehensive testing programmes. The Financial Conduct Authority and Prudential Regulation Authority regulations that came into full effect in March 2025 require firms to prove they can remain within their impact tolerances during severe but plausible disruption scenarios.
Understanding and meeting these testing requirements is not optional. Firms that cannot demonstrate adequate resilience testing face regulatory scrutiny and potential enforcement action. More importantly, robust testing is the only way to have genuine confidence in your ability to maintain critical services during disruption.
Overview of FCA and PRA Operational Resilience Requirements
The operational resilience framework introduced by UK regulators represents a fundamental shift in approach. Rather than focusing primarily on preventing disruptions, the framework emphasises the ability to absorb, adapt to, and recover from operational incidents.
Central to this framework is the concept of important business services. Firms must identify the services that, if disrupted, would cause intolerable harm to consumers, market integrity, or the safety and soundness of the firm itself. For each important business service, firms must set impact tolerances and demonstrate they can remain within those tolerances during disruption.
Testing provides the evidence that these capabilities actually exist. Regulators are clear that untested plans and theoretical analysis are not sufficient. Firms must validate their resilience through practical testing against severe but plausible scenarios.
The requirements apply proportionately based on firm size and complexity. However, all firms within scope must maintain appropriate testing programmes. Smaller firms may conduct simpler tests, but they cannot avoid testing altogether.
The Role of Scenario Testing in Demonstrating Compliance
Scenario testing sits at the heart of regulatory expectations for operational resilience. Firms must develop and test against scenarios that represent severe but plausible disruptions to their important business services.
These scenarios must cover the range of threats that could affect service delivery. Technology failures, including both internal systems and third-party services, feature prominently. Cyber attacks represent an increasingly important category. Loss of key premises, unavailability of people, and disruption to critical suppliers all need consideration.
Testing must be realistic. Regulators expect firms to test against scenarios that would genuinely challenge their response capabilities. Tests that are too easy or that avoid known weaknesses do not satisfy regulatory expectations and do not build genuine resilience.
The frequency and depth of testing should reflect the importance of services and the nature of risks. The most critical services with the most severe potential impacts require more frequent and more rigorous testing than less critical functions.
Severe but Plausible Scenario Development
Developing appropriate scenarios requires understanding both the threats you face and the vulnerabilities in your service delivery. Scenarios should be challenging enough to test your capabilities meaningfully while remaining within the bounds of what could plausibly occur.
Threat intelligence informs scenario development. What types of incidents are affecting similar organisations? What emerging threats could affect your operations? This external perspective helps ensure scenarios remain current and relevant.
Internal vulnerabilities shape how scenarios would affect your organisation specifically. A technology failure at a particular supplier might be severe for your organisation but irrelevant to others. Understanding your specific dependencies is essential for developing meaningful scenarios.
Historical incidents, both your own and those of peers, provide useful input. What has actually happened to similar organisations? How did those incidents unfold? What made the difference between organisations that coped well and those that struggled?
Regulators expect scenarios to evolve over time. As your organisation changes and as the threat landscape develops, your scenarios should be updated accordingly. Testing against the same scenarios year after year does not demonstrate dynamic resilience capability.
Documentation and Evidence Requirements
Regulatory expectations extend beyond conducting tests to maintaining comprehensive documentation of testing activities and outcomes. This documentation provides evidence of compliance and supports ongoing capability development.
Test planning documentation should explain how scenarios were selected, what they are designed to test, and how testing fits into the broader resilience programme. Regulators want to see that testing is systematic and purposeful rather than ad hoc.
Test execution records should capture what happened during testing. What actions were taken? What decisions were made? Where did the organisation succeed and where did it struggle? Detailed records enable meaningful analysis and demonstrate the rigour of testing.
Findings and action tracking demonstrate that testing leads to improvement. Tests invariably identify gaps and weaknesses. Documenting these findings and tracking remediation actions shows that testing drives genuine enhancement of resilience capabilities.
Board reporting provides evidence that senior leadership maintains appropriate oversight. Regulators expect boards to receive regular information about operational resilience including testing activities, outcomes, and improvement actions.
Common Gaps Identified in Regulatory Assessments
Regulatory assessments have identified several common gaps in firms operational resilience testing programmes. Understanding these gaps helps you avoid similar problems.
Testing scope is sometimes too narrow. Firms may test some aspects of their important business services while leaving others unexamined. Complete testing should cover all critical resources including technology, people, premises, and third parties.
Scenario severity is often insufficient. Tests that do not genuinely challenge the organisation fail to identify real weaknesses and do not satisfy regulatory expectations. There is a natural tendency to design tests that the organisation will pass, but this defeats the purpose.
Third-party testing receives inadequate attention. Many important business services depend heavily on external providers. Testing must include scenarios that affect third-party service delivery and must verify that contractual resilience commitments can actually be delivered.
Documentation gaps make it difficult to demonstrate compliance. Even when good testing occurs, inadequate records can leave firms unable to evidence their activities to regulators. Documentation should be a built-in part of testing processes, not an afterthought.
Follow-through on findings is sometimes lacking. Identifying gaps through testing is only valuable if those gaps are then addressed. Regulators look for evidence that testing drives genuine improvement, not just a list of unresolved issues.
Building a Sustainable Testing Programme
Meeting regulatory requirements demands more than occasional testing exercises. Firms need sustainable programmes that deliver appropriate testing on an ongoing basis while managing resource demands.
Multi-year planning helps distribute testing effort appropriately. Not everything needs testing every year, but important areas should not go too long between tests. A rolling programme ensures comprehensive coverage over time while keeping annual demands manageable.
Integration with change management embeds resilience testing into business as usual. When significant changes occur to important business services or their supporting resources, testing should validate that resilience has been maintained.
Capability building ensures you have the skills to conduct effective testing. This includes both internal expertise and access to specialist support when needed. Testing done poorly is worse than useless because it provides false confidence.
Getting Specialist Support
The complexity of regulatory requirements and the practical challenges of effective testing mean that many firms benefit from specialist support. Our Certified Operational Resilience Manager training provides comprehensive coverage of regulatory requirements and practical approaches to building compliant testing programmes. Our Testing and Exercising services can help you design and deliver effective tests that satisfy regulatory expectations while building genuine resilience capability.
Meeting FCA and PRA operational resilience requirements is demanding but achievable. With the right approach to testing and appropriate investment in capability, firms can satisfy regulators while building genuine confidence in their ability to maintain services through disruption.
Related services
More insights
Keep reading.
Related thinking from the Oakwood team.
Operational resilience: what 'beyond March 2025' actually looks like
The FCA's transitional period has closed. The interesting question now isn't whether you're compliant — it's whether the framework you built is doing any real work.
Supply chain resilience: five lessons from a disruptive 2025
From Red Sea disruption to concentrated cloud outages, last year was an unusually clean test of how resilient your suppliers really are. The results were not flattering.
Why most business continuity plans fail under pressure
The plan is rarely the problem. The problem is the gap between the document and the organisation's ability to operate it.
