Skip to main content

Building a Cross-Jurisdictional Governance Case for Operational Resilience

This guide sets out how to construct a governance case for an operational resilience framework that holds up across multiple supervisory regimes at a global bank. After reading, you will know how to sequence the work, resolve regime conflicts, and present a coherent story to your board and lead regulators.

Start with the regime map, not the framework

Most global banks approach operational resilience by picking a lead regime, usually the PRA/FCA rules or DORA, and retrofitting other jurisdictions to it. That is where the governance case falls apart. Supervisors in Singapore, Hong Kong, New York and Sydney read your framework through their own lens, and inconsistencies become the story.

Before you draft anything for the board, produce a one-page regime map showing, per jurisdiction: the definition of an important business service (or its equivalent), tolerance-setting expectations, third-party requirements, testing standards, and reporting obligations. Mark where they conflict, not just where they overlap. The conflicts are what your governance case has to resolve.

Decide what "one framework" actually means

The hardest judgement is how much to centralise. Three models tend to work:

  • Group standard with local overlays. Group sets minimum requirements; local entities add jurisdiction-specific controls. Cleanest for boards, hardest for local CROs who bear personal accountability under regimes like SMCR or HKMA MIC.
  • Federated with common taxonomy. Each entity runs its own framework, but definitions, severity scales and tolerance methodologies are shared. Easier politically, weaker under group supervisory review.
  • Fully centralised with delegated execution. Group owns the framework end-to-end; local entities execute. Efficient, but exposes you when a local regulator wants evidence of independent local judgement.

Pick deliberately. The wrong answer is a hybrid nobody can articulate. Boards and supervisors will both press you to explain, in one sentence, who owns what.

Resolve the tolerance problem before the board sees it

Impact tolerances are where cross-jurisdictional frameworks break. A payments service may be an important business service in the UK, a critical function under DORA, and neither formally in a third jurisdiction where it is still material. If your tolerances differ by entity for the same underlying service, you need a defensible reason, not an accident of local drafting.

Good practice: set a group-level tolerance based on the most conservative regime, then document why any local tolerance sits inside it. Bad practice: let each entity set its own and hope the aggregation works. It will not survive a joint supervisory college.

Build the accountability spine

Regulators care less about your framework document than about who is accountable when it fails. Map, for every important business service, the group-level owner, the local senior manager function or equivalent, and the escalation path between them. Where a service crosses entities, name a single accountable executive and get the local board to acknowledge it in writing.

This is where most banks quietly fail. The framework looks coherent on paper, but when you ask who would be personally on the hook for a specific outage, three names come up and none of them have the authority to fix it.

Sequence the board conversation

The governance case needs three separate board moments, not one:

  1. Scope and model choice. Board agrees the operating model (centralised, federated, hybrid) and the rationale. Do this before any framework detail. If the board approves the framework without owning the model choice, they cannot defend it later.
  2. Tolerances and material services. Board reviews the list of important business services and the tolerance methodology. This is where non-executives should push hardest.
  3. Assurance and testing plan. Board signs off on how the framework will be tested, including severe-but-plausible scenarios that span jurisdictions.

Running these together produces a rubber-stamp discussion. Splitting them forces the judgement calls into the open.

Anticipate the supervisory college

Assume your lead regulator will share your framework with peers. Write it so that a supervisor in Frankfurt, Singapore or New York reading it cold can find their regime reflected without hunting. A short jurisdictional annex per entity, cross-referenced to the group framework, is worth more than a beautifully drafted group document that requires translation.

What good looks like

A general counsel or CRO who can, in a single meeting, explain the operating model choice, point to the accountable executive for any material service, and show how tolerances reconcile across regimes. If any of those three cannot be done in under two minutes, the framework is not yet governance-ready.

Next decision: before commissioning further drafting, get the executive committee to commit to one of the three operating models. Everything else follows from that choice.

Related guides

Boards, Governance & Defensibility

How to Design a Board Risk Appetite Statement That Actually Works

This guide sets out how to build a risk appetite statement that satisfies PRA supervisors while giving non-executive directors something they can genuinely use in the boardroom. Readers will finish with a clear method for calibrating metrics, structuring the document, and avoiding the drafting mistakes that trigger supervisory challenge.

Regulatory changeBoardsRegulators
4 min readRead guide →
Boards, Governance & Defensibility

How to Design a Board-Level Climate Risk Governance Framework That Withstands Supervisory Scrutiny

This guide sets out how to build a board-level climate risk governance framework that holds up under PRA, FCA, ECB or equivalent supervisory review. After reading, you will know where most frameworks fail on inspection and how to structure yours so it does not.

Regulatory changeBoardsRegulators
3 min readRead guide →
Regulation & Regulatory Change

Stakeholder Risk Management for FCA Regulated Firms: A Practical Guide

This guide sets out how senior leaders at FCA regulated firms should identify, assess and manage stakeholder risk in a way that stands up to supervisory scrutiny. After reading, you will know how to structure a stakeholder risk framework that connects to Consumer Duty, SM&CR accountability and board-level reporting.

Regulatory changeRegulatorsBoards
3 min readRead guide →
Regulation & Regulatory Change

How to Structure a Wind-Down Plan That Satisfies FCA Solvent Exit Expectations

This guide explains how to build a Wind-Down Plan that meets FCA solvent exit expectations under WDPG and the new solvent exit rules, without inadvertently signalling going concern doubt to auditors or counterparties. Readers will learn how to sequence triggers, resources and disclosures so the plan is credible to supervisors but ring-fenced from financial reporting consequences.

Regulatory submissionRegulatory changeRegulators
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Threshold Conditions Self-Assessment That Pre-empts FCA Withdrawal Risk

This guide sets out how boards and senior managers should structure a Threshold Conditions self-assessment that identifies authorisation withdrawal risk before the FCA does. After reading, you will know how to sequence the assessment, where the real judgement calls sit, and what evidence a supervisor expects to see.

Regulatory submissionRegulatorsBoards
4 min readRead guide →

Polar Insight helps senior leaders in financial services understand what their key stakeholders actually think before significant decisions are made.