Skip to main content

Building a Cross-Jurisdictional Governance Case for Operational Resilience

This guide sets out how to construct a governance case for an operational resilience framework that holds up across multiple supervisory regimes at a global bank. After reading, you will know how to sequence the work, resolve regime conflicts, and present a coherent story to your board and lead regulators.

Start with the regime map, not the framework

Most global banks approach operational resilience by picking a lead regime, usually the PRA/FCA rules or DORA, and retrofitting other jurisdictions to it. That is where the governance case falls apart. Supervisors in Singapore, Hong Kong, New York and Sydney read your framework through their own lens, and inconsistencies become the story.

Before you draft anything for the board, produce a one-page regime map showing, per jurisdiction: the definition of an important business service (or its equivalent), tolerance-setting expectations, third-party requirements, testing standards, and reporting obligations. Mark where they conflict, not just where they overlap. The conflicts are what your governance case has to resolve.

Decide what "one framework" actually means

The hardest judgement is how much to centralise. Three models tend to work:

  • Group standard with local overlays. Group sets minimum requirements; local entities add jurisdiction-specific controls. Cleanest for boards, hardest for local CROs who bear personal accountability under regimes like SMCR or HKMA MIC.
  • Federated with common taxonomy. Each entity runs its own framework, but definitions, severity scales and tolerance methodologies are shared. Easier politically, weaker under group supervisory review.
  • Fully centralised with delegated execution. Group owns the framework end-to-end; local entities execute. Efficient, but exposes you when a local regulator wants evidence of independent local judgement.

Pick deliberately. The wrong answer is a hybrid nobody can articulate. Boards and supervisors will both press you to explain, in one sentence, who owns what.

Resolve the tolerance problem before the board sees it

Impact tolerances are where cross-jurisdictional frameworks break. A payments service may be an important business service in the UK, a critical function under DORA, and neither formally in a third jurisdiction where it is still material. If your tolerances differ by entity for the same underlying service, you need a defensible reason, not an accident of local drafting.

Good practice: set a group-level tolerance based on the most conservative regime, then document why any local tolerance sits inside it. Bad practice: let each entity set its own and hope the aggregation works. It will not survive a joint supervisory college.

Build the accountability spine

Regulators care less about your framework document than about who is accountable when it fails. Map, for every important business service, the group-level owner, the local senior manager function or equivalent, and the escalation path between them. Where a service crosses entities, name a single accountable executive and get the local board to acknowledge it in writing.

This is where most banks quietly fail. The framework looks coherent on paper, but when you ask who would be personally on the hook for a specific outage, three names come up and none of them have the authority to fix it.

Sequence the board conversation

The governance case needs three separate board moments, not one:

  1. Scope and model choice. Board agrees the operating model (centralised, federated, hybrid) and the rationale. Do this before any framework detail. If the board approves the framework without owning the model choice, they cannot defend it later.
  2. Tolerances and material services. Board reviews the list of important business services and the tolerance methodology. This is where non-executives should push hardest.
  3. Assurance and testing plan. Board signs off on how the framework will be tested, including severe-but-plausible scenarios that span jurisdictions.

Running these together produces a rubber-stamp discussion. Splitting them forces the judgement calls into the open.

Anticipate the supervisory college

Assume your lead regulator will share your framework with peers. Write it so that a supervisor in Frankfurt, Singapore or New York reading it cold can find their regime reflected without hunting. A short jurisdictional annex per entity, cross-referenced to the group framework, is worth more than a beautifully drafted group document that requires translation.

What good looks like

A general counsel or CRO who can, in a single meeting, explain the operating model choice, point to the accountable executive for any material service, and show how tolerances reconcile across regimes. If any of those three cannot be done in under two minutes, the framework is not yet governance-ready.

Next decision: before commissioning further drafting, get the executive committee to commit to one of the three operating models. Everything else follows from that choice.

Related guides

Boards, Governance & Defensibility

How to Design a Board-Level Climate Risk Governance Framework That Withstands Supervisory Scrutiny

This guide sets out how to build a board-level climate risk governance framework that holds up under PRA, FCA, ECB or equivalent supervisory review. After reading, you will know where most frameworks fail on inspection and how to structure yours so it does not.

Regulatory changeBoardsRegulators
3 min readRead guide →
Regulation & Regulatory Change

Stakeholder Risk Management for FCA Regulated Firms: A Practical Guide

This guide sets out how senior leaders at FCA regulated firms should identify, assess and manage stakeholder risk in a way that stands up to supervisory scrutiny. After reading, you will know how to structure a stakeholder risk framework that connects to Consumer Duty, SM&CR accountability and board-level reporting.

Regulatory changeRegulatorsBoards
3 min readRead guide →
Boards, Governance & Defensibility

Positioning a Consumer Duty Review for Board and Regulator Audiences

This guide sets out how to structure a Consumer Duty implementation review so it works for both your board and the FCA without compromising either audience. You will finish with a clear approach to framing, evidence, and sequencing that avoids the common trap of producing two conflicting narratives.

Regulatory submissionBoardsRegulators
3 min readRead guide →
Boards, Governance & Defensibility

Regulated Industry Governance Best Practice: A Practical Guide

This guide sets out what good governance actually looks like in a regulated business, covering board composition, decision records, regulator relationships, and the failure modes that trigger enforcement. After reading, you will be able to pressure-test your current governance model against the standards regulators now apply in practice.

BoardsRegulatorsExecutive teams
3 min readRead guide →
Regulation & Regulatory Change

How to Prepare for an FCA Supervisory Visit

A practical guide to preparing for an FCA supervisory visit, from interpreting the scoping letter to managing the day itself and the follow-up. After reading, you will know what good preparation looks like, where firms typically slip, and how to position your firm to come out of the visit stronger.

Regulatory submissionRegulatorsBoards
3 min readRead guide →

Polar Insight helps senior leaders in financial services understand what their key stakeholders actually think before significant decisions are made.

Book a conversation