Skip to main content

How to Build a Credible Operational Resilience Self-Assessment

This guide sets out how to produce an operational resilience self-assessment that stands up to board challenge and supervisory review. After reading it, senior leaders will know how to structure the document, where the evidence typically falls short, and how to demonstrate genuine capability rather than paper compliance.

The self-assessment is the single artefact that tells your board and supervisor whether operational resilience is real inside your firm or performative. Under SS1/21 and PS6/21, firms have now passed the March 2025 threshold: important business services must remain within impact tolerance through severe but plausible scenarios. Supervisors are no longer interested in how you built the framework. They want to see that it works, that you know where it doesn't, and that you are honest about the gap.

Key Executive Takeaways

  • A credible self-assessment is a decision document, not a status report: it must show what the board concluded, what evidence it relied on, and what it committed to fix.
  • Vulnerabilities identified through mapping and scenario testing are the most scrutinised section: understating them destroys credibility faster than admitting them.
  • The quality of the self-assessment is judged by the traceability between important business services, tolerances, third parties, scenarios, and remediation plans, not by length or polish.

Start with the story the document has to tell

Before drafting, decide what the self-assessment is arguing. It should answer four questions in sequence: Which services matter, and why those? What would unacceptable harm look like, and how have we set tolerances against it? Can we stay within those tolerances today, and how do we know? Where we cannot, what are we doing, by when, and who owns it?

If the document does not answer these cleanly, no amount of appendices will save it. The most common failure is a self-assessment that describes the framework rather than concluding on resilience.

Get the important business services right

Supervisors probe IBS selection hardest. Firms that list too many services dilute focus. Firms that list too few look defensive. The test is intolerable harm to consumers or market integrity, not internal materiality. Document why services were included and, critically, why plausible candidates were excluded. Revisit the list annually and after any material change: acquisitions, product launches, outsourcing shifts.

Set impact tolerances the board can defend

Tolerances expressed only in time (for example, "24 hours") are usually inadequate. Good tolerances combine time with a second dimension: transaction volume, customer segments affected, financial loss, or data exposure. The board should be able to explain why the tolerance sits where it does, referencing customer harm analysis, not operational convenience. If your tolerance was calibrated to what the firm can currently deliver, expect that to be identified.

Make mapping the evidence base, not a diagram

End-to-end mapping is where most self-assessments quietly fall apart. The map must reach through to specific people, applications, facilities, data flows, and third and fourth parties. Concentration risks, single points of failure, and legacy dependencies should be named. If your mapping stops at "Vendor X provides payments processing," you have not mapped. Supervisors expect to see which of Vendor X's sites, which sub-processors, and which contractual recovery commitments sit behind that service.

Test scenarios that could actually break you

Scenario testing is judged by severity and honesty. Weak self-assessments run scenarios the firm can pass. Strong ones deliberately design scenarios that expose the tolerance, then report what happened. Cyber, third-party failure, and people unavailability should all feature. Include at least one scenario where you breach tolerance and explain what you learned. A clean sweep of successful tests is a red flag, not a strength.

Be specific about vulnerabilities and remediation

This is the section the PRA and FCA read most carefully. Each vulnerability should be described in plain language, rated, linked to the affected IBS, assigned to a named accountable executive under SM&CR, and given a dated remediation plan with interim mitigations. Vague commitments ("enhance monitoring in H2") are worse than admitting the problem is unsolved. If remediation extends beyond twelve months, explain why and what compensating controls are in place.

Show the board actually engaged

Minutes should reflect challenge, not endorsement. Include evidence of where the board pushed back on tolerances, questioned scenario design, or required additional testing. A self-assessment that arrives at the board finished, is noted, and disappears will not survive supervisory questioning about governance.

Next step

Before your next submission, read your current self-assessment as a supervisor would. If you cannot trace a single customer, through an IBS, to a tolerance, to a mapped dependency, to a tested scenario, to a named remediation owner, you have work to do before the document leaves the building.

Frequently Asked Questions

How long should a self-assessment be?

Length is not the measure. Traceability and conclusions are. Most credible documents for mid-sized firms run 60 to 120 pages including annexes. Beyond that, clarity usually suffers.

Who should own the drafting?

The accountable SMF should own the conclusions. Drafting is typically led by the operational resilience function with heavy input from technology, operations, and risk. Second line should challenge, not co-author.

How do we handle vulnerabilities we cannot fix quickly?

Name them, explain the constraint, describe compensating controls, and give a realistic timeline. Supervisors respond far better to honest, funded, dated plans than to optimistic ones that slip.

How often should the self-assessment be refreshed?

At minimum annually, and after any material change to services, third parties, technology estate, or following a significant incident or near miss.

What role should internal audit play?

Internal audit should provide independent assurance over the self-assessment process and the reliability of the evidence, particularly mapping and scenario testing. Their opinion should be referenced in the board's conclusions.

Frequently asked questions

How long should a self-assessment be?

Length is not the measure. Traceability and conclusions are. Most credible documents for mid-sized firms run 60 to 120 pages including annexes. Beyond that, clarity usually suffers.

Who should own the drafting?

The accountable SMF should own the conclusions. Drafting is typically led by the operational resilience function with heavy input from technology, operations, and risk. Second line should challenge, not co-author.

How do we handle vulnerabilities we cannot fix quickly?

Name them, explain the constraint, describe compensating controls, and give a realistic timeline. Supervisors respond far better to honest, funded, dated plans than to optimistic ones that slip.

How often should the self-assessment be refreshed?

At minimum annually, and after any material change to services, third parties, technology estate, or following a significant incident or near miss.

What role should internal audit play?

Internal audit should provide independent assurance over the self-assessment process and the reliability of the evidence, particularly mapping and scenario testing. Their opinion should be referenced in the board's conclusions.

Related guides

Regulation & Regulatory Change

Structuring a Threshold Conditions Self-Assessment That Evidences Ongoing Compliance

This guide sets out how to structure a Threshold Conditions self-assessment that credibly evidences continued satisfaction of FSMA Schedule 6 and COND, while surfacing resource or business model pressures honestly and with a clear remediation path. Readers will finish able to commission, review, and sign off a document that stands up to supervisory scrutiny and supports genuine board oversight.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Prepare a Credible SM&CR Statement of Responsibilities Update After a Senior Hire

A practical guide to producing an accurate, defensible Statement of Responsibilities update when a Senior Manager joins or changes role. Readers will finish knowing how to sequence the drafting, capture handovers cleanly, and submit something that stands up to FCA scrutiny.

Regulatory submissionOrganisational changeRegulators
4 min read · Step by stepRead guide →
Boards, Governance & Defensibility

How to Design a Board-Approved Recovery Plan That Meets PRA Resolvability Expectations

This guide sets out how to build a recovery plan that credibly satisfies the PRA's resolvability expectations and earns genuine board ownership. After reading, you will know how to sequence the work, sharpen the judgement calls, and avoid the drafting habits that undermine credibility with supervisors.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Build a Regulator-Ready Wind-Down Plan That Demonstrates Operational Credibility

This guide sets out how to build a wind-down plan that stands up to regulatory challenge and reflects genuine operational capability. Readers will finish with a clear view of what makes a plan credible, where firms typically fall short, and what to fix first.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

How to Build a Credible Consumer Duty Board Report That Withstands FCA Scrutiny

This guide sets out how to produce an annual Consumer Duty board report that demonstrates genuine oversight, not compliance theatre. After reading, you will know how to structure evidence, handle uncomfortable findings, and give the board a document that stands up to supervisory challenge.

Regulatory submissionRegulatorsBoards
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity