How to Build a Credible Operational Resilience Self-Assessment
This guide sets out how to produce an operational resilience self-assessment that stands up to board challenge and supervisory review. After reading it, senior leaders will know how to structure the document, where the evidence typically falls short, and how to demonstrate genuine capability rather than paper compliance.
The self-assessment is the single artefact that tells your board and supervisor whether operational resilience is real inside your firm or performative. Under SS1/21 and PS6/21, firms have now passed the March 2025 threshold: important business services must remain within impact tolerance through severe but plausible scenarios. Supervisors are no longer interested in how you built the framework. They want to see that it works, that you know where it doesn't, and that you are honest about the gap.
Key Executive Takeaways
- A credible self-assessment is a decision document, not a status report: it must show what the board concluded, what evidence it relied on, and what it committed to fix.
- Vulnerabilities identified through mapping and scenario testing are the most scrutinised section: understating them destroys credibility faster than admitting them.
- The quality of the self-assessment is judged by the traceability between important business services, tolerances, third parties, scenarios, and remediation plans, not by length or polish.
Start with the story the document has to tell
Before drafting, decide what the self-assessment is arguing. It should answer four questions in sequence: Which services matter, and why those? What would unacceptable harm look like, and how have we set tolerances against it? Can we stay within those tolerances today, and how do we know? Where we cannot, what are we doing, by when, and who owns it?
If the document does not answer these cleanly, no amount of appendices will save it. The most common failure is a self-assessment that describes the framework rather than concluding on resilience.
Get the important business services right
Supervisors probe IBS selection hardest. Firms that list too many services dilute focus. Firms that list too few look defensive. The test is intolerable harm to consumers or market integrity, not internal materiality. Document why services were included and, critically, why plausible candidates were excluded. Revisit the list annually and after any material change: acquisitions, product launches, outsourcing shifts.
Set impact tolerances the board can defend
Tolerances expressed only in time (for example, "24 hours") are usually inadequate. Good tolerances combine time with a second dimension: transaction volume, customer segments affected, financial loss, or data exposure. The board should be able to explain why the tolerance sits where it does, referencing customer harm analysis, not operational convenience. If your tolerance was calibrated to what the firm can currently deliver, expect that to be identified.
Make mapping the evidence base, not a diagram
End-to-end mapping is where most self-assessments quietly fall apart. The map must reach through to specific people, applications, facilities, data flows, and third and fourth parties. Concentration risks, single points of failure, and legacy dependencies should be named. If your mapping stops at "Vendor X provides payments processing," you have not mapped. Supervisors expect to see which of Vendor X's sites, which sub-processors, and which contractual recovery commitments sit behind that service.
Test scenarios that could actually break you
Scenario testing is judged by severity and honesty. Weak self-assessments run scenarios the firm can pass. Strong ones deliberately design scenarios that expose the tolerance, then report what happened. Cyber, third-party failure, and people unavailability should all feature. Include at least one scenario where you breach tolerance and explain what you learned. A clean sweep of successful tests is a red flag, not a strength.
Be specific about vulnerabilities and remediation
This is the section the PRA and FCA read most carefully. Each vulnerability should be described in plain language, rated, linked to the affected IBS, assigned to a named accountable executive under SM&CR, and given a dated remediation plan with interim mitigations. Vague commitments ("enhance monitoring in H2") are worse than admitting the problem is unsolved. If remediation extends beyond twelve months, explain why and what compensating controls are in place.
Show the board actually engaged
Minutes should reflect challenge, not endorsement. Include evidence of where the board pushed back on tolerances, questioned scenario design, or required additional testing. A self-assessment that arrives at the board finished, is noted, and disappears will not survive supervisory questioning about governance.
Next step
Before your next submission, read your current self-assessment as a supervisor would. If you cannot trace a single customer, through an IBS, to a tolerance, to a mapped dependency, to a tested scenario, to a named remediation owner, you have work to do before the document leaves the building.
Frequently Asked Questions
How long should a self-assessment be?
Length is not the measure. Traceability and conclusions are. Most credible documents for mid-sized firms run 60 to 120 pages including annexes. Beyond that, clarity usually suffers.
Who should own the drafting?
The accountable SMF should own the conclusions. Drafting is typically led by the operational resilience function with heavy input from technology, operations, and risk. Second line should challenge, not co-author.
How do we handle vulnerabilities we cannot fix quickly?
Name them, explain the constraint, describe compensating controls, and give a realistic timeline. Supervisors respond far better to honest, funded, dated plans than to optimistic ones that slip.
How often should the self-assessment be refreshed?
At minimum annually, and after any material change to services, third parties, technology estate, or following a significant incident or near miss.
What role should internal audit play?
Internal audit should provide independent assurance over the self-assessment process and the reliability of the evidence, particularly mapping and scenario testing. Their opinion should be referenced in the board's conclusions.
Frequently asked questions
How long should a self-assessment be?
Length is not the measure. Traceability and conclusions are. Most credible documents for mid-sized firms run 60 to 120 pages including annexes. Beyond that, clarity usually suffers.
Who should own the drafting?
The accountable SMF should own the conclusions. Drafting is typically led by the operational resilience function with heavy input from technology, operations, and risk. Second line should challenge, not co-author.
How do we handle vulnerabilities we cannot fix quickly?
Name them, explain the constraint, describe compensating controls, and give a realistic timeline. Supervisors respond far better to honest, funded, dated plans than to optimistic ones that slip.
How often should the self-assessment be refreshed?
At minimum annually, and after any material change to services, third parties, technology estate, or following a significant incident or near miss.
What role should internal audit play?
Internal audit should provide independent assurance over the self-assessment process and the reliability of the evidence, particularly mapping and scenario testing. Their opinion should be referenced in the board's conclusions.
Related guides
Structuring a Threshold Conditions Self-Assessment That Evidences Ongoing Compliance
This guide sets out how to structure a Threshold Conditions self-assessment that credibly evidences continued satisfaction of FSMA Schedule 6 and COND, while surfacing resource or business model pressures honestly and with a clear remediation path. Readers will finish able to commission, review, and sign off a document that stands up to supervisory scrutiny and supports genuine board oversight.
How to Prepare a Credible SM&CR Statement of Responsibilities Update After a Senior Hire
A practical guide to producing an accurate, defensible Statement of Responsibilities update when a Senior Manager joins or changes role. Readers will finish knowing how to sequence the drafting, capture handovers cleanly, and submit something that stands up to FCA scrutiny.
How to Design a Board-Approved Recovery Plan That Meets PRA Resolvability Expectations
This guide sets out how to build a recovery plan that credibly satisfies the PRA's resolvability expectations and earns genuine board ownership. After reading, you will know how to sequence the work, sharpen the judgement calls, and avoid the drafting habits that undermine credibility with supervisors.
How to Build a Regulator-Ready Wind-Down Plan That Demonstrates Operational Credibility
This guide sets out how to build a wind-down plan that stands up to regulatory challenge and reflects genuine operational capability. Readers will finish with a clear view of what makes a plan credible, where firms typically fall short, and what to fix first.
How to Build a Credible Consumer Duty Board Report That Withstands FCA Scrutiny
This guide sets out how to produce an annual Consumer Duty board report that demonstrates genuine oversight, not compliance theatre. After reading, you will know how to structure evidence, handle uncomfortable findings, and give the board a document that stands up to supervisory challenge.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity