Skip to main content

How to Structure an Operational Resilience Self-Assessment That Withstands Regulator Challenge

This guide sets out how to build an operational resilience self-assessment that holds up to FCA and PRA impact tolerance scrutiny. After reading, senior leaders will know how to sequence evidence, frame judgements, and pre-empt the challenges supervisors are most likely to raise.

The March 2025 deadline has passed, but the self-assessment is not a static artefact. Supervisors are now moving from checking that firms have one to testing whether the judgements inside it survive contact with reality. If your document reads like a compliance narrative rather than a board-owned view of where the firm would actually break, you should expect challenge.

Key Executive Takeaways

  • Impact tolerances must be justified by harm to consumers, market integrity, or safety and soundness, not by internal recovery capability or what the firm happens to be able to deliver.
  • Mapping and scenario testing evidence should demonstrate where you cannot yet remain within tolerance, and what you are doing about it, gaps disclosed are gaps defended.
  • The self-assessment is a board document. If the board cannot speak fluently to the vulnerabilities, sequencing of remediation, and residual risk, the document will not survive supervisory conversation.

Start with the harm, not the service

The most common structural weakness is defining impact tolerances based on what the firm can achieve rather than the point at which intolerable harm crystallises. Regulators read tolerances backwards: they start with the harm and ask whether your number prevents it. If your payments service tolerance is 24 hours because that is what your recovery playbook delivers, you have inverted the logic.

Good practice: for each important business service, document the specific harm vectors (financial loss, access to funds, market disruption, safeguarding failures) and the point at which each becomes intolerable. Then set the tolerance at the tightest of those points. Show your working.

Map to the point of failure, not the point of comfort

Mapping should be granular enough to identify single points of failure, third and fourth party concentrations, and shared resources across services. A map that stops at the vendor name is insufficient. Supervisors want to see the underlying infrastructure, the people dependencies, the data flows, and the substitutability assessment.

Where you rely on a critical third party, name the concentration risk. Where you share a core platform across multiple important business services, show the correlated failure mode. Firms that present clean maps with no concentrations are either unusually well-architected or, more often, not looking hard enough.

Scenario testing that actually tests

The FCA and PRA are increasingly sceptical of scenario libraries that conveniently demonstrate compliance. A credible testing programme includes at least one severe but plausible scenario per important business service, tests the tolerance boundary rather than a comfortable middle case, and includes scenarios the firm expects to fail.

Cyber ransomware, third party insolvency, and simultaneous disruption across correlated services should feature. Document what happened in the test, where recovery times exceeded tolerance, and what specifically will change. A test that shows everything worked is either a bad test or a bad narrative of a good test.

Disclose vulnerabilities, do not bury them

The most counterintuitive point: firms that openly disclose where they cannot yet remain within impact tolerance, with a credible remediation plan and interim risk mitigation, fare better than firms that claim full compliance. Supervisors know the population. They know which services are hard to secure within tight tolerances. A self-assessment claiming universal compliance triggers suspicion; one that identifies three residual gaps with dated remediation and board oversight signals maturity.

Make the board's voice audible

The self-assessment must be approved by the board, and supervisors will test whether the board actually engaged. Include evidence of specific challenge: which tolerances did the board push back on, which scenarios did they commission, which investment decisions did they take as a result. A minutes reference is not enough. If the SMF24 or board chair cannot articulate the top three vulnerabilities and the mitigation timeline in a supervisory meeting, the document fails.

What to do next

Before your next supervisory touchpoint, run a red team read of the current self-assessment against three questions: does every tolerance tie to a specific harm, does every map expose rather than obscure concentration, and does every scenario test the boundary. If any answer is no, the document is not yet ready for challenge.

Frequently Asked Questions

How often should the self-assessment be refreshed?

At minimum annually, but any material change to services, third parties, technology architecture, or the threat environment should trigger an interim update. Supervisors expect the document to reflect current reality, not last year's operating model.

Should we align FCA and PRA self-assessments for dual-regulated firms?

Yes, one document with clearly signposted sections addressing each regulator's specific expectations. Divergent narratives create risk when supervisors compare notes, which they do.

What is the right length?

Length is a poor proxy for quality. What matters is that a supervisor can find the tolerance rationale, the mapping evidence, the testing results, and the remediation plan for any important business service within minutes. If they cannot, structure is the problem.

How do we handle services where we depend on a critical third party we cannot substitute?

Name it, quantify the risk, document the contractual and operational controls, and set out the contingency. Pretending substitutability exists when it does not is the fastest route to supervisory challenge.

What role should internal audit play?

Independent assurance over the self-assessment itself, not just the underlying processes. Audit opinion on the credibility of tolerances and testing carries weight with supervisors and should be referenced in the document.

Frequently asked questions

How often should the self-assessment be refreshed?

At minimum annually, but any material change to services, third parties, technology architecture, or the threat environment should trigger an interim update. Supervisors expect the document to reflect current reality, not last year's operating model.

Should we align FCA and PRA self-assessments for dual-regulated firms?

Yes, one document with clearly signposted sections addressing each regulator's specific expectations. Divergent narratives create risk when supervisors compare notes, which they do.

What is the right length?

Length is a poor proxy for quality. What matters is that a supervisor can find the tolerance rationale, the mapping evidence, the testing results, and the remediation plan for any important business service within minutes. If they cannot, structure is the problem.

How do we handle services where we depend on a critical third party we cannot substitute?

Name it, quantify the risk, document the contractual and operational controls, and set out the contingency. Pretending substitutability exists when it does not is the fastest route to supervisory challenge.

What role should internal audit play?

Independent assurance over the self-assessment itself, not just the underlying processes. Audit opinion on the credibility of tolerances and testing carries weight with supervisors and should be referenced in the document.

Related guides

Regulation & Regulatory Change

How to Structure a Pillar 2 Liquidity Narrative That Anticipates PRA ILAAP Challenge

This guide sets out how to build an ILAAP liquidity narrative that pre-empts the specific challenges PRA supervisors raise on Pillar 2 risks. After reading, senior leaders will know how to sequence the document, where to concentrate evidence, and how to defend judgement calls under supervisory pressure.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Solvency II ORSA Narrative That Pre-empts PRA Capital Challenge

This guide sets out how to build an ORSA narrative that anticipates PRA scrutiny on capital adequacy, risk quantification, and management action credibility. After reading it, senior insurance leaders will know how to sequence the document, evidence key judgements, and close the gaps supervisors most often probe.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Close a Dear CEO Letter Without Inviting Follow-Up

This guide sets out how to structure a response to a Dear CEO letter that answers the supervisor's concerns cleanly and reduces the odds of a second-round information request. It covers what to include, what to leave out, and the judgement calls that separate a closing response from one that opens new fronts.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a MIFIDPRU ICARA That Withstands FCA Prudential Review

This guide sets out how to build an ICARA document that answers the questions FCA supervisors actually ask, rather than reciting the rulebook. After reading, you will know where to place the analytical weight, how to sequence the harm assessment, and how to defend your own funds and liquid assets threshold requirements under challenge.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure an ICAAP Narrative That Pre-empts PRA Capital Add-on Challenge

This guide sets out how to build an ICAAP narrative that anticipates supervisory challenge and reduces the probability of a Pillar 2A or PRA buffer add-on. It shows senior leaders where to place the argument, what to concede early, and how to sequence evidence so the SREP dialogue starts on your terms.

Regulatory submissionRegulatorsBoards
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity