A disruption rarely arrives as a neat operational issue. It starts with a failed payment run, a customer portal outage, or missing data in a core workflow. Within hours, it becomes a finance problem, a governance problem, and often a dispute problem.
Directors then face the same hard questions. What failed. Which service was affected. How long were customers impacted. Did a supplier trigger the issue. Is there a fraud angle. What loss did the business suffer. And, what evidence can you put in front of the FCA, insurers, auditors, lawyers, or the board that will stand up to scrutiny.
That's where FCA operational resilience stops being a compliance slogan and becomes a practical test of control, documentation, and financial proof.
The Hidden Crisis That Disrupts UK Businesses
A Monday morning outage exposes more than weak technology. It exposes weak evidence.
One firm loses access to customer records. Another can't process transactions because an outsourced platform fails. A third discovers that the service interruption didn't just delay operations. It also triggered manual workarounds, payment errors, internal control gaps, and arguments with a supplier over responsibility. By the time management gets a first incident update, the business is already dealing with commercial fallout.
What usually goes wrong first
The immediate instinct is to treat the event as an IT recovery job. That's too narrow.
A serious disruption often creates several parallel problems:
- Financial loss uncertainty: Finance teams know revenue or cash flow has been affected, but they can't yet quantify the loss in a way that supports an insurance claim, board paper, or regulatory response.
- Supplier accountability gaps: Contracts, service schedules, operational records, and incident logs rarely line up neatly when a third party is involved.
- Control failures: Manual overrides, emergency access, and rushed reconciliations can create openings for error, misconduct, or a later fraud investigation.
- Dispute risk: Once losses emerge, legal and commercial teams need a clear evidential trail. Without it, recovery from suppliers, insurers, or counterparties becomes harder.
That's why a disruption response needs more than operations and legal support. It often needs a forensic accountant who can trace the financial impact, test the reliability of records, isolate the cause of loss, and produce analysis that will survive challenge.
Practical rule: If you can't reconstruct the financial effect of an outage from source records, you don't yet understand the incident well enough to defend your position.
Why this matters to directors
Most boards don't struggle with recognising that disruption is serious. They struggle with proving what happened and what it cost.
That proof matters in several places at once. The FCA may want to see whether the firm stayed within tolerance. Insurers may ask for loss quantification. Lawyers may need support in a supplier dispute. Internal audit may review control failures. If there's suspicion of manipulation, a forensic audit or fraud investigation may follow.
The commercial reality is blunt. A firm can restore service and still lose the argument afterwards because it didn't preserve the right evidence.
For that reason, operational resilience should be treated as part compliance framework, part evidence framework, and part financial defence file.
Understanding FCA Operational Resilience
The FCA regime changed the conversation. It moved firms away from broad assurances about continuity and toward a service-based test of whether customers and markets would suffer intolerable harm if disruption occurred.
The rules were formally set out in March 2021 through SYSC 15A of the FCA Handbook, and firms were given a transition period until 31 March 2025 to fully implement them. The framework requires firms to identify important business services, set impact tolerances, map dependencies, and carry out scenario testing so they can recover services before causing intolerable harm, as the FCA set out in its operational resilience observations and guidance.

What the FCA is actually asking for
In plain terms, the regulator wants firms to answer four questions well.
Which services really matter
These are the services where disruption could harm consumers or threaten market integrity.How much disruption is tolerable
This is the firm's impact tolerance. It isn't a vague aspiration. It's the line beyond which harm becomes intolerable.What supports each service
Firms need mapping across people, processes, technology, facilities, information, and dependencies.Can the service survive severe disruption
That's where scenario testing comes in. Firms have to test whether they can remain within tolerance under serious but plausible stress.
Why this isn't ordinary business continuity
Traditional continuity planning often asks whether a system can be restored. FCA operational resilience asks whether an important business service can continue or recover before real harm occurs.
That difference matters. A system might come back online, yet the service may still fail because key staff are unavailable, a supplier is down, customer communications break, or critical data is incomplete. Directors who only focus on technology recovery often miss the wider service chain.
The benchmark isn't whether one platform restarts. It's whether the service stays inside its tolerance when the whole operating model comes under pressure.
Terms directors need to get right
A short working table helps.
| Term | Practical meaning |
|---|---|
| Important business service | A service whose disruption could materially harm customers or market functioning |
| Impact tolerance | The maximum disruption the firm can tolerate before that harm becomes unacceptable |
| Mapping | The evidence trail showing what the service depends on |
| Scenario testing | Stressing the service against severe but plausible disruption to expose weak points |
If those terms remain abstract inside the business, the framework usually becomes a paperwork exercise. When firms define them operationally, they can test and defend them.
The Three Pillars of a Resilient Framework
A resilient framework stands or falls on three areas. Mapping. Tolerance setting. Testing and learning. If one is weak, the whole structure becomes hard to defend.
The FCA approach is scenario-driven and requires firms to test severe but plausible disruptions, identify vulnerabilities, and document remediation with board oversight. That's materially different from traditional continuity planning because the benchmark is whether the service operates within its tolerance, not whether a single system can be restored, as noted in this UK operational resilience commentary.

Pillar one is mapping the service properly
Weak mapping is one of the fastest ways to produce false confidence.
A service map needs to show more than applications and infrastructure. It should capture the people who operate the service, manual interventions, upstream data inputs, approval points, facilities, key records, and third-party dependencies. In practice, a forensic accountant often adds value here by asking a different question from operations teams. Not just “what runs this service?” but “what evidence proves this service can function, be measured, and be reconstructed after failure?”
That distinction matters in disputes and reviews. If incident records, contractual terms, finance data, and operational logs don't align, your map may look complete but still fail under examination.
Pillar two is setting tolerances that mean something
Some firms set impact tolerances in broad language that sounds sensible but isn't usable in a crisis.
A workable tolerance must help management decide whether disruption remains acceptable or has crossed into harm. It should link to customer impact, operational reality, and financial consequence. That often requires quantitative thinking, even where the final articulation includes qualitative judgement.
A forensic accounting review can be helpful at this stage because it forces the firm to examine what disruption would cost, what losses can be evidenced, and where assumptions are too soft.
Pillar three is testing and learning under pressure
A tabletop exercise that avoids uncomfortable failure modes won't tell you much.
Good testing should probe combinations of failure, such as a supplier outage plus poor data availability, or a cyber event plus communication breakdown and delayed reconciliations. It should also ask what records would exist during the event, who would approve emergency actions, and how losses would later be calculated.
Board-level question: If the scenario happened next week, what documents would prove the service stayed within tolerance, and who would sign off that conclusion?
Where firms want a broader control structure around this work, an enterprise risk management framework helps align resilience, incident response, financial exposure, and governance into one discipline rather than separate projects.
Proving Resilience When Third Parties Fail
For many firms, weakness sits outside the building.
Core services depend on cloud platforms, payment processors, outsourced administrators, software vendors, data feeds, contact centres, or group service companies. When one fails, management often says the same thing. “It was the supplier.” That may be true operationally. It doesn't remove the firm's responsibility.
The FCA framework explicitly expects firms to map and test third parties that support each important business service. Commentary after the 31 March 2025 deadline suggests firms may still underweight third-party failure in testing, yet responsibility for an outsourced service failure remains with the regulated firm. The practical challenge is producing documentary evidence that satisfies the FCA after an outage, as discussed in this commentary on FCA findings and outsourced dependencies.

Why supplier contracts don't solve the problem
A contract is useful. It isn't enough.
In practice, third-party outages create four evidence gaps:
- Fragmented incident records: The supplier holds technical logs. The firm holds customer complaints, reconciliations, and service decisions.
- Ambiguous responsibility: Contract wording may not match operational reality.
- Weak service-level evidence: SLAs may exist, but they often don't measure the actual harm caused to the important business service.
- Unclear loss attribution: Finance teams may know there was damage, but not which part is attributable to the supplier failure.
That's where forensic accounting services become practical rather than theoretical. The job is to pull together the event timeline, compare operational records with contractual duties, quantify the financial effect, and create an evidence set that can support regulatory engagement, insurance dialogue, or a business dispute accountant mandate.
What a defensible third-party file should contain
If a major provider fails, the firm should be able to produce a coherent file quickly. That usually includes:
- Service dependency records: Which important business service relied on the supplier, and how.
- Contract and governance documents: Terms, obligations, escalation routes, and oversight records.
- Incident chronology: What happened, when it happened, and what the firm knew at each stage.
- Financial impact analysis: Revenue disruption, additional costs, delayed processing effects, and remediation spend.
- Decision evidence: Why management took the steps it took, and whether those steps were reasonable.
Where an outage escalates into a wider event, crisis management consulting can help management align response actions with evidence preservation and stakeholder communication.
If your supplier's report is vague and your own records are inconsistent, you may win the operational battle and still lose the regulatory or commercial one.
The Forensic Accountant's Role in Resilience
Operational resilience is usually led by risk, compliance, operations, and technology teams. That makes sense. But firms often discover late that they also need stronger financial analysis, investigative discipline, and evidential rigour.
That's where a forensic accountant changes the quality of the programme.
Under the FCA regime, firms had until 31 March 2025 to complete deeper mapping and testing so they could remain within impact tolerances during disruption. The framework judges resilience service by service and requires proof through dependency maps across people, processes, technology, and third parties, as the FCA explained in its policy statement on building operational resilience.

Where forensic accounting adds the most value
A strong resilience framework needs more than policy language. It needs proof that can withstand challenge.
A forensic accountant can help in several ways:
- Loss quantification: Estimating the financial impact of service disruption in a disciplined way, using source documents and defensible assumptions.
- Scenario design: Stressing not only systems but controls, manual processes, approval paths, and points where fraud or error could enter.
- Root cause analysis: Separating technical failure from control failure, human error, poor governance, or supplier breach.
- Evidence preservation: Identifying which records matter before they disappear into normal remediation activity.
- Litigation support: Preparing analysis suitable for solicitors, counsel, insurers, or the court if the matter becomes contentious.
Why this matters in fraud and dispute situations
Disruption creates cover for bad behaviour.
When teams move to emergency processing, controls often loosen. Reconciliations are deferred. Access rights widen. Records become harder to compare. If irregular payments, altered records, side agreements, or unexplained adjustments appear during or after the event, a fraud investigation may be required alongside the resilience review.
In that setting, a standard internal review may not be enough. You may need a forensic audit with a clear chain of evidence and analysis suitable for disciplinary action, recovery action, or external scrutiny.
The expert witness angle
Some incidents don't stay internal. They become insurance claims, negligence allegations, outsourcing disputes, shareholder disputes, or regulatory investigations.
At that point, the difference between a finance summary and expert evidence becomes material. An expert witness accountant can present loss calculations, causation analysis, and financial interpretation in a form that stands up in negotiation or court. That's especially useful where parties disagree over whether the disruption arose from the firm's own controls, a supplier failure, or unrelated commercial factors.
For a fuller view of that role in live disputes and investigations, how forensic accountants help gives a useful practical overview.
Effective Governance and Board Reporting
At board level, FCA operational resilience is not a paperwork exercise. It is a question of whether directors can show they understood the firm's exposure, challenged management properly, and funded the right fixes before a disruption tested the business.
That record matters after the event.
If a payment flow stalls, client assets cannot be accessed, or a key outsourced process fails, the FCA will not be satisfied with a polished dashboard and a statement that the issue was “under review”. It will want to see what the board was told, what assumptions were challenged, what evidence supported impact tolerances, and why unresolved weaknesses were allowed to remain.
Good reporting gives directors a decision-ready picture without hiding the uncertainty. It should translate operational testing into business consequences. That includes customer harm, regulatory breach risk, cash impact, remediation cost, insurance issues, and the quality of the evidence available if the firm later has to defend its actions.
What boards should be reviewing
A useful board pack should let directors test management's conclusions, not just receive them. In practice, that means covering:
- Important business services: The services identified, the reasoning behind them, and any areas management considered but excluded.
- Impact tolerances: The basis for each tolerance, the assumptions used, and whether the financial and customer impact has been evidenced rather than estimated loosely.
- Testing results: What scenarios were tested, where dependencies failed, what workarounds were used, and whether the results would stand up to FCA scrutiny.
- Open weaknesses: The control gaps, data weaknesses, supplier issues, and process failures that still threaten delivery of the service.
- Remediation decisions: What has been approved, what remains unfunded, who owns delivery, and what delay would mean in financial and operational terms.
- Management information quality: Whether records are complete enough to reconstruct events, quantify loss, and support later review by regulators, auditors, insurers, or legal advisers.
A board does not need every operational detail. It does need enough underlying evidence to challenge management where the story is too neat.
What weak oversight looks like
Weak oversight usually appears in the reporting style before it appears in the incident log.
Boards receive traffic-light papers with no explanation of how ratings were reached. Scenario testing is reported as “successful” even though workarounds depended on extra staff, manual overrides, or assumptions that would not hold in a real disruption. Third-party resilience is summarised as contract status or vendor performance, while concentration risk, exit difficulty, and evidential gaps are left out. Financial exposure is described in broad terms, with no disciplined analysis of loss, liquidity strain, claim risk, or customer remediation cost.
That creates a serious problem later. If the FCA asks why the board believed the service could stay within tolerance, the firm needs more than meeting minutes and high-level summaries. It needs a defensible record.
The reporting question directors should press hardest
Can management prove this assessment, or only describe it?
That single question changes the quality of oversight. It pushes management to show the source data behind tolerance setting, the failed steps within test runs, the actual dependency chain, and the financial basis for saying an outage would be manageable. It also exposes where records are incomplete, where estimates are optimistic, and where a disruption could turn into a dispute because the firm cannot evidence causation or loss.
At board level, forensic and audit input proves useful. Independent review can test whether the reporting pack matches the underlying records, whether loss assumptions are supportable, and whether governance decisions are documented well enough to withstand challenge after an incident.
A practical board checklist
Before approving resilience papers, directors should ask:
- Can we explain each important business service in customer and regulatory terms?
- What evidence supports the impact tolerance, including the financial assumptions?
- Which dependencies are most likely to break the service first, and have they been tested properly?
- What weaknesses are still open because of budget, timing, or operational constraints?
- If the service failed tomorrow, could we reconstruct events and quantify the impact from our records?
If those questions produce vague answers, the issue is not only resilience maturity. It is governance risk.
Secure Your Business with Lighthouse Consultants
A serious outage rarely ends with service restoration. The harder phase starts once the board asks for a defensible loss figure, the insurer asks for proof, or the FCA asks how the firm knows its impact stayed within tolerance.
At that point, weak records become an immediate commercial problem. Firms need clear evidence of what failed, when it failed, which dependency caused the break, what controls did not operate as expected, and what the disruption cost. If fraud, manipulation, or vendor misstatement is part of the picture, the standard of evidence needs to be higher again.
Lighthouse Consultants supports firms facing exactly that type of scrutiny. Their team provides forensic accounting services for loss quantification, dispute analysis, fraud investigation, and litigation support, alongside wider audit and business dispute support. The practical value is straightforward. A forensic accountant helps establish the sequence of events, test the reliability of financial records, isolate the causes of loss, and present findings in a form that stands up under challenge.
This work matters before an incident as much as after one. Before a disruption, it helps firms build evidence packs that support impact tolerances with financial logic rather than assumption. During an incident, it helps preserve records, separate fact from management narrative, and quantify developing loss while evidence is still available. After the event, it supports remediation decisions, insurance claims, supplier disputes, and expert witness requirements.
There is a clear trade-off here. Early scrutiny takes time and budget. Leaving the evidence gap untested is often far more expensive once a live incident turns into regulatory challenge, a coverage dispute, or litigation.
If your resilience framework still depends on high-level service maps, generic testing papers, or unverified third-party assurances, the risk is not only operational. It is evidential.
If you need a forensic accountant, forensic accounting services, a focused fraud investigation, independent audit services, or an expert witness accountant to support FCA operational resilience, contact Lighthouse Consultants. Their team can help you quantify loss, test evidence, strengthen governance, and build a resilience position you can defend when the next disruption forces scrutiny.



