A year after the compliance deadline passed, regulators are still asking firms for a credible plan rather than proof. That gap says more about deadlines than discipline.

On 27 March 2026, a year after the deadline for UK operational resilience compliance passed, the Financial Conduct Authority published its verdict on how firms were actually doing. It is a specific, well-evidenced critique, not a vague one: firms had mapped their own technology in detail, then stopped the moment a service left the building, treating outsourced providers as endpoints rather than tracing through to the systems those providers actually run. Some firms claimed in their self-assessments that there was no scenario they could not recover from, without evidence of a test severe enough to support that claim. Communications plans existed on paper and had never been rehearsed. The FCA’s reading is fair, and the obvious response to it is to treat this as a documentation failure: firms wrote thin self-assessments, so firms need to write better ones.

That obvious view has a real basis. Boards did sign off self-assessments that, in the FCA’s words, were “overly high-level or lacked supporting evidence.” Weaker firms had no clear owner for tracking remediation, and little evidence that second or third line functions had reviewed the assessment before it reached the board. None of that is a stretch. But treating it purely as a writing problem misses what the timeline itself is telling you. The Prudential Regulation Authority, reviewing the same population of firms from the banking side, is not asking firms to have closed their gaps by now. Its supervisory statement SS5/25 asks firms only to show, from June 2026, “a credible and ambitious timetable” for closing them. Rules in force since 31 March 2022, full compliance required by 31 March 2025, and 15 months past that deadline the banking regulator is still asking for a plan rather than proof. The PRA is betting that producing a credible timetable is a fair proxy for the ability to deliver against it. That bet rests on an assumption worth testing: a timetable is still a document, drafted under the same deadline pressure and board sign-off process that produced the thin self-assessments a year earlier. Nothing stops it becoming exactly the artefact this piece describes, credible on paper, unproven in practice, with the reckoning pushed out rather than resolved.

That gap is not a discipline problem inside individual firms. It is the predictable output of asking two different kinds of work to hit the same date. A board can approve a self-assessment document in an afternoon. It cannot approve a re-architected third-party dependency chain, or a fully evidenced severe-but-plausible scenario test with recorded participants, timings and remediation actions, on the same timescale, because that work runs through a multi-year change portfolio with its own funding and delivery cycle. Sociologists have a name for what happens when a hard external deadline meets an internal reality that cannot move that fast: decoupling. Meyer and Rowan’s 1977 study of institutionalised organisations found that firms under this kind of pressure adopt the formal structure that satisfies the external audience by deadline day, while the technical work that structure describes proceeds on its own, slower schedule underneath it. The self-assessment is the formal structure. The dependency chain is the technical core. They were never going to finish together, and no amount of better drafting changes that.

The data backs the FCA’s specific diagnosis, not just its general one. In its own account of 2025 incident reports, the FCA found that 27% of incidents notified to it were attributed to a third party, and 37% of those were cyber-related, which is exactly the area its one-year-on review named as the weakest: mapping that stops at the third party instead of tracing through it. The Bank of England’s Systemic Risk Survey, the longest running read on how the industry itself sees this risk, has had cyber-attack inside the top five systemic risks in every survey since it resumed in 2021, cited by 74% of respondents in both the 2021 H2 and 2022 H2 rounds and by 82% in the most recent 2026 H1 round. Four years into a regime built specifically to reduce this exposure, the industry’s own sense of the risk has not fallen. It has risen. That is the surprising number in this data, and decoupling is the explanation for it: a compliance framework can satisfy a regulator’s deadline without touching the underlying exposure at all, and here, it plainly has not.

The July 2024 CrowdStrike outage, which the FCA has separately written up as a case study, is the concrete version of the same story: a single third-party software update disrupted operations across UK financial services and beyond, hitting exactly the dependency layer firms were least able to map. It was not a novel category of failure. It was the one the regulator had already been warning about.

The practical implication is not “write better self-assessments.” It is that the assessment calendar and the remediation calendar need to run as two separate, explicitly funded workstreams from the start of any resilience programme, not one document with a hopeful implementation plan attached to the back of it. Firms that are furthest ahead a year from now will not be the ones with the cleanest self-assessment. They will be the ones that funded and resourced the third-party remediation work as a standalone multi-year programme the moment the framework was signed off, rather than treating the sign-off itself as the finish line. The deadline was always going to produce the document on time. It was never going to produce the resilience on the same schedule, and firms that planned as if it would are the ones the FCA is now naming.

Sources

  • Financial Conduct Authority, “Operational resilience: insights and observations one year on” (27 March 2026)
  • Financial Conduct Authority, “Strengthening resilience across an increasingly interconnected financial system” (28 July 2026)
  • Financial Conduct Authority, “CrowdStrike outage: lessons for operational resilience”
  • Financial Conduct Authority, “PS21/3: Building operational resilience”
  • Bank of England, Prudential Regulation Authority Business Plan 2026/27 (April 2026), on SS5/25
  • Bank of England, Systemic Risk Survey Results, 2021 H2, 2022 H2 and 2026 H1
  • Meyer, J. W. and Rowan, B., “Institutionalized Organizations: Formal Structure as Myth and Ceremony,” American Journal of Sociology, 83(2), 1977