UK operational resilience sits in SYSC 15A of the FCA Handbook, with a matching PRA supervisory statement. It requires an authorised firm to identify its important business services, set an impact tolerance for each, map the people, processes, technology and third parties those services depend on, test whether it can stay within tolerance, and document the whole thing in a self-assessment its board has approved. Unlike DORA it is not one filing on a deadline — it is a standing evidence obligation the regulator can ask to see.
What the rules ask of you
Following the 2021 policy from the Bank of England, PRA and FCA, UK-authorised firms must build and maintain an operational resilience framework. In the FCA Handbook it lives in SYSC 15A; the PRA has a matching supervisory statement. Unlike a one-off return, it's an ongoing discipline a firm must be able to evidence — and the regulator can ask to see it.
The framework rests on four connected ideas: identify your important business services, set an impact tolerance for each, map the people, processes, technology and third parties each service depends on, and then test whether you could stay within tolerance through severe-but-plausible disruption.
Important business services
An important business service is one that, if disrupted, could cause intolerable harm to your customers or risk to market integrity — think payments, claims settlement, or access to funds. The test is external harm: a back-office process can be painful to lose without being an important business service. Naming them too narrowly hides real risk; too broadly and the whole framework becomes unmanageable.
Impact tolerances
For each important business service you set an impact tolerance — the maximum tolerable level of disruption, usually expressed as a time. It's the point beyond which harm becomes unacceptable, set as if disruption will happen rather than hoping it won't. The tolerance is what turns resilience from a vague aspiration into something measurable: an incident either stayed within it or it didn't.
Whether an incident breached tolerance is arithmetic: the disruption ran from detection to recovery, and either exceeded the service's maximum tolerable duration or it didn't. A resilience record that declares a breach flag by hand invites the gap between what was written and what the timestamps show — the first thing a supervisor probes.
Mapping and self-assessment
Mapping documents what each important business service actually relies on — the systems, the people, and crucially the third parties. It's what makes an impact tolerance credible: you can't argue you'd recover a service in two hours if you've never traced what it depends on. The self-assessment then draws it together: your services, tolerances, the mapping, your scenario testing, and any vulnerabilities you've found and are remediating.
UK operational resilience vs EU DORA
The two regimes rhyme but aren't the same. DORA is an EU regulation with a prescriptive, machine-readable Register of Information and detailed ICT third-party rules. The UK framework is outcomes-focused and principles-based — same spirit of resilience, different mechanics. Many groups are in scope of both: a UK-authorised firm with EU entities has UK operational resilience obligations and a DORA register to file. Qgentic runs them as separate rulebooks on one engine.
How Qgentic helps
Qgentic OpRes assembles the resilience record from your GRC data — important business services, impact tolerances, the third-party register and operational incidents — and computes the tolerance-breach determination from the incident timestamps, so the assessment is a calculation you can defend. It carries the 18 March 2027 commencement of the unified incident and third-party reporting rules (FCA PS26/2, PRA PS7/26) in its compliance calendar, on the same approval gate and audit trail as every Qgentic platform.
Qgentic OpRes builds the resilience record from your own data and computes tolerance breaches from timestamps.
See the OpRes platform Book a consultation