In July 2026, the FSCA published its Three-Year Regulation Plan covering April 2026 to March 2029. It arrives at a significant moment: the COFI Bill, the biggest reshaping of financial sector regulation in years, was approved by Cabinet in March 2026 and introduced to Parliament in April. Against that backdrop, one theme in the Plan stands out for financial services providers and the businesses that support them: the FSCA’s operational resilience agenda.
Over the next three years, the FSCA will develop cross-cutting joint standards covering governance, outsourcing, operational resilience and beneficial ownership transparency. For the proposed Joint Standard on Operational Risk and Resilience Requirements, the Plan is specific. Technical work continues throughout 2026/27, and the FSCA plans to publish a draft for public consultation in 2027/28. The FSCA notes that timelines are indicative, but the direction is set.
The pairing of these standards is deliberate: the Plan treats how organisations govern themselves, who they depend on, and whether they can keep operating through disruption as connected questions.
For FSPs, brokers, underwriting managers and the SMEs that serve them, the message is clear. Operational resilience is moving from good practice to expected practice. The organisations that prepare now will find the transition straightforward. Those that wait for final wording will be catching up.
Resilience expectations are not new, and some are already binding
It would be a mistake to treat the proposed Joint Standard as the starting point. For financial institutions, related obligations already exist.
Joint Standard 1 of 2023 sets requirements for IT governance and risk management, placing accountability with the governing body. Joint Standard 2 of 2024, which commenced on 1 June 2025, requires financial institutions to identify, protect against and recover from cybersecurity and cyber resilience risks, and to demonstrate that they do.
The proposed operational resilience standard extends this direction beyond technology. It asks a broader question. Can the organisation continue delivering its important services through any kind of disruption? The cause might be a cyber incident, a supplier failure, a systems outage or the loss of key people.
The practical position for leadership is straightforward: cyber resilience obligations are already in force, operational resilience obligations are on the way, and preparing for one strengthens the other.
Operational resilience is a business capability, not an IT project
Operational resilience means continuing important services through disruption and recovering before customers suffer unacceptable harm. It connects technology, people, suppliers, processes and management decisions.
Consider a common scenario: a financial services firm outsources its email, hosting and client portal to third parties, and a configuration error at one of those suppliers takes client communications offline for two days. The technical failure belongs to the supplier, but everything that follows belongs to the firm: the unanswered clients, the missed instructions, and the questions about oversight that arrive once service resumes. Outsourcing the service did not outsource the accountability.
It is no coincidence that the FSCA lists outsourcing alongside operational resilience in its planned joint standards, with a further proposed standard on cloud computing and data offshoring on the same timeline. Supplier and cloud dependence sit at the centre of all three.
For insurers, brokers and other FSPs, one detail in the Plan matters especially: the Plan includes no new insurance or FAIS specific interventions for the next three years. Instead, insurance and FAIS matters will move into the COFI framework transition to the COFI framework, while nearer-term regulatory change arrives through the cross-cutting standards. For these firms, the absence of a FAIS-specific signal is not a reason to wait.
That is why operational resilience is broader than cybersecurity alone. A cyber incident may trigger a disruption, but unclear responsibilities, poor communication or supplier dependence often determine how serious it becomes.
The practical question is not whether every disruption can be prevented. It is whether the organisation understands its important services, the dependencies behind them and the actions needed when something fails.
Visibility turns assumptions into evidence
Useful resilience planning starts with an accurate picture of the business as it actually operates, not as internal reports describe it.
Internal records typically cover managed systems, approved software and known assets. The outside view often tells a different story. It can reveal forgotten subdomains, unused services still publicly exposed, expired or misconfigured security records, and technology that never made it into any register. These are the weak points an attacker sees first and management sees last.
Supplier relationships create the same blind spot. Email, hosting, payroll and customer platforms are commonly outsourced, yet each one is a dependency that can interrupt an important service.
Leaders therefore need a joined view of internal controls, external exposure and third-party dependencies. No single report proves operational resilience, but together these views replace assumptions with evidence. That distinction matters, because a plan built on outdated asset records or old supplier arrangements creates confidence without protection.
Four questions leadership should be able to answer
A proportionate review does not require a complex programme. It starts with four direct questions.
- Which services must continue, and how long could clients reasonably tolerate disruption? For most firms this is a short list: client communications, transactions or claims processing, access to records, and regulatory reporting.
- What do those services depend on? Map the systems, email, websites, cloud providers, payment processes, key staff and outsourced support behind each one, and confirm who owns each dependency.
- Can we see the risks affecting those dependencies? This should include internal information and the external signals visible to anyone looking at the organisation from outside.
- What evidence could we produce today? Policies help, but current records, assigned ownership, testing and corrective actions are stronger proof of oversight. If the FSCA’s direction becomes a formal requirement, this is the evidence that will matter.
Smaller firms do not need enterprise-scale frameworks. They need current records, clear responsibility and a review whenever something material changes.
FSCA operational resilience starts with visibility
Operational resilience becomes credible when leaders can explain what matters, what could fail and how the organisation would respond. That capability cannot be assembled in the weeks before a standard takes effect. It is built through visibility maintained over time.
A point in time external assessment such as CyberProfiler can support this process by showing publicly visible exposure without requiring system access. It is not a full operational resilience assessment or a regulatory audit. It does, however, provide an evidence-based starting point for the external view that internal reporting cannot supply.
The FSCA has signalled where governance expectations are heading, and has committed to phased consultation so the sector can prepare. That is an opportunity, not a reprieve. Organisations that improve visibility now will engage with the consultations from a position of evidence. They will also make better, more proportionate decisions when the requirements arrive.



