Workshop overview:

This half-day workshop explores the regulatory regimes for operational resilience in both the UK and EU, so that firms can understand their existing and ongoing obligations to strengthen operational resilience. It focuses on understanding the two regimes, their similarities and differences, and practical means for holistic compliance in a cross-border context.

Strengthening operational resilience matters but is not a 'one and done' set of requirements.

Firms subject to the UK operational resilience regime should already be familiar with the core rules that took effect on 31 March 2025.

For firms that also operate in the EU, understanding the similarities and differences with DORA is important to ensure integrated and streamlined compliance, including in areas such as testing, incidents, and third-party risk management. For managing incidents in particular, updated incident reporting requirements will apply in the UK from 18 March 2027. It is important for firms to understand both frameworks as they look to build incident management regimes in the EU under DORA.

Learning outcomes:

  • Examine the UK and EU regimes to understand key similarities and differences
  • Understand incident reporting requirements in the EU and UK, to help inform incident management compliance frameworks
  • Learn about the different requirements for testing, including scenario testing and penetration testing
  • Understand the different types of policies that firms need to have in place
  • Find solutions for contractual requirements and discuss challenges for negotiations
  • Discuss key compliance challenges, including governance aspects
  • Explore the regimes for oversight of critical third parties and the potential relevance for firms.
Martin Dowdall

Martin Dowdall

Partner, Financial Services Regulatory, Winston Taylor

Martin Dowdall is a partner in the financial services regulatory team at Winston Taylor with a particular focus on banking, payment services and the r...

Martin Dowdall is a partner in the financial services regulatory team at Winston Taylor with a particular focus on banking, payment services and the regulation of cryptocurrencies and other digital assets.

His clients include banks, asset managers, payment service providers, the operators of financial market infrastructure, and fintech firms.

Martin has extensive experience in assisting clients with banking and other regulatory authorisation applications both in private practice and while on secondment at a major fintech, and regularly advises on the structuring of new products and services and the innovative use of new technologies including DLT and AI.

Read more
  • Compliance and Risk Officers at firms operating in both the UK and EU
  • Operational Resilience Managers and Business Continuity Leads
  • IT and Cybersecurity Executives managing incident response and testing
  • Third-Party Risk Managers focused on vendor oversight across jurisdictions
  • Senior Managers accountable for regulatory compliance under SM&CR or similar regimes.