You can use the search function to find a range of UK Finance material, from consultation responses to thought leadership to blogs, or to find content on a range of topics from Capital Markets & Wholesale to Payments & Innovation.
14 Jul 2026
The opinions expressed here are those of the authors. They do not necessarily reflect the views or positions of UK Finance or its members.Moving beyond the checklist
For years, operational resilience centred heavily on documentation, standards, and audits. However, static, internally focused compliance struggles to match the speed and complexity of the modern risk landscape. The broader operating environment highlights why a fresh approach is needed:
Technical incidents require flexible recovery options
When a technical disruption occurs, the impact rarely stays confined to the IT department. Because every incident is unique, financial services firms benefit from having a variety of recovery plan options available to maintain operations.
True resilience relies on flexibility rather than a single, rigid path to recovery. Some scenarios require targeted recovery at the application level, focusing on restoring specific databases, software stacks, or technical infrastructure. Other scenarios demand a broader response at the business-service level, protecting the end-to-end customer outcome, regulatory reporting, and executive decision-making regardless of the underlying tech.
Operational excellence isn't about choosing one approach over the other; it is about having the capability to seamlessly deploy the right strategy at the right time.
Third-party risk management
Third-party risk remains one of the greatest resilience challenges across the sector. While most firms understand their immediate tier-one suppliers, gaining meaningful visibility deeper into the supply chain, and knowing exactly who retains access to systems and data, is increasingly critical.
Proactive governance plays a key role here. Reviewing supplier contracts to ensure they include robust security obligations, rapid notification requirements, and enforceable remediation timelines helps mitigate exposure. Furthermore, addressing the growing dependence on a small number of cloud and logistics providers is vital for managing systemic concentration risk across the financial sector.
Capability beats compliance
Perhaps the clearest takeaway from the conference was the distinction between compliance and capability. Compliance provides valuable evidence at a single point in time. Capability, however, is demonstrated continuously through regular exercising, measurement, and ongoing improvement.
The value of active testing is significant:
Ultimately, what gets measured gets managed. The long-term objective is building organisations that grow stronger through disruption, using every incident, near miss, and exercise to refine their capabilities. Compliance is the essential starting point; dynamic capability is the true competitive advantage.
The strategic path forward
Closing the gap between compliance and capability requires three shifts:
This evolution is as much cultural as it is technical. By framing resilience in practical business terms alongside regulatory language, firms can move beyond the baseline checklist and build a lasting operational advantage.
About the Authors: Joleen Engela and Richard Ashby are resilience specialists at CLDigital, a leading provider of connected risk and resilience software.
14.07.26
Joleen Engela, Customer Success Manager, EMEA, CLDigital
Richard Ashby, Business Development Manager EMEA, CLDigital
By downloading this document, you understand and agree that any sharing, distribution or republishing of the content, without prior written authorisation from the author or content managers at UK Finance, shall be constituted as a breach of the UK Finance website terms of use.