Let me ask you something uncomfortable. If one of your critical systems went down right now — your trading platform, your client portal, your payments system — what would happen in the first hour?
Not in theory. Not what the BCP says should happen. What would actually happen.
Who would you call first? Would your Crisis Management Team know they'd been activated? Would your deputies pick up when the primary contact was on holiday? Would you hit the FCA's 4-hour notification threshold, or miss it?
If you're reaching for a 60-page Word document saved on a shared drive, you're already too late. And under FCA SYSC 15A, that's a regulatory problem, not just an operational one.
Why Operational Resilience Is the FCA's Hidden Priority
Consumer Duty gets the headlines. Operational Resilience gets the fines.
Since March 2022, every FCA-regulated firm has been required to comply with SYSC 15A — the operational resilience rulebook. But compliance deadlines for mapping Important Business Services, setting impact tolerances, and demonstrating you can remain within those tolerances under severe but plausible scenarios have rolled forward through to 2025 and beyond.
Many firms treated the early deadlines as paperwork exercises. A consultant wrote a document. The board signed it off. Everyone moved on.
That was then. In 2026, the FCA has made clear that operational resilience is no longer aspirational. Supervisors are asking: Show me your IBS. Show me your impact tolerances. Show me the scenario tests. Show me the evidence.
If you can't produce that evidence quickly, in a structured format, with named owners and timestamps, you don't just have a compliance problem. You have an enforcement problem waiting to happen.
What SYSC 15A Actually Requires
The rulebook runs from SYSC 15A.2 through SYSC 15A.8, and covers four core pillars:
1. Identify your Important Business Services (IBS) — services that, if disrupted, could cause intolerable harm to consumers or threaten market integrity.
2. Set impact tolerances — the maximum tolerable disruption for each IBS, expressed in time (e.g. 2 hours) and data loss (e.g. 30 minutes).
3. Test against severe but plausible scenarios — cyber attacks, supplier failure, premises loss, key person loss, pandemic, technology failure. Not tabletop exercises. Real stress tests with real evidence.
4. Self-assess and remediate — identify where you cannot remain within impact tolerances, document the vulnerabilities, and track remediation plans to completion.
All of this has to be governed by the board, documented with audit-trail evidence, and reviewed at least annually — or after any material incident or organisational change.
The 5-Minute Test Every Firm Should Run
Before I show you how Fenchurch One solves this, try this exercise right now. Ask yourself:
- Can I name my Important Business Services in under 30 seconds?
- Do I know the impact tolerance for each one — the specific maximum disruption in hours and data loss?
- When was the last time I ran a scenario test, and do I have the results logged?
- If my primary IT system failed in the next hour, who is my Crisis Management Team Chair, and who is their deputy if they're unavailable?
- If the disruption lasted more than 4 hours and affected an IBS, do I know exactly who at the FCA to contact and what threshold triggers the notification?
If you hesitated on even one of those, you have a gap. And the FCA is explicit: hesitation isn't an excuse. Preparation is the requirement.
How Fenchurch One Helps You Evidence It
Fenchurch One won't do your resilience thinking for you. Mapping your Important Business Services, setting impact tolerances and deciding what counts as severe but plausible are judgements only your firm can make. What it does is capture the result — so that when a supervisor asks, the evidence is already there, dated and owned.
The operational-resilience attestation walks you through what SYSC 15A expects, each point mapped to the FCA Handbook, and records your position against it — met, in progress, or not yet. It teaches as it records, so you're prompted on what the rule actually asks rather than left to guess. Your supplier arrangements and any incidents sit in registers alongside it, every entry dated, owned and evidenced.
When a supervisor asks to see where you stand, you're not reaching for a 60-page Word document on a shared drive. You open the board and show exactly what you've attested, when, and with the supporting evidence attached to each answer.
See What's On Track — and What Isn't
Too many firms hide behind narrative in their BCP documents. Lots of words, not much substance. The FCA sees through that.
Fenchurch One won't reduce your resilience to a single score — a flattering percentage can hide a firm that hasn't done the thinking. What the dashboard gives you instead is a plain management view: which of your attestations and tasks are on track, which need attention, and which are overdue, across every board.
Your registers sit alongside it — supplier arrangements, incidents and the evidence behind each entry, every one dated and owned. Nothing is invented for you; it reflects only what you've recorded.
This is what a supervisor wants to see. Not a 60-page narrative, but a current, structured picture of what you've attested and what still needs doing.
Severe but Plausible: The Scenarios You Must Test
SYSC 15A.5 is the clause that catches firms out. It requires you to test your resilience against severe but plausible scenarios — not the comfortable ones, the hard ones.
That means cyber ransomware encrypting your core systems. Loss of your London HQ. Your CIO unavailable for four weeks. Your primary supplier (Bloomberg, custodian, banking partner) failing for 8 hours. A pandemic. A major power outage.
Not all of those are likely. But under SYSC 15A, they're all plausible — and therefore testable.
Deciding which of those are plausible for your firm, and running the tests, is work only you can do — Fenchurch One won't do it for you. What it does is keep it on track: the annual review and each scheduled test sit on the compliance calendar, across every board, with email reminders so nothing quietly lapses. When a test is done, you record the date, the outcome and the actions arising, and attach the evidence.
So when the FCA asks "when did you last test your resilience to a severe cyber event?", you don't reach for a consultant's report from two years ago. The date, the result and the evidence are already on the board.
Your Records, Turned Into a Board-Ready Report
Here's where the recording pays off.
Fenchurch One reads what you've actually attested and evidenced and turns it into a board-ready AI Compliance Report. Nothing invented, nothing generic: it draws only on your own records.
Be clear about what this is and isn't. The report doesn't write your Business Continuity Plan for you, and it won't conjure tests you haven't run or tolerances you haven't set — that thinking stays with you. What it does is pull your recorded position on operational resilience into a single, referenced summary the board can read and a supervisor can be shown.
Export it as a dated FCA proof pack — timestamped and referenced back to what you recorded. When anything changes, you update the record and regenerate. Always current, always evidenced. Your own BCP document, meanwhile, lives in Documents, alongside the evidence that supports it.
What This Means for Your Firm
If you're a one-person compliance team, or running lean, operational resilience can feel like a problem built for someone else. It's not.
The FCA's position is that SYSC 15A applies proportionately — but it applies. No firm is exempt. Firms are just expected to demonstrate resilience in a way that fits their size and complexity.
What you can't do is nothing. A Word document nobody tests isn't proportionate. It's non-compliant.
What you can do is structure the problem. Map your IBS honestly. Set impact tolerances that reflect reality. Run the stress tests. Capture the evidence. Use tooling that lets you show your work.
That's the difference between a BCP that survives regulatory scrutiny and one that doesn't.
Stop Guessing. Start Evidencing.
The firms that will be fine in 2026 aren't the ones with the thickest Business Continuity Plan. They're the ones who can show, in under five minutes, exactly where they stand on every requirement of SYSC 15A — with live data, audit trail, and a clear plan for any gap.
Fenchurch One is built for exactly that recording job. Your operational-resilience attestations mapped to SYSC 15A, your supplier and incident registers, and the annual review and every test on the compliance calendar with email reminders — then a board-ready AI Compliance Report drafted from all of it, and a dated FCA proof pack on demand. It won't do your resilience thinking for you. It makes sure the evidence is there the moment the FCA asks.
If your current BCP lives in a Word document, it's already behind. The question isn't whether to modernise. It's how quickly.
See where your firm stands
Fenchurch One puts everything the FCA expects a firm to evidence on one board, from £150 a month, with a 14-day free trial and no minimum term.
Get started