Skip to main content
  • SECTORS
    • INVESTMENT FIRMS
      • Asset Managers
      • Brokers
      • Hedge Funds
      • Investment Advisory
      • Private Equity
      • Wealth Management
    • DIGITAL FINANCE
      • Authorised Payment Institutions
      • Electronic Money Institutions
      • Cryptocurrency
      • Open Banking
      • Money Remittance
    • CONSUMER FINANCE AND INSURANCE
      • Automotive Dealers
      • Claims Management Companies
      • Consumer Credit Lenders
      • Credit Brokers
      • Debt Management & Collection
      • Funeral Planning Companies
      • Insurance Intermediaries
      • Mortgage Intermediaries
  • SOLUTIONS
    • AUTHORISATIONS
      • FCA Authorisation
      • SEC Registration
      • 5MLD Registration
      • Change in control
      • Variation of permission
    • COMPLIANCE ADVISORY
      • Compliance health checks & audits
      • Ongoing support
      • Policy & procedure frameworks
      • Consumer Duty
      • SM&CR
      • Safeguarding audits
      • Operational resilience
    • FINANCIAL CRIME
      • Advisory services
      • Audits and assurance
      • Risk assessments
      • Fraud prevention
    • FINANCIAL RESILIENCE
      • IFPR compliance
      • ICARA
      • Financial forecasting
      • Regulatory capital & liquidity
      • Wind-down planning
    • REGULATORY REPORTING
      • Annex IV
      • RegData reporting
      • FCA notifications & attestations
    • TRAINING
      • Financial Crime training
      • FCA Compliance training
      • SM&CR training
      • Consumer Duty training
      • GDPR training
      • SEC training
      • CASS training
  • TECHNOLOGY
  • Resources
    • ALL RESOURCES
    • ARTICLES
    • EVENTS
    • FACTSHEETS
    • PRESS
  • ABOUT
    • Our Company
      • Our Culture
      • Our Values
      • Learning & Development
      • Corporate Social Responsibility
      • Meet our Team
      • Our People
    • Our Purpose
      • Rule the Rules
    • Current Opportunities
      • Our Perks
    • Contact Us
  • LOGIN
    • CMP+
    • MyCosegic
  • SECTORS
    Back
    • INVESTMENT FIRMS
      Back
      • INVESTMENT FIRMS
      • Asset Managers
      • Brokers
      • Hedge Funds
      • Investment Advisory
      • Private Equity
      • Wealth Management
    • DIGITAL FINANCE
      Back
      • DIGITAL FINANCE
      • Authorised Payment Institutions
      • Electronic Money Institutions
      • Cryptocurrency
      • Open Banking
      • Money Remittance
    • CONSUMER FINANCE AND INSURANCE
      Back
      • CONSUMER FINANCE AND INSURANCE
      • Automotive Dealers
      • Claims Management Companies
      • Consumer Credit Lenders
      • Credit Brokers
      • Debt Management & Collection
      • Funeral Planning Companies
      • Insurance Intermediaries
      • Mortgage Intermediaries
  • SOLUTIONS
    Back
    • AUTHORISATIONS
      Back
      • AUTHORISATIONS
      • FCA Authorisation
      • SEC Registration
      • 5MLD Registration
      • Change in control
      • Variation of permission
    • COMPLIANCE ADVISORY
      Back
      • COMPLIANCE ADVISORY
      • Compliance health checks & audits
      • Ongoing support
      • Policy & procedure frameworks
      • Consumer Duty
      • SM&CR
      • Safeguarding audits
      • Operational resilience
    • FINANCIAL CRIME
      Back
      • FINANCIAL CRIME
      • Advisory services
      • Audits and assurance
      • Risk assessments
      • Fraud prevention
    • FINANCIAL RESILIENCE
      Back
      • FINANCIAL RESILIENCE
      • IFPR compliance
      • ICARA
      • Financial forecasting
      • Regulatory capital & liquidity
      • Wind-down planning
    • REGULATORY REPORTING
      Back
      • REGULATORY REPORTING
      • Annex IV
      • RegData reporting
      • FCA notifications & attestations
    • TRAINING
      Back
      • TRAINING
      • Financial Crime training
      • FCA Compliance training
      • SM&CR training
      • Consumer Duty training
      • GDPR training
      • SEC training
      • CASS training
  • TECHNOLOGY
  • Resources
    Back
    • ALL RESOURCES
    • ARTICLES
    • EVENTS
    • FACTSHEETS
    • PRESS
  • ABOUT
    Back
    • Our Company
      Back
      • Our Company
      • Our Culture
      • Our Values
      • Learning & Development
      • Corporate Social Responsibility
      • Meet our Team
      • Our People
    • Our Purpose
      Back
      • Our Purpose
      • Rule the Rules
    • Current Opportunities
      Back
      • Current Opportunities
      • Our Perks
    • Contact Us
  • LOGIN
    Back
    • CMP+
    • MyCosegic
Get in touch
Resources — Article — Business Continuity and Resilience

Business Continuity and Resilience

Business Continuity and Resilience
Back to resources
Published on: April 9, 2020 Reading time: 1 min By John Burns
Get in touch

In the context of the Covid-19 (Coronavirus) outbreak, financial services regulators have been working with firms to ensure they are responding effectively to the threat of disruption. All firms are expected to have contingency plans in place to deal with major events. Regulators are actively reviewing these plans including firms’ ability to continue to operate effectively, serve and support their customers, and meet their regulatory obligations.

Prior to the current crisis, regulators and industry associations including the Bank of England, Prudential Regulation Authority (PRA), Financial Conduct Authority (FCA) and European Banking Association, had already issued guidelines and communications at the end of 2019 on strengthening business continuity and operational resilience in financial services, thereby already highlighting the importance of this topic. 

Although business continuity and resilience are currently in the spotlight, these concepts are not entirely new. Customers expect services to be available whenever they are ready to complete a transaction.  Client satisfaction suffers when a firm cannot provide the expected level of service, opening the door for competitors. A business continuity plan (BCP) is the process designed to enable a firm to maintain its critical activities when faced with potential disruptions arising from a range of sources such as natural or man-made disasters, terrorist or cyber incidents. A BCP is more comprehensive than traditional Disaster Recovery Plans (DRP) limited to the IT infrastructure, it also covers contingencies for personnel and business partners. Resilience is to do with designing applications and business processes for high availability.

The first and probably most critical step is conducting a rigorous Business Impact Analysis (BIA), which involves identifying the firm’s important business services, defining availability tolerances for these, and mapping the supporting resources (people, processes, technology and third-party providers). Firms then need to implement solutions to protect their people and assets, and to reduce the threat of disruption to an acceptable level, for instance, through technical security measures.  This can pose challenges given the degree of interconnectivity across hybrid IT environments and reliance on outsourcing.  Secondly, procedures must be developed to enable critical services to be maintained without disruption or resumed within acceptable timeframes.  These procedures must be adequately documented and supported by training.  Firms also need to have an effective communication plan in place to provide clear, timely and relevant communications to employees, consumers and other stakeholders in the event of an operational disruption.

The BCP should be reviewed and tested on a regular basis to ensure that it remains fit for purpose and keeps up with the pace of change. In particular, the BCP may not be effective and will need to be revisited to address new scenarios which were not initially foreseen and planned for, notably if a large portion of the population is affected by a disease outbreak.

Business continuity and resilience good practices therefore include:

  1. Conducting a comprehensive Business Impact Assessment
  2. Implementing Disaster Recovery countermeasures to mitigate the risk of any disruptions to the infrastructure, including consideration of Disaster Recovery as a Service (DRaaS)
  3. Documenting the Business Continuity Plan in sufficiently granular detail
  4. Implementing a crisis management and communication plan to be triggered in the event of a disruption
  5. Keeping the plans up-to-date and testing these on a regular basis

Compliancy Services can support you in conducting your Business Impact Assessment and in reviewing your Business Continuity and Resilience arrangements.

To find out more, please contact us on info@compliancy-services.co.uk to book a discussion with one of our experienced consultants.

Don’t just stay abreast. Stay ahead. Subscribe to Cosegic insights.

The author
John Burns
John Burns
John Burns

John is one of the UK’s foremost compliance experts in payment services, and he is an Advisor to Cosegic.

Get in touch
Contact Us
info@cosegic.com +44 (0)20 7060 4499
Connect with us
© 2026 Cosegic Limited. All rights reserved.
  • Terms and conditions
  • Privacy
  • Cookies
  • Settings