The demand that hasn’t called yet Log in
getfishnet
Test my eligibility

Change your language and country?

You are currently viewing the Switzerland version, in English. Another version may be better suited to your situation.

Stay on this version Change version
Market reading · Insurance & brokers

Operational resilience after March 2025: where is the next evidence gap hiding?

How insurers, brokers and resilience advisers can turn the post-2025 operating-resilience cycle into a bounded review and recurring evidence service.

Cellule études getfishnetAnalyse des marchés et acquisition client9 min read

A claims portal returns in forty minutes, yet vulnerable customers wait two days for a manual workaround. A cloud supplier passes its own test, yet nobody can show how the insurer’s customer service stays within tolerance when the dependency fails. Those are not technology anecdotes. They are decision gaps with an owner, evidence and a commercial consequence. The 31 March 2025 milestone required firms in scope to complete the mapping and testing needed to remain within impact tolerances for each important business service. It did not close the market. It moved the buying question from “Are we ready for the deadline?” to “Can the board still prove this service works after the last product, supplier, incident or operating-model change?” This reading explains who is in scope, how to distinguish a customer service from its systems, what a useful review should deliver, and how an adviser can turn recurring evidence gaps into a bounded first engagement and an ongoing resilience service.

What changed when the March 2025 transition period ended?

The March 2025 milestone changed operational resilience from a remediation programme into a continuing operating discipline. In-scope firms had to complete sufficient mapping and testing, make the necessary investment and show that each important business service could remain within its impact tolerance during severe but plausible disruption. Annual and material-change reviews continue after the date.

The Financial Conduct Authority describes operational resilience as the ability to prevent, adapt, respond to, recover and learn from disruption. Its March 2026 observations show why the deadline did not finish the work: services, tolerances, maps, scenarios and vulnerabilities must evolve with incidents and business change. The Prudential Regulation Authority’s SS1/21 applies the same service-led logic to relevant insurers while preserving prudential outcomes such as safety, soundness and policyholder protection.

The practical trigger is therefore not a regulation alone. It is a changed claim journey, product, customer group, location, outsourcing arrangement, system release, acquisition or incident that makes yesterday’s evidence unreliable.

The post-2025 resilience cycleThe post-2025 resilience cycle
  1. 1Define the customer or market outcome
  2. 2Set the point of intolerable disruption
  3. 3Map people, process, technology, facilities, information and third parties
  4. 4Test severe but plausible disruption
  5. 5Fund and verify remediation
  6. 6Reassess after incidents and material change

Which insurers and brokers are actually in scope?

FCA operational-resilience rules cover specified firms including insurers, while PRA expectations cover relevant dual-regulated insurers. Insurance intermediaries can fall within scope when they meet the enhanced-scope SM&CR definition. A broker outside that perimeter may still face resilience requirements through contracts, delegated authority, customer-outcome duties or an insurer’s dependency mapping.

The FCA’s insurance observations make the distinction explicit: Solvency II insurers are in scope, and intermediaries may be in scope according to their regulatory category. That means a campaign cannot begin with a list labelled “insurance”. It must qualify legal entity, permission, group role, regulated perimeter and the service the organisation actually delivers.

For advisers, the adjacent market is often larger than the directly regulated one. Claims administrators, cloud providers, call centres, data processors, loss adjusters and delegated partners may supply a resource that determines whether an insurer remains within tolerance. The offer must still be framed as evidence and operating support—not as a guarantee of regulatory compliance.

Which business service should be reviewed first?

The first review should focus on a service whose disruption can create intolerable customer harm or threaten market integrity, and where a recent change has weakened the evidence. Claims payment, emergency assistance, policy access, renewal or complaint handling can qualify; an application, team or supplier is normally a supporting resource rather than the service itself.

A strong service statement names the customer, the outcome and the start and end of delivery. “Claims platform availability” is too technical. “A retail customer can notify and progress an urgent claim” can be tested across channels, people, data and suppliers. The FCA has repeatedly warned against treating internal processes as important business services without connecting them to external harm.

The most useful acquisition signals are observable: a platform migration, outsourced claims contract, new product line, acquisition, major incident, board review or repeated customer-service failure. They create a reason to examine one service now, rather than sell a broad transformation with no boundary.

How should an impact tolerance differ from a recovery target?

An impact tolerance marks the maximum disruption an important business service can sustain before consumer harm or market impact becomes intolerable. A recovery time objective is an internal recovery target for a system or process. Recovery may need to occur earlier because backlogs, vulnerable customers and manual work continue to generate harm after technology returns.

Time is often necessary but not sufficient. The FCA’s 2024 and 2026 observations encourage clearer rationales and quantitative measures such as transaction volumes or financial thresholds alongside time. An insurer might therefore monitor elapsed time, unprocessed urgent claims, customers without an alternative route and value awaiting payment.

The review should record the rationale, assumptions, customer segments and approval trail. A short tolerance is not automatically prudent, and a long one is not automatically realistic. The question is whether the threshold reflects the harm and can be demonstrated under stress.

MeasureQuestion answeredTypical owner
Impact toleranceWhen does disruption become intolerable?governing body
Recovery time objectiveWhen must a resource be restored?technology or process owner
Backlog thresholdHow much unfinished work can be recovered safely?service owner
Vulnerability measureWhat could prevent the service staying within tolerance?resilience lead

What must end-to-end mapping reveal?

End-to-end mapping must reveal the people, processes, technology, facilities, information and third parties needed to deliver the important service. It should connect each dependency to a failure mode, workaround, owner and recovery evidence. A system inventory alone misses decisions and manual operations; an exhaustive asset catalogue can hide the few dependencies that determine the outcome.

The FCA’s latest observations praise clear methodology, multiple data sources, ownership and the use of mapping to guide testing. They also identify persistent weaknesses: maps remain too technology-centred, third-party vulnerabilities are incompletely assessed and ownership data becomes stale.

A bounded review can begin with one real customer journey and trace it backwards. For an urgent claim, that may include notification channels, identity data, coverage decisions, specialist suppliers, payment rails, communications and manual alternatives. Every dependency should answer a simple question: if this fails, what happens to the customer clock?

What makes scenario testing commercially useful rather than ceremonial?

Scenario testing becomes useful when it challenges the firm’s ability to remain within tolerance, records customer impact and forces a decision about workarounds, investment or accepted exposure. The scenario must be severe but plausible, vary in nature and duration, and connect directly to mapped vulnerabilities. Completing a tabletop agenda is not evidence that the service survived.

Useful scenarios can combine cloud-region failure, cyber compromise, data corruption, workforce loss, supplier collapse or simultaneous disruption. They state what is unavailable, when the clock starts, which customer groups are affected, what information decision-makers receive and what counts as recovery.

The output is not simply a red or green score. It is a timed evidence trail: decisions made, workaround capacity, backlog, communications, breach point, vulnerabilities and funded actions. Retesting closes the loop. The FCA expects remediation to be approved, funded, governed and evidenced at closure rather than left as an aspirational roadmap.

A test should move evidence toward a funded decisionA test should move evidence toward a funded decision
  • Étape 1D00: inject the disruption and start the customer clock
  • Étape 2D01: activate ownership, alternatives and communications
  • Étape 3D02: compare harm and backlog with tolerance
  • Étape 4W01: approve remediation or record accepted exposure
  • Étape 5W06: retest the changed service and close evidence

Where does third-party risk create a buying window?

A third-party buying window appears when an insurer cannot connect a supplier’s controls to its own important business service and tolerance. Certification, uptime or a generic disaster-recovery test may describe the supplier, but they do not prove the insurer’s customer outcome. Contract renewal, concentration, outsourcing change and repeated incidents make the evidence gap commercially actionable.

The review should connect service, supplier component, data, tolerance, test participation, incident information, exit path and substitute capacity. The firm remains responsible for its resilience even when delivery is outsourced. For the supplier, this creates a product opportunity: provide service-specific evidence packs and joint scenario participation instead of sending the same assurance document to every client.

Move from supplier assurance to customer-service evidenceMove from supplier assurance to customer-service evidence
  • Étape 1Insurer: important service, tolerance, accountable owner
  • Étape 2Supplier: component, failure mode, recovery and test evidence
  • Étape 3Joint: incident clock, workaround, communications and exit

What should a paid resilience evidence review deliver?

A paid resilience evidence review should examine one important service and produce an agreed service statement, tolerance rationale, dependency map, scenario design, evidence gaps and prioritised remediation decisions. It should be small enough to buy without a transformation programme and rigorous enough to support board challenge, supplier action and the next testing cycle.

A ten-to-fifteen-working-day engagement can request the service definition, current tolerance, last map, supplier evidence, incident history, scenario results and self-assessment extract. The adviser classifies gaps by customer consequence and decision readiness. Regulated judgements remain with the competent firm and its advisers; the acquisition partner does not certify resilience.

The recurring service follows material change and the annual review cycle: refresh the map, update scenarios, examine live incidents, track remediation and prepare the evidence trail. Recurrence comes from an operating need, not from extending a diagnostic that no longer adds value.

How can a multichannel campaign find firms with a live resilience trigger?

A resilience campaign should target the combination of an in-scope or dependent organisation, an important service and a recent change. Search captures declared needs; specialist content and events build recognition; partner networks expose supplier and governance triggers; email, telephone and account research verify ownership, timing and available evidence before a meeting is accepted.

The campaign starts with several hypotheses, not one channel. Search themes can focus on impact-tolerance review, scenario testing and third-party mapping. Broker and insurance networks can surface renewals or operating changes. Direct research can identify platform migrations, outsourcing, acquisitions and public incidents. Calls and emails should qualify the service and decision, not imply that the recipient is non-compliant.

Non-exhaustive campaign workflow over twelve weeksNon-exhaustive campaign workflow over twelve weeks
  1. 1Étape 1
  2. 2Étape 2
  3. 3Étape 3
  4. 4Étape 4
  5. 5Étape 5

Which numbers decide whether the campaign should scale?

The scale decision should use qualified cases, first-purchase conversion, expert effort, attributable acquisition cost and maintained recurring revenue—not impressions or meetings alone. Channel mix matters only when it is correlated with the service trigger, evidence quality and value retained after delivery. A high-volume channel can lose budget when it repeatedly produces unserviceable cases.

The table below is a planning model for a test cohort, not a disclosure of client performance. It shows the type of decision the campaign must support.

A pivot is justified when the same rejection repeats. No identifiable important service means the segmentation is too broad. No access to evidence means the first purchase is badly designed or the buyer is wrong. Strong demand but slow delivery means the partner must narrow scope, improve intake or add expert capacity before media spend increases.

Channel familyQualified casesFirst reviewsMaintained monthly value
Search and specialist content144£6
Networks and referral partners115£9
Email and telephone qualification184£7
Named-account research73£6

What must the insurance partner provide before acquisition accelerates?

The insurance or resilience partner must provide a defensible service scope, named expert owner, evidence request, qualification rules, response times, capacity and a safe boundary for regulated conclusions. It must also explain how a successful first review becomes remediation, retesting or recurring monitoring without forcing every customer into the same programme.

The minimum operating pack includes one offer page, eligible and excluded profiles, discovery questions, document list, pricing logic, handoff owner, conflict and confidentiality rules, and weekly feedback on accepted and rejected cases. Rapid feedback is essential: GetFishNet can test angles quickly only when the partner explains why a case progressed, stalled or should never have entered the pipeline.

Our role is to identify the market opportunity, build and operate the multichannel acquisition system, measure the economics and move budget toward qualified, maintainable demand. The partner’s role is to make the service true: review the evidence, own specialist judgements, deliver the first purchase and maintain the relationship through useful recurring work.

Which authorities support this reading and what remains outside it?

This reading relies on the Financial Conduct Authority’s operational-resilience rules, insurance-sector observations and 2024–2026 good-practice findings, together with the Prudential Regulation Authority’s SS1/21. It does not determine whether a specific entity or service is in scope, approve an impact tolerance, certify a supplier or promise regulatory, operational or commercial outcomes.

The authoritative entities cited are the Financial Conduct Authority, its PS21/3 policy statement and operational-resilience observations, and the Prudential Regulation Authority’s supervisory statement SS1/21. Their public guidance should be checked again when a live dossier begins because reporting rules, supervisory observations and firm circumstances continue to change.

Related readings remain dynamic. They should connect this analysis to DORA, cyber incident reporting, insurance distribution and third-party governance only when the published route adds a genuine next step for the reader.

Editorial provenance

Cellule études getfishnetAnalyse des marchés et acquisition clientPublished Updated

Sources used

  1. Financial Conduct Authority, Operational resilience
  2. Financial Conduct Authority, Operational resilience: insights and observations one year on
  3. Financial Conduct Authority, Operational resilience: insights and observations for firms
  4. Financial Conduct Authority, Operational resilience insights for insurance firms
  5. Financial Conduct Authority, PS21/3: Building operational resilience
  6. Prudential Regulation Authority, SS1/21: Operational resilience — impact tolerances for important business services
Does your market present a comparable window?

The eligibility report dates and quantifies it, then tests whether it deserves action.

Test my eligibility
g
getfishnet editorial team

The topic is broken down into entities, attributes, evidence, channels, costs and decision points. Institutions are cited in the text; no external resource interrupts the reading path.

documented

All market readings.

Could one resilience evidence gap open your next acquisition window?

GetFishNet will conduct a 100% free eligibility test to compare your current acquisition pain points, offer, market triggers and delivery capacity. If real development synergies exist, we will design a tailored multichannel strategy for a bounded first purchase and recurring client value.

Test my eligibility for free
Test d'éligibilité

Vérifions votre marché.

Dossier reçu.

Nous étudions votre marché et rendons le verdict sous 48 heures.

Fermer

Deux minutes. Verdict sous 48 heures, sans engagement.

Vérifier mon éligibilité