Operational resilience for UK regulated firms

Regulators no longer want to see that operational resilience was designed. They want evidence it’s working today. Toleris keeps your Important Business Services, dependencies, testing and vulnerabilities continuously connected, owned and ready to defend.

Built by

30+ years of combined experience delivering operational resilience programmes to FTSE 100 firms.

Operational resilience doesn’t fail. It goes quietly out of date.

Not through neglect. Through a year of small, properly managed changes — none of which updated the framework built to describe them.

The businessTwelve months, no incident
  1. AprService owner leaves. Register still names them.
  2. JunPayments provider re-contracted onto a second service.
  3. AugCustomer platform consolidates into one cloud region.
  4. SepTolerance paper still describes the old architecture.
Your frameworkLast approved · March

Nothing failed. Nothing was flagged. It simply stopped being true.

You find out when somebody asks you to prove it.

Not the first question. The follow-up — the one that assumes your first answer was true and asks you to show why.

Information request

Operational resilience — request for information

To: Head of Operational Resilience · Response required within 10 working days

Please provide, for each Important Business Service:

  • The current approved impact tolerance and the rationale for setting it.
  • The latest approved version and approval date.
  • Evidence supporting the tolerance, including recent scenario testing.
  • Details of any material changes since approval and why the tolerance remains appropriate.
Which version was approved?Who signed it off?What has changed since?Where is the evidence?
Illustrative. The wording is typical of a supervisory information request; the firm and the sender are fictional.

What it costs

A fortnight, every cycle

Re-collating registers and evidence by hand. The assessment is out of date the day it is finished.

An answer you can’t stand behind

You know the answer you are giving. You do not know whether it is still true.

Your name on the attestation

Somebody signs to say the framework is current. Under SM&CR that attestation carries a name, not a department.

Toleris

The record that can’t quietly go out of date.

Everything connected, owned and dated. Proving it becomes a read of the record, not a project.

The platform

Four things it does that a document cannot.

01Connected record

Change one thing. Everything resting on it says so.

Register a third party, platform, team or data set once, and attach it everywhere it matters. When it changes, everything standing on it is flagged for re-approval.

That is the difference between a record and a folder.

One change

Third party

Amazon Web Services(eu-west-2)

Third party

Supports 5 important business services

IBS register

  • Online & Mobile Banking Access
  • Current Account Servicing & Payments
  • Business Banking Payments
  • Card Payments & Authorisation
  • Customer Onboarding

Scenario test

Cloud region loss — digital channel access

Within tolerance

Impact tolerance

4 hours

Approved · v3

Report

Report readiness

Ready

No open vulnerability

02Defensible numbers

Nobody asks whether you’re resilient.They ask why four hours.

A tolerance on its own is a number somebody will challenge. Toleris holds what it means, how it is measured, why that figure, and who approved it.

Evidence has a shelf life. Toleris watches the clock.

Impact toleranceCurrent Account Servicing & Payments
4hoursTime to intolerable harm
Reads as
Customer harm becomes intolerable if disruption continues beyond four hours.
Measured from
Incident declaration to restoration of customer-facing service, evidenced by the incident timeline and scheme submission logs.
Why this figure
Beyond four hours, customers miss same-day payment obligations and harm crystallises for those with time-critical commitments.
Owner Tom BaxterApproved v3Reviewed 12 April 2026Evidence current
03Findings that land

A breach becomes somebody’s job before you’ve left the room.

Tests are scored against tolerance, not written up in a paper that goes somewhere. Where one breaches, the vulnerability opens itself — carrying the breach it came from, an owner and a date.

Closure is approval-gated. Risk acceptance stays under review rather than quietly disappearing.

Scenario testSevere but plausible

Cloud region loss — digital channel access

Online & Mobile Banking Access · 10 July 2026

Recovery

Tolerance

4 hours

Running
Raised automatically
VulnerabilityCriticalFrom breach: Cloud region loss

Single-region cloud deployment for customer-facing platforms

Cross-region failover exists in design but has never been executed under production load, and device-binding state does not replicate.

Owner Marcus HaleTarget 30 November 2026Closure approval-gated
04Report Studio

Generate evidence in minutes, not weeks.

Regulator-ready reports drafted straight from the live record: the Operational Resilience Assessment, a report per important business service, a scenario testing report and an executive summary. Reports export to PDF or Word; the executive summary also generates as a PowerPoint deck.

One set of facts behind all of them, so the deck and the document can never disagree. Every figure traces back to its source.

None of them publish while an approval is outstanding.

Operational Resilience Assessment · draftAuto-draft
Generated from the live record
  1. §1

    Scope and important business services

    6 services

  2. §2

    Impact tolerances by objective

    18 tolerances

  3. §3

    Dependencies and concentration

    41 linked documents

  4. §4

    Scenario testing and outcomes

    8 tests · 2 breached

  5. §5

    Vulnerabilities and remediation

    9 open

  6. §6

    Attestation and approval

    2 approvals outstanding

Same record, every report you are asked for
  • Operational Resilience AssessmentPDF · DOCX
  • Important Business Service reportPDF · DOCX
  • Scenario testing reportPDF · DOCX
  • Executive summaryPDF · DOCX · PPTX
0 of 6 sections draftedPublication blocked — 2 approvals outstanding

Outcomes

Half the work. At least.

0%

Toleris cuts the work around operational resilience by at least half — from assessment through to remediation and reporting.

Harm assessment

Captured once against the service, then reused — not rewritten every cycle.

Impact tolerances

Meaning, measurement and rationale live on the record. Reviewing a tolerance stops being a drafting exercise.

Scenario testing and evidencing

Outcomes scored against tolerance. Evidence attaches to the test rather than being collated afterwards.

Self-assessment reports

Generated from the live record and routed for approval, not re-collated by hand.

Vulnerability tracking and remediation

Raised from a breach, owned and dated, carried to validated closure.

How it works

The same lifecycle you already run. Connected.

01

Bring what you already have

Registers, tolerance papers, test write-ups, third-party schedules. Toleris drafts the structure — you review and confirm, not transcribe.

02

Model your services the way they actually run

Every service runs the same six-stage assessment: capture, harm, tolerance, dependencies, scenarios, vulnerabilities. Owners and approval gates match how your firm signs off.

03

Understand exactly what supports every service

People, technology, data, third parties, facilities and processes, attached per service. Shared dependencies surface as concentration on their own.

Where the AI stops

AI drafts. People decide. The record shows which.

Every suggestion arrives with its source attached, and nothing becomes workspace data until a named person accepts it.

No public web research. No inferred facts about your firm. Your register comes from your documents and your decisions — and you can point at where every entry came from.

Security & data

Your third-party questionnaire, answered.

You’ll diligence us the way you diligence everyone else. The short version:

  • Information security managementISO27001Certified
  • General Data Protection RegulationGDPRCompliant

Data residency

Configurable to your firm’s requirement. We match the region to your policy, not ours.

Deployment

Cloud, or on-premises in your own environment on request.

Access control

SSO for your identity provider, multi-factor authentication with recovery codes, and permissions scoped to each person’s role.

Isolation

Each firm’s data sits in its own tenant-scoped workspace. The database refuses direct API access outright, and every query is tenant-scoped.

Encryption

Encrypted in transit and at rest, including uploaded source documents.

Audit trail

Every approved artefact is versioned and audit-logged: who changed what, and when.

For your security review

We’ll walk your second line through the architecture, subprocessor list and data flows, and answer your questionnaire in your own format.

Ask at the demo and the pack arrives before you have to chase.

Book a demo

You sign it. So it had better be current.

Find out what your framework actually says today.

Built by people who have carried this obligation themselves — 30+ years of combined operational resilience experience. People who have pulled the assessment together the night before, and signed it.

What a demo actually is

A working session with one of us, on your services and your questions. Not a slide deck.

Bring one important business service. We’ll map it live, then change a dependency in front of you so you can watch what gets flagged.

And bring the follow-up question you’d least like to be asked cold.

Already using Toleris? Sign in

We’ll only use your details to arrange and follow up on your demo. See our privacy notice.