Keep critical services running, and prove it to supervisors.
In financial services, supervisors expect firms to show they can withstand severe disruption, including at their technology suppliers. We help firms meet DORA and UK operational resilience requirements, contain incidents before they reach important business services, and introduce AI with the oversight and evidence supervisors expect.
Situations we help with
Across banks and building societies; insurers; payment and e-money institutions; and investment and asset managers.
- Your DORA register of information shows several critical services depending on one cloud provider.
- A supervisor has asked for evidence that you can remain within impact tolerances in a severe but plausible scenario.
- You have been identified for threat-led penetration testing, and nobody has planned how findings will be remediated and reported to the board.
- Contracts with ICT providers lack the notification, audit, and exit provisions DORA requires.
- Teams are piloting AI in customer servicing or credit decisions, and there is no agreed approach to oversight, explanation, or model risk.
The challenges
Concentrated technology dependence
Core banking, payments, and customer channels can depend on a small number of cloud and technology providers, so an outage at one can affect many important business services at once.
Evidence for supervisors
DORA and the UK operational resilience rules expect firms to show, through testing and documentation, that they can withstand severe disruption and that the board has overseen it.
Attractive to attackers
Financial firms hold money and data that attackers can monetise, and their customer-facing services face fraud, ransomware, and denial-of-service attacks.
Third-party oversight
Firms remain accountable for the services they outsource, so contracts, monitoring, and exit plans for ICT providers need the same rigour as in-house controls.
ENISA's analysis of 488 publicly reported cyber incidents affecting the European financial sector between January 2023 and June 2024 found banks among the most affected, with denial-of-service attacks, data breaches, and ransomware among the main threats.
AI in financial services
Customer servicing
- The value
- Faster, more consistent answers for customers.
- What needs governing
- Incorrect advice or commitments to customers, and conduct obligations for outcomes the AI influences.
Fraud and financial crime detection
- The value
- Earlier detection of suspicious activity.
- What needs governing
- Models that drift, false positives that harm customers, and decisions nobody can explain to supervisors.
Credit and underwriting
- The value
- Faster, better-informed decisions.
- What needs governing
- Fairness, explainability, and model risk management for decisions with significant effects on customers.
AI Factory Design sets the rules for approval, model oversight, and evidence across these uses, so AI can scale in ways you can explain to customers and supervisors. It is part of our AI Governance and Transformation practice.
Regulation that may apply
DORA (EU)
- Applies to
- Financial entities in the EU, including credit institutions, insurers, investment firms, payment and e-money institutions, and crypto-asset service providers.
- What it asks
- The management body is responsible for the ICT risk management framework. A major ICT-related incident is notified to the competent authority within four hours of its classification and no later than 24 hours after becoming aware of it, followed by intermediate and final reports. Designated entities carry out threat-led penetration testing at least every three years.
- Timing
- Applies since 17 January 2025.
UK operational resilience (PRA and FCA)
- Applies to
- Firms within scope of the PRA and FCA rules, including banks, building societies, insurers, and payment and e-money institutions.
- What it asks
- Identify important business services, set an impact tolerance for each, map and test them, and remain within those tolerances in severe but plausible scenarios.
- Timing
- The transition period ended on 31 March 2025, and the requirements now apply in full.
Recommended engagements
Zero Trust Transformation
Limits how far an intrusion can reach important business services, supporting the impact tolerances you have set.
View engagementAI Factory Design
Sets the rules for model oversight, explanation, and approval as AI moves into customer and credit decisions.
View engagementCritical Supplier Cyber Risk Review
Identifies which ICT providers carry material risk, and what DORA requires in their contracts.
View engagementBoard Cyber Governance Review
Tests whether the board's oversight of ICT and operational resilience risk would satisfy a supervisor.
View engagement