Financial services

Keep critical services running, and prove it to supervisors.

In financial services, supervisors expect firms to show they can withstand severe disruption, including at their technology suppliers. We help firms meet DORA and UK operational resilience requirements, contain incidents before they reach important business services, and introduce AI with the oversight and evidence supervisors expect.

Situations we help with

Across banks and building societies; insurers; payment and e-money institutions; and investment and asset managers.

  • Your DORA register of information shows several critical services depending on one cloud provider.
  • A supervisor has asked for evidence that you can remain within impact tolerances in a severe but plausible scenario.
  • You have been identified for threat-led penetration testing, and nobody has planned how findings will be remediated and reported to the board.
  • Contracts with ICT providers lack the notification, audit, and exit provisions DORA requires.
  • Teams are piloting AI in customer servicing or credit decisions, and there is no agreed approach to oversight, explanation, or model risk.

The challenges

Concentrated technology dependence

Core banking, payments, and customer channels can depend on a small number of cloud and technology providers, so an outage at one can affect many important business services at once.

Evidence for supervisors

DORA and the UK operational resilience rules expect firms to show, through testing and documentation, that they can withstand severe disruption and that the board has overseen it.

Attractive to attackers

Financial firms hold money and data that attackers can monetise, and their customer-facing services face fraud, ransomware, and denial-of-service attacks.

Third-party oversight

Firms remain accountable for the services they outsource, so contracts, monitoring, and exit plans for ICT providers need the same rigour as in-house controls.

ENISA's analysis of 488 publicly reported cyber incidents affecting the European financial sector between January 2023 and June 2024 found banks among the most affected, with denial-of-service attacks, data breaches, and ransomware among the main threats.

Source: ENISA Threat Landscape: Finance Sector, February 2025

AI in financial services

Customer servicing

The value
Faster, more consistent answers for customers.
What needs governing
Incorrect advice or commitments to customers, and conduct obligations for outcomes the AI influences.

Fraud and financial crime detection

The value
Earlier detection of suspicious activity.
What needs governing
Models that drift, false positives that harm customers, and decisions nobody can explain to supervisors.

Credit and underwriting

The value
Faster, better-informed decisions.
What needs governing
Fairness, explainability, and model risk management for decisions with significant effects on customers.

AI Factory Design sets the rules for approval, model oversight, and evidence across these uses, so AI can scale in ways you can explain to customers and supervisors. It is part of our AI Governance and Transformation practice.

Regulation that may apply

DORA (EU)

Applies to
Financial entities in the EU, including credit institutions, insurers, investment firms, payment and e-money institutions, and crypto-asset service providers.
What it asks
The management body is responsible for the ICT risk management framework. A major ICT-related incident is notified to the competent authority within four hours of its classification and no later than 24 hours after becoming aware of it, followed by intermediate and final reports. Designated entities carry out threat-led penetration testing at least every three years.
Timing
Applies since 17 January 2025.

UK operational resilience (PRA and FCA)

Applies to
Firms within scope of the PRA and FCA rules, including banks, building societies, insurers, and payment and e-money institutions.
What it asks
Identify important business services, set an impact tolerance for each, map and test them, and remain within those tolerances in severe but plausible scenarios.
Timing
The transition period ended on 31 March 2025, and the requirements now apply in full.

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.