The State of FCA Authorisation in 2026: Why Operational Resilience Outweighs Revenue Targets
Claude
When the FCA published its operational resilience insights in late March 2026, it confirmed what we have been telling clients for months: if your Regulatory Business Plan (RBP) treats operational resilience as a footnote to your financial projections, your authorisation application will stall before it even reaches a case officer. The shift in regulatory philosophy is absolute. The era of the "theoretical application" is over.
Historically, firms treated the RBP like a Series A pitch deck. They focused on hockey-stick growth curves, market share acquisition, and burn rates. In 2026, a Case Officer cares far less about your revenue targets than they do about your ability to survive a total third-party provider failure. We see applications rejected not because the business model is weak, but because the firm cannot prove it has identified its "important business services" or set credible impact tolerances.
On March 27, 2026, the FCA published its most comprehensive set of observations since the operational resilience transition period ended in 2025. These observations are not mere suggestions. They are the benchmark against which your firm is being measured. If your RBP does not reflect these specific findings, you are essentially submitting a document that is already obsolete.
Impact Tolerances Require Nuance, Not Just IT Uptime
A major finding in the FCA's March 2026 report is that firms are failing to establish distinct impact tolerances. For too many years, resilience was treated as a binary state: either the servers were up, or they were down. The regulator has made it clear that a single uptime percentage is an insufficient metric for a modern financial institution.
You must define different tolerances for market integrity versus consumer harm. We often see firms set a blanket "four-hour recovery time objective." This fails the regulatory test because it ignores the nature of the harm. A four-hour outage that prevents a consumer from accessing funds for food or rent is viewed with far more severity than a four-hour delay in internal regulatory reporting that does not impact market liquidity.
Your RBP must detail how you reached these specific numbers. It is no longer enough to say "we aim for 99.9% uptime." You need to evidence the rationale. Why is four hours the limit? What happens to the consumer at hour five? If you cannot answer that, your authorisation clock will likely be paused. We recommend reading our deep dive on Beyond Business Continuity: Defining PRA Impact Tolerances That Pass Regulatory Audit to understand how to map these tolerances before the FCA asks the question.
"Promised" Infrastructure is an Application Killer
One of the most frequent reasons for application failure in 2026 is the presence of "promised" infrastructure. In Step 6 of our internal implementation methodology, we emphasize that systems must be materially in place before the application is submitted. Many founders believe they can hire a Compliance Officer or sign an AWS support contract "once we get the green light." The FCA view is the opposite: if you do not have the infrastructure now, you are not ready for authorisation.
This includes having vendor contracts signed, cybersecurity controls active, and your SMCR (Senior Managers and Certification Regime) responsibilities mapped. The FCA is now using its own internal AI tools to cross-reference your RBP against your financial projections. If your RBP claims 24/7 resilience but your budget does not show the licensing costs or the staff headcount required to manage that resilience, the system flags a discrepancy immediately.
As we have observed across the firms we work with, the true cost of authorisation is often three to five times the initial application fee. Firms that budget only for the £5,000 or £25,000 fee find themselves underwater when they realize they need to evidence a fully built operational resilience framework. For a breakdown of how these costs escalate, see our guide on Why the FCA Rejects Authorisation Applications and How to Secure Your License.
Resource Mapping Beyond the Tech Stack
The FCA's 2026 review explicitly noted that mapping has been too focused on technology. While having a resilient cloud architecture is necessary, it is only one piece of the puzzle. The regulator now expects detailed mapping of facilities, people, and processes.
What happens if your primary office is inaccessible? Who are the "single points of failure" in your senior management team? If your lead developer is the only person with the keys to the kingdom, you do not have a resilient business. You have a key-man risk that the FCA will reject. Mapping must now include third-party testing outcomes. You cannot just state that your outsourcer is resilient; you must prove that you have tested their resilience yourself or audited their SOC2 reports with a critical eye.
We see firms struggle with this because it requires a level of granularity that feels "un-startup-like." However, the FCA's mandate is to protect the UK financial system. They view your firm as a node in a massive, interconnected network. If your node is weak, you are a threat to the network. Your RBP must prove that you have accounted for supply chain failures, physical disruptions, and even the loss of key personnel during a crisis.
Predictions for 2026/2027 Scrutiny
Looking ahead, we expect the FCA to get even more aggressive regarding emerging threats. Suman Ziaullah, the FCA’s Head of Technology, Resilience and Cyber, has already signaled that the real test is how firms handle complex supply chains and emerging tech.
First, expect scenario testing requirements to expand. It will no longer be enough to test for "server failure." You will likely be asked to demonstrate resilience against AI-driven fraud attacks and quantum computing threats that could compromise existing encryption standards. If your RBP doesn't mention how your resilience framework will evolve with these technologies, it will look dated within months of submission.
Second, the FCA is becoming a data-driven regulator. They are testing new tools to identify risks earlier, which means your submissions will be analyzed by algorithms before a human ever sees them. Inconsistencies that a tired human case officer might have missed in 2018 are caught instantly by AI in 2026. This makes the "copy-paste" RBP approach dangerous. Every document must be perfectly aligned.
Embed, Don't Just Execute
The solution is to move away from viewing compliance as a hurdle and start seeing it as a business return on investment. A resilient firm is a more valuable firm. It is more attractive to investors, more reliable for customers, and less likely to face the devastating costs of a Section 166 review later.
We advise firms to use standardized, professional-grade frameworks to map their resources. Our Consumer Duty and Operational Resilience Toolkit, available through our Silver and Gold retainers, provides the templates necessary to ensure your mapping meets the 2026 standard. This is not about filling in blanks; it is about building a methodology that embeds resilience into your daily operations.
I firmly believe that at the intersection of regulatory requirements, consumer rights, commercial viability, and a social conscience, there is a great deal of good that can be created. But that good only happens when the foundation is solid. If you are preparing an application in 2026, stop looking at your projected revenue and start looking at your impact tolerances. That is what the regulator is doing.
Before you submit your application to the FCA, consider an independent benchmark review. It is far cheaper to fix an RBP inconsistency in a mock audit than it is to explain that inconsistency to a regulator after your application has been rejected and your fee forfeited. The 2026 landscape is faster and more efficient for those who are prepared, but it is unforgiving to those who treat resilience as an afterthought.

