Financial Services
Financial services on infrastructure you own
Operational resilience is an architectural question. Third-party risk starts with who holds your data. DORA is now enforceable. The audit trail you need exists in your infrastructure or it does not exist.
UK financial services firms are in the middle of the most significant shift in operational resilience regulation in a decade. DORA came into force in January 2025. NIS2 has applied since October 2024. FCA expectations around AI model governance are being formalised. The direction of travel is clear: regulators want documented evidence of control, not contractual delegation.
The regulatory weight
The current frameworks driving infrastructure decisions in UK financial services:
DORA (Digital Operational Resilience Act)
In force January 2025 for EU-scope firms; UK FCA has signalled equivalent supervisory expectations. Requires ICT risk management, incident classification and reporting, resilience testing, and contractual and oversight requirements for critical third-party ICT providers. Outsourcing to a hyperscaler does not remove the obligation to demonstrate control.
FCA Operational Resilience Policy Statement (PS21/3)
UK firms must identify important business services, set impact tolerances, and demonstrate they can remain within those tolerances by March 2025. Infrastructure that depends on external uptime SLAs is a residual risk, not a documented control.
NIS2 Directive
In force October 2024 for EU-scope entities. Broadened scope, tightened incident reporting timelines (24 hours for initial notification), and direct liability for management bodies. Firms operating across UK and EU need to understand where their obligations sit.
UK GDPR and FCA data governance expectations
Personal and financial data processed under UK GDPR. AI model decisions that affect customers carry additional regulatory scrutiny.
We build the technical documentation DORA's ICT risk management requirements call for into every deployment from the start, rather than retrofitting it after the fact.
Why sovereignty matters specifically here
DORA introduced a specific problem for firms reliant on hyperscaler infrastructure: the concentration risk notification. Where a firm has critical ICT dependencies on a single provider, DORA requires documented management of that concentration risk. For firms whose operational dependencies run through one cloud provider, that documentation is not straightforward.
Three practical issues arise. An FCA operational resilience review asks for evidence that a firm can remain within its impact tolerances when a critical system is unavailable; if that system is a cloud service, the firm’s resilience depends on the vendor’s availability, not the firm’s own controls. A DORA audit of third-party ICT risk requires documented oversight of the providers who hold critical data, and many firms have not mapped this precisely. An AI model used for credit or risk decisions needs to have its governance documented; a model hosted by a third party, trained on data the firm does not fully control, creates a governance chain that is difficult to evidence.
Three typical engagements
Third-party risk assessment
Structured review of current ICT vendor dependencies against DORA Article 28 and FCA operational resilience requirements. Documented risk register, concentration risk analysis, and remediation priorities. Fixed scope, fixed price.
DORA-aligned resilience review
Gap analysis of ICT risk management framework, incident classification process, and resilience testing capability against DORA requirements. Includes assessment of current infrastructure architecture against impact tolerance commitments.
Private AI for risk workflows
Deployment of self-hosted AI for internal risk analysis, compliance review, or operational processes. No client or counterparty data transits external infrastructure. Audit trail built in. Model governance documented.
Proof
Case studies in this sector are in preparation. Work in this area is ongoing; we will publish when client permission is confirmed.
Start here
Fixed scope. Fixed price. No day rates. We will map your current infrastructure posture against DORA and FCA operational resilience expectations on a 30-minute call and tell you exactly what the work involves.
Book a scoping call