FCA Compliance Support

Show the FCA your firm can stay within its impact tolerances. Operational resilience and cyber evidence for authorised firms, built from real testing rather than paperwork.

Service Details

FCA compliance support from Falx gives your firm the technical evidence to show supervisors you can stay within your impact tolerances when systems fail or are attacked. You get dependency maps, tested scenarios and control evidence your compliance team can put in front of the Financial Conduct Authority (FCA), not just policies.

Supervision has moved from policies to proof. Impact tolerances, scenario testing and third-party mapping all need technical work most compliance teams cannot produce alone. We pair regulatory knowledge with hands-on security delivery, as part of our governance programmes.

INFO

You get answers backed by artefacts when supervision probes, rather than assertions your SMF holders have to defend on trust.


Who the FCA rules apply to

Every FCA-authorised firm must have systems and controls proportionate to its business under the Senior Management Arrangements, Systems and Controls sourcebook (SYSC). That includes managing outsourcing and operational risk, and telling the FCA promptly about material incidents such as a significant cyber attack.

The operational resilience rules in SYSC 15A go further for a defined group: banks, building societies, PRA-designated investment firms, insurers, recognised investment exchanges, enhanced scope Senior Managers and Certification Regime (SM&CR) firms, and payment and e-money institutions. The transition period ended on 31 March 2025, so in-scope firms must now be able to remain within their impact tolerances.

What the FCA requires, in plain English

  • Important business services — Identify the services whose disruption would harm your clients or the market.
  • Impact tolerances — Set the maximum disruption each service can bear, and show you can recover inside it.
  • Mapping — Document the people, processes, technology, facilities and suppliers each service depends on, including cloud and fourth parties.
  • Scenario testing — Test against severe but plausible disruption, such as ransomware at a peak period or a compromised IT supplier.
  • Self-assessment — Keep a written record of the above, approved by your board and ready for supervisors.
  • Outsourcing and third parties — Apply SYSC 8 controls to critical suppliers, from due diligence to exit plans.

Where firms typically fall short

Most gaps we find are in the evidence, not the policy. Important business services are identified but dependencies are left unmapped, particularly cloud concentration risk. Scenario tests rarely model a genuine cyber disruption, and impact tolerances are set without proof the firm can recover inside them.

Incident processes are another weak spot. Notification steps are often written down but never rehearsed, so nobody is sure who calls the FCA, when, or with what.


FCA compliance your auditors can follow

Whether you are preparing for authorisation, responding to a skilled person review or keeping SYSC and operational resilience obligations current, we map what applies to your permissions and close the gaps.

We write policies your team will follow, test controls before the regulator does, and package evidence in a form supervisors can review.

Two colleagues reviewing compliance documents together in a bright office

Where we help FCA-regulated firms

Support across the areas supervisors probe most:

Operational Resilience

Important business services, impact tolerances and scenario testing that stand up to scrutiny.

Outsourcing & Third Parties

SYSC 8 controls for critical suppliers, from due diligence through to exit plans.

Authorisation Support

Application packs, policies and interview preparation for firms seeking authorisation.

Incident Readiness

Notification thresholds, playbooks and rehearsed response for when things go wrong.


How an FCA engagement runs

We start with a gap analysis: your permissions and business model mapped to the rules that apply, and your current state assessed against each one. Remediation is phased by regulatory risk, and the results are kept in an evidence pack your compliance officer can hand to a supervisor and keep current.

Gap Analysis

Which rules apply and where you fall short

Remediation

Gaps closed in order of regulatory risk

Evidence

A pack supervisors can review, kept current

Technical evidence comes from penetration testing, threat modelling and security posture reviews. Risk management keeps your tolerances and risk register aligned, and board advisory gives accountable executives reporting they can defend.


FCA work often overlaps with DORA for EU-regulated group entities, ISO 27001 and NIST for the underlying controls, and PCI DSS for firms handling card data. UK GDPR covers the personal data inside your important business services, and Cyber Essentials sets a baseline for smaller firms.

Our compliance support team keeps evidence current between reviews, and identity and access controls who can reach critical systems. For how these fit together, see our end-to-end compliance programme.

We support financial services and insurance firms, and private equity portfolio companies where regulatory standing affects valuation.


Frequently asked questions

Answer supervision with evidence

Tell us your permissions, your important business services and what supervision last asked for. You get a clear view of where your evidence holds up and what to fix first.