FCA Compliance Support
Show the FCA your firm can stay within its impact tolerances. Operational resilience and cyber evidence for authorised firms, built from real testing rather than paperwork.
Service Details
FCA compliance support from Falx gives your firm the technical evidence to show supervisors you can stay within your impact tolerances when systems fail or are attacked. You get dependency maps, tested scenarios and control evidence your compliance team can put in front of the Financial Conduct Authority (FCA), not just policies.
Supervision has moved from policies to proof. Impact tolerances, scenario testing and third-party mapping all need technical work most compliance teams cannot produce alone. We pair regulatory knowledge with hands-on security delivery, as part of our governance programmes.
INFO
You get answers backed by artefacts when supervision probes, rather than assertions your SMF holders have to defend on trust.
Who the FCA rules apply to
Every FCA-authorised firm must have systems and controls proportionate to its business under the Senior Management Arrangements, Systems and Controls sourcebook (SYSC). That includes managing outsourcing and operational risk, and telling the FCA promptly about material incidents such as a significant cyber attack.
The operational resilience rules in SYSC 15A go further for a defined group: banks, building societies, PRA-designated investment firms, insurers, recognised investment exchanges, enhanced scope Senior Managers and Certification Regime (SM&CR) firms, and payment and e-money institutions. The transition period ended on 31 March 2025, so in-scope firms must now be able to remain within their impact tolerances.
What the FCA requires, in plain English
- Important business services — Identify the services whose disruption would harm your clients or the market.
- Impact tolerances — Set the maximum disruption each service can bear, and show you can recover inside it.
- Mapping — Document the people, processes, technology, facilities and suppliers each service depends on, including cloud and fourth parties.
- Scenario testing — Test against severe but plausible disruption, such as ransomware at a peak period or a compromised IT supplier.
- Self-assessment — Keep a written record of the above, approved by your board and ready for supervisors.
- Outsourcing and third parties — Apply SYSC 8 controls to critical suppliers, from due diligence to exit plans.
Where firms typically fall short
Most gaps we find are in the evidence, not the policy. Important business services are identified but dependencies are left unmapped, particularly cloud concentration risk. Scenario tests rarely model a genuine cyber disruption, and impact tolerances are set without proof the firm can recover inside them.
Incident processes are another weak spot. Notification steps are often written down but never rehearsed, so nobody is sure who calls the FCA, when, or with what.
FCA compliance your auditors can follow
Whether you are preparing for authorisation, responding to a skilled person review or keeping SYSC and operational resilience obligations current, we map what applies to your permissions and close the gaps.
We write policies your team will follow, test controls before the regulator does, and package evidence in a form supervisors can review.

Where we help FCA-regulated firms
Support across the areas supervisors probe most:
Operational Resilience
Important business services, impact tolerances and scenario testing that stand up to scrutiny.
Outsourcing & Third Parties
SYSC 8 controls for critical suppliers, from due diligence through to exit plans.
Authorisation Support
Application packs, policies and interview preparation for firms seeking authorisation.
Incident Readiness
Notification thresholds, playbooks and rehearsed response for when things go wrong.
How an FCA engagement runs
We start with a gap analysis: your permissions and business model mapped to the rules that apply, and your current state assessed against each one. Remediation is phased by regulatory risk, and the results are kept in an evidence pack your compliance officer can hand to a supervisor and keep current.
Gap Analysis
Which rules apply and where you fall short
Remediation
Gaps closed in order of regulatory risk
Evidence
A pack supervisors can review, kept current
Technical evidence comes from penetration testing, threat modelling and security posture reviews. Risk management keeps your tolerances and risk register aligned, and board advisory gives accountable executives reporting they can defend.
Related frameworks and services
FCA work often overlaps with DORA for EU-regulated group entities, ISO 27001 and NIST for the underlying controls, and PCI DSS for firms handling card data. UK GDPR covers the personal data inside your important business services, and Cyber Essentials sets a baseline for smaller firms.
Our compliance support team keeps evidence current between reviews, and identity and access controls who can reach critical systems. For how these fit together, see our end-to-end compliance programme.
We support financial services and insurance firms, and private equity portfolio companies where regulatory standing affects valuation.
Frequently asked questions
Answer supervision with evidence
Tell us your permissions, your important business services and what supervision last asked for. You get a clear view of where your evidence holds up and what to fix first.