FCA Business Continuity Requirements: SYSC Rules Explained

Team of professionals seated around an oval conference table in a high-tech room, monitoring multiple screens and laptops.

If your firm is regulated by the Financial Conduct Authority, you’re expected to have more than a vague plan for when things go wrong. FCA business continuity requirements are set out clearly in the Senior Management Arrangements, Systems and Controls (SYSC) sourcebook, primarily under SYSC 4.1 and SYSC 13.8, and they leave little room for ambiguity about what regulators expect.

These rules require firms to establish and maintain continuity arrangements that keep critical operations running during disruptions, whether caused by cyber attacks, system failures, or third-party outages. Non-compliance isn’t just a regulatory risk; it can directly threaten client assets, market integrity, and your firm’s ability to operate. That’s precisely why, at TrustedIA, we work with regulated organisations to build business continuity and disaster recovery capabilities that meet both operational reality and regulatory standards.

This article breaks down the specific SYSC rules that govern business continuity for FCA-regulated firms, explains what they mean in practice, and outlines what your firm needs to demonstrate to stay compliant. Whether you’re reviewing your current arrangements or building them from scratch, this guide gives you a clear reference point to work from.

What the FCA means by business continuity

The FCA does not define business continuity as simply having a backup plan stored somewhere on a server. Business continuity, in the FCA’s view, means maintaining the ongoing delivery of critical functions even when something goes wrong. That includes keeping services available to clients, protecting data integrity, and ensuring your firm can meet its regulatory obligations without interruption. The regulator expects you to treat continuity planning as an active, tested, and documented process rather than a document that gets reviewed once a year and filed away.

The core definition under SYSC

SYSC 13.8 is the primary source for business continuity obligations, and it sets out that firms must establish and maintain contingency arrangements to ensure they can operate continuously and limit losses in the event of severe disruption. The FCA expects these arrangements to be proportionate to the nature, scale, and complexity of your business. A larger firm with more critical infrastructure will face a higher bar, but no regulated firm is exempt from having some form of documented, tested continuity plan in place.

The FCA’s expectation is not that disruptions will never happen, but that your firm has credible, tested arrangements to deal with them when they do.

The rule also requires that these arrangements cover people, processes, systems, and third-party dependencies. That last point carries real weight. If a critical supplier fails and your operations grind to a halt, the FCA will want to know what you had in place to manage that risk. Relying entirely on a vendor without any contingency is not an acceptable position for a regulated firm to be in.

What counts as a disruption

Ransomware attacks, IT system failures, physical incidents, and supply chain breakdowns all fall within scope. The fca business continuity requirements are not limited to large-scale disasters; a cyber incident that takes down your systems for 48 hours is exactly the kind of event these rules are designed to address.

Your continuity arrangements must account for realistic disruption scenarios that are relevant to your firm’s specific risk profile. That means you cannot copy a generic template and call it done. The FCA expects your plan to reflect how your business actually operates, which critical functions you rely on, and which systems or people are essential to delivering them.

The difference between continuity and recovery

Business continuity and disaster recovery are related but distinct concepts. Continuity focuses on keeping operations running during a disruption, while recovery focuses on restoring full functionality afterwards. Both matter to the FCA, but continuity comes first. The regulator wants to see that your firm can maintain critical services throughout an incident, not just clean up after one has passed. Understanding that distinction shapes how you build your arrangements and what you document when demonstrating compliance.

Which FCA rules apply and who they cover

The FCA business continuity requirements sit within two specific parts of the SYSC sourcebook: SYSC 4.1 and SYSC 13.8. SYSC 4.1 sets out the broad organisational requirements, requiring firms to have robust governance, internal controls, and management structures. SYSC 13.8 then goes deeper, specifically addressing operational risk and contingency arrangements, which is where most of the practical business continuity obligations live.

How SYSC 4.1 and SYSC 13.8 work together

SYSC 4.1 establishes the foundation. It requires firms to have sound administrative and accounting procedures, IT systems, and control arrangements that reflect the scale and nature of their business. This creates the baseline expectation that your firm is organised well enough to withstand operational pressure.

SYSC 13.8 builds on that foundation by requiring firms to establish and maintain specific contingency arrangements, making it the more actionable of the two rules for business continuity planning purposes.

SYSC 13.8 then requires firms to identify sources of operational risk, implement controls to manage them, and test continuity arrangements regularly. Together, the two rules create a joined-up framework where governance and operational planning are expected to reinforce each other.

Who these rules cover

Both rules apply to a wide range of FCA-regulated firms, including banks, insurers, investment firms, asset managers, and payment service providers. The obligations are not uniform across all firm types. MiFID investment firms, for example, face stricter requirements under the applied provisions of SYSC, while some smaller firms operating under simplified regimes have lighter-touch obligations. That said, every regulated firm carries some continuity responsibility under SYSC 4.1 regardless of size.

You can check your specific firm category and the applicable SYSC provisions directly in the FCA Handbook, which outlines exactly which rules apply to which firm types and regulatory permissions.

Why FCA continuity requirements matter

The FCA does not treat business continuity as a box-ticking exercise, and neither should you. Regulatory enforcement for inadequate continuity arrangements has resulted in significant fines and restrictions on firms’ ability to operate. Beyond the penalties, your clients and counterparties rely on your systems being available and your processes being intact when disruptions hit. That is the underlying purpose of these rules: protecting the people and markets your firm serves.

Continuity failures rarely stay contained. A firm that cannot maintain critical functions during an incident risks harming clients, breaching other regulatory obligations, and triggering supervisory scrutiny across multiple fronts at once.

The cost of getting it wrong

When your continuity arrangements fail, the consequences spread quickly. The FCA can impose financial penalties, require remediation programmes, or restrict parts of your permission set. Those outcomes sit on top of the operational costs your firm absorbs during and after an incident, including lost revenue, reputational damage, and the expense of recovering without a tested plan already in place.

Firms that lack documented and tested continuity plans also find themselves at a disadvantage during routine supervisory engagement. Supervisors ask for evidence of your arrangements, and gaps in your documentation become gaps in your defence when questions are raised.

Why clients and market integrity are central

The fca business continuity requirements exist primarily to protect clients and maintain orderly markets, not just to keep firms administratively compliant. If your firm cannot process client transactions, access client assets, or deliver services during a disruption, real harm flows to real people. The FCA expects you to take that responsibility seriously and build arrangements that genuinely reflect it.

Regulatory risk and client risk are two sides of the same coin. Treating continuity planning as a fundamental operational commitment rather than an administrative overhead is what separates firms that satisfy supervisory expectations from those that simply claim to.

How to meet SYSC business continuity expectations

Meeting SYSC business continuity expectations starts with understanding what the FCA actually wants to see: evidence that your arrangements are documented, proportionate, and regularly tested. A continuity plan that exists only in theory will not satisfy supervisors. You need to demonstrate that your firm has identified what matters most, prepared for realistic disruption scenarios, and rehearsed your response.

Document your critical functions and dependencies

Before you can build effective continuity arrangements, you need a clear picture of which functions are critical to your operation and which systems, people, and third parties support them. Map your dependencies carefully. If a core process relies on a single vendor or a single member of staff, that dependency represents a risk your plan must address directly. The FCA expects your documentation to reflect how your firm actually operates, not a theoretical version of it.

Your continuity plan should cover people, processes, systems, and suppliers as distinct areas of risk. Third-party dependencies carry particular weight here. Review your contractual arrangements with key suppliers to confirm they include continuity provisions, and document what your firm would do if a critical vendor became unavailable. Supervisors will look for evidence that your risk management extends beyond your own walls.

Test your plan and record the results

Testing is where many firms fall short of what the FCA expects. Writing a plan is the starting point, but the fca business continuity requirements demand that you validate it through regular exercises and record the outcomes. That means running realistic disruption scenarios, identifying gaps, and updating your arrangements whenever your business changes significantly.

Keep records of every test: what scenarios you ran, who participated, what gaps you identified, and what changes you made as a result.

Supervisors will ask for evidence of testing during reviews, and a plan that has never been exercised is difficult to defend. Regular, documented testing converts a static document into a credible operational capability that demonstrates genuine compliance.

How business continuity links to operational resilience

Business continuity and operational resilience are closely related, but the FCA treats them as distinct obligations. Business continuity focuses on maintaining critical functions during a disruption. Operational resilience, introduced through FCA Policy Statement PS21/3, sets a higher bar: it requires firms to assume disruptions will happen and demonstrate they can stay within defined impact tolerances for their important business services.

The shift from continuity to resilience means the FCA now expects you to prove your firm can absorb shocks, not just recover from them.

What operational resilience adds to the picture

The FCA’s operational resilience framework, which came into full effect in March 2025, requires firms to identify their important business services, set impact tolerances, and test whether they can remain within those tolerances during severe but plausible disruption scenarios. This goes beyond the SYSC 13.8 continuity requirements because it demands you demonstrate outcomes, not just document processes. Your continuity plan feeds directly into this framework, providing the underlying mechanisms that allow important business services to keep running.

Your business continuity arrangements need to align with the impact tolerances you set for each important business service. If your tolerance for a critical payment service is four hours, your continuity plan must be capable of delivering recovery within that window. Mapping the two together is essential to satisfying both sets of fca business continuity requirements and operational resilience expectations simultaneously.

Keeping both frameworks aligned

Treating continuity and resilience as separate workstreams creates unnecessary complexity and gaps in your overall preparedness. Integrate your continuity planning into your broader operational resilience programme so that testing, documentation, and governance cover both obligations together. Reviewing your impact tolerances and continuity arrangements at the same time ensures changes in one area are reflected in the other, giving supervisors a coherent picture of how your firm manages operational risk end to end.

Firms that align both frameworks also find it easier to demonstrate compliance during supervisory reviews. Rather than maintaining two separate sets of documentation, a unified approach reduces duplication and makes it clearer how your governance structures, continuity plans, and resilience testing connect.

Where to go from here

The fca business continuity requirements covered in this article give you a clear view of what SYSC 4.1 and SYSC 13.8 demand, how those rules connect to operational resilience, and what strong compliance looks like in practice. Meeting these obligations requires more than having a document saved somewhere on a shared drive. You need tested plans, mapped dependencies, and governance arrangements that hold up when supervisors ask direct questions about your approach.

Building those capabilities takes time and expertise that many firms lack in-house. TrustedIA works with regulated organisations to develop business continuity and disaster recovery programmes that satisfy FCA expectations and genuinely protect your operations during real disruptions. Our solution-agnostic approach means we focus on what works for your specific risk profile rather than fitting you into a fixed vendor solution. To find out how we can support your continuity programme, speak to the TrustedIA team today.