Operational Resilience, Outsourcing and 3rd Party Risk
By Michael Faber
It was great to attend the Infoline Operational Resilience, Outsourcing and 3rd Party Conference this week, and to join the panel discussion on Business Continuity within the context of Operational Resilience.
What a great start!
The event started off well with a presentation from the Bank of England on the PRA discussion paper 3/22 and FCA discussion paper 22/3 Operational Resilience: Critical third parties to the UK finance sector. These are early discussion papers and are dependent on the Financial Services and Markets Bill which is currently at the report stage within the House of Commons. It will then need to go through the House of Lords before final stages of agreement. The aim is to define the critical third parties, and then to allow the financial regulators to set rules for these third parties to adhere to, with the power to conduct reviews and actions similar to UK financial firms which are currently regulated in this way. It was highlighted as important to note that those firms inside current regulation would not be in scope for this new regulation.
Fifth parties and beyond …
There were several discussions around the need to look further than third parties, potentially fourth party, fifth party and more. Some interesting examples were cited such as a company who had outsourced their HR to a third party, where new staff vetting was further outsourced to a fourth party, including sensitive personal data capture etc., but had not been noted at all in the associated service contract. Another third party said that it had “a plan if losing a key fourth party”. When asked what their plan was, the response was “we will convene a crisis management meeting!” Clearly this is an area where further consideration and work is required.
Toilet paper and flour …
It was nice to catch up with an old friend Professor Simon Ashby and to hear his entertaining presentation regarding building resilience for new black swan risks. He particularly spoke about the human response and like me, having been involved in pandemic planning for many years, still did not predict that the UK would have gone into a lockdown and the effects it would bring. It was also interesting to note that early human response to the pandemic resulted in supermarkets running out of toilet paper and flour!
Key takeaway …
One particular takeaway from the panel discussion I was involved with, together with other panels and indeed break time chats over the two days was associated with one of the core components of Operational Resilience, that of resource mapping. Whilst mapping may have now been performed for the firms’ Important Business Services, many have used simple recorders such as spreadsheets and Visio. Two key reasons were cited – either firms have not yet found any suitable tools, or are concerned that additional regulatory changes may render their chosen tool unsuitable in the future.
The solution for business process mapping …
Our experience has been very different when assisting firms with their operational resilience work, as we have chosen to partner with BusinessOptix, and use their transformation suite that includes process discovery and mapping tools to provide total operational transparency as to how processes, people, and technology interact. We combine their software with our business domain knowledge to create a solution that adds value not only in complying with the Operational Resilience regulations, but also enables objective data-led discussions as to where business processes can be improved or informs the impact of a future state model of a business transformation.
The clients we have worked with have recognised wider benefits from the investment made in resource mapping using a fit-for-purpose platform, including improved data alignment between departments, business process improvements, informing incident and crisis events, and the power of digital twinning.
Get in touch
If you are looking to deliver wider benefits than the regulatory driver from your process mapping we would welcome a discussion as to how we can help you create a tangible solution for capturing and modelling your processes, tailored to how you do business. We’ll help you shape up for the future. Contact one of us or send an e-mail to info@shapesfirst.com.