The signals that matter: What FCA supervision means for governance and insurance
By Chris Rigg; Richard Langdon, Howden
Published: 21 September 2026
The UK’s operational resilience framework is well established. What’s changing is how the FCA supervises firms. Its observations are becoming a valuable source of risk intelligence and an opportunity for alternative investment managers to reassess whether their governance, resilience and insurance arrangements have kept pace with an operating model that’s changing faster than ever.
The operational resilience conversation has changed. Not because the rules have changed. Because the regulator has.
For several years, alternative investment managers have invested heavily in identifying critical business services, mapping dependencies and testing disruption scenarios. Those capabilities are now embedded across much of the industry.
The FCA has noticed, and in its recent supervisory activity suggested the conversation is moving beyond implementation. Increasingly, the question isn’t whether firms have a framework. It’s whether that framework reflects how the business really operates and whether boards understand where operational risk now sits.¹
As the FCA puts it, firms should treat resilience as “a core business capability, integrated into strategic planning... rather than as a standalone exercise.”1
That’s a subtle shift, but one with much wider implications than compliance alone.
Supervision is becoming a source of risk intelligence
Regulation traditionally tells firms what they need to do. Supervision tells firms where others are still getting it wrong, and that’s an important distinction.
Portfolio letters, thematic reviews and supervisory observations are more than regulatory updates. Read collectively, they offer an independent view of the operational risks that continue to challenge firms across the market.
Rather than waiting for an incident or a regulatory finding to expose weaknesses, firms can use those observations to test their own assumptions.
The question is no longer simply “Are we compliant?” It’s increasingly “If the regulator continues to identify these weaknesses elsewhere, could they exist within our business too?”
That makes supervisory insight more than a compliance exercise. It becomes a governance tool.
Why this matters for insurance
Insurance may not be the focus of supervisory communications, but it’s often where the financial consequences of operational failures ultimately land.
Yet many of the issues attracting regulatory attention, supplier failure, cyber events, technology outages and governance weaknesses, share one characteristic: they can all create significant financial loss.
This is where supervisory insight becomes particularly valuable.
Alternative investment managers have transformed the way they operate. Outsourcing has increased. Technology has become more interconnected. Critical services increasingly depend on external providers rather than internal infrastructure.
Those changes affect far more than operational resilience. They also change the nature of financial risk.
The rapid adoption of generative AI is a good example. Many firms are embedding AI into research, operations and client-facing processes, often through third-party platforms. While these technologies offer clear opportunities, they also introduce new questions around governance, accountability, intellectual property, data security and third-party dependency.
The issue isn’t whether firms should adopt AI. It’s whether the controls, resilience planning and insurance arrangements supporting that adoption are evolving at the same pace. As with cloud technology before it, innovation changes the operational risk profile and supervisory expectations are evolving alongside it.
Verizon’s 2025 Data Breach Investigations Report found that around 30% of breaches involved a third party, highlighting the growing financial impact of supplier-related incidents.2
The question therefore isn’t whether firms have insurance. It’s whether their insurance has evolved at the same pace as their operating model. Insurance shouldn’t be the last conversation after resilience planning. It should be one of the first.
Governance means challenging assumptions
The FCA’s supervisory observations reinforce a broader message for boards. Resilience isn’t demonstrated through policies alone. It is demonstrated through decision-making.
That applies equally to insurance governance.
Reviewing insurance once a year as part of the renewal process may have been appropriate when operating models changed slowly. Today’s environment is different. Technology, outsourcing arrangements and supplier ecosystems evolve continuously, meaning firms’ exposures evolve too.
Insurance should therefore be reviewed alongside governance discussions, resilience assessments and scenario testing, not because regulation requires it, but because good governance does.
Reading the signals
Every supervisory observation is an opportunity to ask a better question.
Rather than waiting for a regulatory finding, firms should use those observations to challenge whether their governance, operational resilience and insurance arrangements still reflect the way the business operates today.
That doesn’t mean buying more insurance. It means reviewing whether the cover, limits and scope of protection remain aligned with an evolving operating model, changing supplier dependencies and emerging operational risks. In a world where supervision increasingly focuses on outcomes rather than frameworks, regular insurance reviews should become part of good governance, not just good procurement.
1 Financial Conduct Authority (2026). Operational resilience: Insights and observations one year on.
2 Verizon. (2025). 2025 Data Breach Investigations Report.
