Operational Resilience Fails Without Understanding Human Risk
- davidjamesgrosse
- Apr 8, 2025
- 2 min read
Updated: Dec 29, 2025
๐๐๐ฉ๐๐๐ญ ๐๐๐ญ๐๐ซ ๐ฆ๐ โ โ๐ข๐ ๐ ๐ก๐๐ฏ๐งโ๐ญ ๐ฉ๐ซ๐ข๐จ๐ซ๐ข๐ญ๐ข๐ณ๐๐ ๐๐ง ๐ฎ๐ง๐๐๐ซ๐ฌ๐ญ๐๐ง๐๐ข๐ง๐ ๐จ๐ ๐ก๐ฎ๐ฆ๐๐ง ๐ซ๐ข๐ฌ๐ค ๐๐ง๐ ๐๐๐ก๐๐ฏ๐ข๐จ๐ฎ๐ซ๐๐ฅ ๐๐ซ๐ข๐ฏ๐๐ซ๐ฌ ๐ข๐ง ๐ฆ๐ฒ ๐จ๐ซ๐ ๐๐ง๐ข๐ณ๐๐ญ๐ข๐จ๐ง ๐ข๐ญ ๐ฐ๐ข๐ฅ๐ฅ ๐ง๐จ๐ญ ๐๐ ๐จ๐ฉ๐๐ซ๐๐ญ๐ข๐จ๐ง๐๐ฅ๐ฅ๐ฒ ๐ซ๐๐ฌ๐ข๐ฅ๐ข๐๐ง๐ญโ
In 11 days time the final PRA and FCA requirements on Operational Resilience come into force (for financial services firms).
Doubtless everyone has now dotted their Iโs & crossed their Tโs, on their important business services, impact tolerances and the myriad of technical, process & governance obligations.
But is there the danger that this could lead to the โillusion-of-resilienceโ or โresilience-theatreโ?
Tackling the technical risks that arise from cyber, technology & key third parties is of the utmost importance, but without (also) addressing the human factor it is a 2 legged stool โ likely to be wobbly when you sit on it.
I was reminded of these imperatives over the last 2 days as I attended the 1LoD Culture & Conduct deep dive.
The excellent opening debate covered what Financial Services can learn from other highly regulated industries. Whether Aircraft Safety, the UK Met Police or Nuclear Accidents it was clear that when an incident happened there was always a human element entwined within the root causes.
Prior thoughts on the lessons from nuclear accidents and Fukushima here:
And on the difference between proximate and ultimate causation here:
As I was (once again) pondering why key behavioural risks take a back seat, as everyone clambers for the comforting balm of technical solutions, a new survey popped into my feed from KPMG USA on Risk & Resilience.
This majored on the usual risk & resilience levers โ but it did note (in passing) that โtwo-thirds to nearly three-quarters (of firms) - face moderate to strong barriers in effectively managing riskโ.
These barriers included performing duplicative efforts (71%), cultural resistance (66%) & lack of awareness and communication (72%).
These obstacles are not technical they are behavioural.
๐๐๐ฉ๐๐๐ญ ๐๐๐ญ๐๐ซ ๐ฆ๐ โ โ๐ข๐ ๐ ๐ก๐๐ฏ๐งโ๐ญ ๐ฉ๐ซ๐ข๐จ๐ซ๐ข๐ญ๐ข๐ณ๐๐ ๐๐ง ๐ฎ๐ง๐๐๐ซ๐ฌ๐ญ๐๐ง๐๐ข๐ง๐ ๐จ๐ ๐ก๐ฎ๐ฆ๐๐ง ๐ซ๐ข๐ฌ๐ค ๐๐ง๐ ๐๐๐ก๐๐ฏ๐ข๐จ๐ฎ๐ซ๐๐ฅ ๐๐ซ๐ข๐ฏ๐๐ซ๐ฌ ๐ข๐ง ๐ฆ๐ฒ ๐จ๐ซ๐ ๐๐ง๐ข๐ณ๐๐ญ๐ข๐จ๐ง ๐ข๐ญ ๐ฐ๐ข๐ฅ๐ฅ ๐ง๐จ๐ญ ๐๐ ๐จ๐ฉ๐๐ซ๐๐ญ๐ข๐จ๐ง๐๐ฅ๐ฅ๐ฒ ๐ซ๐๐ฌ๐ข๐ฅ๐ข๐๐ง๐ญโ*





Comments