Sector guide
Financial services.
Operational resilience, information security and governance
Operating priorities
Where to focus first.
Operational resilience, information security and governance.
Map the activities that most affect users, customers and staff. Identify material risks, requirements and dependencies before selecting a framework or tool. Verify sector-specific legal duties with competent advice.
- Select a critical service or process.
- Name its owner, outcome and main dependencies.
- Collect recent performance and incident evidence.
- Choose a short improvement cycle and review its effect.
First field test
Observe this work directly.
Test one important business service under a supplier or system outage scenario.
Time to recover and unmet customer obligations.
Record the owner, evidence, conclusion and next review date. Select applicable legal and customer requirements before calling this a formal control.
Relevant standards
Useful frameworks to examine.
Information security management
A risk-based management system for protecting information, choosing controls and showing that those controls remain effective.
View standard ISO 22301:2019Business continuity
A system for preparing an organisation to keep priority activities running through disruption and recover in a controlled way.
View standard ISO 37301:2021Compliance management
A framework for identifying obligations, assigning responsibility and checking whether compliance arrangements are effective.
View standardEvidence to examine
Start with a real process and its records.
Information security scope
Define the information and systems in scope, assess risks, choose proportionate treatment, involve suppliers and test the response to incidents. Read framework context
Risk assessment and treatment
Define the information and systems in scope, assess risks, choose proportionate treatment, involve suppliers and test the response to incidents. Read framework context
Business impact analysis
Identify the activities whose interruption would hurt most, their dependencies, tolerable outage and recovery choices; rehearse the plan rather than merely filing it. Read framework context
Continuity strategies and plans
Identify the activities whose interruption would hurt most, their dependencies, tolerable outage and recovery choices; rehearse the plan rather than merely filing it. Read framework context
These examples show possible evidence across relevant management systems. Applicability depends on the organisation, activity and current obligations.
Connected improvement topics
Follow the work across functions.
Tender readiness
Build evidence, capacity and response discipline before chasing a procurement opportunity.
Explore Improvement topicProcurement
Translate requirements into fair sourcing decisions, supplier controls and measurable outcomes.
Explore Improvement topicAI governance
Keep an inventory of AI uses, accountable owners, impact assessments and monitoring decisions.
Explore Improvement topicData management
Define data ownership, quality, access, retention and the decisions data is allowed to support.
Explore Improvement topicCybersecurity
Prioritise information assets, common attack paths, recovery capability and supplier exposure.
Explore Improvement topicRisk management
Describe uncertain events in operational terms and choose proportionate responses with owners and review dates.
Explore