Governance, Risk & Operational Resilience Health Check
A short self-assessment for small financial services firms to identify whether their governance, risk management and operational resilience arrangements are keeping pace with regulatory expectations, business growth and operational complexity.
Scoring
- Yes = 2 pts
- Partially = 1 pt
- No = 0 pts
Best suited for
Outcome
Participant details
Please enter your email address before completing the survey. An acknowledgement will be sent to you once you submit.
Section 1: Governance
1.Do you have clearly documented roles and responsibilities for senior leaders?
2.Is there a formal governance structure with defined reporting lines?
3.Do management meetings have agendas, minutes and action tracking?
4.Is there a documented delegation of authority framework?
5.Are key business decisions formally recorded?
6.Does the Board or leadership team receive regular management information and risk reporting?
7.Have you clearly assigned responsibility for regulatory obligations?
8.Are regulatory changes monitored and assessed for business impact?
9.Do you regularly review governance arrangements against FCA expectations?
Section 2: Risk Management
10.Do you maintain a documented Risk Management Framework?
11.Do you have an up-to-date Risk Register?
12.Are risks assigned to accountable owners?
13.Are risks reviewed at least quarterly?
14.Have you defined your risk appetite?
15.Are key risks reported to senior management?
16.Have you documented key controls for your major risks?
17.Are control weaknesses tracked and remediated?
18.Do you conduct periodic compliance or control reviews?
19.Is third-party and supplier risk assessed regularly?
Section 3: Operational Resilience
20.Have you identified your important business services?
21.Have you documented the processes supporting those services?
22.Do you understand your key dependencies, including people, systems, suppliers and data?
23.Have you established recovery priorities for critical services?
24.Do you have a documented Business Continuity Plan?
25.Has the plan been tested within the last 12 months?
26.Do you have a Crisis Management Plan or Incident Playbook?
27.Are key contact lists maintained and reviewed?
28.Have cyber incident response arrangements been documented and tested?
Section 4: People, Culture and Accountability
29.Do employees understand their governance and risk responsibilities?
30.Is there a process for escalating incidents or concerns?
31.Do you provide regular compliance or risk training?
32.Is accountability clearly understood across the organisation?
33.Do you assess key person dependencies and succession risks?
Section 5: Strategic Readiness
34.Could you confidently explain your governance framework to the FCA today?
35.Would your Board be comfortable discussing key risks with regulators?
36.Do you have a clear governance roadmap supporting future growth?
37.Are governance arrangements keeping pace with business growth?
38.Are investors, customers or regulators increasingly asking about resilience, governance or controls?
Need support strengthening your governance, risk or resilience arrangements?
We help small financial firms build practical, proportionate and regulator-ready governance, risk and operational resilience frameworks that support growth, oversight and decision-making.
Request a follow-up reviewThis tool provides an indicative self-assessment only and does not constitute legal, regulatory or compliance advice.