Investment & Asset Management

Operational resilience, outsourcing and third-party risk in asset management

Building an operational resilience framework in asset management that covers custody, fund administration, technology and other critical third parties.

By Jonas Adam Mohamed Osman AbdelghafourPublished 15 March 2026

Summary

Asset managers are heavily outsourced businesses. Custody, fund administration, technology and data services are commonly provided by third parties whose failures translate directly into client harm. Operational resilience frameworks — increasingly a regulatory expectation — apply with particular force here. This article sets out how to build a resilience framework that covers the critical third parties on which the business depends.

Important business services

The starting point is a defensible identification of important business services — those that, if disrupted, would harm clients, threaten market integrity or threaten the firm's viability. Trade execution, valuation, subscriptions and redemptions, custody, and client reporting are typical candidates.

Impact tolerances

For each important business service, an impact tolerance defines the maximum tolerable disruption. Impact tolerances should be expressed in time and quantitative terms and stress-tested against severe-but-plausible scenarios.

Third-party governance

Critical third parties require governance over selection, contracting, ongoing oversight, incident management and exit. Concentration risk — multiple important services depending on the same third party — is often the largest exposure.

Scenario testing

Severe-but-plausible scenarios should test the resilience of important business services end to end, including third-party dependencies. Findings should drive investment in remediation, not sit in registers.

Governance rhythm

Board oversight includes approval of important business services, impact tolerances, and material remediation plans. Executive management runs the programme. The risk function provides second-line challenge and independent testing.

CRO and board implications

Boards should be able to answer, for any material client-facing service: what fails if this service is disrupted, how long can it be disrupted, and what happens next?

Practical implementation

Important business services mapping; impact tolerances with quantitative expression; third-party inventory with tiering and oversight; severe-but-plausible scenario testing; remediation programme with owners and dates.

Limitations

Regulatory expectations on operational resilience are evolving. Application should be confirmed with qualified counsel.

Related reading

See Investment & Asset Management risk governance, Enterprise Risk and Regulatory Compliance.

Frequently asked questions

What should risk leaders know about important business services?

The starting point is a defensible identification of important business services — those that, if disrupted, would harm clients, threaten market integrity or threaten the firm's viability. Trade execution, valuation, subscriptions and redemptions, custody, and client reporting are typical candidates.

What should risk leaders know about impact tolerances?

For each important business service, an impact tolerance defines the maximum tolerable disruption. Impact tolerances should be expressed in time and quantitative terms and stress-tested against severe-but-plausible scenarios.

What should risk leaders know about third-party governance?

Critical third parties require governance over selection, contracting, ongoing oversight, incident management and exit. Concentration risk — multiple important services depending on the same third party — is often the largest exposure.

What should risk leaders know about scenario testing?

Severe-but-plausible scenarios should test the resilience of important business services end to end, including third-party dependencies. Findings should drive investment in remediation, not sit in registers.

What should risk leaders know about governance rhythm?

Board oversight includes approval of important business services, impact tolerances, and material remediation plans. Executive management runs the programme. The risk function provides second-line challenge and independent testing.