Summary
Asset managers are heavily outsourced businesses. Custody, fund administration, technology and data services are commonly provided by third parties whose failures translate directly into client harm. Operational resilience frameworks — increasingly a regulatory expectation — apply with particular force here. This article sets out how to build a resilience framework that covers the critical third parties on which the business depends.
Important business services
The starting point is a defensible identification of important business services — those that, if disrupted, would harm clients, threaten market integrity or threaten the firm's viability. Trade execution, valuation, subscriptions and redemptions, custody, and client reporting are typical candidates.
Impact tolerances
For each important business service, an impact tolerance defines the maximum tolerable disruption. Impact tolerances should be expressed in time and quantitative terms and stress-tested against severe-but-plausible scenarios.
Third-party governance
Critical third parties require governance over selection, contracting, ongoing oversight, incident management and exit. Concentration risk — multiple important services depending on the same third party — is often the largest exposure.
Scenario testing
Severe-but-plausible scenarios should test the resilience of important business services end to end, including third-party dependencies. Findings should drive investment in remediation, not sit in registers.
Governance rhythm
Board oversight includes approval of important business services, impact tolerances, and material remediation plans. Executive management runs the programme. The risk function provides second-line challenge and independent testing.
CRO and board implications
Boards should be able to answer, for any material client-facing service: what fails if this service is disrupted, how long can it be disrupted, and what happens next?
Practical implementation
Important business services mapping; impact tolerances with quantitative expression; third-party inventory with tiering and oversight; severe-but-plausible scenario testing; remediation programme with owners and dates.
Limitations
Regulatory expectations on operational resilience are evolving. Application should be confirmed with qualified counsel.
Related reading
See Investment & Asset Management risk governance, Enterprise Risk and Regulatory Compliance.
Frequently asked questions
What should risk leaders know about important business services?
The starting point is a defensible identification of important business services — those that, if disrupted, would harm clients, threaten market integrity or threaten the firm's viability. Trade execution, valuation, subscriptions and redemptions, custody, and client reporting are typical candidates.
What should risk leaders know about impact tolerances?
For each important business service, an impact tolerance defines the maximum tolerable disruption. Impact tolerances should be expressed in time and quantitative terms and stress-tested against severe-but-plausible scenarios.
What should risk leaders know about third-party governance?
Critical third parties require governance over selection, contracting, ongoing oversight, incident management and exit. Concentration risk — multiple important services depending on the same third party — is often the largest exposure.
What should risk leaders know about scenario testing?
Severe-but-plausible scenarios should test the resilience of important business services end to end, including third-party dependencies. Findings should drive investment in remediation, not sit in registers.
What should risk leaders know about governance rhythm?
Board oversight includes approval of important business services, impact tolerances, and material remediation plans. Executive management runs the programme. The risk function provides second-line challenge and independent testing.