The Pressure Points: Legal, Compliance, Risk and Data in Financial Services
Week 2: Operational Resilience
Continuing The Pressure Points, my mini-series exploring what is actually happening across legal, compliance, risk and data in financial services. Each week brings together two posts: a short market view, followed by a deeper dive into the themes coming through from firms, regulators and advisory work. The aim is to keep it useful, commercially relevant, and focused on what feels real.
Market View: Operational Resilience Has Become a Talent Issue
Following on from my last post, one area that feels especially relevant right now is operational resilience.
Operational resilience is still often talked about as a regulatory topic. I think that understates it. It has become a hiring and organisational issue too.
Once you get into resilience properly, the pressure moves quickly beyond policy and into delivery: critical services, third-party exposure, incident processes, governance, accountability, data, testing, reporting.
At that point, this stops being something one team can "own" neatly. It becomes cross-functional very quickly. That is why resilience-related hiring is often more nuanced than it looks on paper.
Firms are not always looking for more policy expertise. Quite often they are looking for people who can connect risk, legal, compliance, operations and technology in a way that actually works.
That tends to be where the strongest profiles sit too. People who can help a business move from "we know what the rules are" to "we know how this actually operates under pressure". Feels like one of the clearest examples of regulation shaping talent demand in a more practical way.
Are firms in your market properly set up for that yet?
Deeper Dive: From Frameworks to Operating Models
Following on from my post earlier this week on operational resilience, this is the part I think matters most.
A lot of the policy work has already been done. What comes next is where things get more real.
The direction of travel now is toward testing, reporting, oversight and direct accountability for outcomes. That matters because resilience is not just about whether a framework exists.
It is about whether firms can show:
- what their important services are
- where the third-party dependencies sit
- what happens if those dependencies fail
- how incidents are identified and escalated
- and whether governance stands up when pressure is real
The third-party point is especially important. There is a lot of focus now on outsourcing, concentration risk and critical third parties, but firms still remain accountable for their own resilience outcomes.
That is a meaningful shift in practice. It means operational resilience is increasingly a live delivery issue across legal, compliance, procurement, risk, cyber and operations.
From a hiring perspective, that usually creates demand for people who can do more than interpret policy. It creates demand for people who can make the operating model hold together.
That is where I think a lot of the interesting searches will sit over the next 12 to 24 months.
Is resilience in your world still treated as a programme, or is it now part of the core operating model conversation?
This is part of The Pressure Points, a weekly series exploring what’s really happening across legal, compliance, risk and data in financial services.
Missed the previous week? Catch up here:
If you’d like to follow the series and stay close to these market shifts, you can follow or connect with Jordan Forbes on LinkedIn.
