Operational resilience in compliance functions: What happens when systems fail?

Introduction

In today’s financial environment, compliance functions have become increasingly dependent on technology. Transaction monitoring systems, sanctions screening tools, automated reporting platforms, customer risk rating engines, and case management applications now sit at the center of Anti-Money Laundering (AML) and financial crime frameworks. These systems are designed to improve efficiency, strengthen oversight, and support regulatory compliance. However, an uncomfortable reality often receives far less attention, what happens when these systems fail?

Operational resilience has become a major regulatory focus across the UK financial sector, particularly following increased cyber threats, major third-party outages, and growing dependence on digital infrastructure. The Financial Conduct Authority, Prudential Regulation Authority, and Bank of England have repeatedly stressed that firms must not only prevent disruptions but also demonstrate the ability to continue delivering important business services during operational incidents (Bank of England, 2021).

Despite this, many organisations continue to build compliance frameworks with the assumption that systems will always remain available. In practice, that assumption is increasingly dangerous. A sophisticated transaction monitoring platform becomes ineffective the moment data feeds fail. Sanctions controls become vulnerable when screening systems experience delays or outages. Automated regulatory reporting cannot function when source data becomes corrupted or inaccessible. The issue is not simply technological failure; it is the institution’s ability to maintain effective control during disruption.

Operational resilience within compliance functions is therefore no longer an IT concern alone. It has become a core risk management issue.

The growing dependence on automated compliance infrastructure

Over the past decade, financial institutions have invested heavily in automation to manage increasing regulatory expectations. This shift has been driven by rising transaction volumes, expanding sanctions requirements, enhanced AML obligations, and pressure to improve operational efficiency.

Today, many compliance functions rely heavily on:

  • Automated transaction monitoring systems
  • Sanctions and PEP screening tools
  • Customer risk-rating models
  • Automated suspicious activity workflows
  • Regulatory reporting systems
  • Case management platforms
  • Data integration engines

These systems undoubtedly improve scalability. However, they also create a dangerous operational dependency. Once controls become heavily automated, manual oversight often weakens over time. Staff become accustomed to trusting system-generated outputs without fully understanding the underlying processes or data flows supporting them.

This creates a critical vulnerability. When systems fail, many organisations discover that manual contingency processes are either underdeveloped, outdated, or operationally impractical.

The challenge becomes even more significant in smaller institutions where compliance teams operate with limited resources and high reliance on third-party vendors. In such environments, operational resilience is often assumed rather than genuinely tested.

System failure does not mean regulatory obligations stop

One of the most important realities often overlooked in operational resilience discussions is that regulatory obligations continue regardless of system availability.

A system outage does not remove a bank’s obligation to identify suspicious activity. It does not pause sanctions compliance requirements. It does not suspend customer due diligence responsibilities or regulatory reporting timelines.

From a regulatory perspective, firms are expected to maintain effective control environments even during disruption. The FCA has repeatedly emphasised that firms must establish adequate systems and controls proportionate to their business model and operational risks (FCA, 2021).

This is where many organisations face a significant gap between policy and operational reality.

On paper, contingency arrangements may exist within Business Continuity Plans (BCPs). However, in practice, many compliance teams have never genuinely tested whether manual processes can operate effectively under real operational pressure. A documented contingency process is not the same as an operationally viable one.

The operational reality of manual controls

In practice, manual controls are significantly more difficult than many institutions anticipate.

During a major system outage, compliance teams may suddenly face:

  • Delayed or unavailable transaction data
  • Incomplete customer information
  • Backlogs of unscreened payments
  • Inability to access historical alerts
  • Communication breakdowns between departments
  • Increased operational pressure and human error risk

Under these conditions, manual controls become heavily dependent on coordination, escalation discipline, and data integrity.

In one instance, during a major operational disruption affecting internal systems, manual monitoring controls had to be introduced temporarily to support transaction oversight. Prior-day balances and reconciliations were used as reference points to identify unusual movements while operational teams performed additional verification checks before transaction release. Escalation procedures were tightened to ensure that higher-risk activity received enhanced review before processing.

The control framework remained operational, but the process immediately became slower, more resource intensive, and significantly more reliant on human judgement. This highlighted an important reality; resilience is not simply about maintaining operations but maintaining control effectiveness during disruption.

Many firms underestimate how quickly operational pressure can weaken control quality when automation disappears.

Data integrity: the hidden dependency

Operational resilience discussions often focus heavily on system availability, but data integrity presents an equally significant risk.

Compliance systems are only as reliable as the data feeding them. If customer information is incomplete, transaction data becomes corrupted, or interfaces between systems fail, monitoring effectiveness deteriorates rapidly even if systems technically remain operational.

This issue becomes particularly dangerous during system migrations, infrastructure upgrades, or cyber incidents.

In many organisations, data ownership is fragmented across multiple departments. Compliance functions may rely on operations teams, IT departments, onboarding units, or external vendors for critical data inputs. When governance over these dependencies becomes weak, operational resilience deteriorates long before a full outage occurs.

This reinforces a fundamental point: operational resilience within compliance is not solely a technology issue. It is also a data governance issue.

Cyber risk and third-party dependency

The increasing digitalisation of financial services has significantly expanded cyber and third-party risks.

Financial institutions now rely heavily on external vendors for:

  • Cloud infrastructure
  • Screening software
  • Transaction monitoring platforms
  • Data hosting
  • Payment processing
  • Customer onboarding solutions

While outsourcing can improve efficiency, it also creates concentration risk. A third-party outage can quickly become a compliance incident for multiple institutions simultaneously.

Recent industry incidents have demonstrated how quickly operational disruptions can impact payment systems, customer access, and regulatory processes across the sector. Regulators have increasingly recognized this vulnerability, particularly where firms become overly dependent on a small number of critical providers.

The challenge for compliance functions is that outsourcing responsibility does not outsource accountability. Regulators will still hold firms responsible for maintaining effective controls.

Operational resilience requires more than policies

One of the biggest weaknesses within many resilience programmes is the assumption that documentation alone creates resilience.

Policies, frameworks, and contingency plans are important. However, genuine resilience is built through testing, governance, escalation discipline, and operational preparedness.

Effective compliance resilience requires:

  • Realistic scenario testing
  • Manual process simulations
  • Clear escalation frameworks
  • Cross-functional coordination
  • Strong data governance
  • Defined accountability structures
  • Staff training under disruption scenarios
  • Senior management involvement

Importantly, resilience testing should not remain limited to IT functions alone. Compliance teams themselves must actively participate in operational disruption exercises.

This is particularly important because many operational failures emerge not from the initial outage itself, but from confusion, delays, and inconsistent decision-making during the response process.

Conclusion

As financial institutions continue to digitalise, operational resilience within compliance functions will become increasingly important. Automation undoubtedly improves efficiency, but it also creates operational dependency. When systems fail, firms are exposed not only technologically, but operationally and regulatorily.

The real test of a compliance framework is therefore not how it performs during normal conditions, but how effectively it continues to operate during disruption.

Firms that rely entirely on automated controls without robust contingency arrangements may discover that their resilience exists more strongly in policy documents than in operational reality.

Ultimately, operational resilience is not about preventing every disruption. That is unrealistic. The real objective is ensuring that critical compliance controls remain effective when disruption inevitably occurs.


References

Bank of England, 2021. Operational Resilience: Impact Tolerances for Important Business Services. London: Bank of England.

Financial Conduct Authority (FCA), 2021. Building Operational Resilience. London: FCA.

Financial Action Task Force (FATF), 2021. Opportunities and Challenges of New Technologies for AML/CFT. Paris: FATF.

Prudential Regulation Authority (PRA), 2021. Operational Resilience Policy Statement PS6/21. London: PRA.

Basel Committee on Banking Supervision (BCBS), 2021. Principles for Operational Resilience. Basel: Bank for International Settlements.

This article is also available on LinkedIn for wider readership.

Leave a comment