When it comes to resilience, many firms are still making the same mistake: focusing heavily on cyber risk while overlooking supplier, service and concentration risks that are just as likely to disrupt critical services. At the same time, regulatory pressure has increased significantly.
Frameworks such as DORA and the UK’s operational resilience regime have pushed firms to think more seriously about their dependencies, their critical services and their ability to withstand disruption. The risks are not limited to cyber events. Supplier failure, service deterioration and concentration risk all have the potential to disrupt critical services. This applies to both FinTech providers and the financial institutions that rely on them.
That’s all positive, and most firms have adapted well. However, a more subtle misconception is emerging. Being cyber secure is often taken as a sign that an organisation is resilient. In practice, it rarely works like that.
Organisations everywhere have been required to document their processes by mapping important business services, identifying suppliers and putting policies in place. On paper, it often looks robust – but when you start to delve into the detail and test what happens if a key supplier fails, things can look very different.
That gap between what’s written down and what actually works is where the real risk sits.
The problem with ‘on paper’ resilience
Most resilience frameworks rely heavily on documentation and firms are rightly asked to demonstrate that they understand their dependencies. Their contingency plans are checked – as are their abilities to exit from critical suppliers if needed. The issue is that much of this is built on assumption, not evidence.
Supplier contracts often include continuity clauses. Due diligence processes gather assurances from vendors about how resilient they are. Internal teams record that an exit is ‘possible’. Possible it may be, but very few organisations actually test whether those things hold up under pressure. There is a significant difference between an exit being theoretically possible and a stressed exit that has been tested and proven to work under disruption.
If a supplier fails, it’s not enough to just have a clause sitting in a contract. You need to know whether you can access the underlying software, rebuild it, move it, replace it – and how long that will take. That’s a very different question. Regulated entities now need to focus on whether their plans actually work.
The hidden risk in third- and fourth-party dependencies
One of the biggest blind spots in FinTech is the dependency chain. Most firms have a reasonable or good understanding of their direct suppliers, but what’s much less visible are the suppliers behind those suppliers – platforms, libraries, cloud services and infrastructure that everything ultimately sits on. That’s where concentration risk starts to build.
Too many FinTech platforms rely on the same hyperscale cloud providers. Many also depend on a relatively small number of specialist software vendors. When everything works, that concentration drives up efficiency and drives down cost. But when something goes wrong, it creates a shared point of failure.
You only really discover that exposure when something goes wrong. At that point, it’s too late to map the dependencies or negotiate alternative arrangements. You’re dealing with the consequences of decisions that were made months or years earlier, and it’s those decisions that can start as operational contagion, but rapidly move to financial contagion.
That’s why regulators are increasingly focused on sub-outsourcing and fourth-party risk. It’s also why firms need to move beyond a surface-level view of their supply chain.
Why supplier failure is not a theoretical risk
Supplier failure is often treated as an edge case, but in practice it’s far more common than many organisations assume. Most organisations have already had to deal with a supplier failing at some point. Across both fintechs and established providers, disruption and service deterioration are regular features of the market, and as the number of software providers grows – particularly with the rise of AI-driven services – that risk only increases.
Supplier insolvency, service deterioration and withdrawal of support are all real scenarios that firms are dealing with today. When they happen, the impact is immediate. In many cases, there is little time to react once a failure occurs. Systems stop working as expected, updates aren’t delivered, and the organisation is left trying to work out how to maintain continuity.
The challenge is that many of the controls needed to respond to those situations have to be put in place in advance. You can’t build a stressed exit strategy in the middle of a failure. Just like you can’t negotiate access to critical software once the supplier has disappeared. And you can’t quickly untangle complex dependencies when everything is already under pressure.
Moving from assumption to evidence
Currently, what we’re seeing in the sector is a shift towards evidence. Historically, firms have relied on supplier statements, certifications and contractual commitments. But that’s no longer enough. Regulators are now starting to test whether services can actually be maintained and whether exits can be executed in practice. They’re also looking at whether contingency plans have been thought through in detail. For FinTechs and the financial institutions that rely on them, that changes the conversation quite quickly.
It’s no longer sufficient to say ‘we have a plan’. The question becomes: can you demonstrate that your most critical services will continue to operate if a key supplier fails?
That involves testing stressed exit scenarios, validating that software can be rebuilt, and ensuring that there are clear, enforceable rights over the assets needed to maintain a service. These are practical steps that determine whether a business can continue to function under stress.
The role of leadership in resilience
One of the more interesting shifts is where these conversations are happening. Resilience has traditionally sat with IT or risk teams, but regulatory expectations have now pushed accountability firmly into the boardroom. CFOs are becoming more aware of the financial impact of downtime and supplier failure, and CIOs are balancing the need for agility with the risk of long-term lock-in. But there is still a gap between where decisions are made and where accountability sits. In practice, many of those decisions are being made across IT, procurement and legal teams, often without clear oversight at board level. That creates a clear challenge for leadership: decisions on risk are being made across the organisation, but accountability still sits at the top.
Much of the focus remains on cyber risk, which is understandable. What’s often less clearly owned are the non-cyber risks, such as supplier insolvency, service degradation, concentration risk and the practical ability to exit or replace a vendor.
Delegating responsibility for these risks is tricky, as they don’t sit neatly in one function. They cut across technology, procurement, legal, finance and operations. They also sit within vendor management, business continuity and disaster recovery functions, with different teams making decisions on risk that ultimately sits with senior leadership. That makes them harder to manage, but also harder to ignore.
The organisations that are getting ahead of this are the ones treating resilience as a shared responsibility, rather than something that sits in a single team. They are also recognising escrow as a key control and embedding it into their control frameworks as a key control.
What FinTech leaders should be doing now
None of this means tearing up existing strategies or abandoning the cloud. It starts with understanding where key risks sit, including supplier failure, service deterioration and concentration risk.
That means mapping where critical services actually sit, including the layers beneath direct suppliers. It also means identifying where concentration risk exists and where no credible, tested exit is in place.
From there, it’s about putting in place the controls that allow you to respond if something goes wrong. That includes ensuring access to the underlying source code that runs critical services and validating that the underlying source code and supporting components can be rebuilt into a working system.
One way organisations are addressing this is by introducing independent controls such as escrow. This ensures that source code, dependencies and supporting materials are securely held, verified and accessible, allowing systems to be rebuilt and operated if a supplier can no longer support a service.
Closing the gap
Regulation has pushed resilience up the agenda, which is a good thing. But compliance is only part of the picture. The real test is what happens when something actually fails.
Suppliers that focus solely on meeting regulatory requirements risk missing that point. Those that examine whether their systems, suppliers and services can actually withstand disruption will be in a much stronger position, because when a critical supplier fails, the difference between compliance and resilience becomes very clear, very quickly.
Learn more at escode.com
- Cybersecurity
- Digital Payments