Investment & Asset Management

Operational resilience, outsourcing and third-party risk in asset management

Building an operational resilience framework in asset management that covers custody, fund administration, technology and other critical third parties.

By Jonas Osman AbdelfourPublished March 15, 2026

Summary Asset managers are heavily outsourced businesses. Custody, fund administration, technology and data services are commonly provided by third parties whose failures translate directly into client harm. Operational resilience frameworks — increasingly a regulatory expectation — apply with particular force here. This article sets out how to build a resilience framework that covers the critical third parties on which the business depends.

Important business services The starting point is a defensible identification of important business services — those that, if disrupted, would harm clients, threaten market integrity or threaten the firm's viability. Trade execution, valuation, subscriptions and redemptions, custody, and client reporting are typical candidates.

Impact tolerances For each important business service, an impact tolerance defines the maximum tolerable disruption. Impact tolerances should be expressed in time and quantitative terms and stress-tested against severe-but-plausible scenarios.

Third-party governance Critical third parties require governance over selection, contracting, ongoing oversight, incident management and exit. Concentration risk — multiple important services depending on the same third party — is often the largest exposure.

Scenario testing Severe-but-plausible scenarios should test the resilience of important business services end to end, including third-party dependencies. Findings should drive investment in remediation, not sit in registers.

Governance rhythm Board oversight includes approval of important business services, impact tolerances, and material remediation plans. Executive management runs the programme. The risk function provides second-line challenge and independent testing.

CRO and board implications Boards should be able to answer, for any material client-facing service: what fails if this service is disrupted, how long can it be disrupted, and what happens next?

Practical implementation Important business services mapping; impact tolerances with quantitative expression; third-party inventory with tiering and oversight; severe-but-plausible scenario testing; remediation programme with owners and dates.

Limitations Regulatory expectations on operational resilience are evolving. Application should be confirmed with qualified counsel.

Related reading See [Investment & Asset Management risk governance](/insights/risk-governance-for-investment-firms), [Enterprise Risk](/expertise/enterprise-risk) and [Regulatory Compliance](/expertise/regulatory-compliance).

Frequently asked questions

What should risk leaders know about important business services?

The starting point is a defensible identification of important business services — those that, if disrupted, would harm clients, threaten market integrity or threaten the firm's viability. Trade execution, valuation, subscriptions and redemptions, custody, and client reporting are typical candidates.

What should risk leaders know about impact tolerances?

For each important business service, an impact tolerance defines the maximum tolerable disruption. Impact tolerances should be expressed in time and quantitative terms and stress-tested against severe-but-plausible scenarios.

What should risk leaders know about third-party governance?

Critical third parties require governance over selection, contracting, ongoing oversight, incident management and exit. Concentration risk — multiple important services depending on the same third party — is often the largest exposure.

What should risk leaders know about scenario testing?

Severe-but-plausible scenarios should test the resilience of important business services end to end, including third-party dependencies. Findings should drive investment in remediation, not sit in registers.

What should risk leaders know about governance rhythm?

Board oversight includes approval of important business services, impact tolerances, and material remediation plans. Executive management runs the programme. The risk function provides second-line challenge and independent testing.