Key Takeaways
- Operational resilience is shifting from a compliance requirement to a business capability that supports faster, better-informed decisions.
- Specialist functions remain essential, but they need a shared view of services, dependencies, and business impact.
- AI can extend third-party risk capacity, but it still needs human oversight, clear guardrails, and accountable decision-making.
- Managing concentration risk requires ongoing dependency mapping and stronger visibility across the wider ecosystem.
At the 4th Edition Operational Resilience and Third-Party Risk for Financial Institutions GFMI (Global Financial Markets Intelligence) conference, held September 29-30, 2026, in London, one message came through clearly: operational resilience is moving beyond compliance-led programs and isolated risk practices. Financial institutions are being asked to understand how disruption moves through the business, across third parties, and throughout the wider ecosystem.
The conversations reflected both progress and pressure. Organizations including State Street, SMBC, Zurich, and Allianz explored how financial institutions are advancing automation and AI while confronting the limits of visibility when critical services depend on shared providers, complex supply chains, and interconnected market infrastructure.
The next stage of maturity will require better context, clearer ownership, and stronger collaboration across functions and firms.
Resilience Is Becoming a Business Discipline
Operational resilience is increasingly being discussed in business terms. That means connecting resilience activity to critical services, customer outcomes, financial exposure, and the decisions leaders need to make when conditions change.
This doesn’t reduce the importance of regulation. Instead, it gives regulatory requirements a more practical role within the organization.
When risk, business continuity, cyber, technology, and third-party risk management teams share a view of business services and dependencies, they can move from proving that controls exist to understanding whether the business can continue to deliver under stress.
That shift also changes how resilience teams communicate. The most useful conversations are less about individual plans or control status and more about questions such as:
- What is affected?
- What happens next?
- What is the financial exposure?
- What should be prioritized?
Expertise Still Matters, but Silos Need a Shared Context
The goal is not to eliminate specialist functions. Cybersecurity, technology, operational risk, procurement, and business teams all hold knowledge that is essential to resilience. The challenge is making that knowledge usable together.
A mature program deliberately connects expertise across those areas. It provides a common way to understand services, processes, systems, suppliers, and recovery options, while retaining the accountability and depth of each function.
This makes it easier to spot where a local issue could become a business-wide problem and to coordinate a response when it does.
AI Is Moving into Everyday Third-Party Risk Work
The discussion around AI and resilience preparation has become more practical. Automation is beginning to support routine work in third-party risk management, including gathering information, identifying changes, summarizing risk signals, and helping users find the right guidance. This can give teams more capacity to focus on judgement, escalation, and action.
But AI does not remove the need for accountable decision-making. Human oversight remains essential, particularly when information is incomplete, risk tolerance must be applied, or potential impacts extend across multiple services and counterparties.
The strongest approaches pair automation with clear guardrails, well-defined ownership, and the ability to validate outputs against real business context. Fusion’s approach to AI is built on the same principle, grounding automation in validated enterprise data while keeping people accountable for reviewing outputs and making decisions.
Concentration Risk Requires an Ecosystem View
Third-party risk management cannot be fully understood one supplier at a time. Firms may have visibility into their direct relationships while still lacking a clear view of shared providers, common technologies, and dependencies that create systemic exposure across the sector.
This is especially important where many organizations rely on the same critical services. A disruption at one point in the ecosystem can affect multiple firms at once, making individual contingency plans necessary but insufficient. Resilience teams need to understand both their own dependencies and the broader patterns that could amplify impact.
That requires continued investment in dependency mapping, even when the work is difficult. It also reinforces the need for appropriate information sharing and collaboration across the industry, so organizations can build a clearer picture of interconnected risk without losing sight of their own responsibilities.
The Next Step Is Turning Visibility into Better Decisions
The themes from GFMI London point toward a common priority: organizations need more than data about risk. An enterprise resilience decision system connects that data to business context so teams can interpret impact, understand exposure, and make decisions quickly when disruption occurs.
For resilience leaders, this means bringing together the information that already exists across the organization and using it to test assumptions, identify weak points, and prepare for severe but plausible scenarios.
It means treating dependency mapping as an ongoing capability, not a one-time exercise. And it means using technology to support people, rather than expecting technology to replace the judgement resilience requires.
The path forward is not simple, but the direction is clear. Operational resilience is the capability to keep critical services running through disruption, supported by connected expertise, stronger ecosystem awareness, and the ability to turn insight into action.