top of page

Join the community driving the latest GRC, sustainability and resilience ideas, without the background noise.
Also, free reports and guides which will help drive a better future.
We can't predict the future, but we can be ready to thrive in it.



1. Operational Resilience APRA guide
2. Operational Resilience FCA guide
3. Operational Resilience Outlook Report
4. Double Materiality Guide
News and insights backed up by downloadable
our guides and reports


UK Housing Sector Outlook: What’s next for UK housing associations?
Practical strategies to turn pressure into progress—drawn from twelve leaders helping to create safer, sustainable homes. Why we created this report The last 18 months have moved UK housing associations from policy statements to proof. Consumer standards, programmed inspections, Tenant Satisfaction Measures and SRS v2.0 have hardened expectations, while costs, ageing stock and climate pressures stretch capacity. The Housing Association Outlook Report 2026 was built to help h

Charlotte Clark-Wilson
3 min read


Three operational resilience predictions we got right (and one we got wrong) in 2024
In our Operational Resilience Outlook Report 2024, we outlined the shifts we expected to see across regulation, risk, and organisational maturity. A year later, some of those predictions have become reality while others were underplayed.
Here’s what we got right, what we missed, and what it means for the road ahead.

Charlotte Clark-Wilson
3 min read


Mini report, big strategy: Could these AI agents build your next 3-year plan?
The Sustainability & Business Strategy Report was built for SME owners, managers, and executives across industries. If you’re responsible for setting strategy, managing risks, or planning for growth, it gives you a practical way to bring sustainability into the core of your decision-making through risk & opportunity analysis, industry benchmarks, priority insights, and actionable OKRs turned into clear next steps.

Charlotte Clark-Wilson
3 min read


From risk awareness to risk assurance: Without controls, you’re only telling half the story
Most organisations, including many Drova customers, already log their risks. It’s the entry point: identify what might go wrong,...

Charlotte Clark-Wilson
3 min read


What happens when operational resilience fails… very publicly?
When operational resilience fails, the world notices.
The past year has shown that business continuity plans are not enough. Ransomware attacks, global outages, power grid failures and data breaches have exposed a pattern of unpreparedness. It is no longer about having a backup plan. It is about proving your organisation can withstand disruption, recover fast and protect what matters most. Resilience is no longer optional. It is the standard.

Andrew Lingley
3 min read


SYSC15A and the credibility gap: Why are resilience plans falling short under scrutiny?
There is a difference between having a plan and being ready to prove it.
Under the FCA’s PS21/3 standard, many firms look compliant on paper but fall short under scrutiny. The planning phase is over. The focus now is on outcomes and evidence. The FCA expects firms to show how they will keep services running during disruption, with proof that is current, complete, and connected. Anything less reveals a credibility gap that regulators are ready to test.

Andrew Lingley
4 min read


Third-party resilience under PS21/3: What the FCA wants you to prove - and the simplest way to prove it
Third-party resilience is now a board-level accountability.
Under the FCA’s PS21/3 standard, outsourcing doesn’t remove responsibility. Firms must prove they can withstand supplier disruption and stay within impact tolerances. That means mapping dependencies, testing scenarios, and holding evidence that stands up to scrutiny. When failure hits, the regulator won’t ask who caused it; they’ll ask why you weren’t ready.

Andrew Lingley
3 min read


The Board can’t outsource CPS 230 accountability… and APRA knows it
CPS 230 has dragged operational resilience out of the server room and into the boardroom.
No longer a back-office task, it’s now a live legal responsibility for directors. APRA expects boards to approve frameworks, set tolerances, test scenarios — and be able to explain, in plain language, how the organisation stays standing when disruption hits.
You can outsource the work. But not the accountability.

Andrew Lingley
4 min read


‘We’ve got it covered’: The four most expensive words in CPS 230 compliance
APRA expects live proof, not outdated docs or assumptions. That means updated critical operation maps, tested tolerances, and board oversight. Gaps in vendor registers or forgotten dependencies are compliance risks, not prep issues. It’s time to go from “we’ve got it covered” to “here’s the proof.”

Andrew Lingley
4 min read
Useful guides and reports

FREE to download
Operational Resilience APRA Guide

FREE to download
Operational Resilience Outlook Report

FREE to download
Operational Resilience FCA Guide

FREE to download
Double Materiality Guide
bottom of page