The Lloyd's Market operates as a dynamic ecosystem, intricately weaving together insurers, brokers, suppliers, and shared market infrastructure. This interconnected web means that disruption in any single segment can ripple throughout the entire network, potentially impacting the delivery of important business services (IBSs). In a landscape where companies increasingly depend on common providers and established market utilities, understanding these interdependencies is crucial for anticipating challenges and ensuring resilience.
Recognising the interconnected nature of the Lloyd's Market, participants have concluded that individual firm resilience cannot be effectively addressed in isolation. To enhance overall stability, they have emphasised the importance of holistic testing that encompasses scenario planning beyond the confines of their own operations. In April 2026, the Lloyd's Market Association (LMA) took a significant step in this direction by conducting a market-wide third-party vendor test, which was designed and facilitated by the consulting team at Crowe UK. The scenario focused on the loss of a shared claims management system and workflow tool, which is critical to the functioning of many firms. To further challenge the resilience of participating members, the exercise included a further outage to a market utility that participants would typically rely on as a workaround, consequently limiting their ability to execute established response arrangements.
The simulation test conducted underscored the value of exploring scenarios that extend beyond isolated supplier outages. By examining the interplay between third-party dependencies, market infrastructure, and workaround strategies, participants were compelled to evaluate whether their confidence in existing contingency plans was substantiated by evidence. This approach highlighted four key considerations for organisations looking to strengthen their resilience to widespread market or third-party disruptions.
01
The existence of a documented workaround does not, by itself, demonstrate resilience.
The exercise revealed that workarounds are most effective during the initial stages of a disruption, characterised by manageable transaction volumes, clear roles, and accessible supporting systems. However, as the situation progressed, participants had to evaluate the continued efficacy of these workarounds amid rising transaction volumes and the unavailability of systems, external parties, and market infrastructure. In such scenarios, firms often resorted to more manual, resource-intensive processes, which hindered record-keeping, document exchange, payments, reporting, management information, and overall control operations.
This led to a crucial insight, testing should extend beyond merely verifying the activation of a workaround. It should also assess:
A more robust approach to testing workarounds offers a comprehensive, evidence-based perspective on resilience, rather than simply relying on documented procedures.
02
Time-based impact tolerances remain an important measure of resilience. However, they do not always provide sufficient insight into how service conditions are deteriorating during a disruption.
The exercise showed that operational pressure can build well before a firm’s ability to remain within time-based impact tolerances is threatened. Participants identified this through increasing backlogs, reduced processing capacity, weaker visibility of work in progress and greater reliance on manual activity. These conditions also increased the likelihood of control exceptions, incomplete records and inconsistent information.
This led to another key insight, firms should assess deterioration using operational evidence, not elapsed time alone. An excessive focus on time-based impact tolerances can create a reactive approach to resilience management, limiting visibility of deteriorating service conditions until issues have already become significant. Resilience testing should assess the operational metrics, management information and decision-making triggers that provide early warning of deterioration and support escalation and intervention before customer, business or regulatory impacts occur.
Depending on the service and operating model, this may include:
An evidence-based approach to measuring the impact of disruption supports a more robust understanding of emerging risks, drives actionable management information, and reduces the risk of organisations managing resilience reactively through time-based measures alone.
03
Some of the most significant resilience challenges highlighted during the test arose from dependencies between organisations rather than from processes controlled by a single firm.
As disruption evolved, participants became increasingly reliant on brokers, suppliers, market bodies and shared infrastructure to support workaround activities.
Information provided by these parties was relied upon to:
As reliance on external parties increased, communication became an essential part of the workaround itself, demonstrating that external information can become a critical dependency during disruption.
This led to another key insight, resilience extends beyond organisational boundaries, and communication is a critical component of operational resilience during disruption.
Resilience playbooks should identify:
Plans should also define how information will be validated, how conflicting updates will be managed and how critical activities and vulnerable customers will be prioritised.
Where the effectiveness of a workaround depends on multiple organisations, internal testing alone may not provide sufficient insight. Collaborative exercises can help identify dependencies, assumptions and coordination challenges that may remain hidden during firm-level testing, enabling organisations to better understand critical dependencies, strengthen coordination arrangements and build greater confidence in their ability to respond to widespread disruption.
04
The restoration of technology does not mark the end of a disruption. In many cases, it begins a further phase of controlled recovery.
During the disruption, firms relied on manual, offline or alternative processes to maintain service delivery. Once systems are restored, this activity must be reconciled. Documentation needs to be uploaded, records validated and outstanding work prioritised.
At the same time, firms must continue to manage live demand. Without clear ownership and appropriate controls, this can create risks such as:
This led to the final key insight, recovery should be treated as a distinct phase of disruption rather than the point at which disruption ends.
Recovery plans should define:
Recovery arrangements that are clearly defined and tested can reduce operational risk, improve control over recovery activities and support a controlled return to normal operations.
The exercise demonstrated that resilience cannot be assessed through the testing of individual components in isolation. The loss of a supplier may be manageable. A workaround may initially appear effective. Recovery may appear straightforward. However, disruption often becomes more challenging as dependencies interact, operational pressures increase, and established response arrangements become constrained.
The most valuable resilience insights are often found beyond the initial response. They emerge as firms test the sustainability of workarounds, monitor deteriorating conditions, coordinate across organisational boundaries and manage the transition back to normal operations. By exploring these challenges through increasingly realistic exercises, firms can build greater confidence in their ability to remain within impact tolerance and strengthen the resilience of the wider market.
Speak to Crowe UK’s Resilience and Supply Chain team to discuss further insights that resulted from this market-wide test, how scenario testing can help your organisation explore third-party dependencies, test the sustainability of workarounds and strengthen recovery arrangements.