UK Operational Resilience: FCA SYSC 15A, PRA SS1/21 and SS2/21, and Critical Third Parties compliance software
Assess and evidence the FCA and PRA operational resilience rules per group or per regulated firm: important business services, impact tolerances, mapping, scenario testing and the self-assessment, with SS2/21 outsourcing, the critical third parties regime and the PS26/2 incident and third-party reporting that applies from 18 March 2027.
- RulesFCA SYSC 15A and SYSC 8; PRA Operational Resilience Part, SS1/21 and SS2/21; PRA Critical Third Parties Part and SS6/24
- Key datesWithin impact tolerances by 31 March 2025; first CTPs designated 13 July 2026; PS26/2 reporting from 18 March 2027
- Assessable items218 requirements in 11 domains, 82 of them critical
- DomainsGovernance and SMF24, important business services, impact tolerances, mapping, scenario testing, communications, self-assessment, incidents, outsourcing, critical third parties, cyber resilience and testing
- Reporting clockFrom 18 March 2027: initial incident report within 24 h of a threshold being met (4 h for payment service providers); final report within 30 working days of resolution for enhanced-reporting firms
- ScopeGroup or legal entity; profiles PRA firm, FCA solo-regulated firm, CTP user, designated CTP, CBEST / STAR-FS
What UK Operational Resilience requires
Who it applies to
- Banks, building societies, PRA-designated investment firms and UK Solvency II insurers, under the PRA Operational Resilience Part, SS1/21 and SYSC 15A
- Enhanced scope SM&CR firms, recognised investment exchanges, consolidated tape providers, and payment and e-money institutions for their payment services and e-money (SYSC 15A)
- Firms that rely on a designated critical third party, and the designated critical third parties themselves
- Financial groups with several regulated entities that need one view of services, tolerances and third-party exposure
The FCA and the PRA published their final operational resilience rules in March 2021: SYSC 15A in the FCA Handbook (PS21/3) and the Operational Resilience Part of the PRA Rulebook with supervisory statement SS1/21. Firms identify their important business services, set a time-based impact tolerance for each at the point where further disruption would become intolerable, map the people, processes, technology, facilities, information and third parties that deliver them, test their ability to stay within tolerance in severe but plausible scenarios, and keep a self-assessment approved by the board. Since 31 March 2025 firms have had to be able to remain within their impact tolerances.
Third-party risk sits alongside. PRA SS2/21 sets expectations for outsourcing and third-party risk management, and FCA SYSC 8 covers outsourcing. Under powers added by the Financial Services and Markets Act 2023, HM Treasury designates critical third parties to the financial sector, whose resilience the Bank of England, the PRA and the FCA then oversee. The first designations took effect on 13 July 2026: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. The regime complements firms' own outsourcing and resilience duties, which they keep in full.
From 18 March 2027, FCA PS26/2 and PRA PS7/26 bring in one joint regime for operational incident and third-party reporting. Firms send an initial incident report as soon as practicable, expected within 24 hours of determining that a reporting threshold is met (4 hours for payment service providers), with intermediate and final reports for enhanced-reporting firms. They also notify new or significantly changed material third-party arrangements in advance, and submit a register of those arrangements every year.
How GRCLens supports UK Operational Resilience
UK Operational Resilience runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Group and firm assessment with roll-up
The group answers governance, policy and framework items once, and each regulated firm is assessed on its own as a PRA or FCA solo-regulated firm, a user of a critical third party, a designated CTP or a firm in CBEST or STAR-FS scope. Firms roll up into a group view with a heat map across 15 risk areas.
The resilience chain, link by link
Important business services identified, a tolerance set for each (against both regulators' objectives for a dual-regulated firm), mapping complete, scenario tests run and remediated, communications planned and the self-assessment approved by the board, with the SMF24 chief operations responsibility allocated: each link is assessed as its own requirement.
Outsourcing, third parties and CTPs
SS2/21 and SYSC 8 due diligence, contract terms and exit plans, the material third-party register and advance notifications under PS26/2, and the critical third parties regime, with the four designated CTPs carried by name, make up the two largest domains.
Four stakeholder dashboards
The board and the SMF24 holder see conformity and critical gaps; the CRO and operational risk team the heat map, domain scores and gaps; operations the control validation and open remediation; third-party and procurement teams the outsourcing, register and critical-third-party findings.
Continuous assurance, register and KRIs
Incident records, backup and restore, vulnerability and patch, identity and MFA, the third-party register, resilience testing, training (LMS) and log monitoring are read against the questionnaire, alongside the existing Entra, Tenable, Qualys, Splunk and ITSM connectors. Gaps become owned, dated actions in a multi-owner assurance register and a remediation and risk treatment plan, and key risk indicators name the requirements they measure.
Baseerah summary, Word and PDF reports
Baseerah, the platform's AI assistant running on a self-hosted language model, writes a one-paragraph executive summary for the board, the SMF24 holder and the CRO. Firm and group reports export as Word and PDF.
UK Operational Resilience frequently asked questions
Who do the UK operational resilience rules apply to?
SYSC 15A covers banks, building societies, PRA-designated investment firms, UK Solvency II insurers, enhanced scope SM&CR firms, recognised investment exchanges, consolidated tape providers, and payment and e-money institutions and registered account information service providers for their payment services and e-money. PRA-regulated firms also apply the PRA Rulebook's Operational Resilience Part and SS1/21, and set impact tolerances against both regulators' objectives.
What is an impact tolerance?
A time-based limit, set for each important business service, at the point beyond which further disruption would become intolerable, on the assumption that disruption will happen. For the FCA that point is intolerable harm to clients or risk to market integrity; for the PRA it is a risk to the firm's safety and soundness, to policyholder protection for an insurer or, for the largest banks, to UK financial stability.
When did firms have to be within their impact tolerances?
By 31 March 2025. The final rules were published in March 2021, and the first phase, to 31 March 2022, was for identifying important business services, setting impact tolerances, mapping and testing. Since 31 March 2025 firms have had to be able to remain within their impact tolerances.
What changes on 18 March 2027?
The joint FCA, PRA and Bank of England regime for operational incident and third-party reporting (FCA PS26/2, PRA PS7/26) applies. Incidents that meet a threshold are reported on one form through FCA Connect, with the initial report expected within 24 hours of determining the threshold is met, or 4 hours for payment service providers; enhanced-reporting firms then file intermediate and final reports. Firms must also notify material third-party arrangements before entering into or significantly changing them, and submit a register of them annually.
Which critical third parties have been designated?
HM Treasury's first designations took effect on 13 July 2026: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. The Bank of England, the PRA and the FCA oversee the resilience of the services they provide to UK firms. Designation is not authorisation, and firms using them keep their own outsourcing and resilience duties in full.
One platform, many obligations
See all supported frameworks → Every framework that applies in United Kingdom →

Talk to us about UK Operational Resilience
Security Solution Consultants provides UK operational resilience advisory alongside the platform, so you can combine tooling with hands-on expertise.