If the FCA or PRA regulates your firm, you need systems and controls that fit your business, oversight of every IT provider you rely on, and a way to tell your regulator promptly about significant operational incidents. Banks, insurers, larger investment firms and payment firms must also identify their important business services and stay within impact tolerances. From 18 March 2027, new rules standardise how firms report operational incidents and material third-party arrangements. Outsourcing IT does not outsource responsibility.
There is no single IT rulebook. For a firm authorised by the Financial Conduct Authority (FCA), and for the banks, insurers and major investment firms also supervised by the Prudential Regulation Authority (PRA), technology and cyber expectations sit in a few places, plus UK data protection law.
The regulators apply these proportionately. A ten-person advisory firm and a bank are not expected to look the same, but each must be able to show that its approach fits its size, complexity and risk.
The table summarises the main areas and the evidence that tends to satisfy a reviewer. Operational resilience rules apply in full to in-scope firms, but the same disciplines are good practice for any regulated firm. It is a guide for orientation; the Handbook and Rulebook text is the authority.
| Area | What regulators expect | Evidence worth keeping |
|---|---|---|
| Governance and accountability | Board oversight of operational and cyber risk, named senior managers accountable under SM&CR and, for in-scope firms, a board-approved operational resilience self-assessment. | The self-assessment, board minutes showing review, named owners, statements of responsibilities. |
| Important business services | In-scope firms identify the services whose disruption could cause intolerable harm to clients or the market, and set an impact tolerance for each. | A list of important business services with impact tolerances and the reasoning behind them. |
| Mapping | The people, processes, technology, facilities and information, including third parties, that support each important business service. | Service maps, asset register, provider register. |
| Protect | Controls such as least-privilege access with regular reviews, multi-factor authentication, timely patching, encryption, secure configuration and staff awareness training. | MFA coverage report, patch compliance reports, access review records, configuration baselines, training completion records. |
| Test | Scenario testing of your ability to stay within impact tolerances in severe but plausible scenarios, plus regular security testing and a process to fix what it finds. | Scenario test results, penetration test report, remediation tracker with dates and sign-off. |
| Detect, respond and report | Monitoring, a tested incident response plan, and prompt notification to your regulator of significant operational incidents. | Incident log, threshold decision records, exercise records, copies of notifications. |
The exact wording, and any change since this guide was reviewed, is in SYSC 15A in the FCA Handbook and the PRA’s SS1/21.
SYSC 8 requires a firm that relies on a third party for critical or important operational functions to take reasonable steps to avoid undue additional operational risk, and makes clear that the firm remains fully responsible for its regulatory obligations. Outsourcing must not impair the quality of your internal control or the FCA’s ability to monitor your compliance. The FCA’s guidance for firms outsourcing to the cloud and other third-party IT services (FG16/5) sets out what it expects on due diligence, data security, access and audit rights, and exit plans.
For dual-regulated firms, the PRA’s SS2/21 goes further, covering non-outsourcing third-party arrangements, materiality assessments, contract terms, business continuity and exit planning. In practice that means a register of your IT and cloud providers, proportionate checks before you sign, and evidence that you review them. Our guide to vendor and outsourcing management covers how to do that.
Today, FCA-regulated firms must tell the FCA promptly about significant operational incidents under Principle 11 and SUP 15.3, for example an incident that could cause material disruption, affect a significant number of customers or involve unauthorised access to systems or data. Dual-regulated firms have equivalent obligations to the PRA.
From 18 March 2027, the FCA’s policy statement PS26/2 introduces a single reporting form and clearer thresholds. Most solo-regulated firms submit one report, as soon as practicable and within 24 hours of deciding that an incident meets the threshold. Larger and dual-regulated firms also send updates and a final report within 30 working days of resolution, and payment service providers have a shorter deadline. Firms must also notify their regulator of new or significantly changed material third-party arrangements. A personal data breach may separately need to be notified to the ICO within 72 hours where feasible.
Decide these things before an incident, not during one:
These are patterns that commonly appear when regulated firms test their own controls:
Most are cheap to fix once you can see them. Our audit readiness checklist shows how to build the evidence pack that exposes them early.
Solicitors and law firms answer to the Solicitors Regulation Authority (SRA) rather than the FCA. The SRA’s expectations are outcomes-focused: effective systems and controls, protection of client money and confidential information, and prompt reports of serious breaches and of cyber incidents that affect clients. See our page for law firms and the comparison on our regulated industries page.
Last reviewed 25 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
