Insights

Expert guides for regulated firms in the UK.

Plain-English guidance on FCA, PRA and SRA technology expectations, Microsoft 365 governance, Cyber Essentials, ISO 27001, audit readiness and vendor management.
How we write these guides

Sourced, dated and written by a named expert

Each guide cites the regulator’s own text or another primary source, states when it was last reviewed, and is written under the name of a Cre8 IT specialist rather than a faceless team.
They describe what regulators expect and how firms can meet it. They are not legal advice, and where the rules are a matter of judgement we say so.

What every guide includes

All guides

Topics regulated firms ask us about

FCA and PRA

FCA and PRA IT requirements: what regulated firms need to evidence

A plain-English guide to UK operational resilience (SYSC 15A and SS1/21), outsourcing (SYSC 8 and SS2/21), the new incident and third-party reporting rules, and the evidence a regulated firm should be able to show.
7 min read · Reviewed 25 September 2026
Microsoft 365

Microsoft 365 governance for regulated firms: a practical baseline

How to govern Microsoft 365 in an FCA-, PRA- or SRA-regulated firm: identity, devices, data, logging and licences, with a 30-day order of work.
4 min read · Reviewed 25 September 2026
Cyber Essentials

Cyber Essentials for UK regulated firms: what changed in 2026 and why it matters

What Cyber Essentials covers, what changed in April 2026, why it matters to FCA- and SRA-regulated firms, and how it compares with ISO 27001 and the regulators’ own rules.
4 min read · Reviewed 25 September 2026
ISO 27001

ISO 27001 for regulated firms: how it supports FCA, PRA and SRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to FCA, PRA and SRA expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 25 September 2026
Audit readiness

IT audit readiness for regulated firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 25 September 2026
Vendor management

IT vendor and outsourcing management for FCA, PRA and SRA regulated firms

How to manage IT providers when you are regulated in the UK: a register, tiering, due diligence, contract terms, ongoing oversight and the new third-party reporting rules.
4 min read · Reviewed 25 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.