Insights · FCA and PRA

FCA and PRA IT requirements: what regulated firms need to evidence

A plain-English guide to UK operational resilience (SYSC 15A and SS1/21), outsourcing (SYSC 8 and SS2/21), the new incident and third-party reporting rules, and the evidence a regulated firm should be able to show.
The short answer

If the FCA or PRA regulates your firm, you need systems and controls that fit your business, oversight of every IT provider you rely on, and a way to tell your regulator promptly about significant operational incidents. Banks, insurers, larger investment firms and payment firms must also identify their important business services and stay within impact tolerances. From 18 March 2027, new rules standardise how firms report operational incidents and material third-party arrangements. Outsourcing IT does not outsource responsibility.

Key points
  • IT and cyber expectations sit mainly in SYSC (systems and controls), SYSC 8 (outsourcing) and, for in-scope firms, SYSC 15A (operational resilience). Dual-regulated firms also follow the PRA’s SS1/21 and SS2/21.
  • In-scope firms had to be able to remain within impact tolerances for their important business services by 31 March 2025.
  • New operational incident and third-party reporting rules (FCA PS26/2) apply from 18 March 2027.
  • Using a managed service provider does not transfer accountability: you must choose it carefully and supervise it.
  • Evidence matters as much as controls. Keep it where you can find it in minutes.

Which UK rules cover IT and cyber security

There is no single IT rulebook. For a firm authorised by the Financial Conduct Authority (FCA), and for the banks, insurers and major investment firms also supervised by the Prudential Regulation Authority (PRA), technology and cyber expectations sit in a few places, plus UK data protection law.

  • SYSC, systems and controls. The FCA’s requirement for robust governance, effective risk management and adequate internal controls, which covers how you run IT and cyber risk.
  • SYSC 15A, operational resilience, and for dual-regulated firms the PRA’s Operational Resilience Part and SS1/21. They apply to banks, building societies, insurers, enhanced scope SM&CR firms, and payment and e-money institutions, among others.
  • SYSC 8, outsourcing, and the PRA’s SS2/21 on outsourcing and third party risk management. Using a provider does not remove your responsibility.
  • UK GDPR and the Data Protection Act 2018, enforced by the Information Commissioner’s Office (ICO). They govern how you protect personal data and report breaches.

The regulators apply these proportionately. A ten-person advisory firm and a bank are not expected to look the same, but each must be able to show that its approach fits its size, complexity and risk.

What operational resilience expects in practice

The table summarises the main areas and the evidence that tends to satisfy a reviewer. Operational resilience rules apply in full to in-scope firms, but the same disciplines are good practice for any regulated firm. It is a guide for orientation; the Handbook and Rulebook text is the authority.

AreaWhat regulators expectEvidence worth keeping
Governance and accountabilityBoard oversight of operational and cyber risk, named senior managers accountable under SM&CR and, for in-scope firms, a board-approved operational resilience self-assessment.The self-assessment, board minutes showing review, named owners, statements of responsibilities.
Important business servicesIn-scope firms identify the services whose disruption could cause intolerable harm to clients or the market, and set an impact tolerance for each.A list of important business services with impact tolerances and the reasoning behind them.
MappingThe people, processes, technology, facilities and information, including third parties, that support each important business service.Service maps, asset register, provider register.
ProtectControls such as least-privilege access with regular reviews, multi-factor authentication, timely patching, encryption, secure configuration and staff awareness training.MFA coverage report, patch compliance reports, access review records, configuration baselines, training completion records.
TestScenario testing of your ability to stay within impact tolerances in severe but plausible scenarios, plus regular security testing and a process to fix what it finds.Scenario test results, penetration test report, remediation tracker with dates and sign-off.
Detect, respond and reportMonitoring, a tested incident response plan, and prompt notification to your regulator of significant operational incidents.Incident log, threshold decision records, exercise records, copies of notifications.

The exact wording, and any change since this guide was reviewed, is in SYSC 15A in the FCA Handbook and the PRA’s SS1/21.

Outsourcing IT does not outsource responsibility

SYSC 8 requires a firm that relies on a third party for critical or important operational functions to take reasonable steps to avoid undue additional operational risk, and makes clear that the firm remains fully responsible for its regulatory obligations. Outsourcing must not impair the quality of your internal control or the FCA’s ability to monitor your compliance. The FCA’s guidance for firms outsourcing to the cloud and other third-party IT services (FG16/5) sets out what it expects on due diligence, data security, access and audit rights, and exit plans.

For dual-regulated firms, the PRA’s SS2/21 goes further, covering non-outsourcing third-party arrangements, materiality assessments, contract terms, business continuity and exit planning. In practice that means a register of your IT and cloud providers, proportionate checks before you sign, and evidence that you review them. Our guide to vendor and outsourcing management covers how to do that.

Incident reporting, now and from March 2027

Today, FCA-regulated firms must tell the FCA promptly about significant operational incidents under Principle 11 and SUP 15.3, for example an incident that could cause material disruption, affect a significant number of customers or involve unauthorised access to systems or data. Dual-regulated firms have equivalent obligations to the PRA.

From 18 March 2027, the FCA’s policy statement PS26/2 introduces a single reporting form and clearer thresholds. Most solo-regulated firms submit one report, as soon as practicable and within 24 hours of deciding that an incident meets the threshold. Larger and dual-regulated firms also send updates and a final report within 30 working days of resolution, and payment service providers have a shorter deadline. Firms must also notify their regulator of new or significantly changed material third-party arrangements. A personal data breach may separately need to be notified to the ICO within 72 hours where feasible.

Decide these things before an incident, not during one:

  • Who decides whether an incident meets the reporting threshold, and how quickly they can be reached.
  • Who can submit reports to the regulator, and whether the process has been rehearsed.
  • Which logs, contacts and system details you will need in the first 24 hours.
  • How your IT provider must notify you, in writing in the contract, so that their delay does not use up your reporting window.

Gaps that tend to surface in reviews

These are patterns that commonly appear when regulated firms test their own controls:

  • Multi-factor authentication with exceptions: legacy protocols, shared mailboxes, service accounts and “temporary” exclusions that became permanent.
  • An incident response plan that exists on paper but has never been exercised.
  • No single register of technology providers, so nobody can say which ones are material.
  • Evidence scattered across individual mailboxes, which turns a simple request into a scramble.
  • Personal or unmanaged devices reaching firm data with no controls.

Most are cheap to fix once you can see them. Our audit readiness checklist shows how to build the evidence pack that exposes them early.

If you are a law firm

Solicitors and law firms answer to the Solicitors Regulation Authority (SRA) rather than the FCA. The SRA’s expectations are outcomes-focused: effective systems and controls, protection of client money and confidential information, and prompt reports of serious breaches and of cyber incidents that affect clients. See our page for law firms and the comparison on our regulated industries page.

Sources and further reading

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a managed IT and cyber security company that has supported businesses across the UK, the UAE and Saudi Arabia since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Does the FCA require ISO 27001?

No. The FCA and PRA do not require a particular standard; their rules are principles-based and proportionate. ISO 27001 is one recognised way to structure and independently evidence your approach, and many firms use it alongside Cyber Essentials. See our ISO 27001 guide.

How quickly must an FCA-regulated firm report an operational incident?

Today, promptly, under Principle 11 and SUP 15.3, for significant incidents. From 18 March 2027, most firms must report within 24 hours of deciding that an incident meets the threshold in PS26/2, and larger firms must also send updates and a final report. Agree your process and decision-maker in advance.

Can a regulated firm outsource IT and cyber security to a managed service provider?

Yes, but you remain responsible. Carry out due diligence before you appoint, agree contract terms covering security, access and audit, incident notification and exit, and supervise the provider throughout the relationship. Material arrangements deserve the closest scrutiny and, from 18 March 2027, new or significantly changed ones must be notified to your regulator.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
Vendor management

IT vendor and outsourcing management for FCA, PRA and SRA regulated firms

How to manage IT providers when you are regulated in the UK: a register, tiering, due diligence, contract terms, ongoing oversight and the new third-party reporting rules.
4 min read · Reviewed 25 September 2026
Audit readiness

IT audit readiness for regulated firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 25 September 2026
ISO 27001

ISO 27001 for regulated firms: how it supports FCA, PRA and SRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to FCA, PRA and SRA expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 25 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.