| FCA | PRA | SRA | |
|---|---|---|---|
| Who it regulates | The conduct of all authorised financial services firms, and the prudential standards of firms the PRA does not supervise | The safety and soundness of banks, building societies, insurers and major investment firms (dual-regulated with the FCA) | Solicitors and law firms in England and Wales |
| IT and resilience rules | SYSC systems and controls, including SYSC 15A operational resilience for in-scope firms | Operational Resilience Part of the PRA Rulebook and SS1/21 | Code of Conduct for Firms: effective governance, systems and controls |
| Outsourcing and IT providers | SYSC 8 outsourcing, and FG16/5 on cloud and third-party IT | SS2/21 Outsourcing and third party risk management | Firms stay accountable for outsourced services and client confidentiality |
| Incident reporting | Significant operational incidents under Principle 11 and SUP 15.3; new reporting rules (PS26/2) apply from 18 March 2027 | Notification rules today; new operational incident and third-party reporting rules from 18 March 2027 | Report serious breaches promptly, and cyber incidents that affect or could affect clients |
| Personal data breaches | UK GDPR: notify the ICO without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to individuals | ||
Summary for orientation, reviewed 25 September 2026. Confirm the current wording in the FCA Handbook, PRA Rulebook and SRA Standards and Regulations. This is not legal advice.
