Don’t do SECURITY. Do business SECURELY.

FCA and PRA publish operational resilience rules

UK financial regulators have published final rules requiring firms to identify important business services, set impact tolerances and test resilience.

The FCA (PS21/3) and PRA (PS6/21 and supervisory statement SS1/21) have published their final policy on operational resilience, alongside the PRA’s supervisory statement on outsourcing and third-party risk management (SS2/21).

What firms must do

  • Identify their important business services.
  • Set impact tolerances for the maximum tolerable disruption to each.
  • Map the people, processes, technology, facilities and information that support those services.
  • Test their ability to remain within tolerance through severe but plausible scenarios, including cyber-attacks.

The rules apply from 31 March 2022, with firms required to be able to remain within their impact tolerances by 31 March 2025 at the latest.

Technology and service suppliers to financial firms will increasingly be asked for resilience evidence, including business continuity, incident management and exit planning.

Source: PS21/3 Building operational resilience (FCA)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights