Today marks the end of the transition period for the FCA and PRA operational resilience rules introduced in 2021.
From today, in-scope firms must be able to remain within their impact tolerances for each important business service in severe but plausible scenarios, including cyber-attacks and third-party failures.
What regulators expect to see
- Complete and current mapping of the resources supporting important business services.
- Scenario testing that is realistic and challenging, with lessons learned acted upon.
- Remediation of vulnerabilities identified through mapping and testing.
- Board-approved self-assessments that are kept up to date.
For suppliers, this means continued requests for resilience evidence, business continuity testing results and robust exit plans.
Source: PS21/3 Building operational resilience (FCA)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.