Don’t do SECURITY. Do business SECURELY.

UK operational resilience deadline arrives

UK financial firms must now be able to remain within impact tolerances for their important business services.

Today marks the end of the transition period for the FCA and PRA operational resilience rules introduced in 2021.

From today, in-scope firms must be able to remain within their impact tolerances for each important business service in severe but plausible scenarios, including cyber-attacks and third-party failures.

What regulators expect to see

  • Complete and current mapping of the resources supporting important business services.
  • Scenario testing that is realistic and challenging, with lessons learned acted upon.
  • Remediation of vulnerabilities identified through mapping and testing.
  • Board-approved self-assessments that are kept up to date.

For suppliers, this means continued requests for resilience evidence, business continuity testing results and robust exit plans.

Source: PS21/3 Building operational resilience (FCA)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights