The regulators have responded to industry feedback by largely aligning their frameworks and simplifying reporting requirements.
By Rob Moulton, Nicola Higgs, Becky Critchley, and Charlotte Collins
Link to Key Points: Key Points:
- The FCA and PRA have aligned definitions and streamlined reporting processes, though some thresholds remain regulator-specific.
- They have also reduced the volume of information to be reported, and clarified various aspects of the new rules through their guidance.
- The new frameworks will apply from 18 March 2027, and firms should begin preparing for implementation now.
On 18 March 2026, the FCA and the PRA published linked Policy Statements setting out requirements for reporting operational incidents and material third-party arrangements (FCA PS26/2 and PRA PS7/26). The regulators previously consulted on this policy in December 2024 (see this Latham blog post).
Broadly, the operational incident reporting rules set out a standardised reporting process for firms to report incidents to the regulator(s) that exceed certain prescribed thresholds. The third-party reporting rules require firms to notify the regulator(s) of any new material third-party arrangements (or any significant changes to existing arrangements), and to keep a register of their material third-party arrangements. The aim of these new rules is to increase supervisory awareness of incidents encountered by firms, and to increase visibility of third-party dependencies across the sector.
In the original consultations, the regulators proposed parallel regimes with different definitions and thresholds for reporting, as well as different reporting processes. Firms will be pleased to see that the regulators have listened to feedback concerning the difficulties for dual-regulated firms in complying with similar but not identical regimes, and have aligned their approach in most areas. The regulators have also sought to reduce the burden on firms in general by streamlining processes and decreasing the amount of information required to be reported. Further, they have clarified aspects of their guidance to assist firms with interpreting and applying the new regimes.
Firms will welcome this more pragmatic approach, as the proposals stood as something of an outlier in the current regulatory climate (in which the regulators are focused on reducing the regulatory burden on firms, in line with the government’s growth agenda). However, many firms will still face the challenge of implementing these requirements so shortly after the new operational resilience frameworks, and question whether this work could have been streamlined and amalgamated to lessen the demand on firms’ resources.
Link to Application of the Rules Application of the Rules
Although now largely aligned, the regulators have still created separate rules and guidance. Therefore, dual-regulated firms must familiarise themselves with both the FCA and PRA regimes. Solo-regulated firms should note that the third-party reporting requirements only apply to larger or more significant firms (enhanced scope SMCR firms and CASS large firms).
The regulators have decided to exclude third-country branches from the third-party reporting notification obligations (but the FCA has not excluded them from the requirement to maintain and submit a register), and the PRA has removed smaller credit unions from its third-party reporting requirements entirely (rather than just from the register requirements).
The frameworks apply as follows:
| Operational incident reporting | Third-party reporting | |
|---|---|---|
| FCA | • All firms with a Part 4A permission (including UK branches of overseas firms) • Payment service providers • UK Recognised Investment Exchanges • Registered trade repositories • Registered credit rating agencies | • Enhanced scope SMCR firms • Banks • Designated investment firms • Building societies • Solvency II firms • CASS large firms • UK Recognised Investment Exchanges • Authorised electronic money institutions or authorised payment institutions • Consolidated tape providers • UK branches of overseas firms (register submission only) |
| PRA | • UK banks, building societies, PRA-designated investment firms, and UK branches of overseas banks • UK Solvency II firms, the Society of Lloyd’s, and its managing agents | • UK banks, building societies, PRA-designated investment firms • UK Solvency II firms, the Society of Lloyd’s, and its managing agents • UK credit unions with at least £50 million in total assets |
For completeness, we note that the Bank of England has also issued policy materials applicable to financial market infrastructures, but we do not cover these further in this blog post.
Link to Operational Incident Reporting Operational Incident Reporting
Helpfully, the regulators have aligned their approach to create a single incident definition, single approach to reporting thresholds (but not identical thresholds), identical timing for reporting, and a single reporting portal. This is intended to reduce duplication for dual-regulated firms. The revised definition of an operational incident is:
Either a single event or a series of linked events which disrupts the firm’s operations such that it:
1. disrupts the delivery of a service to an end user external to the firm; or
2. impacts the availability, authenticity, integrity, or confidentiality of information or data relating or belonging to such an end user.
The regulators have clarified that firms do not need to report uncrystallised events or near misses (although they may wish to consider reporting these to supervisors via other channels). The regime also does not capture controlled service interruptions such as system updates (unless these go wrong). Some respondents asked whether an operational incident could be defined as a material disruption affecting important business services, to align with the operational resilience regime and avoid imposing additional requirements on firms. However, the regulators declined to do so, noting that a focus only on important business services would risk limiting supervisory oversight, given that an operational incident could affect a service not classified as an important business service and still pose a risk to the regulators’ objectives.
Importantly, reporting thresholds and the factors that firms must consider when assessing the thresholds still differ between the regimes, as these are based around the regulators’ statutory objectives. The FCA’s thresholds are that:
A firm reasonably believes that an operational incident poses a risk:A firm reasonably believes that an operational incident poses a risk:
1. of causing intolerable levels of harm to consumers from which consumers cannot easily recover;
2. to the safety and soundness of the firm and/or other market participants; or
3. to market stability, market integrity, or confidence in the UK financial system.
The FCA has adjusted the wording of these thresholds to clarify its expectations, for example by introducing the concept of a firm’s reasonable belief. Both regulators have clarified that the threshold assessment should be based on the information available at the time.
The PRA has decided to maintain its proposed thresholds as follows:
An operational incident which could pose a risk to:
1. where the firm is, or is controlled by, an O-SII or is a relevant Solvency II firm, the stability of the UK financial system;
2. the firm’s safety and soundness; or
3. in the case of an insurer, an appropriate degree of protection for those who are or may become the firm’s policyholders.
Therefore, dual-regulated firms may still find that certain incidents are only reportable to the PRA or the FCA. The regulators have included some examples in their guidance of incidents that would meet both regulators’ thresholds.
In response to feedback, the regulators have reduced the number of questions that firms need to complete when reporting incidents and have confirmed that they only require essential information at the outset so that firms can focus resources on responding to the incident. The FCA has also divided firms into two groups to keep the requirements proportionate. Most FCA solo-regulated firms will be subject to standard reporting, requiring a single, short report. Larger FCA firms (enhanced scope SMCR firms and CASS large firms) and dual-regulated firms will need to make enhanced reports, using a three-stage structure. However, rather than making three separate reports as originally proposed (initial, intermediate, and final), firms will instead be able to update a single form, although timings remain as proposed. The regulators have maintained the position that firms must submit the initial phase of an incident report as soon as practicable (at the very most, within 24 hours of determining that it meets one or more of the thresholds). The intermediate phase must be submitted as soon as practicable after any significant change in circumstances from those described in the initial report. The final phase of the report must then be provided within 30 working days of the incident being resolved (unless there are circumstances meaning that more time is required, in which case a limit of 60 working days applies).
All firms will submit incident reports via the FCA’s Connect portal. For dual-regulated firms, the single report will be shared with both regulators. However, the regulators clarify that a report must be submitted for each group entity affected by an incident; group reporting is not possible.
Link to Third-Party Reporting Third-Party Reporting
Again, the regulators have aligned their regimes so that there is a single definition of a third-party arrangement, single templates, and a single reporting portal. The definition of a third-party arrangement is designed to include both outsourcing and non-outsourcing arrangements. The final formulation is as follows:
An arrangement of any form between a firm and a person who provides a product or service to the firm, whether or not the product or service is:
– one which would otherwise be provided by the firm itself;
– provided directly or by a sub-contractor; or
– provided by a person within the same group as the firm.
However, the definition of a material third-party arrangement differs for each regulator, based on their statutory objectives. The FCA has maintained its proposed definition as follows:
A third-party arrangement which is of such importance that a disruption or failure in the performance of the product or service provided to the firm could:
– cause intolerable levels of harm to the firm’s clients;
– pose a risk to the soundness, stability, resilience, confidence, or integrity of the UK financial system; or
– cast serious doubt on the firm’s ability to satisfy the threshold conditions, or meet its obligations under the Principles, or under SYSC 15A.
The PRA has also maintained its proposed definition as follows:
A third-party arrangement which is of such importance that a disruption or failure in the performance of the product or service provided to the firm could:
1. pose a risk to:
– the firm’s safety and soundness;
– in the case of an insurer, an appropriate degree of protection for those who are or may become the firm’s policyholders; or
– where the firm is, or is controlled by, an O-SII, or is a relevant Solvency II firm, the stability of the UK financial system; or
2. cast serious doubt upon the firm’s ability to satisfy the threshold conditions, the Fundamental Rules, the Operational Resilience Part, the Insurance – Operational Resilience Part, or the Operational Continuity Part.
The PRA has expanded its obligations by requiring firms to submit notifications on all material third-party arrangements, to align with the FCA position (it originally proposed that firms only need to notify arrangements which, due to the risks, necessitate a high degree of due diligence, risk management, or governance by the firm). However, the regulators have reduced the scope of the requirements by only requiring material intra-group arrangements to be reported where there is an external third-party dependency (although Recognised Investment Exchanges will need to report all intra-group arrangements, and ring-fenced bodies will need to report arrangements where the provider is a permitted supplier).
There are still no prescribed timelines for notifying the regulator(s), although the regulators clarify that they do expect firms to notify at an early stage, and to submit the notification before making any internal or external commitments. The regulators also clarify that the notification process is not an approval process, and that the register does not need to be resubmitted each time a notification is required, only on an annual basis. As with operational incident reporting, all firms will be able to submit material third-party notifications via the Connect portal. Registers of material third parties will need to be submitted annually via FCA RegData.
Link to Next Steps Next Steps
The rules will take effect on 18 March 2027. The FCA has issued non-Handbook guidance on each regime to assist firms with applying the new frameworks (FG26/3 and FG26/4). This guidance includes further explanations of the relevant definitions, as well as on how to complete and submit the notification templates. For dual-regulated firms, the PRA has issued Supervisory Statement 1/26 – Operational resilience: Incident reporting, and has set out further expectations and examples on material third-party reporting in Chapter 5 of Supervisory Statement 2/21 – Outsourcing and third party risk management. The regulators plan to engage with firms during the 12-month implementation period to assist them with preparing for the changes. As part of this, the FCA is hosting a webinar on 29 April 2026. The regulators are set to review the rules two years after implementation to assess how they are functioning.
While the alignment of the regimes and the additional clarifications are welcome, the nature of the new rules will require firms to use a reasonable amount of judgement, particularly in relation to deciding when an operational incident needs reporting. Firms should familiarise themselves with the new rules and guidance now, and start preparing for implementation.
