Compliance

FCA Operational Resilience: The 2027 Reporting Deadline

PS26/2 makes operational incident and material third-party reporting mandatory from 18 March 2027. What changed in 2026, and the work to do now.

Nerdster Team

The FCA’s operational resilience rules have been fully in force since 31 March 2025. The next hard date is 18 March 2027, when the operational incident and material third-party reporting rules in Policy Statement PS26/2 take effect. The FCA published PS26/2 on 18 March 2026 with a twelve-month implementation period, which means that as of today just over seven months of that window remain.

If your firm identified its important business services, set impact tolerances and then filed the self-assessment away, 2026 has moved the goalposts twice: once with a supervisory review that named exactly where firms are falling short, and once with a new reporting regime that turns operational disruption into a regulatory notification with a clock attached.

Here is what actually changed, and what to do with the time left.

Where the framework stands today

Nothing in 2026 replaced the underlying rules. The FCA’s operational resilience framework sits in SYSC 15A of the Handbook and came into force on 31 March 2022. Firms then had a three-year transition, and the FCA is explicit that firms “had until 31 March 2025 to ensure they could operate their important business services within their impact tolerances.”

The logic chain is unchanged:

  • Identify your important business services. SYSC 15A defines one as a service provided to clients which, if disrupted, could cause intolerable levels of harm to clients, or pose a risk to the soundness, stability or resilience of the UK financial system.
  • Set an impact tolerance for each — the maximum tolerable disruption before harm becomes intolerable.
  • Map the resources that support each service, in enough detail to expose single points of failure.
  • Test against severe but plausible scenarios.
  • Maintain a self-assessment that a supervisor can read and follow.

That is the base layer. Everything below is built on top of it. Our FCA operational resilience compliance page covers the framework itself in more depth.

What changed in 2026

1. The FCA published its report card

On 27 March 2026 the FCA published Operational resilience: insights and observations one year on, setting out good and poor practice from the first year after the transition ended.

The good practice it named included clear methodologies for defining important business services, “increased use of quantitative non-time-based metrics when setting impact tolerances (e.g. transaction volumes, financial thresholds)”, firms “expanding scenario testing to include a broader range of cyber threats and alternate scenarios than those tested in the previous year”, and governance with genuine board-level oversight.

The poor practice list is the more useful document. The FCA flagged firms that had not set distinct impact tolerances for market integrity as well as consumer harm; weakness in “identifying, assessing and remediating third party vulnerabilities”; a lack of “evidence of having tested this using sufficiently severe scenarios”; and “unclear board engagement, approval processes, and document review trails.”

Read that list as a supervisory question set. Three of the four failures are documentation and evidence failures, not engineering failures.

2. PS26/2 turned incidents into notifications

On 18 March 2026 the FCA published PS26/2: Operational incident and third party reporting, developed jointly with the PRA and the Bank of England, alongside finalised guidance FG26/3 (incident reporting) and FG26/4 (material third-party arrangements). The rules come into force on 18 March 2027.

Operational incident reporting. The framework captures a broad population. The FCA’s own policy-statement page lists it as all firms with a Part 4A permission, payment service providers, UK recognised investment exchanges (RIEs), registered trade repositories and registered credit rating agencies. An operational incident is defined as a single event or a series of linked events that disrupts a firm’s operations and either disrupts service delivery to external end users or affects the availability, authenticity, integrity or confidentiality of their data. The deliberate breadth means cascading failures and data-integrity events are in scope, not just outages.

You report when the incident crosses a threshold tied to intolerable harm to consumers, the safety and soundness of the firm or market participants, or confidence in the UK financial system. The mechanics that matter operationally:

  • Two tiers — a standard, concise submission for most solo-regulated firms, and an enhanced, lifecycle-based report for larger and more complex firms.

On the specific clock, read the source before you build to it. The FCA’s policy-statement page confirms the population, the definition and the 18 March 2027 date, but does not state the submission deadlines on the page itself. The figures circulating in practitioner analyses are an initial submission as soon as practicable and ordinarily within 24 hours of determining the threshold is met, a shorter four-hour deadline for payment service providers, and a final report within 30 working days of resolution for enhanced reporters, with a longer backstop where justified. We have not been able to confirm those three figures against the text of PS26/2 itself, so treat them as the working planning assumption and verify them against the policy statement before they become your operational SLA.

Whichever figure binds you, the shape of the problem does not change: deciding whether a threshold has been met, assembling the facts and getting a submission signed off is a same-day exercise. That is a runbook problem, and it is solvable now.

Material third-party reporting. A narrower set of firms — the FCA lists enhanced-scope SM&CR firms, banks, designated investment firms, building societies, Solvency II firms, CASS large firms, UK RIEs, authorised electronic money institutions and authorised payment institutions, and consolidated tape providers — must notify the FCA of new material third-party arrangements and material changes to existing ones, and submit an annual register. Notification is expected early, before the firm is contractually or operationally committed. Macfarlanes reports the register is to be accurate as at 31 December and submitted within 90 calendar days of the FCA opening the reporting window; the precise first window is set by the FCA. Third-country branches are reported to be excluded from the notification requirement but still in scope for the annual register.

If you have never assembled a defensible list of which suppliers are material, that exercise is the long pole. It is not an IT inventory. It is a judgement about which failures would breach an impact tolerance.

3. The first critical third parties were designated

On 10 July 2026 HM Treasury made the first designations under the critical third parties (CTP) regime, with the regulations coming into force on 13 July 2026. The four designated entities are Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited.

The CTP rules themselves took effect on 1 January 2025 under PS24/16, but only bite once HM Treasury formally designates an entity. Designated CTPs must now meet operational resilience requirements covering governance and risk management, supply chain risk management, cyber resilience, change management, and incident management and reporting.

The obvious question is whether this takes work off your plate. It does not. Morrison Foerster’s analysis is blunt: the designations do “not diminish the regulatory responsibilities of financial services firms using the services of the CTPs. Financial services firms remain responsible for managing their own third-party risks in line with existing operational resilience and outsourcing requirements.” Lewis Silkin makes the same point: designation should not be treated “as a substitute for their own outsourcing, third-party risk management and operational resilience obligations.”

In practice the designations do one useful thing for you: they confirm that the regulators consider concentration on these four providers a systemic issue. If your mapping shows a single hyperscaler under every important business service, that is now a documented supervisory concern rather than an abstract one.

What to do in the next seven months

A realistic programme between now and 18 March 2027, in order:

  1. Re-read your self-assessment against the FCA’s March 2026 poor-practice list. Distinct tolerances for market integrity and consumer harm; evidence of severe scenarios; a visible board approval trail. Fix the gaps in the document before you touch anything technical.
  2. Classify your third parties by materiality, not by spend. Start from each important business service and work outwards. The output is the seed of your PS26/2 register.
  3. Write the same-day incident notification runbook. Who determines the threshold has been met, who drafts, who approves, who submits, and what the out-of-hours path is. Build it against the deadline in PS26/2 once you have confirmed it. The widely-reported figures are 24 hours, and four hours if you are a PSP. Design for the shorter one and the longer is free.
  4. Decide now whether you fall into standard or enhanced reporting, and confirm your dual-regulated position if the PRA also has an interest. That decision changes how much reporting machinery you need.
  5. Test the technology layer against your stated tolerances, not against an RTO in a DR plan. Recovery you have not rehearsed is an assumption. Our backup and disaster recovery checklist covers what a testable recovery capability looks like in practice.
  6. Review your cloud concentration and exit arrangements in light of the CTP designations.
  7. Align with DORA if you also serve EU entities. The two frameworks share a principle but differ in prescriptiveness, and duplicated programmes waste money. See our guide to what DORA requires from your IT provider.
  8. Close the architectural gaps testing exposes. For most firms this is identity, segmentation and privileged access; our zero trust implementation guide sets out the controls that actually move the needle.

What this adds up to

None of this requires a new platform purchase. The 2026 changes are, overwhelmingly, demands for evidence: evidence that you know which services matter, evidence that you tested them hard enough, evidence that you know which suppliers could break them, and evidence that you can tell the regulator, the same day, when something goes wrong.

Firms that treated operational resilience as a documentation exercise in 2024 will find that 2027 turns the documentation into an operational commitment with a stopwatch on it. Seven months is enough time to fix that. It is not enough time to start in February.

We work with FCA-regulated firms — hedge funds, wealth managers, private equity and family offices — on the technology and evidence side of operational resilience: dependency mapping, scenario testing, recovery capability, third-party risk and the IT evidence a self-assessment needs. If you would like a second pair of eyes on where you stand before the 2027 deadline, book an operational resilience review.


This article summarises published regulatory material for general information. It is not legal or regulatory advice, and the requirements that apply depend on your permissions and firm category. Confirm your own position against the FCA Handbook and the source documents below.

Sources (all retrieved 10 August 2026):

FCAoperational resiliencefinancial servicescompliancethird-party risk

FAQ

FCA Operational Resilience: your questions answered

When do the new FCA operational incident reporting rules come into force?

18 March 2027. The FCA published Policy Statement PS26/2, 'Operational incident and third party reporting', on 18 March 2026 and gave firms a twelve-month implementation period. The FCA's own operational resilience page states that 'firms have 12 months to prepare ahead of the new requirements coming into force on 18 March 2027.'

Is FCA operational resilience already in force?

Yes. The SYSC 15A rules came into force on 31 March 2022 and the transition period ended on 31 March 2025. Since that date every firm in scope must be able to operate its important business services within its impact tolerances during a severe but plausible disruption. PS26/2 does not replace that framework. It adds reporting obligations on top of it.

How quickly will we have to report an operational incident?

PS26/2 sets a two-tier regime: a standard, concise submission for most solo-regulated firms and an enhanced, lifecycle-based report for larger and more complex firms. The FCA's policy-statement page confirms the scope and the 18 March 2027 date but does not publish the submission clock on the page itself. Practitioner analyses report an initial submission as soon as practicable and ordinarily within 24 hours of the firm determining the threshold is met, a shorter four-hour deadline for payment service providers, and a final report within 30 working days of resolution for enhanced reporters. Confirm those figures against PS26/2 itself before adopting them as your operational deadline.

Does the FCA still expect a self-assessment document?

Yes. The self-assessment remains the artefact that evidences your programme. In its March 2026 review the FCA cited as good practice self-assessments that explain the methodologies the firm used, and criticised firms showing 'unclear board engagement, approval processes, and document review trails.' A self-assessment written once in 2024 and never revisited is now a supervisory finding waiting to happen.

AWS, Microsoft, Google and Oracle are now designated critical third parties. Does that reduce our obligations?

No. HM Treasury designated Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited in July 2026, but designation regulates the provider, not your reliance on it. As Morrison Foerster put it, the designations do 'not diminish the regulatory responsibilities of financial services firms using the services of the CTPs.' You still own your mapping, your exit arrangements and your testing.

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report