Operational Resilience for FCA-Regulated Firms
A practical guide to PS21/3, SS1/21 and DORA for UK financial services boards. Important business services, impact tolerances, third-party risk and evidence that stands up to supervisory scrutiny.
The UK operational resilience framework at a glance
Operational resilience is the ability of a firm, its group and the wider sector to prevent, adapt to, respond to, recover from and learn from operational disruptions. In the UK, the framework is set by the FCA policy statement PS21/3 and the PRA supervisory statement SS1/21, both of which came fully into effect on 31 March 2025 after a three-year transition.
Boards are expected to own the firm's resilience posture. That means approving important business services, setting impact tolerances, commissioning severe but plausible scenario testing, and receiving credible assurance that vulnerabilities are being remediated on a defined timeline.
Identifying important business services
An important business service is one that, if disrupted, could cause intolerable harm to consumers or pose a risk to market integrity. It is defined from the outside in, by the outcome the customer or counterparty relies on, not by the internal system that delivers it.
Common examples include making payments, executing trades, honouring insurance claims, providing access to funds and enabling regulated advice. Firms should be able to explain, in one sentence per service, what the customer would lose if it stopped working.
Setting and evidencing impact tolerances
An impact tolerance is a time-based limit on disruption. It is set at the point where harm becomes intolerable, not where it becomes inconvenient. Tolerances must be justified with evidence: customer behaviour, market conventions, contractual obligations and regulatory expectations.
Firms must be able to remain within their tolerances during a range of severe but plausible scenarios, including cyber attack, third-party failure, technology outage and loss of premises or people. Scenario testing should stretch the organisation, and lessons learned should feed a prioritised remediation backlog.
Mapping people, processes, technology and third parties
Each important business service depends on a chain of resources: staff, applications, data, infrastructure, facilities and suppliers. Mapping this chain to the level of granularity needed to identify vulnerabilities is a core regulatory expectation.
Good maps are living artefacts, connected to the CMDB, HR systems and third-party register. They should highlight single points of failure, concentration risk and recovery dependencies, so investment decisions are grounded in evidence rather than intuition.
DORA readiness for UK-headquartered firms
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) applies to EU financial entities and their ICT third-party service providers. UK firms are typically in scope through EU-authorised subsidiaries, cross-border services and intra-group provision of ICT services.
DORA introduces harmonised requirements across five pillars: ICT risk management, ICT-related incident reporting, digital operational resilience testing including threat-led penetration testing, ICT third-party risk management, and information sharing. Firms already aligned to PS21/3 have a strong base, but should not assume equivalence. A control-set mapping exercise avoids duplicated effort and identifies genuine gaps, particularly around register-of-information requirements and TLPT.
Third-party and ICT concentration risk
The majority of material operational incidents originate with a supplier. UK firms must meet the FCA and PRA outsourcing and third-party risk expectations, and, where in scope of DORA, the more prescriptive ICT third-party risk rules including register of information, contractual requirements and exit strategies.
The UK critical third parties (CTP) regime brings systemic providers such as major cloud platforms into direct regulatory oversight. Firms should still expect to own the risk end to end, with clear accountability, defined exit and stressed-exit plans, and continuous monitoring rather than annual questionnaires.
Cyber incident response and regulatory reporting
A resilient firm is one that responds well, not one that never has incidents. Playbooks should cover ransomware, data loss, third-party outage, market-wide disruption and insider events, with pre-agreed decision rights, communications templates and regulator notification triggers.
Under DORA, major ICT-related incidents must be reported to competent authorities within tight windows: an initial notification within four hours of classification, an intermediate report and a final root-cause report. UK firms report to the FCA and PRA under Principle 11 and SUP 15, and to the ICO where personal data is involved.
Board reporting and self-assessment
Boards need a concise, comparable view of resilience: important business services, tolerances, current vulnerabilities, third-party exposure, incident trends and remediation progress. Regulators expect a written self-assessment, reviewed at least annually, that a supervisor could read and understand without a walkthrough.
The most effective self-assessments are candid about what is not yet within tolerance, and specific about the investment, decisions and dates required to close the gap.
A 12-month roadmap to demonstrable resilience
Months 1 to 3: refresh the important business service list, validate impact tolerances with customer and market evidence, and complete a DORA applicability assessment.
Months 4 to 6: deepen resource and third-party mapping, run two severe but plausible scenarios end to end, and rebuild the third-party register to DORA standard where in scope.
Months 7 to 9: remediate the highest-severity vulnerabilities, run a threat-led penetration test on the most critical service, and rehearse regulator-facing incident communications.
Months 10 to 12: refresh the board self-assessment, integrate resilience metrics into the risk appetite statement, and lock in the next annual cycle of testing and third-party review.
Related reading
Operational resilience consulting
Senior-led support to design, test and evidence your resilience posture.
Explore the service →ISO/IEC 27001 consulting
Certification support and ISMS design for regulated organisations.
Read more →Virtual CISO (vCISO)
Senior cyber security leadership without a permanent hire.
Explore vCISO services →Turn regulatory pressure into resilience advantage
Talk to a senior practitioner about PS21/3, DORA readiness or your next self-assessment.
