FCA, 2025
27%
of incidents reported to the FCA in 2025 came from a third party
The FCA's operational resilience regime, in plain English.
What PS21/3 and SYSC 15A ask of firms, the four stages of the work, what you must keep doing now the transition period has ended, and what is changing next with incident and third-party reporting.
FCA operational resilience is what the Financial Conduct Authority expects of firms under its policy statement PS21/3, Building Operational Resilience, and the SYSC 15A rules in the FCA Handbook. It asks firms to identify their important business services, set an impact tolerance for each, map what those services depend on, test that they can stay within tolerance under severe but plausible disruption, and record it all in a self-assessment.
The rules came into force on 31 March 2022. The transitional period ended on 31 March 2025, so firms must now operate their important business services within impact tolerances and keep reviewing, testing and self-assessing on an ongoing basis.
Disruption is a matter of when, not if. Data breaches, supplier failures, cyber incidents, extreme weather and system outages all interrupt the services firms provide, and most organisations are less prepared than they would like to be. Operational resilience is the discipline of knowing which of your services matter most, how much disruption you can absorb, and being able to keep going when something breaks.
The FCA introduced PS21/3 so UK financial firms manage this deliberately, to reduce harm to consumers and protect the integrity of the market.
FCA, 2025
27%
of incidents reported to the FCA in 2025 came from a third party
FCA, 2025
40%
of cyber incidents reported to the FCA in 2025 involved a third party
NCSC, 2025
204
nationally significant cyber attacks in the year to August 2025, up from 89
Disruption is increasingly driven by third parties and cyber, and the reporting bar is rising.
PS21/3 applies to a defined set of UK financial firms:
Its objectives are to strengthen firms' ability to prevent, adapt to, respond to, recover and learn from disruption, and to minimise harm to consumers and risk to market integrity.
Start by identifying the important business services that, if disrupted, could harm consumers or market integrity, threaten the firm's viability, or cause instability in the financial system. For each one, break it into the critical processes behind it and map the people, processes, technology, facilities and information those processes depend on.
With RunReady:
For each important business service, set an impact tolerance: the maximum level of disruption you can accept before the harm becomes intolerable, including around data loss. This is the line between an inconvenience and intolerable harm.
With RunReady:
Drova RunReady
Map important business services, set tolerances, and measure impact over time in one workspace.
Test your ability to stay within impact tolerances using severe but plausible scenarios. Include failures within your control, such as an IT system outage, and outside it, such as a cyber attack or a loss of power. The question each test answers: how would this event hit your most important services, and what happens next?
With RunReady:
Develop and maintain the monitoring, analysis and reporting that shows how you manage operational risk, and the escalation process for incidents. Document your approach, the scenario tests you have run, the lessons learned and the remediation you are undertaking, in a written self-assessment you keep current.
With RunReady: keep the self-assessment evidence, test results and remediation together in one place, so the picture you show the Board and the FCA is always up to date rather than rebuilt at reporting time.
The full PS21/3 operating guide
Every stage, in a format you can share with your board or risk committee.
31 March 2022. The rules and guidance came into force. Firms had to have identified their important business services, set impact tolerances, and begun mapping and testing.
31 March 2025. The three-year transitional period ended. From this point firms must be able to remain within their impact tolerances for every important business service.
Now. Operational resilience is business as usual. Firms review their important business services, impact tolerances and mapping at least annually, or whenever the business or market changes materially, and keep testing and learning from incidents. The FCA reviews firms' annual self-assessments and publishes its observations.
Operational resilience keeps evolving. On 18 March 2026 the FCA published new requirements for operational incident reporting and third-party notification (Policy Statement PS26/2). They come into force on 18 March 2027, so firms have until then to prepare.
PS26/2 sits alongside PS21/3, extending the picture from staying within impact tolerances to how firms report incidents when they happen and manage the third parties their important business services depend on. The mapping and service register you build for PS21/3 is the same foundation you will lean on for it.
PS21/3 is a strong foundation, but operational resilience is wider than any single regime. It spans cyber threats, third and fourth-party resilience, and climate resilience, and it connects to how a firm manages risk, controls, events, contracts, policy and regulatory change.
RunReady is the operational resilience module of Drova's RunGood platform, so the mapping, tolerances, testing and evidence you build for PS21/3 sit alongside the rest of your risk and compliance work rather than in a silo. The same foundation also supports adjacent obligations as they arrive.
UK banks and building societies, PRA-designated investment firms, insurers, Recognised Investment Exchanges, enhanced scope SM&CR firms, and entities under the Payment Services Regulations 2017 or Electronic Money Regulations 2011.
No. The rules came into force on 31 March 2022 and the transitional period ended on 31 March 2025. Firms must now operate their important business services within impact tolerances on an ongoing basis, not work towards a future date.
At least annually, or whenever there is a material change to the business or the market. Important business services, impact tolerances and mapping should be kept current, with ongoing scenario testing and lessons learned from incidents.
SYSC 15A is the section of the FCA Handbook that sets the operational resilience rules introduced by PS21/3.
A service a firm provides to an external client whose disruption could cause intolerable harm to consumers or threaten market integrity, the firm's viability, or financial stability. Identifying these is Stage 1.
The maximum level of disruption to an important business service a firm can tolerate, usually expressed as a maximum duration, before the harm becomes intolerable.
The FCA's policy statement on operational incident and third party reporting, published 18 March 2026 and coming into force 18 March 2027. It adds incident-reporting and third-party-notification requirements alongside PS21/3.
Both are operational resilience regimes built on critical or important services and tolerances. PS21/3 is the UK FCA regime; CPS 230 is the Australian APRA regime.
RunReady keeps your important business services, impact tolerances, testing and self-assessment in one place.