Risk Horizon
Live

Intelligence generated by AI from public regulatory sources. Not investment or regulatory advice. Verify before relying on any output.

Alignment
PRASS1/21v1Updated 27 Jul 2026

FCA/PRA Operational Resilience Policy (PS21/3 & SS1/21) Alignment Pack

PRA Supervisory Statement SS1/21 and FCA Policy Statement PS21/3 — Operational Resilience: Impact Tolerances for Important Business Services

The joint PRA/FCA operational resilience framework, in force since 31 March 2022 with a transitional runway to 31 March 2025, requires banks, building societies, PRA-designated investment firms, insurers and FMIs to identify their important business services (IBS), set impact tolerances expressed as maximum tolerable disruption, and demonstrate through severe-but-plausible scenario testing that they can remain within those tolerances by the end of the transition period. As of March 2025, supervisors have moved decisively out of the design phase and into active challenge: firms are being asked to evidence that mapping is granular enough to identify single points of failure, that impact tolerances are calibrated against consumer harm and financial stability rather than internal appetite, and that lessons learned from real incidents (CrowdStrike, Synapse, ION Markets, and repeated cloud outages) have been fed back into resilience planning. The PRA's Dear CEO letters through 2024 have highlighted persistent weaknesses in third-party mapping, concentration risk in cloud and market data providers, and insufficient testing of substitutability assumptions. Boards are expected to own the self-assessment document, and internal audit is expected to provide independent assurance. For CROs, the framework is now the primary operational risk supervisory lens in the UK, sitting alongside the incoming Critical Third Parties regime under FSMA 2023 sections 312L–312S, which extends direct supervisory reach to designated CTPs such as hyperscale cloud providers.

Op ResilienceBoard PackRisk CommitteeSupervisoryScenario DesignThematic Review

5

Obligations

2

Linked Themes

0

Intelligence Packs

Regulatory Obligations(5)
SS1/21 §2.1–2.6#01

A firm should identify its important business services, being services provided by the firm to an external end user or participant where a disruption could pose a risk to the firm's safety and soundness, the stability of the UK financial system, or in the case of an insurer, an appropriate degree of policyholder protection.

Applicability

Identification is the foundational obligation. Firms must apply externally-focused criteria rather than internal materiality; supervisors have criticised firms that catalogue too many or too few IBS. The register must be reviewed when the business model changes and defended against consumer harm and market integrity yardsticks.

SS1/21 §3.1–3.9#02

A firm should set an impact tolerance for each important business service, being the maximum tolerable level of disruption to an important business service, including the maximum tolerable duration of a disruption, measured by length of time and any other relevant metrics.

Applicability

Impact tolerances must be expressed in time and other measurable dimensions (e.g. transaction volumes, number of affected consumers). They are hard external thresholds — not appetite statements — and boards must approve them. Supervisors expect calibration papers linking tolerances to specific harm scenarios.

SS1/21 §4.1–4.11#03

A firm should identify and document the people, processes, technology, facilities and information necessary to deliver each of its important business services. Mapping should be sufficiently detailed to allow a firm to identify vulnerabilities and test its ability to remain within impact tolerances.

Applicability

End-to-end mapping is where most supervisory findings concentrate. Firms must map to a granularity that reveals single points of failure, third-party concentrations, and substitutability gaps. Post-CrowdStrike, mapping of upstream software supply chains is under particular scrutiny.

SS1/21 §5.1–5.12#04

A firm should carry out scenario testing to assess its ability to remain within its impact tolerance for each of its important business services in the event of a severe but plausible disruption of its operations. Firms should regularly test their ability to remain within impact tolerances and use the results to identify and remediate vulnerabilities.

Applicability

Testing must be severe-but-plausible, not merely business-as-usual continuity exercises. Scenarios should include cyber ransomware, third-party failure, data corruption, and simultaneous multi-event scenarios. Remediation plans and re-testing evidence are core supervisory asks.

SS1/21 §6.1–6.7 (Self-Assessment)#05

A firm should prepare, and keep up-to-date, a written self-assessment of its compliance with the operational resilience requirements. The self-assessment should be approved by the firm's board.

Applicability

The self-assessment is the single most requested document in supervisory engagement. It must be board-approved, evidence-rich, and honestly reflect residual vulnerabilities. Firms that produce marketing-style documents are being sent back for rework.

Control Expectations(6)

Operational Resilience

Impact tolerance declarations, resilience testing outcomes, and continuity planning evidence.

Board Governance

Board-level regulatory posture reporting and risk appetite oversight against this framework.

Committee Oversight

Risk committee challenge records and control effectiveness monitoring relevant to this regulation.

Supervisory Dialogue

Pre-submission briefings, regulatory correspondence, and supervisory engagement records.

Scenario Planning

Stress scenario design frameworks, assumption registers, and sensitivity analysis records.

Thematic Review

Structured response documentation and supporting evidence packs for thematic review obligations.

Evidence Requirements

Regulatory Submission Statement

Firms must maintain: (i) a board-approved self-assessment document updated at least annually; (ii) an IBS register with mapping down to people, processes, technology, facilities, information and third parties; (iii) impact tolerance calibration papers with quantified consumer harm and market integrity thresholds; (iv) a severe-but-plausible scenario testing programme with results, remediation plans and re-test evidence; (v) third-party dependency registers cross-referenced to the CTP regime; (vi) incident post-mortems demonstrating feedback into IBS mapping; (vii) internal audit reports on resilience governance; and (viii) minutes of the board or board risk committee where impact tolerances were approved.

Related Themes(2)