Insights · 24 July 2026

What the FCA found: the 2026 operational resilience review, decoded

The FCA operational resilience review highlights weak evidence and gaps in supplier oversight; learn how to close gaps and strengthen scenario testing in 2026. What you get: a practical plan.

The fca operational resilience review finds firms give weak evidence for recovery arrangements, run scenario tests that lack sufficient severity and leave gaps in third‑party oversight, as set out in the Financial Conduct Authority's Annual Report and Accounts (Annual Report and Accounts - GOV.UK).

At CyPro, we treat the fca operational resilience review as a prompt to close evidence gaps, strengthen supplier mapping and run more severe, plausible scenario tests, drawing on related regulator findings such as the Information Commissioner’s Office incident reporting (Information Commissioner’s Office report) and sector threat analysis from the European Union Agency for Cybersecurity (ENISA finance sector threat analysis).

  • Headline: The fca operational resilience review highlights weak evidence, low‑severity testing and supplier governance gaps (Annual Report and Accounts - GOV.UK).
  • Regulatory ask: The Financial Conduct Authority requires end‑to‑end evidence mapped to important services under Policy Statement PS21/3 (see the Annual Report and Accounts linked above).
  • Immediate steps: Complete an evidence gap analysis, rerun more severe plausible scenario tests and update supplier maps, using regulator guidance and sector reporting (Information Commissioner’s Office report, ENISA finance sector threat analysis).
  • Where we help: At CyPro, we review self‑assessment artefacts and prepare firms for targeted supervisory follow‑up, including supplier oversight and scenario design.

What did the FCA's 27 March 2026 review find and why does it matter?

The FCA's 27 March 2026 review found that many firms are failing to provide convincing evidence of resilience against severe-but-plausible disruptions, and this matters because the regulator expects outcomes, not just plans. The Financial Conduct Authority (FCA) sets the bar in Policy Statement PS21/3 for mapped important business services, impact tolerances and demonstrable testing, and the FCA's Annual Report and Accounts 2024/25 restates supervisory concern where firms cannot show recovery within tolerances (Annual Report and Accounts - GOV.UK).

Key Takeaway

Firms must produce dated, auditable evidence: mapped important services, impact tolerances tested by severe scenarios, and supplier oversight linked to those services.

Headline findings

The Financial Conduct Authority (FCA) highlighted three recurring shortfalls: weak documentary evidence in self-assessments, scenario testing that was not severe enough to validate recovery, and gaps in oversight of third parties that support important services. The FCA connects these shortfalls to PS21/3 expectations and to follow-up supervision where evidence is absent (Annual Report and Accounts - GOV.UK).

Why this matters now

The European Union Agency for Cybersecurity's finance sector threat report shows increasing sophistication in attacks and a higher potential for systemic impact, which explains why the FCA links weak arrangements to wider system risk (ENISA THREAT LANDSCAPE: FINANCE SECTOR). For UK firms, the FCA's emphasis means resilience programmes must prove recovery within stated impact tolerances, not just document plans.

Practical implications for firms

The fca operational resilience review shifts supervision from policy statements to evidence-driven assessment. Firms should prioritise a short evidence-gap analysis, rerun at least one severe-but-plausible scenario test with dated outcomes, and align supplier maps to important services. In our experience, a focused self-assessment review followed by an evidence pack speeds regulatory closure: see our guidance on the operational resilience self-assessment and scenario testing for practical templates and runbooks (Operational Resilience Self-Assessment, Scenario Testing: severe, plausible).

What are the FCA operational resilience requirements firms must meet now?

Firms must follow the Financial Conduct Authority (FCA) policy in PS21/3: identify important business services, set measurable impact tolerances, map end-to-end dependencies, run severe-but-plausible scenario testing, and keep evidence for supervisory review.

Core obligations the FCA cites

The FCA requires firms to define important business services and set impact tolerances expressed in hours or days, not vague terms. The FCA also expects senior accountability, documented third-party assurance, and scenario testing that shows services remain within impact tolerances under disruption. Firms should be ready to show artefacts linking tests, results and remediation back to named services and owners.

What the 2026 review found

The FCA's 2026 operational resilience review identified common shortcomings: weak supporting evidence in self-assessments, scenario tests that were not sufficiently severe, and gaps in third-party oversight. The FCA's Annual Report and Accounts 2024/25 summarises supervisory work and sets out that many firms still need to strengthen documented evidence to meet PS21/3 expectations (Annual Report and Accounts - GOV.UK, 2024).

Evidence the FCA expects in practice

The Information Commissioner’s Office (ICO) highlights that operational incident records and follow-up actions are central to regulators assessing resilience, so cyber-related scenario outcomes should map to incident response artefacts and data protection logs (Information Commissioner’s Office, 2025). The FCA will look for clear dependency maps, impact tolerance calculations, signed governance minutes, test plans, test results and remediation tracking that links to named important services.

Practical next steps for UK firms

In our experience, firms should prioritise three short actions: 1) rerun at least one severe-but-plausible scenario that stresses third-party dependencies, 2) attach test evidence to each named important service and its impact tolerance, and 3) escalate residual gaps to the board with timebound remediation. If you need a structured review, our PS21/3 explained and evidenced service helps firms convert partial mappings and tabletop notes into the end-to-end artefacts supervisors expect (PS21/3 explained and evidenced).

Finally, sector reporting shows attackers increasingly exploit supplier and infrastructure weaknesses, so firms should treat third-party assurance as central to meeting the FCA requirements rather than an add-on (Verizon, 2025).

What the FCA found: the 2026 operational resilience review, decoded - supporting illustration

How should firms decode each finding into evidence and self-assessment terms?

Answer: Map each FCA finding to a self-assessment line item, identify the specific artefact that proves the claim, and record a measurable test or metric that shows the artefact works in practice. This approach turns high-level comments into concrete evidence.

Start by tagging each finding to the self-assessment sections the Financial Conduct Authority expects: important services, impact tolerances, dependency mapping, scenario testing and governance. For every finding write one sentence that restates it as an assertion you can evidence, for example, "We can meet Impact Tolerance X for Service Y for 24 hours."

Key Takeaway

Translate each FCA finding into a single self-assessment assertion, a named artefact (policy, runbook, log extract) and the test or metric that proves it worked.

Acceptable evidence examples

Acceptable evidence needs to be observable and dated. For impact tolerances provide time-stamped availability dashboards, incident logs showing recovery within the stated tolerance, and signed capacity statements from key suppliers. For scenario testing include the test script, participant list, photos or recordings, and a signed after-action report with measured outcomes. For governance show board minutes that record decisions about tolerances and supplier risk.

Common gaps and fixes

The FCA review found many firms had assertions without artefacts or had weak scenario severity. Use the fca operational resilience review findings to rerun tests at clearly severe levels and keep all outputs. Link supplier evidence to your assertion by storing supplier SOC reports, SLAs and contact lists alongside the self-assessment entry. Where third-party evidence is missing, obtain a dated attestation or run a joint scenario with the supplier; this is what regulators expect under PS21/3.

Operationally, keep a single evidence register that maps finding → assertion → artefact URL or file → test result. For help designing severe-but-plausible tests see our Scenario testing service. Use regulator guidance when calibrating severity levels, for example ENISA and the 2025 Verizon DBIR for threat context.

Keep the self-assessment alive: update assertions after every test or material supplier change, and use the evidence register during audits and supervisory meetings to demonstrate remediation progress against the fca operational resilience review findings.

Who needs to act: which firms, sectors and internal teams are in scope?

Large and mid-market UK firms that provide an "important service" under the FCA's PS21/3, their material third parties, and firms in regulated sectors such as banking, payments and markets must act now, and board, operations, IT, resilience and legal teams must provide evidence and assurance.

Which firms are in scope?

Under the FCA policy PS21/3, firms that deliver important services to UK consumers or financial markets fall in scope; this includes banks, insurers, payment firms and market infrastructures, plus other firms whose failure could disrupt the financial system. The FCA's review highlights persistent gaps in self-assessments across mid-market firms, so many organisations that previously judged themselves low risk should reassess against PS21/3.

Which internal teams must act?

Senior management and the board must own assertions and sign off impact tolerances, while operations, IT and resilience teams provide mapping, testing and remediation evidence; legal and third-party risk teams must tighten supplier contracts and oversight. The FCA expects cross-functional evidence packages, not single-team write-ups, so the evidence must show coordinated ownership across functions.

Practical checklist for financial services, legal and tech firms

Start by identifying which services qualify as important under PS21/3 and map upstream suppliers and downstream customers; run severe-but-plausible scenario tests and record outcomes in an evidence register. For benchmarked threat context use sector reporting such as IBM's operational technology analysis and market research on breach patterns when calibrating scenarios. See our guidance on PS21/3 for practical templates and fixed-fee reviews to firm up assertions (PS21/3, explained and evidenced).

Operational and resilience teams should also read analyst guidance on emerging operational threats to ensure scenario severity reflects current attacker capabilities (Gartner and IBM X-Force publications).

In our experience, firms that treat the fca operational resilience review as a single IT project fail; the review is a business-wide programme. Begin with governance and clear responsibilities, then loop in suppliers and legal to close the evidence gaps the FCA identified in 2026. That way the fca operational resilience review findings become a governance improvement, not a box-ticking exercise.

How much will fixing the FCA-identified gaps cost in the UK? £

The short answer: expect a one-off remediation range of £30,000 to £500,000 plus recurring costs of £5,000 to £150,000 per year, depending on size, complexity and third-party coverage. The fca operational resilience review makes clear evidence gaps, not just policy gaps, drive cost.

Cost bands by organisation size

Small firms (under 100 staff) typically face £30,000 to £75,000 in 2026 for a self-assessment, supplier mapping and 1 to 2 scenario tests; mid-market firms (100 to 1,000 staff) see £75,000 to £250,000; large or complex firms can hit £250,000 to £500,000. Recurring annual work, including live evidence maintenance and periodic scenario testing, runs from £5,000 to £150,000 per year. These ranges reflect remediation to close the evidence and testing shortfalls the fca operational resilience review highlighted, and the extra cost of supplier assurance for outsourced services.

Organisation size One-off remediation (2026) Annual recurring (2026) Typical deliverables
Small (<100 staff) £30,000 to £75,000 £5,000 to £15,000 Self-assessment, supplier map, 1 scenario test
Mid-market (100 to 1,000 staff) £75,000 to £250,000 £15,000 to £60,000 Impact tolerance workshops, supplier audits, 2 to 3 tests
Enterprise (1,000+ staff) £250,000 to £500,000+ £60,000 to £150,000+ End-to-end evidence register, supplier programme, annual exercises

What those bands include and budgeting guidance

Included items: a documented self-assessment, an evidence register mapping assertions to artefacts, impact tolerance workshops, severe-but-plausible scenario testing and supplier assurance. External research shows incidents and supplier failures drive much of the cost uplift; see Verizon, 2025 and breach threat context in Mandiant, 2025. For budgeting, split costs as: 60 percent remediation and testing, 25 percent supplier assurance, 15 percent continuous evidence upkeep. If you want a fixed-fee pricing benchmark for planning, see our pricing page for published examples on self-assessment and scenario testing.

What the FCA found: the 2026 operational resilience review, decoded - supporting illustration

How does FCA operational resilience compare with PRA rules and DORA?

They overlap on outcomes but differ in legal form, scope and cross-border obligations. The FCA's regime under PS21/3 is a conduct-focused, firm-level requirement, the Prudential Regulation Authority (PRA) expects prudential firms to embed resilience into safety-and-soundness controls, and the EU Digital Operational Resilience Act (DORA) is a binding EU regulation for ICT third-party risk across financial entities.

Scope and legal basis

The FCA's PS21/3 is a UK rule that applies to important business services and asks firms to set impact tolerances and evidence testing; the PRA's expectations sit inside prudential supervision and link to capital and governance. The EU ENISA summary of DORA shows DORA imposes mandatory ICT risk management, incident reporting and third-party oversight across EU banks, insurers and investment firms.

Cross-border and third-party obligations

DORA has explicit cross-border rules for third-party ICT providers and mandatory contractual terms; the FCA's review emphasised supplier mapping and evidence on outsourcing chains without naming bespoke contract clauses. The FCA's annual report and related material emphasise supervisory testing and firm-level evidence collection, and firms that operate in the EU will often need to meet both PS21/3 evidence standards and DORA's contractual and reporting duties (Annual Report and Accounts - GOV.UK).

Practical implication for UK firms

For UK firms the practical effect of the fca operational resilience review is to prioritise demonstrable testing, supplier assurance and evidence registers; PRA-regulated firms must also show governance and board oversight that links resilience failings to prudential outcomes. Firms operating in both the UK and EU should treat DORA as additive: meet DORA's mandatory ICT contract and reporting items, and use PS21/3 evidence and scenario testing to satisfy the FCA. For hands-on support, see our operational resilience consulting for UK financial services (Operational resilience consulting for UK financial services).

How to choose who helps you: build in-house, buy a supplier or use our services?

Decide by matching capability, time and regulatory need: build in-house when you have long-term headcount, buy a supplier for fast delivery, and use our services when you need an FCA-focused, fixed-fee route that maps directly to evidence requirements. The fca operational resilience review emphasises the need for demonstrable scenario testing, supplier assurance and clear evidence trails, as set out in the Financial Conduct Authority's Annual Report 2024/25 (Financial Conduct Authority, 2025).

Build in-house: when it makes sense

Build in-house when you already have an established resilience team, steady budget for permanent hires, and a governance model that can absorb ongoing scenario testing and evidence upkeep. Organisations that choose this route must commit to recurring exercises, supplier assurance processes and board-level reporting aligned to PS21/3. If those capabilities are not already in place, building can take many months and increase risk that regulatory evidence is inconsistent.

Buy a supplier: pros, cons and red flags

Buying a supplier speeds up scenario testing, impact tolerance work and evidence collation. Use suppliers who publish methodologies referencing PS21/3 and who allow contractual audit rights over subcontractors. Avoid vendors who deliver slide decks without audit-ready evidence packs. Sector reporting such as the 2025 Data Breach Investigations Report shows external providers often provide faster detection and forensic capacity, which matters when time-to-evidence is short.

Use our services: when it is the pragmatic choice

At CyPro, we offer a fixed-fee, UK-regulatory focused service that maps deliverables to FCA expectations and PS21/3 evidence slots. Our approach suits firms that must close an evidence gap quickly, have a finite budget window, or need a repeatable template for board reporting. We link our evidence-mapping sprint to the self-assessment template and the main FCA operational resilience service page so responsibilities and artefacts are traceable.

Practical checklist: match your decision to three things, cost, time-to-evidence and auditability. If fast, auditable evidence matters more than permanent capability, prefer a specialist supplier or our fixed-fee service to minimise execution risk in response to the fca operational resilience review.

Frequently asked questions

Do I need to update my self-assessment because of the FCA's 27 March 2026 review?

Key fact: the Financial Conduct Authority (FCA) expects firms to update assessments where findings touch previously closed areas. If the 27 March 2026 review overlaps your self-assessment, update evidence, record remediation plans and note owners and dates. Firms subject to Policy Statement PS21/3 should expect follow-up questions and preserve scenario testing outputs that affect impact tolerances and third-party dependencies.

What is the typical implementation time for remediating gaps the FCA found?

Key fact: simple fixes can take weeks, while major remediation programmes typically run three to nine months. Timelines depend on supplier changes, scenario testing cycles, board approvals and internal resource availability. Plan for at least one round of scenario testing, evidence consolidation and a formal governance gate before closure to meet the FCA's expectations on demonstrable progress.

Can operational resilience be outsourced and still meet FCA expectations?

Key fact: regulated firms remain responsible under Policy Statement PS21/3 even where functions are outsourced. Outsourcing is acceptable if the firm can evidence governance, oversight and control of third parties. Choose suppliers that provide auditable outputs, scenario test packs and clear Service Level Agreements (SLAs), and be prepared to show the FCA concentration analysis and recovery capability evidence for critical suppliers.

Do I still need scenario testing if I have good incident response and ISO 27001?

Key fact: International Organization for Standardization (ISO) 27001 certification and strong incident response do not replace severe-plausible scenario testing required by the Financial Conduct Authority (FCA). Scenario testing proves impact tolerances and supply-chain dependencies that ISO 27001 and runbooks do not. Map existing artefacts into scenario evidence to reduce duplication, but run at least one bespoke severe-plausible scenario.

What immediate actions should boards take after the FCA's 2026 review?

Key fact: boards should request a concise gap summary against the Financial Conduct Authority's 27 March 2026 findings and an owners-and-dates remediation plan. Ensure impact tolerances are approved, scenario testing outcomes are scheduled for board review and decisions are recorded. Preserve documented evidence and meeting minutes so the FCA can readily verify governance and progress in subsequent engagement.

Rocket above the Operational Resilience UK call to action

Where to begin

Find out how your resilience programme actually reads

A free 45 minute scoping call with a consultant covers where your resilience genuinely stands against what the regulators now expect, and which fixed-fee service closes the gap. Nobody sells at you.