Ben Gibbins reacts to the recent publication of the new PS26/2: Operational incident and third party reporting policy which was recently published by the FCA.
The new rules created under the policy were developed after a public consultation period and create a single FCA, PRA, and Bank of England regulatory regime for operational incident and third party reporting that will apply from 18 March 2027.
According to the FCA, the FG26/3: Operational Incident Reporting rules:
- Define what an operational incident is.
- Set out the thresholds for when firms must report an incident.
- Introduce a standardized reporting process so all firms make a single submission regardless of the regulator(s) the report is for.
- Set out how firms will submit standard or enhanced incident reports.
In terms of third party reporting the FG26/4: Material Third Party Reporting rules:
- Define what a material third party arrangement is.
- Require firms to notify the FCA of any new, or any significant changes to, material third party arrangements.
- Require firms to maintain a register for their material third party arrangements, and to submit it to the FCA annually.
The new rules are distinct from the EU’s Digital Operational Resilience Act (DORA). Both follow the same ethos and emphasize the need to bolster collaboration on incident response and third-party risk management (TPRM) across the financial services and insurance (FS&I) sector. However, there are distinct differences, including prescriptive requirements, that FS&I firms will need to understand, interpret, and embed into their ongoing governance, risk, and compliance policies and processes.
While many UK financial sector organizations will have undertaken steps to be compliant with DORA, they must not assume that the new UK rules are a copy-and-paste situation. For other organizations without any footprint in mainland Europe, this policy could require a significant uplift in their incident response and third-party risk management capabilities. With 12 months to comply, FS&I organizations must begin taking stock of what is needed immediately; delaying action could see a last-minute scramble early next year, and even result in some missing the March 2027 deadline altogether.
The new rules are part of a global trend where regulators, cyber security authorities, and threat intelligence leaders have been sounding the alarm on the risks to critical national infrastructure posed by interconnected supply chains, and exacerbated by growing geopolitical tensions. With 40% of incidents reported to the FCA in 2025 involving at least one third party and the trend showing no signs of slowing, it is only a matter of time until the resilience of the UK’s financial systems is truly tested.
However, regulators cannot address systemic supply chain risks on their own. Addressing the systemic supply chain risks to the UK and global financial systems will require collaboration across firms and partnerships with innovative private companies. I encourage the various regulators to work with leading, innovative TPRM providers who have been building collaboration forums and the capabilities to identify concentration risks, so that the information they collect can be used as effectively as possible.
The author
Ben Gibbins is Head of Financial Services, Insurance and Legal at Orange Cyberdefense.






