By Rachael Elliott
For several years, operational resilience regulation has focused on a core proposition: firms must be able to prevent, adapt to, respond to, recover from, and learn from disruption to important business services. In the UK, that agenda was achieved by the Bank of England, Prudential Regulation Authority (PRA), and Financial Conduct Authority’s (FCA) 2021 operational resilience framework, including the PRA’s expectation that firms identify important business services and set impact tolerances.
Now, the regulatory emphasis is developing. The latest UK regulation is no longer simply about whether a regulated firm has mapped its important business services and tested severe-but-plausible scenarios. It is also about whether supervisors receive timely, structured intelligence on incidents and on the third parties that may trigger them. The FCA’s Policy Statement PS26/2, published on 18 March 2026, introduces final rules and guidance on reporting operational incidents and material third-party arrangements. The new rules will come into effect on 18 March 2027.
This shows that operational resilience is becoming more explicitly ecosystem-based, adding to the policy statement released in late 2024. Regulators are highlighting that regulation is not only about a firm’s own controls, but also about dependencies, concentrations, subcontracting chains, and the sector-wide intelligence that can be drawn from them. In PS26/2, the FCA says incidents originating from third parties have been the top root cause of disruption for firms, and that improved third-party data will help identify systemic risks and inform possible recommendations to the UK’s Treasury on critical third parties.
However, this thinking extends beyond the UK. In the EU, the Digital Operational Resilience Act (DORA) has applied since 17 January 2025 and creates an oversight framework for critical ICT third-party providers. In Australia, the Australian Prudential Regulation Authority’s (APRA) CPS 230 has been in force since 1 July 2025 and expressly requires entities to maintain critical operations through disruption and manage risks arising from service providers. In December 2025, the Basel Committee published global principles for the sound management of third-party risk, establishing a common baseline for banks and supervisors. In addition, the Monetary Authority of Singapore (MAS) has consulted on broader third-party risk management and updated operational risk management guidelines.
Resilience regulation is clearly expanding from “Can you withstand disruption?” to “Can you evidence, report, govern, and manage dependency risk across your wider operating model?”
Where we are now: the global regulatory picture
Firstly, regulators are becoming more explicit about service continuity. The PRA’s operational resilience framework is built around important business services and impact tolerances. DORA focuses on digital operational resilience across EU financial entities. APRA CPS 230 requires Australian firms to continue delivering critical operations within tolerance levels through severe disruptions.
Secondly, third-party risk is being broadened beyond classic outsourcing. In PS26/2, the FCA has expanded the scope of existing outsourcing notifications to include both material outsourcing and non-outsourcing arrangements and defines a third-party arrangement broadly as an arrangement under which a person provides a product or service to the firm, whether directly, via a subcontractor, or within the same company.
Thirdly, regulators and supervisors are seeking more structured reporting and better market-wide visibility. The FCA’s new rules standardise operational incident reporting and create notification and register requirements for material third-party arrangements. The PRA’s parallel policy will help it gain better oversight of risks arising from operational incidents and the use of third parties.
What is changing in the UK
The FCA’s new regime has two principal add-ons to the earlier operational resilience framework.
The first is standardised operational incident reporting. In FG26/3, the FCA explains that firms had told it that they were unclear on when and how to notify incidents. The new rules therefore define an operational incident and introduce a standardised process for reporting relevant incidents. FG26/3 also makes clear that firms only need to report established incidents that have met one or more thresholds.
The FCA’s definition appears to be deliberately practical. An operational incident is either a single event or a series of linked events that disrupts an organization’s operations or services to an external end user. The guidance distinguishes reportable incidents from near misses and from planned interruptions that go to plan.
The other new development is deliberate third-party reporting. FG26/4 says its purpose is to help organizations to assess whether a third-party arrangement is material, understand the related definitions, and complete notification and register templates. PS26/2 also confirms that firms will maintain and annually submit a register of material third-party arrangements, and that notifications should be made sufficiently early in the decision-making process.
The earlier UK resilience framework already required dependency mapping and scenario testing. What is new is a more formal regulatory data model around those dependencies. Supervisors are not only expecting firms to know their third parties, but also to classify them, register them, notify material changes, and explain them in a standard format.
Why has this add-on been introduced?
The risk picture has changed. Digital transformation has made firms more dependent on a smaller number of technology, data, cloud, payments, and specialist service providers. The Basel Committee notes that digitalization has expanded banks’ reliance on third-party service providers and that managing supply chain and nth-party risk is now central to operational resilience. The EU’s DORA framework similarly targets systemic and concentration risks arising from dependence on a limited number of ICT providers.
The FCA’s own explanation is equally direct. It says that third parties have been the top root cause for organizations’ incidents and that better data will help it understand linkages, dependencies, and wider industry vulnerabilities.
In other words, this new piece of regulation has been introduced because resilience failures are increasingly due to network failures. A firm may have robust internal recovery plans and still suffer disruption because of a shared provider outage, a subcontractor failure, a data centre issue, a cyber incident in the supply chain, or concentration in a single platform.
What it means for regulated organizations
For regulated firms, the implications are operational, managerial, and strategic. Operationally, firms need better taxonomy, triggers, and workflows. Incident management teams must be able to determine whether an event fits the FCA definition, whether thresholds are met, and when initial, intermediate, and final reporting is required. Supply chain or supplier governance teams must maintain a defensible register of material third-party arrangements and update it as services, ownership structures, locations, or subcontractors change.
Managerially, this raises the bar for governance. Under APRA CPS 230, the board is ultimately accountable for operational risk management, including business continuity and service provider arrangements. The same logic is implicit in the UK framework: resilience is no longer the responsibility of a specialist function. It is a board-level issue (specifically for the Chief Operations Officer) which combines operational continuity, risk, technology, compliance, procurement, and legal oversight.
Strategically, firms need to revisit the way they define criticality. Materiality under the reporting rules is not a label. It is more a resilience judgement about whether disruption in a supplier-provided product or service could cause intolerable customer harm, threaten market integrity, or cast serious doubt on the firm’s ability to meet threshold conditions or operational resilience obligations.
Senior management should therefore expect three practical consequences:
- More rigorous dependency mapping across business services, processes, technology, data, and suppliers.
- Closer alignment between resilience, outsourcing, vendor management, and incident response.
- More formal evidence for regulators, internal audit, and the board on why a supplier is, or is not, considered material.
What it means for non-regulated suppliers
Non-regulated suppliers should not assume they are excluded from the regulation. While the regulation applies to regulated firms, not directly to most suppliers, the burden will be transmitted contractually and operationally. Suppliers serving regulated firms should expect more due diligence, more structured questionnaires, more requests for incident information, more scrutiny of subcontracting chains, and greater demand for timely updates where service changes could alter a firm’s regulatory assessment.
In effect, suppliers will need to behave as if resilience transparency is part of the product they sell. Non-regulated suppliers should be ready to provide:
- Clear service descriptions and dependency maps.
- Incident escalation paths and notification timeframes.
- Subcontractor visibility.
- Testing, recovery, and assurance evidence.
- Information on data location, concentration risk, and control changes.
Suppliers that cannot provide this will increasingly look risky, even if their technical service is sound.
How this will affect global organizations
For organizations with a global remit, the challenge is not only about compliance, but about how different regulations can be used interoperably.
The UK, EU, and Australia are using slightly different regulatory architectures, but they revolve around similar themes: critical services, tolerance-based resilience, incident reporting, and third-party risk management.
That creates a familiar dilemma for global organizations. Local rules differ, but the underlying data needed to comply is often the same. If a fragmented approach is taken – with separate registers, definitions, and workflows for each jurisdiction – it will become expensive, unreliable, and could potentially fail.
The better model is a global control framework with local regulatory overlays. At a minimum, multinational firms could seek a common backbone for:
- Business service and process inventories.
- Supplier and subcontractor inventories.
- Incident severity and regulatory trigger matrices.
- Materiality assessment criteria.
- Board reporting and audit evidence packs.
Using the DRI Professional Practices to implement best practice
Practitioners might look toward the DRI Professional Practices for guidance. For this regulatory cycle, five Professional Practices are particularly relevant.
1. Risk Assessment The second Professional Practice calls for entity-wide risk identification, including supply chain, cyber security, legal, and regulatory impacts. This can serve as a model for assessing how incident reporting thresholds and third-party reporting obligations link to real exposure.
2. Business Impact Analysis (BIA) Professional Practice three, the BIA, explains how data collection should include internal and external dependencies, participation by third-party provider representatives, and documentation of dependencies across supply chain, third parties, and technology.
3. Business Continuity Strategies Professional Practice four recognises third-party service providers and outsourcers as continuity strategies, but also requires cost-benefit analysis and assessment of supply chain issues affecting recovery.
4. Incident Preparedness and Response Professional Practice five focuses on incident management preparation for all incidents. This aligns with the FCA’s standardised incident reporting model.
5. Exercise/Test, Assessment, and Maintenance Professional Practice eight explains the importance of frequent exercising, post-test recommendations, maintenance, governance, and audit. Exercises should now include regulatory reporting triggers and supplier failure scenarios.
Conclusion
The latest operational resilience changes represent a move from resilience as just preparedness to resilience as supervised interconnectedness.
The new UK reporting rules do not replace the original operational resilience framework; rather, they complete it to provide resilience across internal and external networks.
For senior management, boards should ask not only whether the firm can withstand disruption, but whether it can rapidly classify, explain, and evidence disruption across its supplier ecosystem.
For practitioners, the task is to turn that expectation into a disciplined operating model; and following guidance from a recognised framework such as the DRI Professional Practices provides a strong blueprint for doing exactly that.
The author
Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.







