Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Operational resilience»Operational resilience is entering its next phase (Page 9)
Operational resilience

Operational resilience is entering its next phase

May 5, 202610 Mins Read
Next level concept - four blocks make a staircase.

By Rachael Elliott

For several years, operational resilience regulation has focused on a core proposition: firms must be able to prevent, adapt to, respond to, recover from, and learn from disruption to important business services. In the UK, that agenda was achieved by the Bank of England, Prudential Regulation Authority (PRA), and Financial Conduct Authority’s (FCA) 2021 operational resilience framework, including the PRA’s expectation that firms identify important business services and set impact tolerances.

Now, the regulatory emphasis is developing. The latest UK regulation is no longer simply about whether a regulated firm has mapped its important business services and tested severe-but-plausible scenarios. It is also about whether supervisors receive timely, structured intelligence on incidents and on the third parties that may trigger them. The FCA’s Policy Statement PS26/2, published on 18 March 2026, introduces final rules and guidance on reporting operational incidents and material third-party arrangements. The new rules will come into effect on 18 March 2027.

This shows that operational resilience is becoming more explicitly ecosystem-based, adding to the policy statement released in late 2024. Regulators are highlighting that regulation is not only about a firm’s own controls, but also about dependencies, concentrations, subcontracting chains, and the sector-wide intelligence that can be drawn from them. In PS26/2, the FCA says incidents originating from third parties have been the top root cause of disruption for firms, and that improved third-party data will help identify systemic risks and inform possible recommendations to the UK’s Treasury on critical third parties.

However, this thinking extends beyond the UK. In the EU, the Digital Operational Resilience Act (DORA) has applied since 17 January 2025 and creates an oversight framework for critical ICT third-party providers. In Australia, the Australian Prudential Regulation Authority’s (APRA) CPS 230 has been in force since 1 July 2025 and expressly requires entities to maintain critical operations through disruption and manage risks arising from service providers. In December 2025, the Basel Committee published global principles for the sound management of third-party risk, establishing a common baseline for banks and supervisors. In addition, the Monetary Authority of Singapore (MAS) has consulted on broader third-party risk management and updated operational risk management guidelines.

Resilience regulation is clearly expanding from “Can you withstand disruption?” to “Can you evidence, report, govern, and manage dependency risk across your wider operating model?”

Where we are now: the global regulatory picture

Firstly, regulators are becoming more explicit about service continuity. The PRA’s operational resilience framework is built around important business services and impact tolerances. DORA focuses on digital operational resilience across EU financial entities. APRA CPS 230 requires Australian firms to continue delivering critical operations within tolerance levels through severe disruptions.

Secondly, third-party risk is being broadened beyond classic outsourcing. In PS26/2, the FCA has expanded the scope of existing outsourcing notifications to include both material outsourcing and non-outsourcing arrangements and defines a third-party arrangement broadly as an arrangement under which a person provides a product or service to the firm, whether directly, via a subcontractor, or within the same company.

Thirdly, regulators and supervisors are seeking more structured reporting and better market-wide visibility. The FCA’s new rules standardise operational incident reporting and create notification and register requirements for material third-party arrangements. The PRA’s parallel policy will help it gain better oversight of risks arising from operational incidents and the use of third parties.

What is changing in the UK

The FCA’s new regime has two principal add-ons to the earlier operational resilience framework.

The first is standardised operational incident reporting. In FG26/3, the FCA explains that firms had told it that they were unclear on when and how to notify incidents. The new rules therefore define an operational incident and introduce a standardised process for reporting relevant incidents. FG26/3 also makes clear that firms only need to report established incidents that have met one or more thresholds.

The FCA’s definition appears to be deliberately practical. An operational incident is either a single event or a series of linked events that disrupts an organization’s operations or services to an external end user. The guidance distinguishes reportable incidents from near misses and from planned interruptions that go to plan.

The other new development is deliberate third-party reporting. FG26/4 says its purpose is to help organizations to assess whether a third-party arrangement is material, understand the related definitions, and complete notification and register templates. PS26/2 also confirms that firms will maintain and annually submit a register of material third-party arrangements, and that notifications should be made sufficiently early in the decision-making process.

The earlier UK resilience framework already required dependency mapping and scenario testing. What is new is a more formal regulatory data model around those dependencies. Supervisors are not only expecting firms to know their third parties, but also to classify them, register them, notify material changes, and explain them in a standard format.

Why has this add-on been introduced?

The risk picture has changed. Digital transformation has made firms more dependent on a smaller number of technology, data, cloud, payments, and specialist service providers. The Basel Committee notes that digitalization has expanded banks’ reliance on third-party service providers and that managing supply chain and nth-party risk is now central to operational resilience. The EU’s DORA framework similarly targets systemic and concentration risks arising from dependence on a limited number of ICT providers.

The FCA’s own explanation is equally direct. It says that third parties have been the top root cause for organizations’ incidents and that better data will help it understand linkages, dependencies, and wider industry vulnerabilities.

In other words, this new piece of regulation has been introduced because resilience failures are increasingly due to network failures. A firm may have robust internal recovery plans and still suffer disruption because of a shared provider outage, a subcontractor failure, a data centre issue, a cyber incident in the supply chain, or concentration in a single platform.

What it means for regulated organizations

For regulated firms, the implications are operational, managerial, and strategic. Operationally, firms need better taxonomy, triggers, and workflows. Incident management teams must be able to determine whether an event fits the FCA definition, whether thresholds are met, and when initial, intermediate, and final reporting is required. Supply chain or supplier governance teams must maintain a defensible register of material third-party arrangements and update it as services, ownership structures, locations, or subcontractors change.

Managerially, this raises the bar for governance. Under APRA CPS 230, the board is ultimately accountable for operational risk management, including business continuity and service provider arrangements. The same logic is implicit in the UK framework: resilience is no longer the responsibility of a specialist function. It is a board-level issue (specifically for the Chief Operations Officer) which combines operational continuity, risk, technology, compliance, procurement, and legal oversight.

Strategically, firms need to revisit the way they define criticality. Materiality under the reporting rules is not a label. It is more a resilience judgement about whether disruption in a supplier-provided product or service could cause intolerable customer harm, threaten market integrity, or cast serious doubt on the firm’s ability to meet threshold conditions or operational resilience obligations.

Senior management should therefore expect three practical consequences:

  • More rigorous dependency mapping across business services, processes, technology, data, and suppliers.
  • Closer alignment between resilience, outsourcing, vendor management, and incident response.
  • More formal evidence for regulators, internal audit, and the board on why a supplier is, or is not, considered material.

What it means for non-regulated suppliers

Non-regulated suppliers should not assume they are excluded from the regulation. While the regulation applies to regulated firms, not directly to most suppliers, the burden will be transmitted contractually and operationally. Suppliers serving regulated firms should expect more due diligence, more structured questionnaires, more requests for incident information, more scrutiny of subcontracting chains, and greater demand for timely updates where service changes could alter a firm’s regulatory assessment.

In effect, suppliers will need to behave as if resilience transparency is part of the product they sell. Non-regulated suppliers should be ready to provide:

  • Clear service descriptions and dependency maps.
  • Incident escalation paths and notification timeframes.
  • Subcontractor visibility.
  • Testing, recovery, and assurance evidence.
  • Information on data location, concentration risk, and control changes.

Suppliers that cannot provide this will increasingly look risky, even if their technical service is sound.

How this will affect global organizations

For organizations with a global remit, the challenge is not only about compliance, but about how different regulations can be used interoperably.

The UK, EU, and Australia are using slightly different regulatory architectures, but they revolve around similar themes: critical services, tolerance-based resilience, incident reporting, and third-party risk management.

That creates a familiar dilemma for global organizations. Local rules differ, but the underlying data needed to comply is often the same. If a fragmented approach is taken – with separate registers, definitions, and workflows for each jurisdiction – it will become expensive, unreliable, and could potentially fail.

The better model is a global control framework with local regulatory overlays. At a minimum, multinational firms could seek a common backbone for:

  • Business service and process inventories.
  • Supplier and subcontractor inventories.
  • Incident severity and regulatory trigger matrices.
  • Materiality assessment criteria.
  • Board reporting and audit evidence packs.

Using the DRI Professional Practices to implement best practice

Practitioners might look toward the DRI Professional Practices for guidance. For this regulatory cycle, five Professional Practices are particularly relevant.

1. Risk Assessment The second Professional Practice calls for entity-wide risk identification, including supply chain, cyber security, legal, and regulatory impacts. This can serve as a model for assessing how incident reporting thresholds and third-party reporting obligations link to real exposure.

2. Business Impact Analysis (BIA) Professional Practice three, the BIA, explains how data collection should include internal and external dependencies, participation by third-party provider representatives, and documentation of dependencies across supply chain, third parties, and technology.

3. Business Continuity Strategies Professional Practice four recognises third-party service providers and outsourcers as continuity strategies, but also requires cost-benefit analysis and assessment of supply chain issues affecting recovery.

4. Incident Preparedness and Response Professional Practice five focuses on incident management preparation for all incidents. This aligns with the FCA’s standardised incident reporting model.

5. Exercise/Test, Assessment, and Maintenance Professional Practice eight explains the importance of frequent exercising, post-test recommendations, maintenance, governance, and audit. Exercises should now include regulatory reporting triggers and supplier failure scenarios.

Conclusion

The latest operational resilience changes represent a move from resilience as just preparedness to resilience as supervised interconnectedness.

The new UK reporting rules do not replace the original operational resilience framework; rather, they complete it to provide resilience across internal and external networks.

For senior management, boards should ask not only whether the firm can withstand disruption, but whether it can rapidly classify, explain, and evidence disruption across its supplier ecosystem.

For practitioners, the task is to turn that expectation into a disciplined operating model; and following guidance from a recognised framework such as the DRI Professional Practices provides a strong blueprint for doing exactly that.

The author

Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.

DRI logo
Resilience Perspectives
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleWhy building a systemic risk capacity is a vital way forward for organizations
Next Article Adapted cyber approaches are putting operational technology at risk

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
AI implementation concept

Why AI is forcing a rethink of enterprise resilience

June 18, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?