LawFlash

Looking Ahead: UK FCA New Operational Incident and Third-Party Reporting Rules Take Effect in March 2027

September 08, 2026

The UK Financial Conduct Authority, working with the UK Prudential Regulation Authority and the Bank of England, has published its policy statement PS26/2 Operational Incident and Third-Party Reporting, establishing a unified regulatory regime for operational incident reporting and third-party arrangements reporting across the UK regulated financial sector. This regime would work alongside parallel regulatory regimes established by the UK General Data Protection Regulation, and to the extent applicable, the EU Digital Operational Resilience Act, EU General Data Protection Regulation, and EU Market Abuse Rules.

The new framework, effective from 18 March 2027, introduces comprehensive requirements for timely notification of serious operational incidents and expanded reporting of material third-party arrangements, with implications for fund and portfolio managers, other investment firms, banks, payment service providers (PSPs), and other regulated entities. With six months before the new regime takes effect, firms should now be in preparation mode.

The final rules were published earlier this year further to a consultation launched by the UK Financial Conduct Authority (FCA) as long ago as December 2024, giving the industry a year to implement the new regime which aims to enhance operational resilience and regulatory oversight across the financial sector, and alignment with international standards such as the EU’s Digital Operational Resilience Act (DORA). The FCA launched the consultation in response to ever-increasing attacks by threat actors on the financial sector and the third parties on which regulated firms increasingly rely to boost efficiency and support their innovations and the exacerbating ripple effect arising from the increasing interconnectedness of the sector.

For operational incident reporting, the FCA has created a single FCA, UK Prudential Regulation Authority (PRA), and Bank of England reporting regime, comprising the following:

  • A single definition of “incident”
  • A single reporting portal
  • Identical timelines for reporting[1]
  • A single approach to thresholds for reporting only serious incidents
  • Significantly reduced information requirements than originally consulted on, by moving to a single short form with 10 required questions for the majority of FCA solo-regulated firms (and credit unions)

For reporting third-party arrangements, the FCA has created a unified FCA, PRA, and Bank of England regime, comprising a single third-party arrangements definition, approach to defining a material third party arrangement, notification template, register template, and portal.

BACKGROUND

The United Kingdom’s existing approach to operational incident and third-party arrangements reporting faced persistent shortcomings, including inconsistent reporting practices, delayed notifications, and limited visibility of third-party risks. Data collected by the FCA since 2018 showed that only 2–2.5% of regulated firms reported operational incidents, with over 20% of those reports submitted more than 11 days after the incident began, indicating significant under-reporting and slow regulatory response. The FCA’s objective is to strengthen consumer protection, market integrity, and the overall resilience of the UK financial system by introducing clear definitions, structured templates, and expanded specific requirements for operational incident and third-party arrangement reporting.

SCOPE

The new rules on operational incident reporting will apply to all firms with a Part 4A permission from the FCA or PRA, as well as PSPs, UK recognised investment exchanges (RIEs), registered trade repositories and registered credit rating agencies. The new rules on reporting third-party arrangements will apply to a much narrower group comprising enhanced scope SMCR firm[2] banks, designated investment firms, building societies, Solvency II firms, CASS large firms, authorised electronic money institutions, authorised payment institutions, UK RIEs, and consolidated tape providers.

OPERATIONAL INCIDENT REPORTING

A harmonized definition of “operational incident” will apply across the FCA, PRA, and Bank of England, as follows “either a single event or a series of linked events which disrupts the firm’s operations such that it (a) disrupts the delivery of a service to an end user external to the firm or (b) impacts the availability, authenticity, integrity or confidentiality of information or data relating or belonging to such an end user.” 

Given these aspects, firms will need to consider whether the same circumstances also constitute a (1) “personal data breach” that is reportable under the UK General Data Protection Regulation (UK GDPR) to the Information Commissioners’ Office (ICO), and if applicable, under the EU General Data Protection Regulation (EU GDPR) to supervisory authorities in the European Economic Area (EEA); (2) “major ICT incident” that is reportable (if applicable) under DORA; and/or (3) reportable compromise of “inside information” under EU Market Abuse Rules (MAR).

Incidents become reportable by firms if they consider one or more of the following thresholds, is or may be met, namely, that the incident poses a risk

  • of causing intolerable harm to consumers from which consumers cannot easily recover;
  • to the safety and soundness of the firm and/or other market participants; or
  • to market stability, market integrity, or confidence in the UK financial system.

Notably, the trigger for an “operational incident” under these rules is less prescriptive relative to (for example) when a “major ICT Incident” is deemed to have occurred under DORA. The latter involves a more complex multi-pronged test dependent on (among other factors) whether the incident has affected a financial entity’s “critical services.”    

The FCA considers the thresholds “set a high bar for reporting generally.” Potential or crystallized events (e.g., “near-misses”) are not reportable under the new rules. However, firms may be obliged to report “near misses” under general reporting requirements under Principle 11 and SUP 15.3. 

Firms are divided into “standard” and “enhanced” reporting cohorts. About 90% of firms fall under standard reporting, which requires submission of a single short form with 10 required questions. Enhanced reporting for strategically important firms[3] entails dynamic reporting throughout the incident lifecycle—initial, intermediate, and final reports. Standard reporting requires submission of a single report providing basic information about an operational incident.

Under both standard and enhanced reporting, the report (or, in the enhanced reporting context, the initial report) must be made as soon as practicable subject to the FCA’s guidance that it expects the submission to be made to them at least within 24 hours of the firm determining that an incident meets any of their thresholds. Notifications must be made via the FCA’s Connect platform.

THIRD-PARTY ARRANGEMENTS REPORTING

Reporting obligations will extend beyond material outsourcing to cover all material third-party arrangements, including non-outsourcing agreements. A “third party arrangement” is an arrangement of any form between a firm and a person who provides a product or service to the firm, whether or not the product or service is:

  • one which would otherwise be provided by the firm itself;
  • provided directly or by a sub-contractor; or
  • provided by a person within the same group as the firm.”

The arrangement will be classified as “material” where it is of such importance that a disruption or failure in the performance of the product or service provided to the firm could: (a) cause intolerable levels of harm to the firm’s clients; (b) pose a risk to the UK financial system; or (c) cast serious doubt on the firm’s ability to satisfy the threshold conditions or meet its regulatory obligations.

Firms must (a) notify the FCA upon entering into or significantly changing material third-party arrangements using prescribed templates and (b) maintain a register of all such arrangements submitted annually to the FCA via FCA RegData. The FCA expects firms to notify it at an early stage and before making any internal or external commitments. 

Notifications of new or amended arrangements are to be made through FCA Connect. Exclusions apply for statutory audit functions, basic utilities (except telecoms and data storage), and third country branches (for notifications, but not the annual register). Intra-group reporting is limited to arrangements with external dependencies, except for UK RIEs.  Firms must provide detailed information on service types, supply chain ranking, risk and due diligence assessments, and more.

RECOMMENDATIONS

Covered firms must comply by 18 March 2027, 12 months after the final rules were published. Importantly, however, while a firm’s incident-related policies and procedures relating to DORA, the EU GDPR, and the UK GDPR may be relevant to compliance with the FCA’s incident reporting requirements, these are unlikely to, in and of themselves, fully reflect the latter. That is, firms will need to actively consider the FCA’s incident reporting requirements even if they have previously considered parallel requirements under DORA, the EU GDPR, the UK GDPR and/or MAR.

Therefore, we suggest the following:

  • Firms should conduct a comprehensive review of their operational incident detection, escalation, and reporting processes to ensure they meet the new, lower reporting thresholds and structured template requirements, and integrate these into any existing DORA, EU GDPR, UK GDPR and/or MAR-related policies and procedures (including incident response plans (IRPs)).
  • Firms should update third-party risk management frameworks to include both outsourcing and non-outsourcing material arrangements to capture the expanded scope of reporting, and in turn appropriately update the firm’s policies and procedures, including IRPs. Maintaining the required annual register and collecting detailed supply chain and risk information may require investment in new systems or upgrades to existing tools.
  • Firms should regularly conduct realistic customised “tabletop exercises” (which should include senior firm leadership, legal advisors, and information technology staff) to test and validate their IRPs relative to the FCA’s requirements, and any companion requirements under DORA, the EU GDPR, the UK GDPR and/or MAR.

Affected firms are encouraged to begin internal gap analyses and consult with industry groups ahead of the March 2027 compliance deadline, as well as to submit feedback to the FCA should any practical challenges or uncertainties arise during implementation. Given the regime’s international alignment, multinational organizations should review and harmonize their cross-border reporting obligations to streamline compliance and avoid duplication.

Contacts

If you have any questions or would like more information on the issues discussed in this LawFlash, please contact any of the following:

Authors
William Yonge (London)
Vishnu Shankar (London / Brussels)

[1] Except for PSPs

[2] The enhanced scope category of SMCR firms only applies to a small number of firms whose size, complexity, and potential impact on consumers or markets warrant correspondingly higher accountability standards. Only c. 550 firms are currently categorised as enhanced, c. 1% of all SMCR firms. Many of these have opted-in to enhanced status for various reasons, rather than being caught by the thresholds.

[3] Firms subject to enhanced reporting comprise enhanced scope SMCR firms, banks, designated investment firms, building societies, Solvency II firms, CASS large firms, PSPs, UK RIEs, registered trade repositories and registered credit rating agencies.