as at 28 Jul 2026
UK 10Y Gilt5.10%−7 bp
UK 20Y Gilt5.77%−6 bp
SONIA3.7307%
BoE Rate3.75%
GBP/EUR1.1693−0.15%
GBP/USD1.3317−0.05%
FTSE 10010,828.88+0.44%
BPA YTD~£18bn
Insurance Asset News
Regulation & Policy

PRA operational resilience deadline takes effect March 2025

By IAN Editorial Desk
31 March 2025·Updated 24 May 2026·5 min read

The FCA operational resilience transition period ends on 31 March, bringing into full effect the joint PRA–FCA regime that requires firms to prove they can run important business services within defined impact tolerances during severe disruption. The rules apply to PRA‑regulated banks and insurers under Supervisory Statement SS1/21 and to FCA‑regulated firms under Policy Statement PS21/3 on building operational resilience.

From mapping to full operationalisation

The regime has run on a staged timetable since an initial milestone on 31 March, when financial firms were required to identify their critical business services, map the dependencies that support them, and set impact tolerances for each service. For plans to be effective, firms were required to have started putting those plans into effect by the same 31 March 2022 date, ahead of the end of the transition period.

By the 31 March deadline, firms must have fully operationalised their resilience strategies and be able to demonstrate that they can continue delivering critical business services within the impact tolerances they have set. From that date, in‑scope firms must be able to operate their important business services consistently within those tolerances in the event of a severe disruption, rather than only on a best‑efforts basis.

The main FCA requirements are set out in Policy Statement PS21/3, which established the operational resilience framework and expectations on identifying important business services, setting tolerances and testing. PRA‑authorised banks, insurers and other firms are also subject to Supervisory Statement SS1/21, which focuses on impact tolerances for important business services and how those tolerances should be used in supervision.

Supervisory expectations on testing and remediation

The FCA has set out detailed expectations for how firms close vulnerabilities identified through their mapping and scenario testing. It expects remediation plans to be approved, fully funded and appropriately governed to ensure delivery, with closure evidenced through repeated scenario tests that verify the relevant vulnerability has been resolved. The FCA has stated that the operational resilience policy transition period ends on 31 March, reinforcing that from that date it will supervise against the fully implemented standards rather than transitional expectations.

Advisers have noted that the requirement to be operationally resilient after 31 March is not a “once and done” activity or a matter of “tick‑box regulatory compliance”, but an ongoing obligation that will be tested and revisited over time. Legal and consulting commentary has also stressed that operational resilience should be fully integrated into strategic planning and not treated merely as a compliance obligation.

PRA focus on sector‑wide resilience and governance

The PRA has stated that its policy objective for operational resilience is to improve the resilience of both individual firms and the wider financial sector to operational disruptions, rather than focusing only on firm‑specific outcomes. In its 2025 supervisory priorities, the PRA emphasised the need to ensure that operational resilience is a key board consideration on any business expansion, linking resilience explicitly to growth decisions.

For international groups operating through UK branches, the PRA has reiterated that UK branches should ensure they deliver “similar outcomes” on operational resilience to those required of UK‑incorporated banks. The PRA has also indicated that it intends, together with the FCA, to start consulting in the second half of 2025 on policy relating to the management of information and communication technology and cyber risks, extending the resilience agenda into more detailed technology‑risk requirements.

Enforcement tools and potential restrictions

Both the PRA and FCA have a range of enforcement tools available where firms fall short of the operational resilience standards that apply from 31 March. They can impose regulatory fines on firms that fail to meet resilience standards, and past penalties for related failings have ranged from hundreds of thousands to millions of pounds depending on the severity of the breach. Legal and technology providers have warned that these sanctions sit alongside the requirement that, after 31 March, maintaining operational resilience must be a dynamic activity rather than a one‑time compliance exercise.

Culture, strategy and ongoing supervision

Law firms and consultants have reported that regulators expect operational resilience to be embedded into firm culture, rather than treated as a discrete regulatory project that ends with the transition deadline. Commentary has also stated that it is crucial for operational resilience to be fully integrated into strategic planning, including decisions on outsourcing, technology investment and new product launches.

The PRA’s 2025 supervisory communication stated that operational resilience should be a key board consideration on any business expansion, indicating that supervisors will look at how resilience is factored into growth and restructuring plans. For UK branches, the PRA’s expectation that they deliver similar outcomes to UK‑incorporated banks on operational resilience means international groups will need to align branch arrangements with home‑state frameworks while meeting local standards.

The FCA has said that governing bodies must approve and regularly review operational resilience self‑assessments, which are expected to evolve as firms refine their mapping, testing and remediation. The FCA has also set out that remediation plans should be fully funded and governed, with closure evidenced through repeated scenario tests, indicating that supervisors will look for a documented testing trail over time.

From the end of the transition period on 31 March 2025, firms that have identified vulnerabilities but not completed remediation may face closer supervisory scrutiny, with the possibility of fines or operational restrictions where standards are not met. At the same time, the planned joint consultation in the second half of 2025 on information and communication technology and cyber risks is expected to add a further layer of policy detail to the existing operational resilience framework.

The next formal step will be the end‑March 2025 transition deadline, after which the PRA and FCA will supervise against fully implemented resilience standards while beginning work on the forthcoming technology and cyber risk policy consultation in the second half of the year.

--- Sources: https://www.bankofengland.co.uk/prudential-regulation https://www.fca.org.uk/firms/operational-resilience/insights-observations https://www.sidley.com/en/insights/newsupdates/2025/01/uk-operational-resilience-rules-are-you-ready-for-31-march-2025