The New Operational Incident Reporting Regime: What Firms Need to Do
CyberKainos. Reading time: 6 mins
The UK Operational Incident Reporting Regime
There is a date that every operational resilience, compliance, and risk team in UK financial services needs to have in their calendar: 18 March 2027.
That is when the FCA and PRA’s new framework for reporting serious operational incidents and material third-party arrangements comes into force. This represents the most significant overhaul of operational incident reporting in the UK in years. They introduce a unified reporting framework, stricter timelines, a new two-tier reporting structure, and a comprehensive new regime for notifying regulators of material third-party arrangements.
This all comes into force in a little over 6 months’ time. The breadth of changes required across incident management processes, escalation frameworks, third-party governance, cross-functional coordination, and annual reporting means that firms which delay preparation until 2027 will find themselves scrambling. The time to start is now.
What the New Framework Does
The new regime was developed jointly by the FCA, PRA, and Bank of England with two explicit aims: to give regulators better visibility of operational disruption and third-party dependencies, and to support a more data-driven approach to supervision. In practical terms, it replaces a patchwork of existing reporting obligations with a single, harmonised UK framework with one submission route, one template, and one definition of an operational incident.
Dual-regulated firms will make a single submission via FCA Connect which will be shared across regulators. This is designed to reduce duplication and improve consistency. It also means there is no longer any room for different parts of a firm to interpret reporting obligations differently depending on which regulator they primarily interact with.
The framework sits alongside, and complements, existing operational resilience requirements. Critically, it extends beyond important business services. Incidents that fall outside a firm’s IBS framework may still be reportable under the new rules. Data loss incidents and failed planned changes that cause unintended disruption are both explicitly in scope. The regime is deliberately broader than what many firms currently report, and internal definitions will need to be recalibrated accordingly.
What Counts as a Reportable Incident
The new definition of an operational incident is intentionally wide. It covers any single event, or series of linked events, that disrupts the firm’s operations such that it disrupts delivery of a service to an external end user, or affects the availability, integrity, authenticity, or confidentiality of information relating to such an end user.
End users are defined broadly: retail and business customers, market participants, supervisory regulators, and members of the firm’s own group all fall within scope. Reportability is not restricted to incidents affecting an important business service.
There are two important exclusions: near misses, and planned interruptions that proceed as intended. However, if a planned change does not end up going to plan, and the resulting disruption meets the reporting threshold, the incident becomes reportable. In practice, this means change management and incident management processes need to be closely joined.
The PRA and FCA have adopted broadly aligned but not identical reporting thresholds, which creates a specific challenge for dual-regulated firms. The PRA requires reporting where an incident poses a risk to financial system stability, the safety and soundness of the firm, or policyholder protection. The FCA requires reporting where there is a reasonable belief that an incident poses a risk of intolerable consumer harm, safety and soundness risk to the firm or market participants, or a threat to market stability or confidence. An incident may meet one threshold but not the other, requiring independent assessment against each set of criteria. Firms that apply a single internal threshold across the board will find it does not consistently satisfy both regulators.
Standard vs Enhanced Reporting: Know Which Applies to You
One of the most important early tasks for any firm is confirming which tier of the new reporting regime applies to them.
Standard reporting will apply to most FCA-authorised firms. It requires a single report providing basic information about a reportable operational incident. There is no obligation to update the submission, although the FCA may follow up depending on severity or the quality of information provided.
Enhanced reporting applies to a defined category of organisations, broadly those with assets under management of £50 billion or more on a three-year rolling average plus payment service providers. Enhanced reporting firms must submit a more detailed report in phases across the lifecycle of an incident: an initial report, intermediate updates after each significant change in circumstances, and a final report within 30 working days of resolution.
The Third-Party Reporting Dimension
The incident reporting framework is only half the picture. The new regime also introduces significant new requirements for material third-party arrangements. This is where many firms will find the greatest operational challenge.
The definition of a material third-party arrangement is deliberately broad. It covers any arrangement under which a third party provides a product or service to the firm. The FCA’s guidance gives practical examples of what will typically be material: cloud and data centre services, cyber services, and services that underpin important business services. Legal services, consultancy, utilities, and office supplies are generally not expected to be material.
In addition, in-scope firms must maintain and submit an annual register of material third-party arrangements. Regulators will use this data to identify systemic dependencies, monitor concentration risk, and inform potential designations under the Critical Third Party regime. The register requirement will be new for most firms, and the data collection and validation infrastructure needed to produce it reliably needs to be built well before the March 2027 deadline.
Six Things Firms Should Be Doing Right Now
The implementation period is well underway. Firms that are not yet actively preparing should treat the following as immediate priorities.
Confirm your scope. Are you a standard or enhanced reporting firm? Do you fall within the third-party notification and register requirements? These are not complex questions, but they need to be answered formally, with sign-off, so that implementation planning is built on a correct foundation
Conduct a gap analysis. Map your current incident reporting processes, escalation frameworks, outsourcing and third-party governance arrangements, and operational resilience documentation against the new requirements. Identify where the gaps are largest and prioritise accordingly.
Recalibrate your incident definitions. Internal incident classifications, triage criteria, and escalation triggers need to be aligned with the new regulatory definitions and thresholds of both the FCA and PRA where applicable. Where existing definitions are narrower than the new framework, the gap is a compliance risk from day one of implementation.
Build your reporting capability. The 24-hour initial reporting obligation (four hours for PSPs) is not achievable without a functioning, joined-up detection-to-reporting process. That means detection tools, triage processes, threshold assessment frameworks, and reporting templates all need to be in place and tested before March 2027.
Review and restructure third-party governance. Identify your material third-party arrangements under the new definition which will likely be broader than your current outsourcing register. Establish the governance structures and procurement processes needed to ensure early-stage notifications are submitted before commitments are finalised. Begin planning the annual register: who owns it, what data it requires, and how it will be maintained.
Leverage existing DORA work where relevant. Firms with EU-based affiliates already working through DORA compliance will find significant overlap in the evidence, processes, and governance structures required. The two frameworks are not identical, but the gap analysis for one can usefully inform the other, and firms should avoid treating them as entirely separate workstreams.
How CyberKainos Can Help
At CyberKainos, we work with financial services firms to navigate exactly this kind of regulatory transition, from initial scoping and gap analysis through to implementation planning, process design, and board-level reporting.
Whether you need help recalibrating your incident definitions against the new FCA and PRA thresholds, building the detection-to-reporting capability your timelines require, restructuring your third-party governance to meet notification and register obligations, or integrating the new framework with your existing DORA and operational resilience work, our team has the regulatory expertise and practical experience to get you there.
18 March 2027 is closer than it looks. The firms that start now will be ready. Visit CyberKainos.com to find out how we can help you build the capability the new regime requires.