UK operational resilience requirements
The UK framework asks firms to identify their important business services, set tolerances for how much disruption is acceptable, and show they can stay within them — including where services depend on third parties.
REGREP is an independent software provider. This page explains the framework in plain language and is not legal or regulatory advice — confirm your obligations against the FCA and PRA rules that apply to you.
- Instrument
- FCA and PRA operational resilience requirements
- Scope
- FCA and PRA regulated firms in scope of the regime
- Reporting artefacts
- Self-assessment · third-party records
- Format
- Firm records produced on supervisory request
- Supervisor
- FCA · PRA · Bank of England
- Penalties
- Supervisory and enforcement powers for firms unable to evidence resilience
What UK Operational Resilience asks of you
The short version: what the framework requires, who it applies to and when it bites.
What it requires
Firms identify important business services, set impact tolerances, map the people, processes, technology and third parties each service depends on, and test against severe but plausible scenarios.
Who it applies to
Banks, building societies, insurers, investment firms and payment businesses within the scope the FCA and PRA set.
When it applies
On an ongoing basis. Firms maintain and periodically review the self-assessment, and evidence it to supervisors on request rather than filing a scheduled return.
What has to be done
Supervisory consequences follow from the FCA and PRA rulebooks giving effect to the operational resilience framework.
| Obligation | What it means in practice |
|---|---|
| Identify important business services | Determine which services, if disrupted, would cause intolerable harm to consumers or risk to market integrity. |
| Set impact tolerances | Set a maximum tolerable level of disruption for each important business service and justify it. |
| Map dependencies | Map the resources each service relies on, including the third parties and the chain behind them. |
| Test and remediate | Test against severe but plausible scenarios, and act on what the testing shows. |
| Document the self-assessment | Maintain a written self-assessment that can be produced to supervisors and kept current as the business changes. |
From your data to a validated filing
Activate only the module the obligation needs. Every price covers one regulated entity unless stated otherwise, and excludes VAT.
Register of Information (DORA)
Firms operating on both sides of the Channel commonly maintain one inventory of ICT third-party arrangements. The DORA module builds, validates and exports that register in the EU supervisory format.
€1,000/yearUp to 50 ICT arrangements · 1 regulated entity Create free account →Scoped resilience work
REGREP has no self-serve UK operational resilience module. Where the underlying third-party and dependency data needs structuring, we scope it as an engagement.
Talk to usScoped to your service and dependency model Talk to usRelated to UK Operational Resilience
DORA
The EU counterpart framework, with a prescribed Register of Information and a defined supervisory format.
Read the requirements →Operational resilience guide
Plain-language explainers on the UK and EU resilience regimes and where they overlap.
Read the guide →Group and multi-entity reporting
How groups with UK and EU entities keep one dependency inventory across both regimes.
Read use case →Questions, answered
Is there a UK equivalent of the DORA register?
Does REGREP have a UK operational resilience module?
How do the UK and EU regimes overlap?
Do I file anything on a schedule?
One dependency inventory, both regimes.
Talk to us about structuring your third-party data, or start with the DORA register module.