Regulations · Operational resilience

UK operational resilience requirements

The UK framework asks firms to identify their important business services, set tolerances for how much disruption is acceptable, and show they can stay within them — including where services depend on third parties.

REGREP is an independent software provider. This page explains the framework in plain language and is not legal or regulatory advice — confirm your obligations against the FCA and PRA rules that apply to you.

Framework factsUK
Instrument
FCA and PRA operational resilience requirements
Scope
FCA and PRA regulated firms in scope of the regime
Reporting artefacts
Self-assessment · third-party records
Format
Firm records produced on supervisory request
Supervisor
FCA · PRA · Bank of England
Penalties
Supervisory and enforcement powers for firms unable to evidence resilience
In plain language

What UK Operational Resilience asks of you

The short version: what the framework requires, who it applies to and when it bites.

What it requires

Firms identify important business services, set impact tolerances, map the people, processes, technology and third parties each service depends on, and test against severe but plausible scenarios.

Who it applies to

Banks, building societies, insurers, investment firms and payment businesses within the scope the FCA and PRA set.

When it applies

On an ongoing basis. Firms maintain and periodically review the self-assessment, and evidence it to supervisors on request rather than filing a scheduled return.

Obligations

What has to be done

Supervisory consequences follow from the FCA and PRA rulebooks giving effect to the operational resilience framework.

ObligationWhat it means in practice
Identify important business servicesDetermine which services, if disrupted, would cause intolerable harm to consumers or risk to market integrity.
Set impact tolerancesSet a maximum tolerable level of disruption for each important business service and justify it.
Map dependenciesMap the resources each service relies on, including the third parties and the chain behind them.
Test and remediateTest against severe but plausible scenarios, and act on what the testing shows.
Document the self-assessmentMaintain a written self-assessment that can be produced to supervisors and kept current as the business changes.
How REGREP automates it

From your data to a validated filing

Activate only the module the obligation needs. Every price covers one regulated entity unless stated otherwise, and excludes VAT.

Adjacent capability

Register of Information (DORA)

Firms operating on both sides of the Channel commonly maintain one inventory of ICT third-party arrangements. The DORA module builds, validates and exports that register in the EU supervisory format.

€1,000/yearUp to 50 ICT arrangements · 1 regulated entity Create free account
Solution Layers

Scoped resilience work

REGREP has no self-serve UK operational resilience module. Where the underlying third-party and dependency data needs structuring, we scope it as an engagement.

Talk to usScoped to your service and dependency model Talk to us
Keep reading

Related to UK Operational Resilience

Regulation

DORA

The EU counterpart framework, with a prescribed Register of Information and a defined supervisory format.

Read the requirements
Guide

Operational resilience guide

Plain-language explainers on the UK and EU resilience regimes and where they overlap.

Read the guide
Use case

Group and multi-entity reporting

How groups with UK and EU entities keep one dependency inventory across both regimes.

Read use case
FAQ

Questions, answered

Is there a UK equivalent of the DORA register?
Not in the same prescribed form. The UK framework requires firms to map dependencies, including third parties, and evidence that mapping — but it does not mandate a single supervisory register file the way DORA does.
Does REGREP have a UK operational resilience module?
No. There is no self-serve module for this framework. Firms that also fall under DORA commonly use the Register of Information module for the ICT third-party inventory, and anything beyond that is scoped as an engagement.
How do the UK and EU regimes overlap?
Both push firms towards knowing which services matter, what they depend on and which third parties sit underneath. The artefacts differ: the UK expects a maintained self-assessment, while DORA expects a register in a defined supervisory format.
Do I file anything on a schedule?
The framework is built around maintained records and evidence on supervisory request rather than a periodic return. Confirm what your supervisor expects of your firm and when.

One dependency inventory, both regimes.

Talk to us about structuring your third-party data, or start with the DORA register module.