FCA, PRA And Bank of England Seek To Turn Resilience From Compliance To Governance-Led For Financial Market Infrastructures
From March 18, 2027, UK firms will be required to report operational incidents within 24 hours of determining that a materiality threshold has been met, while the limit for payment providers will be four hours. Introduced under a single operational incident and third-party reporting framework by the Financial Conduct Authority (FCA), Prudential Regulation Authority (PRA) and Bank of England (BoE), the new reporting regime aims to address growing third-party risk management (TPRM) and operational resilience concerns. Organizations in scope now have six months to improve their incident identification and remediation processes as the new requirements will force them to tackle the root cause of incidents by building stronger risk identification, third-party monitoring, incident management and reporting capabilities.
Operational disruptions are rising, yet most incidents go unreported
Growing geopolitical uncertainty, deteriorating macroeconomic conditions, and declining visibility into third-party practices and technology have all contributed to significant operational disruption in 2026. For instance, in early September, UK airports broke out into chaos after more than 1,000 flights were cancelled across the nation due to a technical issue from third-party air traffic control servicer provider NATS. Although this happened in aviation, it shows the risk the framework is designed to address: a single third-party failure cascading into widespread disruption. The same scenario could hit a payment provider or financial institution, leaving customers unable to complete transactions. The most alarming aspect is that when incidents like this do occur, stakeholders and regulators hear about them late, if at all. FCA data show that only 2% to 2.5% of firms report their operational incidents, and more than a fifth of those reports come after 11 days of the incident initiating.
Without visibility into these incidents, remediation and post-event assessments such as root cause analysis are not possible. At the end of 2025, a report from VikingCloud found that 48% of cybersecurity leaders admitted to not reporting material cyber incidents to their boards in the past year. Missing reporting procedures and incident management strategies both play a role here, which explains why only 46% of CISOs show high confidence in their ability to manage a major cyber incident without external escalation (see Verdantix Global Corporate Survey 2026: CISO Priorities, Pressures And Preparedness). In the face of this reluctance to be transparent, regulations offer a powerful tool to enforce step-by-step reporting and deeper governance. The introduction of tougher requirements will force organizations to explore the root cause of their perceived lack of capability, prompting the introduction of robust risk identification, third party monitoring and incident reporting capabilities.
Firms must revisit their incident reporting procedures to stay compliant after March 2027
Moving forwards, firms should start preparing for compliance by setting up an internal governance and reporting committee. From there, the regulators' definition of an incident should be mapped against existing regulations like DORA, so that there is one consistent response in the event of an incident. Scenario testing can also help teams practise threshold judgements ahead of a real crisis (see Verdantix If The Latest Crisis In The Middle East Does Not Convince You Of The Importance Of Scenario Modelling, Nothing Will), and third-party registers should now be clearly labelled and organized according to dependency levels. Organizations should also consider mapping and monitoring their nth parties – which are widening firms' exposure to cybersecurity threats and vulnerabilities.
For more risk management insights, check out our enterprise risk and resilience research.
About The Author

Mahum Khawar
Analyst



