Operational Resilience

FCA Operational Incident Reporting 2027: New Rules and Implementation

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 8 min read

The FCA's new operational incident reporting rules take effect on 18 March 2027. They introduce a standardised reporting framework for incidents that meet specified thresholds and will apply to almost all FCA-regulated firms, alongside the related PRA and Bank of England regime where relevant.

The FCA gives practical examples of the events that can become reportable, including cyber attacks, failed system changes and disruption at third parties. The new framework is intended to make the threshold and reporting process clearer, but it does not remove the need for firms to make fast judgement under pressure.

The main implementation task is therefore not the Connect form. It is building an incident process that can identify a potentially reportable event, collect the right information, make a threshold decision, coordinate other regulatory notifications and preserve an audit trail from first alert to final resolution.

The current regime remains in force until 18 March 2027

Until the new framework starts, firms subject to Principle 11 should continue to disclose matters of which the FCA would reasonably expect notice, with SUP 15.3 providing additional rules and guidance. Payment service providers also need to consider the current Payment Services Regulations and SUP 15.14 incident-reporting framework during the transition.

The FCA's current incident page gives indicators of materiality such as material disruption to financial services, impact on a large number of customers, unauthorised access to information systems, significant loss of data and unavailability or loss of control of IT systems.

Firms should therefore run two clearly dated procedures during implementation: the current notification route and the new PS26/2 route that activates on 18 March 2027. Testing the future form should not accidentally displace today's obligations.

The new thresholds focus on regulatory impact

From March 2027, the standardised framework requires reporting where an operational incident meets one or more thresholds by posing a risk of intolerable consumer harm from which consumers cannot easily recover, risk to the safety and soundness of the firm or other market participants, or risk to market stability, integrity or confidence in the UK financial system.

That is a risk-based test rather than a simple outage-duration trigger. A short incident can be significant if it exposes sensitive customer data or prevents a critical transaction, while a longer disruption in a low-impact internal service may not meet the same regulatory threshold.

Firms should translate the regulatory tests into decision guidance using their real services, customer populations and incident history. The internal framework should support judgement rather than create a mechanical score that staff treat as legally determinative.

Incident classification should be consistent across technology and business teams

Technology teams often classify incidents by severity using availability, cybersecurity or service-management criteria. Those classifications are useful but do not necessarily answer the FCA reporting test.

The regulatory process should therefore map internal severity to customer and market impact. An incident initially labelled medium by IT may become a regulatory priority if it affects vulnerable customers or prevents access to a time-critical financial service. Conversely, a high-priority technical issue may be contained before it creates a reportable regulatory impact.

A common taxonomy should identify service affected, start time, customer impact, data impact, third-party involvement, business-service mapping and recovery status. Compliance or regulatory affairs can then make the reporting assessment using facts that operational teams already collect.

Standard and enhanced reporting need different operating plans

The FCA says most solo-regulated firms will submit a short standard report. A smaller subset of enhanced reporting firms will need to provide more information where there are significant changes in incident status and to finalise their report after the incident is resolved.

Firms should establish which category applies before March 2027 and use the FCA's published templates to understand the data fields. Waiting for the first live incident to discover that the business cannot produce a required field creates avoidable delay.

Enhanced reporters in particular should plan for an incident that evolves over several days. Ownership of updates, evidence of significant status changes and the point at which a final report can be completed should be clear in the incident playbook.

Connect reporting should be integrated with the incident command process

The new framework uses a single form through Connect regardless of which participating regulator the report is for. That simplifies submission, but the firm still needs an internal route from incident command to regulatory filing.

The incident lead should know who has authority to submit, who approves the regulatory description and how the firm will obtain the facts needed while technical recovery is still underway. Reporting should not depend on one compliance employee being available at the exact moment an incident occurs.

The final narrative should distinguish facts, estimates and unresolved questions. The objective is timely and accurate reporting, not delaying until every root-cause issue is known. The FCA's finalised guidance and reporting template should be built into the firm's procedure before go-live.

Third-party incidents remain the firm's reporting problem

A material operational incident can originate at a cloud provider, payments processor, software vendor or other third party. The FCA specifically identifies third-party disruption as a potential incident source.

Contracts and escalation routes should therefore enable the regulated firm to obtain enough information quickly to assess its own regulatory threshold. A supplier's internal severity rating or contractual service level does not determine whether the firm's FCA reporting obligation has been triggered.

The incident framework should identify concentration where several services depend on the same provider. One external outage can affect multiple business services and customer groups at the same time, making aggregate impact more important than any individual service ticket.

Other authority notifications should be coordinated, not assumed to be identical

An operational incident can trigger several notification regimes. The FCA's current guidance points firms to potential reporting to the PRA, the National Cyber Security Centre, law-enforcement channels and the Information Commissioner's Office depending on the facts.

The legal triggers and deadlines are not identical. A data breach can require an ICO assessment, while a cyber incident can raise separate NCSC or criminal-reporting considerations. One Connect submission should not be assumed to satisfy every external obligation.

The incident playbook should therefore contain a notification matrix showing the relevant regulators and authorities, decision owner and legal trigger. Facts and figures should be coordinated so different bodies do not receive inconsistent descriptions of the same incident.

Evidence should be captured while the incident is live

Post-incident reconstruction is difficult where key decisions were made through calls and instant messages that were not retained. The firm should maintain an incident log recording material events, customer impact assessments, reporting decisions, regulator contact and recovery milestones.

This does not require every technical message to become a regulatory record. The objective is to preserve the decisions that explain when management knew the incident might be material, how thresholds were assessed and why a report was or was not made.

If facts change, the record should show the change rather than overwrite the original assessment. This becomes particularly important for enhanced reporting and for any later FCA review of notification timeliness.

Tabletop testing should include the regulatory decision, not only recovery

Many firms already test cyber recovery and operational resilience. The 2027 regime makes it useful to add the regulatory-reporting decision to those scenarios.

A test can simulate a third-party outage, data loss or failed release and require the team to determine whether the FCA threshold is met, identify the report type, populate the form and coordinate other authorities. The exercise should reveal missing data, unclear ownership and approval bottlenecks.

The scenario should also test ambiguity. Real incidents rarely arrive with a clear label saying they are material, so a useful exercise changes the facts over time and asks the firm to reassess as customer impact becomes clearer.

What firms should complete before March 2027

Firms should confirm scope and reporting category, map the new thresholds to their incident taxonomy, review the FCA templates, define submission authority, connect third-party escalation, build the multi-regulator notification matrix and run at least one end-to-end dry exercise.

The implementation should also align with material third-party reporting and operational-resilience records. The same provider, service and customer-impact data should not be maintained differently across three compliance frameworks without a clear reason.

The target is a process that works at 2am during a live incident, not merely a policy that accurately describes PS26/2 during normal office hours.

How Regulatory Counsel can support

Regulatory Counsel supports FCA-regulated firms with the regulatory, governance and remediation issues covered in this article. We can review the existing framework, identify gaps and support practical implementation or independent assurance.

Speak to Regulatory Counsel to discuss this area.

Frequently Asked Questions

The new framework comes into force on 18 March 2027.

Yes. The current Principle 11 and SUP 15 framework continues until the new rules take effect, together with sector-specific obligations such as the current payment-services incident regime where applicable.

Examples include cyber attacks, failed system changes and third-party disruption. Under the new rules the firm must assess the incident against the FCA impact thresholds.

Most FCA solo-regulated firms will use a standard report, while a smaller subset of enhanced reporters must provide additional updates and finalisation information.

The FCA says the new framework will use a single form through Connect.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert