3 minute read
The PRA and FCA Mean Business: What the 2026/27 Business Plans Signal for Operational Resilience
The PRA’s 2026/27 Business Plan is out. Read alongside the FCA’s Business Plan published a few weeks earlier, the regulatory direction is clear and consistent: building a resilience framework is no longer the benchmark. Demonstrating that it works under pressure is.
This article summarises the four areas firms in financial services should be acting on now, and what each means in practice.
1. Prepare for Active Scrutiny
The PRA has signalled a step up in supervisory intensity. It will conduct active assessments of firms’ cyber and operational resilience capabilities, with a specific focus on response and recovery from severe but plausible disruptions. CBEST assessments continue, in close coordination with the NCSC.
This is not a documentation review. Supervisors will be looking for evidence that self-assessments reflect operational reality, that testing is genuine, and that boards are sighted on gaps.
What this means in practice: Review your operational resilience self-assessment for accuracy. Stress test your assumptions. Ensure your board can speak to the outcomes, not just the process.
2. Map and Test Your Third-Party Dependencies
Third-party risk is the dominant theme of this year’s plan. The PRA will assess how firms have implemented SS2/21 on outsourcing and third-party risk management, and the joint PRA-industry exercise, SIMEX26, will simulate an extended outage at a major third-party technology provider.
The scenario is deliberate. Concentration risk in cloud, payments, and data infrastructure is a known systemic vulnerability, and regulators want to see whether firms can actually respond when a critical provider goes down, not just whether they have a contract in place.
What this means in practice: Map your material third-party dependencies against your important business services. Identify single points of failure. Include third parties in your scenario testing, not just internal processes.
3. Understand Where the Cyber Security and Resilience Bill Sits Relative to DORA
The PRA and FCA are working with HMT and DSIT on the Cyber Security and Resilience (NIS) Bill currently before Parliament. For firms operating across the UK and EU, the interaction between this legislation and EU DORA is a practical compliance question that needs an answer now, not when the Bill receives Royal Assent.
The two regimes share objectives but differ in scope, thresholds, and reporting obligations. Firms that assume alignment without checking are taking a risk.
What this means in practice: Conduct a gap analysis between your current DORA obligations (if applicable) and the emerging UK regime. Flag divergences early. Build flexibility into your incident reporting workflows so they can satisfy both.
4. The March 2027 Deadline Is Closer Than It Looks
In March 2026, the PRA and FCA published final policy on operational incident and third-party reporting. The new rules come into force in March 2027, giving firms 12 months to prepare.
That sounds manageable. It is not, once you factor in gap analysis against the new thresholds, system configuration for incident capture and reporting, third-party notification workflows, and testing before go-live. Firms that start in Q1 2027 will be behind.
What this means in practice: Review the final rules in PS7/26 (PRA) and PS26/2 (FCA). Identify what your current incident management capability captures versus what will be required. Build a 12-month implementation plan with realistic milestones.
The Bottom Line
Compliance got firms to the starting line. The 2026/27 supervisory agenda is about what happens when things actually go wrong. Firms that have invested in genuine testing, mapped dependencies, and evidence-based reporting will be in a materially stronger position than those still treating resilience as a documentation exercise.
If this has you re‑thinking your own resilience programme, don’t wait for the next review cycle. Reach out to Battleground and we’ll help you pressure‑test where you stand and what to fix first.











