FCA PS21/3 Building operational resilience and SYSC 15A Operational resilience

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
PS21/3, Building operational resilience, is the Financial Conduct Authority's policy statement that finalized the UK's operational resilience rules for FCA-regulated firms and introduced chapter SYSC 15A, Operational resilience, into the FCA Handbook. Together they require firms to identify their important business services, set impact tolerances for each, map the resources that deliver them, run scenario tests, and maintain a self-assessment that shows how they meet the rules.
The FCA published PS21/3 on 29 March 2021 following consultation paper CP19/32, in coordination with the Bank of England and the PRA. SYSC 15A came into force on 31 March 2022 and applies to banks, building societies, PRA-designated investment firms, Solvency II insurers, UK recognised investment exchanges, enhanced scope SM&CR firms, payment institutions, electronic money institutions, and registered account information service providers with a UK head office.
Firms implement the rules by agreeing important business services and impact tolerances at senior management level, mapping people, processes, technology, facilities, and information to each service, testing whether they can stay within tolerance under severe but plausible scenarios, and investing to close the gaps. Firms had a transitional period to 31 March 2025 to be able to remain within their impact tolerances, and the self-assessment must be kept current and approved by the governing body.
Why it Matters
SYSC 15A is the enforceable operational resilience rulebook for the widest set of UK financial firms, from banks to payment institutions, and PS21/3 records the FCA's reasoning behind each rule. Together they put customers and market integrity at the center of resilience: what matters is whether an important service can keep running within a tolerable level of disruption.
Key benefits include:
- Customer-focused resilience
Important business services are defined by the harm their disruption would cause to clients and market integrity, not by internal systems.
- Measurable limits
Impact tolerances give each service a maximum tolerable disruption that management can test against.
- End-to-end understanding
Mapping shows the resources and third parties each service depends on, including outsourced and intra-group arrangements.
- Tested, not assumed
Scenario testing against severe but plausible events shows whether tolerances can be met and what to fix.
- One program for dual-regulated firms
The FCA and PRA rules share concepts and timing, and the same work supports the Basel principles, DORA, and ISO 22301.
How it Works
SYSC 15A is organized into nine sections: 15A.1 Application; 15A.2 Operational resilience requirements; 15A.3 Strategies, processes and systems; 15A.4 Mapping; 15A.5 Scenario testing; 15A.6 Self-assessment and lessons learned documentation; 15A.7 Governance; 15A.8 Communications; and 15A.9 Supervisory review and feedback. PS21/3 explains the feedback received on CP19/32 and the FCA's final position on each of these areas.
Firms identify important business services and set an impact tolerance for each, expressed at least as a maximum tolerable duration of disruption; map the people, processes, technology, facilities, and information needed to deliver each service; test their ability to remain within tolerance under severe but plausible scenarios; and document the results and lessons learned in a self-assessment approved by the governing body. The rules came into force on 31 March 2022, and firms had until 31 March 2025 to be able to remain within their impact tolerances. Communications plans cover how the firm will keep clients and other stakeholders informed during a disruption.
Within SmartSuite, teams maintain the important business services register and impact tolerances, link mapped resources and third parties to each service, schedule and record scenario tests, track remediation, and produce the SYSC 15A self-assessment and lessons learned documentation from live records.
Key Elements
- Important business services
Services whose disruption could cause intolerable harm to clients or pose a risk to the soundness, stability, or resilience of the UK financial system or the orderly operation of markets.
- Impact tolerances
A maximum tolerable level of disruption for each important business service, including a duration and, where appropriate, other metrics.
- Strategies, processes, and systems
The arrangements a firm needs so that it can remain within its impact tolerances.
- Mapping
Identification and documentation of the people, processes, technology, facilities, and information required to deliver each important business service.
- Scenario testing
Regular tests of the firm's ability to remain within tolerance under severe but plausible scenarios, with lessons learned recorded.
- Self-assessment and governance
A written self-assessment, reviewed and approved by the governing body, that the FCA can request at any time.
- Communications
Internal and external communication strategies for use during operational disruptions.
Framework Scope
SYSC 15A applies to banks, building societies, PRA-designated investment firms, Solvency II firms, UK recognised investment exchanges, enhanced scope SM&CR firms, electronic money institutions, payment institutions, registered account information service providers, and consolidated tape providers with their registered or head office in the United Kingdom. It covers the important business services those firms provide and the resources and third parties that deliver them; it does not apply to firms whose head office is outside the UK or to the temporary-permission categories the chapter excludes.
Framework Objectives
The FCA's aim is that firms can prevent, adapt to, respond to, recover from, and learn from operational disruptions.
Protect consumers and market integrity by keeping important business services within a tolerable level of disruption.
Make senior management identify and own the services that matter most and the tolerances set for them.
Require firms to understand and document the resources and dependencies behind each service.
Test resilience against severe but plausible scenarios and act on what the tests reveal.
Ensure firms can communicate effectively with clients and stakeholders during a disruption.
Give the FCA a consistent basis for supervisory review across all firm types in scope.
Framework in Context
PS21/3 and SYSC 15A were published on the same day as the PRA's SS1/21 and share its concepts of important business services, impact tolerances, mapping, scenario testing, and self-assessment, so dual-regulated firms run one program against both. The Basel Committee's Principles for Operational Resilience of March 2021 set the international baseline for banks, EU DORA applies a comparable regime to EU financial entities with a focus on ICT, and ISO 22301 provides a business continuity management system that supports the mapping and testing rules.
Common Framework Mappings
FCA PS21/3 and SYSC 15A are commonly mapped to the PRA's parallel policy, the Basel operational resilience principles, EU DORA, ISO 22301, and equivalent prudential regimes so that one resilience program satisfies several supervisors.
Mapped frameworks include:
PRA SS1/21
BCBS Operational Resilience Principles
EU DORA
ISO 22301
APRA CPS 230
- ClassificationCategoryOperational ResilienceDomainOperational ResilienceFramework FamilyOther
- Regulatory ContextTypeRegulationLegal InstrumentHandbook Rules and Policy StatementSectorFinancial SectorIndustryFinancial Services
- Region / PublisherRegionUnited KingdomRegion DetailUnited KingdomPublisherFinancial Conduct Authority (FCA)
- VersioningVersionPS21/3 (March 2021); SYSC 15AEffective DateMarch 31, 2022Issue DateMarch 29, 2021
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
PS21/3 and the FCA Handbook are published free of charge by the Financial Conduct Authority, and the SYSC 15A requirements are included with the platform as a requirement set.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports FCA SYSC 15A
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For FCA SYSC 15A, SmartSuite holds the important business services register, impact tolerances, resource and third-party maps, scenario tests, communications plans, and remediation actions, and generates the self-assessment and lessons learned documentation from live records.
Important Business Services Register
Record each service, the clients and markets it serves, the rationale for its importance, and its impact tolerance.
Ownership, Cadence, and Accountability
Assign service owners, schedule tolerance reviews and annual self-assessment approval, and track governing body sign-off.
Evidence Collection and Audit Trail
Attach mapping outputs, test reports, and approvals with timestamps so each SYSC 15A requirement is evidenced.
Scenario Testing
Plan severe but plausible scenarios, record results against each tolerance, and capture lessons learned per SYSC 15A.6.
Third-Party and Resource Mapping
Link people, processes, technology, facilities, information, and suppliers to the services they support.
Supervisory Reporting
Produce the self-assessment document and dashboards showing tolerance status and remediation progress for the FCA.
Related frameworks

PRA SS1/21 sets the Prudential Regulation Authority's expectations for how UK banks and insurers identify important business services, set impact tolerances, and stay within them.

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

ISO 22301 is a business continuity management standard helping organizations prepare for, respond to, and recover from disruptions.

CPS 230 is an APRA standard requiring banks, insurers, and superannuation funds to manage operational risks and ensure resilience.
Frequently Asked Questions For FCA SYSC 15A
PS21/3 is the FCA's March 2021 policy statement that finalized the UK operational resilience rules for FCA-regulated firms. SYSC 15A is the chapter of the FCA Handbook that contains those rules. PS21/3 explains the reasoning and feedback; SYSC 15A is what firms must comply with.
It applies to banks, building societies, PRA-designated investment firms, Solvency II insurers, UK recognised investment exchanges, enhanced scope SM&CR firms, payment institutions, electronic money institutions, registered account information service providers, and consolidated tape providers with a UK head office. Firms with a head office outside the UK and the temporary-permission categories named in the chapter are excluded.
Firms must identify their important business services, set an impact tolerance for each, map the people, processes, technology, facilities, and information that deliver them, and carry out scenario testing. They must keep a self-assessment and lessons learned documentation approved by the governing body, maintain communications strategies for disruptions, and address vulnerabilities the work reveals.
The rules came into force on 31 March 2022, by which point firms needed important business services, impact tolerances, and initial mapping and testing in place. The transitional period ended on 31 March 2025, by which time firms had to be able to remain within their impact tolerances. Compliance is now an ongoing obligation.
The concepts are the same and the two were published together, but the FCA rules apply to a wider range of firms, including solo-regulated firms such as payment institutions and enhanced scope SM&CR firms. The FCA frames harm in terms of clients and market integrity, while the PRA focuses on safety and soundness, policyholders, and financial stability. Dual-regulated firms must satisfy both.
EU DORA imposes a comparable operational resilience regime on EU financial entities with a strong ICT focus, and firms operating in both jurisdictions map the two. ISO 22301 provides a certifiable business continuity management system whose analysis, planning, and exercising support the mapping and scenario testing rules. The Basel Committee principles give the international baseline for banks.
SmartSuite keeps the important business services register, impact tolerances, resource and third-party maps, scenario tests, communications plans, and remediation actions in one linked system. Each requirement in SYSC 15A has an owner, cadence, and evidence, and the self-assessment and lessons learned documentation are generated from live records.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
