Operational Resilience
DETAIL

FCA PS21/3 Building operational resilience and SYSC 15A Operational resilience

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

PS21/3, Building operational resilience, is the Financial Conduct Authority's policy statement that finalized the UK's operational resilience rules for FCA-regulated firms and introduced chapter SYSC 15A, Operational resilience, into the FCA Handbook. Together they require firms to identify their important business services, set impact tolerances for each, map the resources that deliver them, run scenario tests, and maintain a self-assessment that shows how they meet the rules.

The FCA published PS21/3 on 29 March 2021 following consultation paper CP19/32, in coordination with the Bank of England and the PRA. SYSC 15A came into force on 31 March 2022 and applies to banks, building societies, PRA-designated investment firms, Solvency II insurers, UK recognised investment exchanges, enhanced scope SM&CR firms, payment institutions, electronic money institutions, and registered account information service providers with a UK head office.

Firms implement the rules by agreeing important business services and impact tolerances at senior management level, mapping people, processes, technology, facilities, and information to each service, testing whether they can stay within tolerance under severe but plausible scenarios, and investing to close the gaps. Firms had a transitional period to 31 March 2025 to be able to remain within their impact tolerances, and the self-assessment must be kept current and approved by the governing body.

Why it Matters

SYSC 15A is the enforceable operational resilience rulebook for the widest set of UK financial firms, from banks to payment institutions, and PS21/3 records the FCA's reasoning behind each rule. Together they put customers and market integrity at the center of resilience: what matters is whether an important service can keep running within a tolerable level of disruption.

Key benefits include:

  • Customer-focused resilience

Important business services are defined by the harm their disruption would cause to clients and market integrity, not by internal systems.

  • Measurable limits

Impact tolerances give each service a maximum tolerable disruption that management can test against.

  • End-to-end understanding

Mapping shows the resources and third parties each service depends on, including outsourced and intra-group arrangements.

  • Tested, not assumed

Scenario testing against severe but plausible events shows whether tolerances can be met and what to fix.

  • One program for dual-regulated firms

The FCA and PRA rules share concepts and timing, and the same work supports the Basel principles, DORA, and ISO 22301.

How it Works

SYSC 15A is organized into nine sections: 15A.1 Application; 15A.2 Operational resilience requirements; 15A.3 Strategies, processes and systems; 15A.4 Mapping; 15A.5 Scenario testing; 15A.6 Self-assessment and lessons learned documentation; 15A.7 Governance; 15A.8 Communications; and 15A.9 Supervisory review and feedback. PS21/3 explains the feedback received on CP19/32 and the FCA's final position on each of these areas.

Firms identify important business services and set an impact tolerance for each, expressed at least as a maximum tolerable duration of disruption; map the people, processes, technology, facilities, and information needed to deliver each service; test their ability to remain within tolerance under severe but plausible scenarios; and document the results and lessons learned in a self-assessment approved by the governing body. The rules came into force on 31 March 2022, and firms had until 31 March 2025 to be able to remain within their impact tolerances. Communications plans cover how the firm will keep clients and other stakeholders informed during a disruption.

Within SmartSuite, teams maintain the important business services register and impact tolerances, link mapped resources and third parties to each service, schedule and record scenario tests, track remediation, and produce the SYSC 15A self-assessment and lessons learned documentation from live records.

Key Elements

  • Important business services

Services whose disruption could cause intolerable harm to clients or pose a risk to the soundness, stability, or resilience of the UK financial system or the orderly operation of markets.

  • Impact tolerances

A maximum tolerable level of disruption for each important business service, including a duration and, where appropriate, other metrics.

  • Strategies, processes, and systems

The arrangements a firm needs so that it can remain within its impact tolerances.

  • Mapping

Identification and documentation of the people, processes, technology, facilities, and information required to deliver each important business service.

  • Scenario testing

Regular tests of the firm's ability to remain within tolerance under severe but plausible scenarios, with lessons learned recorded.

  • Self-assessment and governance

A written self-assessment, reviewed and approved by the governing body, that the FCA can request at any time.

  • Communications

Internal and external communication strategies for use during operational disruptions.

Framework Scope

SYSC 15A applies to banks, building societies, PRA-designated investment firms, Solvency II firms, UK recognised investment exchanges, enhanced scope SM&CR firms, electronic money institutions, payment institutions, registered account information service providers, and consolidated tape providers with their registered or head office in the United Kingdom. It covers the important business services those firms provide and the resources and third parties that deliver them; it does not apply to firms whose head office is outside the UK or to the temporary-permission categories the chapter excludes.

Framework Objectives

The FCA's aim is that firms can prevent, adapt to, respond to, recover from, and learn from operational disruptions.

Protect consumers and market integrity by keeping important business services within a tolerable level of disruption.

Make senior management identify and own the services that matter most and the tolerances set for them.

Require firms to understand and document the resources and dependencies behind each service.

Test resilience against severe but plausible scenarios and act on what the tests reveal.

Ensure firms can communicate effectively with clients and stakeholders during a disruption.

Give the FCA a consistent basis for supervisory review across all firm types in scope.

Framework in Context

PS21/3 and SYSC 15A were published on the same day as the PRA's SS1/21 and share its concepts of important business services, impact tolerances, mapping, scenario testing, and self-assessment, so dual-regulated firms run one program against both. The Basel Committee's Principles for Operational Resilience of March 2021 set the international baseline for banks, EU DORA applies a comparable regime to EU financial entities with a focus on ICT, and ISO 22301 provides a business continuity management system that supports the mapping and testing rules.

Common Framework Mappings

FCA PS21/3 and SYSC 15A are commonly mapped to the PRA's parallel policy, the Basel operational resilience principles, EU DORA, ISO 22301, and equivalent prudential regimes so that one resilience program satisfies several supervisors.

Mapped frameworks include:

PRA SS1/21

BCBS Operational Resilience Principles

EU DORA

ISO 22301

APRA CPS 230

At a Glance
FCA PS21/3 Building operational resilience and SYSC 15A Operational resilience
  • Classification
    Category
    Operational Resilience
    Domain
    Operational Resilience
    Framework Family
    Other
  • Regulatory Context
    Type
    Regulation
    Legal Instrument
    Handbook Rules and Policy Statement
    Sector
    Financial Sector
    Industry
    Financial Services
  • Region / Publisher
    Region
    United Kingdom
    Region Detail
    United Kingdom
    Publisher
    Financial Conduct Authority (FCA)
  • Versioning
    Version
    PS21/3 (March 2021); SYSC 15A
    Effective Date
    March 31, 2022
    Issue Date
    March 29, 2021
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: Yes

PS21/3 and the FCA Handbook are published free of charge by the Financial Conduct Authority, and the SYSC 15A requirements are included with the platform as a requirement set.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
PS21/3 Building operational resilience
The FCA policy statement page with the final rules, feedback to CP19/32, and implementation dates.
SYSC 15A Operational resilience (FCA Handbook)
The Handbook chapter containing the operational resilience rules and guidance, sections 15A.1 to 15A.9.
PS21/3 (PDF)
The full text of the policy statement, including the rule instrument and the FCA's response to consultation feedback.
FCA operational resilience for firms
The FCA's page for firms on operational resilience expectations, observations, and related publications.
SMARTSUITE

How SmartSuite Supports FCA SYSC 15A

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For FCA SYSC 15A, SmartSuite holds the important business services register, impact tolerances, resource and third-party maps, scenario tests, communications plans, and remediation actions, and generates the self-assessment and lessons learned documentation from live records.

Important Business Services Register

Record each service, the clients and markets it serves, the rationale for its importance, and its impact tolerance.

Ownership, Cadence, and Accountability

Assign service owners, schedule tolerance reviews and annual self-assessment approval, and track governing body sign-off.

Evidence Collection and Audit Trail

Attach mapping outputs, test reports, and approvals with timestamps so each SYSC 15A requirement is evidenced.

Scenario Testing

Plan severe but plausible scenarios, record results against each tolerance, and capture lessons learned per SYSC 15A.6.

Third-Party and Resource Mapping

Link people, processes, technology, facilities, information, and suppliers to the services they support.

Supervisory Reporting

Produce the self-assessment document and dashboards showing tolerance status and remediation progress for the FCA.

Related frameworks

PRA SS1/21

PRA SS1/21 sets the Prudential Regulation Authority's expectations for how UK banks and insurers identify important business services, set impact tolerances, and stay within them.

BCBS Operational Resilience Principles

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

EU DORA

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

ISO 22301

ISO 22301 is a business continuity management standard helping organizations prepare for, respond to, and recover from disruptions.

APRA CPS 230

CPS 230 is an APRA standard requiring banks, insurers, and superannuation funds to manage operational risks and ensure resilience.

NIS2 (EU 2022/2555)

NIS2 establishes mandatory cybersecurity and incident-reporting requirements to strengthen resilience across essential and important EU organizations.

ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ONBOARDING FAQS

Frequently Asked Questions For FCA SYSC 15A

What are FCA PS21/3 and SYSC 15A?

PS21/3 is the FCA's March 2021 policy statement that finalized the UK operational resilience rules for FCA-regulated firms. SYSC 15A is the chapter of the FCA Handbook that contains those rules. PS21/3 explains the reasoning and feedback; SYSC 15A is what firms must comply with.

Which firms does SYSC 15A apply to?

It applies to banks, building societies, PRA-designated investment firms, Solvency II insurers, UK recognised investment exchanges, enhanced scope SM&CR firms, payment institutions, electronic money institutions, registered account information service providers, and consolidated tape providers with a UK head office. Firms with a head office outside the UK and the temporary-permission categories named in the chapter are excluded.

What does SYSC 15A require?

Firms must identify their important business services, set an impact tolerance for each, map the people, processes, technology, facilities, and information that deliver them, and carry out scenario testing. They must keep a self-assessment and lessons learned documentation approved by the governing body, maintain communications strategies for disruptions, and address vulnerabilities the work reveals.

What were the key dates?

The rules came into force on 31 March 2022, by which point firms needed important business services, impact tolerances, and initial mapping and testing in place. The transitional period ended on 31 March 2025, by which time firms had to be able to remain within their impact tolerances. Compliance is now an ongoing obligation.

How is the FCA's regime different from the PRA's SS1/21?

The concepts are the same and the two were published together, but the FCA rules apply to a wider range of firms, including solo-regulated firms such as payment institutions and enhanced scope SM&CR firms. The FCA frames harm in terms of clients and market integrity, while the PRA focuses on safety and soundness, policyholders, and financial stability. Dual-regulated firms must satisfy both.

How does SYSC 15A relate to DORA and ISO 22301?

EU DORA imposes a comparable operational resilience regime on EU financial entities with a strong ICT focus, and firms operating in both jurisdictions map the two. ISO 22301 provides a certifiable business continuity management system whose analysis, planning, and exercising support the mapping and scenario testing rules. The Basel Committee principles give the international baseline for banks.

How does SmartSuite support FCA SYSC 15A?

SmartSuite keeps the important business services register, impact tolerances, resource and third-party maps, scenario tests, communications plans, and remediation actions in one linked system. Each requirement in SYSC 15A has an owner, cadence, and evidence, and the self-assessment and lessons learned documentation are generated from live records.

Operationalize FCA SYSC 15A (PS21/3) with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.