PRA Supervisory Statement SS1/21 – Operational resilience: Impact tolerances for important business services

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
Supervisory Statement SS1/21, Operational resilience: Impact tolerances for important business services, sets out the Prudential Regulation Authority's expectations for the operational resilience of firms' important business services. It explains how the PRA expects firms to meet the Operational Resilience Parts of the PRA Rulebook: identify important business services, set impact tolerances for each, map the resources that deliver them, test their ability to stay within tolerance, and govern the whole through a documented self-assessment.
The PRA, part of the Bank of England, published SS1/21 on 29 March 2021 alongside policy statement PS6/21 and updated it in March 2022 to take effect on 31 March 2022. It applies to UK banks, building societies, PRA-designated investment firms, and CRR consolidation entities, and to UK Solvency II firms, the Society of Lloyd's, and its managing agents. Firms had until 31 March 2025 to be able to remain within their impact tolerances.
Firms implement SS1/21 by agreeing at board level which services are important, setting a maximum tolerable level of disruption for each, mapping people, processes, technology, facilities, and information to those services, running severe but plausible scenario tests, and remediating the vulnerabilities the tests expose. The self-assessment document records the reasoning and is reviewed and approved by the board.
Why it Matters
SS1/21 is the PRA's statement of what good operational resilience looks like for the UK's largest financial firms, and it is the basis on which supervisors challenge boards. Its focus on services rather than systems changed how firms organize continuity, third-party, and technology risk work.
Key benefits include:
- Service-level accountability
Boards approve the list of important business services and the impact tolerance for each, so responsibility for resilience is explicit.
- Clear limits on disruption
Impact tolerances give every important service a measurable maximum tolerable disruption, expressed in time and other metrics.
- Visibility of dependencies
Mapping shows which people, processes, technology, facilities, information, and third parties each service relies on.
- Evidence from testing
Scenario testing against severe but plausible disruptions shows whether tolerances can be met and where investment is needed.
- Alignment with the FCA and international regimes
The PRA and FCA policies share concepts, and the same work supports DORA, the Basel principles, and ISO 22301.
How it Works
SS1/21 has nine chapters: Introduction; Important business services; Impact tolerances; Actions to remain within impact tolerance; Mapping; Scenario testing; Governance; Self-assessment; and Groups. Each chapter explains how the PRA interprets the corresponding rules in the Operational Resilience Part (for banks) and the Insurance – Operational Resilience Part (for insurers) of the PRA Rulebook, and what evidence supervisors expect to see.
Firms identify the services whose disruption could pose a risk to their safety and soundness, policyholder protection, or financial stability; set an impact tolerance for each; map the resources that deliver it; and test whether they can remain within tolerance under severe but plausible scenarios. Where they cannot, the PRA expects a prioritized plan, with the requirement to be able to remain within impact tolerances met no later than 31 March 2025. The board approves the self-assessment and reviews it regularly, and groups coordinate the work across entities.
Within SmartSuite, teams keep the register of important business services, the impact tolerance and rationale for each, the resource maps, the scenario test plans and results, and the remediation actions in one linked system, and generate the self-assessment and board reporting from live data.
Key Elements
- Important business services
Services provided to external end users whose disruption could threaten the firm's safety and soundness, policyholder protection, or UK financial stability.
- Impact tolerances
The maximum tolerable level of disruption to each important business service, set by the board and expressed with a time-based metric and other relevant measures.
- Actions to remain within impact tolerance
A prioritized plan and investment to close the gap between current capability and the tolerance, in effect no later than 31 March 2025.
- Mapping
Identification and documentation of the people, processes, technology, facilities, and information needed to deliver each important business service.
- Scenario testing
Tests of the firm's ability to remain within impact tolerance under severe but plausible scenarios, with lessons learned recorded.
- Governance and self-assessment
Board ownership of the approach and a written self-assessment that the PRA can request at any time.
- Groups
Expectations for how firms in a group identify services, set tolerances, and manage shared resources across entities.
Framework Scope
SS1/21 applies to UK banks, building societies, PRA-designated investment firms, and CRR consolidation entities, and to UK Solvency II firms, the Society of Lloyd's, and its managing agents. It covers the important business services those firms provide to external end users and the internal and outsourced resources that deliver them; it does not set requirements for firms regulated only by the FCA, which are covered by SYSC 15A.
Framework Objectives
The PRA's policy objective is to improve the resilience of firms and the wider financial sector to operational disruption.
Ensure firms identify the business services whose disruption would harm safety and soundness, policyholders, or financial stability.
Require boards to set and own a maximum tolerable level of disruption for each important business service.
Make firms understand and document the resources and third parties on which each service depends.
Prove through testing that firms can remain within impact tolerances under severe but plausible scenarios.
Drive investment where testing shows a firm cannot yet meet its tolerances.
Give supervisors a consistent, proportionate minimum standard to assess across the sector.
Framework in Context
SS1/21 was published on the same day as the FCA's PS21/3 and the rules in SYSC 15A, and the two regulators use the same concepts of important business services, impact tolerances, mapping, scenario testing, and self-assessment, so dual-regulated firms run one program. Internationally it aligns with the Basel Committee's Principles for Operational Resilience of March 2021 and with the EU's Digital Operational Resilience Act, and ISO 22301 supplies a business continuity management system that supports the mapping and testing expectations.
Common Framework Mappings
PRA SS1/21 is commonly mapped to the FCA's parallel rules, the Basel operational resilience principles, EU DORA, ISO 22301, and equivalent prudential regimes so that one resilience program satisfies several supervisors.
Mapped frameworks include:
FCA SYSC 15A (PS21/3)
BCBS Operational Resilience Principles
EU DORA
ISO 22301
APRA CPS 230
- ClassificationCategoryOperational ResilienceDomainOperational ResilienceFramework FamilyOther
- Regulatory ContextTypeGuidanceLegal InstrumentSupervisory StatementSectorFinancial SectorIndustryFinancial Services
- Region / PublisherRegionUnited KingdomRegion DetailUnited KingdomPublisherPrudential Regulation Authority (PRA), Bank of England
- VersioningVersionSS1/21 (March 2022 update)Effective DateMarch 31, 2022Issue DateMarch 29, 2021
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
SS1/21 is published free of charge by the Bank of England, and its expectations are included with the platform as a requirement set.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports PRA SS1/21
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For PRA SS1/21, SmartSuite holds the important business services register, each impact tolerance with its rationale, resource maps, scenario test results, and remediation plans, and generates the board self-assessment from live records.
Important Business Services Register
Record each service, its end users, the board-approved rationale for its importance, and the impact tolerance set for it.
Ownership, Cadence, and Accountability
Assign service owners, schedule tolerance reviews and annual self-assessment updates, and track board approvals.
Evidence Collection and Audit Trail
Attach mapping outputs, test reports, and board minutes with timestamps so the self-assessment is backed by evidence.
Scenario Testing
Plan severe but plausible scenarios, record results against each tolerance, and log lessons learned and actions.
Third-Party and Resource Mapping
Link people, processes, technology, facilities, information, and suppliers to the services they support.
Board and Supervisory Reporting
Produce the self-assessment document and dashboards showing tolerance status and open vulnerabilities.
Related frameworks

FCA PS21/3 and SYSC 15A require UK-regulated firms to identify important business services, set impact tolerances, map and test their resilience, and self-assess against them.

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

ISO 22301 is a business continuity management standard helping organizations prepare for, respond to, and recover from disruptions.

CPS 230 is an APRA standard requiring banks, insurers, and superannuation funds to manage operational risks and ensure resilience.
Frequently Asked Questions For PRA SS1/21
SS1/21 is the Prudential Regulation Authority's supervisory statement on operational resilience, first published on 29 March 2021 and updated in March 2022. It explains how the PRA expects firms to identify important business services, set impact tolerances, map resources, test, and self-assess. It interprets the Operational Resilience Parts of the PRA Rulebook.
It applies to UK banks, building societies, PRA-designated investment firms, and CRR consolidation entities, and to UK Solvency II insurers, the Society of Lloyd's, and its managing agents. Firms regulated only by the FCA follow the FCA's SYSC 15A rules instead. Dual-regulated firms meet both.
It is a service a firm provides to external end users whose disruption could pose a risk to the firm's safety and soundness, to policyholder protection, or to UK financial stability. Firms identify these services at board level and document the rationale. Internal services that only support other services are usually not important business services in their own right.
An impact tolerance is the maximum tolerable level of disruption to an important business service, set by the board. The PRA expects it to include a time-based metric and any other measures that fit the service, such as the number of customers affected. Firms then test whether they can remain within it.
The policy took effect on 31 March 2022, by which time firms needed to have identified their important business services, set impact tolerances, and begun mapping and testing. Firms then had until 31 March 2025 to be able to remain within their impact tolerances. After that date the PRA treats maintaining resilience as an ongoing activity.
The FCA published PS21/3 and SYSC 15A on the same day with the same core concepts, so dual-regulated firms run a single program. EU DORA and the Basel Committee's Principles for Operational Resilience cover similar ground for EU firms and internationally active banks. ISO 22301 supports the mapping and testing expectations with a business continuity management system.
SmartSuite keeps the important business services register, impact tolerances, resource maps, scenario tests, and remediation plans in one linked system. Owners, review cadences, and evidence are tracked against each service, and the self-assessment and board reporting are generated from live data rather than assembled by hand.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

