Operational Resilience
DETAIL

PRA Supervisory Statement SS1/21 – Operational resilience: Impact tolerances for important business services

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

Supervisory Statement SS1/21, Operational resilience: Impact tolerances for important business services, sets out the Prudential Regulation Authority's expectations for the operational resilience of firms' important business services. It explains how the PRA expects firms to meet the Operational Resilience Parts of the PRA Rulebook: identify important business services, set impact tolerances for each, map the resources that deliver them, test their ability to stay within tolerance, and govern the whole through a documented self-assessment.

The PRA, part of the Bank of England, published SS1/21 on 29 March 2021 alongside policy statement PS6/21 and updated it in March 2022 to take effect on 31 March 2022. It applies to UK banks, building societies, PRA-designated investment firms, and CRR consolidation entities, and to UK Solvency II firms, the Society of Lloyd's, and its managing agents. Firms had until 31 March 2025 to be able to remain within their impact tolerances.

Firms implement SS1/21 by agreeing at board level which services are important, setting a maximum tolerable level of disruption for each, mapping people, processes, technology, facilities, and information to those services, running severe but plausible scenario tests, and remediating the vulnerabilities the tests expose. The self-assessment document records the reasoning and is reviewed and approved by the board.

Why it Matters

SS1/21 is the PRA's statement of what good operational resilience looks like for the UK's largest financial firms, and it is the basis on which supervisors challenge boards. Its focus on services rather than systems changed how firms organize continuity, third-party, and technology risk work.

Key benefits include:

  • Service-level accountability

Boards approve the list of important business services and the impact tolerance for each, so responsibility for resilience is explicit.

  • Clear limits on disruption

Impact tolerances give every important service a measurable maximum tolerable disruption, expressed in time and other metrics.

  • Visibility of dependencies

Mapping shows which people, processes, technology, facilities, information, and third parties each service relies on.

  • Evidence from testing

Scenario testing against severe but plausible disruptions shows whether tolerances can be met and where investment is needed.

  • Alignment with the FCA and international regimes

The PRA and FCA policies share concepts, and the same work supports DORA, the Basel principles, and ISO 22301.

How it Works

SS1/21 has nine chapters: Introduction; Important business services; Impact tolerances; Actions to remain within impact tolerance; Mapping; Scenario testing; Governance; Self-assessment; and Groups. Each chapter explains how the PRA interprets the corresponding rules in the Operational Resilience Part (for banks) and the Insurance – Operational Resilience Part (for insurers) of the PRA Rulebook, and what evidence supervisors expect to see.

Firms identify the services whose disruption could pose a risk to their safety and soundness, policyholder protection, or financial stability; set an impact tolerance for each; map the resources that deliver it; and test whether they can remain within tolerance under severe but plausible scenarios. Where they cannot, the PRA expects a prioritized plan, with the requirement to be able to remain within impact tolerances met no later than 31 March 2025. The board approves the self-assessment and reviews it regularly, and groups coordinate the work across entities.

Within SmartSuite, teams keep the register of important business services, the impact tolerance and rationale for each, the resource maps, the scenario test plans and results, and the remediation actions in one linked system, and generate the self-assessment and board reporting from live data.

Key Elements

  • Important business services

Services provided to external end users whose disruption could threaten the firm's safety and soundness, policyholder protection, or UK financial stability.

  • Impact tolerances

The maximum tolerable level of disruption to each important business service, set by the board and expressed with a time-based metric and other relevant measures.

  • Actions to remain within impact tolerance

A prioritized plan and investment to close the gap between current capability and the tolerance, in effect no later than 31 March 2025.

  • Mapping

Identification and documentation of the people, processes, technology, facilities, and information needed to deliver each important business service.

  • Scenario testing

Tests of the firm's ability to remain within impact tolerance under severe but plausible scenarios, with lessons learned recorded.

  • Governance and self-assessment

Board ownership of the approach and a written self-assessment that the PRA can request at any time.

  • Groups

Expectations for how firms in a group identify services, set tolerances, and manage shared resources across entities.

Framework Scope

SS1/21 applies to UK banks, building societies, PRA-designated investment firms, and CRR consolidation entities, and to UK Solvency II firms, the Society of Lloyd's, and its managing agents. It covers the important business services those firms provide to external end users and the internal and outsourced resources that deliver them; it does not set requirements for firms regulated only by the FCA, which are covered by SYSC 15A.

Framework Objectives

The PRA's policy objective is to improve the resilience of firms and the wider financial sector to operational disruption.

Ensure firms identify the business services whose disruption would harm safety and soundness, policyholders, or financial stability.

Require boards to set and own a maximum tolerable level of disruption for each important business service.

Make firms understand and document the resources and third parties on which each service depends.

Prove through testing that firms can remain within impact tolerances under severe but plausible scenarios.

Drive investment where testing shows a firm cannot yet meet its tolerances.

Give supervisors a consistent, proportionate minimum standard to assess across the sector.

Framework in Context

SS1/21 was published on the same day as the FCA's PS21/3 and the rules in SYSC 15A, and the two regulators use the same concepts of important business services, impact tolerances, mapping, scenario testing, and self-assessment, so dual-regulated firms run one program. Internationally it aligns with the Basel Committee's Principles for Operational Resilience of March 2021 and with the EU's Digital Operational Resilience Act, and ISO 22301 supplies a business continuity management system that supports the mapping and testing expectations.

Common Framework Mappings

PRA SS1/21 is commonly mapped to the FCA's parallel rules, the Basel operational resilience principles, EU DORA, ISO 22301, and equivalent prudential regimes so that one resilience program satisfies several supervisors.

Mapped frameworks include:

FCA SYSC 15A (PS21/3)

BCBS Operational Resilience Principles

EU DORA

ISO 22301

APRA CPS 230

At a Glance
PRA Supervisory Statement SS1/21 – Operational resilience: Impact tolerances for important business services
  • Classification
    Category
    Operational Resilience
    Domain
    Operational Resilience
    Framework Family
    Other
  • Regulatory Context
    Type
    Guidance
    Legal Instrument
    Supervisory Statement
    Sector
    Financial Sector
    Industry
    Financial Services
  • Region / Publisher
    Region
    United Kingdom
    Region Detail
    United Kingdom
    Publisher
    Prudential Regulation Authority (PRA), Bank of England
  • Versioning
    Version
    SS1/21 (March 2022 update)
    Effective Date
    March 31, 2022
    Issue Date
    March 29, 2021
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: Yes

SS1/21 is published free of charge by the Bank of England, and its expectations are included with the platform as a requirement set.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
SS1/21 publication page
The Bank of England page for SS1/21 with the current March 2022 version, the original March 2021 version, and the related policy statements.
SS1/21 March 2022 (PDF)
The full text of the supervisory statement as updated in March 2022 and in effect from 31 March 2022.
PRA Rulebook
The PRA Rulebook, including the Operational Resilience Part and the Insurance – Operational Resilience Part that SS1/21 interprets.
Prudential Regulation Authority
The PRA's home on the Bank of England site, with policy, supervisory statements, and consultations.
SMARTSUITE

How SmartSuite Supports PRA SS1/21

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For PRA SS1/21, SmartSuite holds the important business services register, each impact tolerance with its rationale, resource maps, scenario test results, and remediation plans, and generates the board self-assessment from live records.

Important Business Services Register

Record each service, its end users, the board-approved rationale for its importance, and the impact tolerance set for it.

Ownership, Cadence, and Accountability

Assign service owners, schedule tolerance reviews and annual self-assessment updates, and track board approvals.

Evidence Collection and Audit Trail

Attach mapping outputs, test reports, and board minutes with timestamps so the self-assessment is backed by evidence.

Scenario Testing

Plan severe but plausible scenarios, record results against each tolerance, and log lessons learned and actions.

Third-Party and Resource Mapping

Link people, processes, technology, facilities, information, and suppliers to the services they support.

Board and Supervisory Reporting

Produce the self-assessment document and dashboards showing tolerance status and open vulnerabilities.

Related frameworks

FCA SYSC 15A (PS21/3)

FCA PS21/3 and SYSC 15A require UK-regulated firms to identify important business services, set impact tolerances, map and test their resilience, and self-assess against them.

BCBS Operational Resilience Principles

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

EU DORA

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

ISO 22301

ISO 22301 is a business continuity management standard helping organizations prepare for, respond to, and recover from disruptions.

APRA CPS 230

CPS 230 is an APRA standard requiring banks, insurers, and superannuation funds to manage operational risks and ensure resilience.

NIS2 (EU 2022/2555)

NIS2 establishes mandatory cybersecurity and incident-reporting requirements to strengthen resilience across essential and important EU organizations.

Basel III

Basel III is an international banking regulation framework that strengthens banks' capital, liquidity, and risk management to reduce systemic risk.

ONBOARDING FAQS

Frequently Asked Questions For PRA SS1/21

What is PRA SS1/21?

SS1/21 is the Prudential Regulation Authority's supervisory statement on operational resilience, first published on 29 March 2021 and updated in March 2022. It explains how the PRA expects firms to identify important business services, set impact tolerances, map resources, test, and self-assess. It interprets the Operational Resilience Parts of the PRA Rulebook.

Which firms does SS1/21 apply to?

It applies to UK banks, building societies, PRA-designated investment firms, and CRR consolidation entities, and to UK Solvency II insurers, the Society of Lloyd's, and its managing agents. Firms regulated only by the FCA follow the FCA's SYSC 15A rules instead. Dual-regulated firms meet both.

What is an important business service?

It is a service a firm provides to external end users whose disruption could pose a risk to the firm's safety and soundness, to policyholder protection, or to UK financial stability. Firms identify these services at board level and document the rationale. Internal services that only support other services are usually not important business services in their own right.

What is an impact tolerance?

An impact tolerance is the maximum tolerable level of disruption to an important business service, set by the board. The PRA expects it to include a time-based metric and any other measures that fit the service, such as the number of customers affected. Firms then test whether they can remain within it.

What were the key dates for SS1/21?

The policy took effect on 31 March 2022, by which time firms needed to have identified their important business services, set impact tolerances, and begun mapping and testing. Firms then had until 31 March 2025 to be able to remain within their impact tolerances. After that date the PRA treats maintaining resilience as an ongoing activity.

How does SS1/21 relate to the FCA's rules and to DORA?

The FCA published PS21/3 and SYSC 15A on the same day with the same core concepts, so dual-regulated firms run a single program. EU DORA and the Basel Committee's Principles for Operational Resilience cover similar ground for EU firms and internationally active banks. ISO 22301 supports the mapping and testing expectations with a business continuity management system.

How does SmartSuite support PRA SS1/21?

SmartSuite keeps the important business services register, impact tolerances, resource maps, scenario tests, and remediation plans in one linked system. Owners, review cadences, and evidence are tracked against each service, and the self-assessment and board reporting are generated from live data rather than assembled by hand.

Operationalize PRA SS1/21 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.