---
title: "Operational resilience for UK insurers: what is in force, and what commences in 2027"
source_url: https://abgalis.com/regulation/operational-resilience
canonical: https://abgalis.com/regulation/operational-resilience
description: "The UK operational resilience regime for insurers: the Insurance Part, impact tolerances, the first CTP designations of 13 July 2026, and PS7/26 — published but not in force until March 2027."
publisher: Abgalis Limited
author: Abgalis Research
date_published: 2026-08-22
date_modified: 2026-08-22
keywords: ["operational resilience", "important business services", "impact tolerance", "critical third parties", "PS7/26", "SS1/21", "SS2/21", "CTP", "concentration risk", "Solvency II", "incident reporting"]
retrieved: 2026-08-22
content_signal: search=yes, ai-input=yes, ai-train=no
citation: "Abgalis Research, 'Operational resilience for UK insurers: what is in force, and what commences in 2027', Abgalis Limited, https://abgalis.com/regulation/operational-resilience"
license_note: >-
  May be quoted and cited in AI-generated answers with attribution to the author named
  above and a link to source_url. Not licensed for model training or fine-tuning
  (ai-train=no; Art. 4 reservation, EU Directive 2019/790).
---

Regulation · Operational resilience

# Operational resilience for UK insurers: what is in force, and what commences in 2027

Three things happened to this regime in 2026, and they are widely reported at the wrong
dates. **PS7/26 was published on 18 March 2026 and does not commence until 18 March 2027.**
The first critical third parties were **designated on 13 July 2026**, not announced-and-designated
on the 10th. And the transition deadline for remaining within impact tolerances passed on
**31 March 2025** with no formal supervisory statement of what the regulators found.

This page sets out what actually binds an insurer today, what binds it next March, and where
the regime has a gap the Bank has named and not closed.

---

## Which rules actually apply to insurers?

**Not the ones most commentary cites.** There are two separate PRA Rulebook Parts, and
insurers are governed by the one that is easy to miss:

| | Insurers | Banks / CRR firms |
|---|---|---|
| Rulebook Part | **Insurance – Operational Resilience** | Operational Resilience |
| Applies to | UK Solvency II firms, the Society of Lloyd's, managing agents (rule 1.1) | CRR firms |
| Distinctive content | **Chapter 9: Lloyd's** · a **policyholder protection** limb | neither |

Citing "the Operational Resilience Part" for an insurer is citing the wrong instrument.

**The core obligations**, all effective 31 March 2022:

> **2.1** — "A firm must identify its important business services and, where Group Supervision
> 22.2 applies, its important group business services."
>
> **2.2** — "A firm must set an impact tolerance for each of: (1) its important business
> services; and (2) where Group Supervision 22.2 applies, its important group business
> services."
>
> **4.1** — "…a firm must identify and document the necessary people, processes, technology,
> facilities and information required to deliver each of its important business services."
>
> **5.1** — "A firm must carry out regular scenario testing of its ability to remain within its
> impact tolerance for each of its important business services."

Impact tolerance is defined at **1.2** as *"the maximum tolerable level of disruption to an
important business service or important group business service as measured by a length of
time and other relevant metrics."*

**The policyholder limb is the genuinely insurer-specific part.** SS1/21 §2.2: *"The
Operational Resilience Parts set out that insurers must also identify important business
services that may pose a risk to policyholder protection."* It runs through the whole regime —
identifying services, calibrating tolerances, and now the 2027 reporting threshold. It is why
an insurer's set of important business services is not a bank's with different labels.

**Also in force:** **SS1/21** (current version March 2022 — not superseded), **SoP1/21**
(effective 31 December 2024), **SS2/21** on outsourcing and third-party risk (the 15 November
2024 version binds today), and FCA **SYSC 15A** for dual-regulated insurers in their conduct
capacity.

---

## What happened to the 31 March 2025 deadline?

It passed, and the regulators have said remarkably little about it.

> **SS1/21 §4.14:** "Firms are expected to have a prioritised plan which sets out how they
> will comply with the requirement to be able to remain within their impact tolerances within
> a reasonable time, and no later than Monday 31 March 2025."

Note the drafting split: **PS6/21** says firms *"must"* be able to remain within tolerances by
that date; SS1/21 frames it as an expectation attached to a plan. The hard obligation sits in
the Rulebook Part; the supervisory statement is gloss.

**As at August 2026 we can find no PRA or FCA publication formally stating a supervisory
position on the passed deadline** — no thematic review of compliance, no enforcement stance,
no closing statement. The FCA's insurance operational resilience page, last updated 5 December
2025, still speaks in expectation terms: *"We expect all in-scope firms to address any
remaining gaps or shortcomings in their operational resilience frameworks, and meet all
obligations under our rules, by 31 March 2025."*

The regulators appear to have moved on to the reporting and critical-third-party workstreams.
If a consultancy tells you the PRA has published its post-deadline findings, ask for the
reference.

**What the FCA has published** is insurer-specific good and poor practice. Good: firms that
*"identified all the important business services expected for the firms' business model"* and
considered harm across *"purchasing, amending and renewing a policy, as well as the ability to
make a claim or a complaint"*, with *"carefully calibrated tolerances with accompanying
rationales"*. Poor: firms that *"did not meaningfully consider the impact of unavailable
important business services on vulnerable customers"*.

---

## Who are the critical third parties, and what does designation actually do?

**Four legal entities, designated 13 July 2026** by **The Critical Third Parties (Designation)
Regulations 2026, SI 2026/777** — made 8 July, in force 13 July, under section 312L(1) FSMA
2000:

1. **Amazon Web Services EMEA SARL** *(Luxembourg)*
2. **Google Cloud EMEA Limited** *(Ireland)*
3. **Microsoft Ireland Operations Limited** *(Ireland)*
4. **Oracle Corporation UK Limited** *(UK)*

**Two precision points that most coverage gets wrong.** The instrument designates **specific
corporate entities, not groups** — "Microsoft" is not designated; Microsoft Ireland Operations
Limited is. And **three of the four are not UK entities.** If your third-party register names
a different group company, designation does not automatically reach it.

**What designation does not mean**, from the Bank's own announcement of 10 July 2026:

> "Designation under this regime is not the same as authorisation by the regulators. Oversight
> is limited to the resilience of the services they provide to UK financial firms."

> The regime "complements, but does not replace, existing outsourcing and operational
> resilience rules for regulated firms who remain responsible for managing their own
> third-party arrangements including due diligence, risk management and contingency planning."

**PS16/24 §1.5** is blunter still: the CTP regime *"does not impose additional, explicit
requirements or expectations on firms"*, and firms *"will remain accountable and responsible
for managing the risks in any outsourcing or third party arrangements they have"*. §2.42
confirms accountability *"will not change due to the implementation of the CTP oversight
regime."*

*A citation note: PS16/24 and FCA PS24/16 are not two documents. They are one joint policy
statement of 12 November 2024 carrying two numbers.*

---

## What commences on 18 March 2027?

**PS7/26 — *Operational resilience: operational incident and third-party reporting*** — was
published on **18 March 2026** by the PRA, FCA and the Bank in its FMI capacity. It introduced
**SS1/26**, a revised **SS2/21**, and new Rulebook chapters.

**None of it bites until 18 March 2027.** Anything describing PS7/26 as a current obligation
is a year early.

### Incident reporting

**SS1/26 §3.2** sets three thresholds — risk to UK financial stability, to the firm's safety
and soundness, or to *"an appropriate degree of protection for those who are or may become the
firm's policyholders."*

The financial-stability limb reaches only **"relevant Solvency II firms"** — defined by gross
written premiums above **£15 billion** or technical provisions above **£75 billion**, on a
rolling three-year average. **For most UK insurers that limb does not engage**, and reporting
turns on safety and soundness and policyholder protection.

Three phases, one incident:

| Report | Timing |
|---|---|
| Initial | *"as soon as practicable"* — expectation of **within 24 hours** of determining a threshold is met (§4.5) |
| Intermediate | *"as soon as practicable after there has been a significant change in circumstances"* (§§4.8–4.9) |
| Final | **within 30 working days** of resolution, or where impracticable *"not exceeding 60 working days"* (§4.14) |

### Third-party reporting — the bigger change

Scope moves from **material outsourcing** to all **material third party arrangements**. Two
new duties: notification before entering into or significantly changing an MTP, via FCA
Connect; and an **annual register** of all MTPs via RegData.

SS2/21 (March 2026) §5.1 defines an MTP by whether disruption could *"pose a risk to the
firm's safety and soundness"* or *"cast serious doubt upon the firm's ability to satisfy the
threshold conditions."* Intragroup arrangements are generally outside the notification duty.

### ⚠️ Dual-regulated insurers face two different tests

FCA **PS26/2** creates **SUP 15.18** and **15.19**, and Solvency II firms are *enhanced
reporting firms* under SUP 15.18.3R(5) — so the full three-phase cycle applies on the FCA side
too. But the FCA threshold includes *"causing intolerable levels of harm to consumers from
which consumers cannot easily recover"* — a **consumer-harm limb absent from the PRA test**.

**The two tests are not co-extensive, both commence on the same day, and neither policy
statement resolves whether a firm can operate a single trigger.** This is the most practically
significant unaddressed question in the 2027 package.

---

## Where is the gap in the regime?

**The CTP regime makes dominant providers more resilient. It does nothing about how dominant
they are.**

The regime's instrument is the resilience of each designated provider, one at a time. The
regulators' approach document is explicit that, with one exception, *"the regulators' rules
only apply in relation to a CTP's provision of systemic third party services to firms"* (§19).
There are no caps, no diversification requirements, no substitutability mandate, and no power
to refuse a concentration. And since PS16/24 §1.5 confirms no new duties fall on firms, the
lever is not being pulled from that side either.

**The Bank has diagnosed this in its own framing.** The approach document records the FPC's
position that *"the greater the share of the financial sector relying on a third party, the
greater the risk to the UK financial system in the event of a failure in, or disruption to,
the services that the third party provides."*

**And it has named the population the regime does not reach.** The **Financial Stability
Report of July 2026** — published three days before the CTP announcement — discusses the
resilience expected of *"other material third-party technology providers that **may not meet
the threshold for CTP designation**."*

The same report opens a newer front:

> "Where multiple firms rely on the same providers, software components or essential services,
> a vulnerability, compromise or defensive shutdown at a common supplier could affect several
> institutions at once."

…and, on AI: *"To the extent that firms come to rely on a handful of frontier AI providers to
improve their defensive cyber capabilities, to identify vulnerabilities, and to fix processes,
this could also represent a new channel of concentration risk."*

Note "software components" — that reaches well beyond four cloud providers.

**The honest statement of the position:** the risk is identified in the Bank's own words; the
regime built in response addresses provider resilience, not market structure. The PS7/26
material-third-party register is the closest thing to an answer, and it is a data-collection
measure commencing in 2027, not a resilience obligation on the providers.

---

## How does this interact with climate?

**SS5/25** — the PRA's climate supervisory statement, published 3 December 2025 — brings
climate drivers into the operational resilience machinery rather than building a parallel one.

> **§4.44** "Firms should assess the impact of climate-related risk drivers from the
> perspective of both their general operations and their ability to continue providing
> important business services, including those supported by outsourcing and third-party
> arrangements, in severe but plausible scenarios."

Read with **§4.43**, which lists the channels — *"business continuity contingency planning and
disaster recovery, infrastructure (both in the UK and globally), operations, and outsourcing
and third-party arrangements"* — and **§4.45**, on physical risk.

**The drafting choice matters.** §4.44 does not create a climate impact tolerance. It tells
firms to run climate drivers through the **existing** important business services and the
severe-but-plausible scenario testing they already do. Separately, **§4.11** brings climate
into board-level risk appetite for third-party arrangements and cross-refers expressly to
SS2/21.

*A citation trap: SS5/25's PDF is hosted under a filename reading `ss425`, and the Bank's page
notes "Amended from SS4/25". The instrument is **SS5/25**. Anyone citing SS4/25 is citing the
filename.*

---

## What about Solvency II Article 49 and Delegated Regulation Article 274?

**Do not cite them as live UK requirements.** They are not.

**PS15/24 — *Review of Solvency II: Restatement of assimilated law*** (15 November 2024,
implementation 31 December 2024) restated the governance and outsourcing provisions into the
PRA Rulebook, *"without material changes to the policy substance unless explicitly mentioned"*.
The live references are Rulebook Parts.

The insurer governance rules now sit in **Conditions Governing Business** — including **2A.3**,
the business continuity rule and the closest analogue to a resilience obligation outside the
dedicated Part:

> "A firm must establish, implement and maintain a business continuity policy aimed at
> ensuring, in the case of an interruption to its systems and procedures, the preservation of
> essential data and functions and the maintenance of insurance and reinsurance activities,
> or, where that is not possible, the timely recovery of such data and functions and the
> timely resumption of their insurance or reinsurance activities."

Also **3.1(2)(c)**, which requires the risk-management system to cover operational risk, and
**3.8(1)**, the ORSA. Outsourcing is Chapter 7.

This is one of the most frequently repeated errors in UK operational resilience commentary
written since 2024.

---

## Where Abgalis fits

The regime asks an insurer to hold three things together: a mapped set of important business
services with calibrated tolerances; a register of material third-party arrangements that will
be reportable from March 2027; and — from SS5/25 §4.44 — climate drivers run through the same
machinery. Concentration across those dependencies is the risk the CTP regime identifies and
does not close.

That is a cross-domain dependency problem. Abgalis carries operational risk alongside the other
six domains in one continuously updated model, so a common dependency shared across services,
providers and risk types is visible as one exposure rather than six separate register entries.

Accountability for every regulatory judgement remains with the firm. Abgalis is analytics, not
authority.

---

## Sources

- **PRA Rulebook: Insurance – Operational Resilience** — [prarulebook.co.uk](https://www.prarulebook.co.uk/pra-rules/insurance---operational-resilience)
- **SS1/21** — [Operational resilience: Impact tolerances for important business services](https://www.bankofengland.co.uk/prudential-regulation/publication/2021/march/operational-resilience-impact-tolerances-for-important-business-services-ss), current version March 2022
- **PS7/26** — [Operational resilience: operational incident and third-party reporting](https://www.bankofengland.co.uk/prudential-regulation/publication/2026/march/operational-incident-and-third-party-reporting-policy-statement), 18 March 2026, commencing 18 March 2027
- **SS1/26** — [Operational resilience: Incident reporting](https://www.bankofengland.co.uk/prudential-regulation/publication/2026/march/operational-resilience-incident-reporting-supervisory-statement)
- **PS16/24 / FCA PS24/16** — [Critical third parties to the UK financial sector](https://www.bankofengland.co.uk/prudential-regulation/publication/2024/november/operational-resilience-critical-third-parties-to-the-uk-financial-sector-policy-statement), 12 Nov 2024
- **SI 2026/777** — [The Critical Third Parties (Designation) Regulations 2026](https://www.legislation.gov.uk/uksi/2026/777/made)
- **Financial Stability Report, July 2026** — [Bank of England](https://www.bankofengland.co.uk/financial-stability-report/2026/july-2026)
- **PS15/24** — [Review of Solvency II: Restatement of assimilated law](https://www.bankofengland.co.uk/prudential-regulation/publication/2024/november/review-of-solvency-ii-restatement-of-assimilated-law-policy-statement)
- **FCA PS26/2** — [Operational Incident and Third Party Reporting](https://www.fca.org.uk/publication/policy/ps26-2.pdf)

---

**Source:** [https://abgalis.com/regulation/operational-resilience](https://abgalis.com/regulation/operational-resilience) · Abgalis Research, published by Abgalis Limited (England and Wales, no. 17247499)

**Cite as:** Abgalis Research, *Operational resilience for UK insurers: what is in force, and what commences in 2027*, Abgalis Limited. https://abgalis.com/regulation/operational-resilience

**Usage:** citation with attribution permitted; model training not permitted (`ai-train=no`).

**More:** [https://abgalis.com/llms.txt](https://abgalis.com/llms.txt) · full corpus: [https://abgalis.com/llms-full.txt](https://abgalis.com/llms-full.txt)
