Not the ones most commentary cites. There are two separate PRA Rulebook Parts, and insurers are governed by the one that is easy to miss:
| Insurers | Banks / CRR firms | |
|---|---|---|
| Rulebook Part | Insurance – Operational Resilience | Operational Resilience |
| Applies to | UK Solvency II firms, the Society of Lloyd's, managing agents (rule 1.1) | CRR firms |
| Distinctive content | Chapter 9: Lloyd's · a policyholder protection limb | neither |
Citing "the Operational Resilience Part" for an insurer is citing the wrong instrument.
The core obligations, all effective 31 March 2022:
2.1 — "A firm must identify its important business services and, where Group Supervision 22.2 applies, its important group business services." 2.2 — "A firm must set an impact tolerance for each of: (1) its important business services; and (2) where Group Supervision 22.2 applies, its important group business services." 4.1 — "…a firm must identify and document the necessary people, processes, technology, facilities and information required to deliver each of its important business services." 5.1 — "A firm must carry out regular scenario testing of its ability to remain within its impact tolerance for each of its important business services."
Impact tolerance is defined at 1.2 as "the maximum tolerable level of disruption to an important business service or important group business service as measured by a length of time and other relevant metrics."
The policyholder limb is the genuinely insurer-specific part. SS1/21 §2.2: "The Operational Resilience Parts set out that insurers must also identify important business services that may pose a risk to policyholder protection." It runs through the whole regime — identifying services, calibrating tolerances, and now the 2027 reporting threshold. It is why an insurer's set of important business services is not a bank's with different labels.
Also in force: SS1/21 (current version March 2022 — not superseded), SoP1/21 (effective 31 December 2024), SS2/21 on outsourcing and third-party risk (the 15 November 2024 version binds today), and FCA SYSC 15A for dual-regulated insurers in their conduct capacity.
---
It passed, and the regulators have said remarkably little about it.
SS1/21 §4.14: "Firms are expected to have a prioritised plan which sets out how they will comply with the requirement to be able to remain within their impact tolerances within a reasonable time, and no later than Monday 31 March 2025."
Note the drafting split: PS6/21 says firms "must" be able to remain within tolerances by that date; SS1/21 frames it as an expectation attached to a plan. The hard obligation sits in the Rulebook Part; the supervisory statement is gloss.
As at August 2026 we can find no PRA or FCA publication formally stating a supervisory position on the passed deadline — no thematic review of compliance, no enforcement stance, no closing statement. The FCA's insurance operational resilience page, last updated 5 December 2025, still speaks in expectation terms: "We expect all in-scope firms to address any remaining gaps or shortcomings in their operational resilience frameworks, and meet all obligations under our rules, by 31 March 2025."
The regulators appear to have moved on to the reporting and critical-third-party workstreams. If a consultancy tells you the PRA has published its post-deadline findings, ask for the reference.
What the FCA has published is insurer-specific good and poor practice. Good: firms that "identified all the important business services expected for the firms' business model" and considered harm across "purchasing, amending and renewing a policy, as well as the ability to make a claim or a complaint", with "carefully calibrated tolerances with accompanying rationales". Poor: firms that "did not meaningfully consider the impact of unavailable important business services on vulnerable customers".
---
Four legal entities, designated 13 July 2026 by The Critical Third Parties (Designation) Regulations 2026, SI 2026/777 — made 8 July, in force 13 July, under section 312L(1) FSMA 2000:
1. Amazon Web Services EMEA SARL (Luxembourg) 2. Google Cloud EMEA Limited (Ireland) 3. Microsoft Ireland Operations Limited (Ireland) 4. Oracle Corporation UK Limited (UK)
Two precision points that most coverage gets wrong. The instrument designates specific corporate entities, not groups — "Microsoft" is not designated; Microsoft Ireland Operations Limited is. And three of the four are not UK entities. If your third-party register names a different group company, designation does not automatically reach it.
What designation does not mean, from the Bank's own announcement of 10 July 2026:
"Designation under this regime is not the same as authorisation by the regulators. Oversight is limited to the resilience of the services they provide to UK financial firms."
The regime "complements, but does not replace, existing outsourcing and operational resilience rules for regulated firms who remain responsible for managing their own third-party arrangements including due diligence, risk management and contingency planning."
PS16/24 §1.5 is blunter still: the CTP regime "does not impose additional, explicit requirements or expectations on firms", and firms "will remain accountable and responsible for managing the risks in any outsourcing or third party arrangements they have". §2.42 confirms accountability "will not change due to the implementation of the CTP oversight regime."
A citation note: PS16/24 and FCA PS24/16 are not two documents. They are one joint policy statement of 12 November 2024 carrying two numbers.
---
PS7/26 — Operational resilience: operational incident and third-party reporting — was published on 18 March 2026 by the PRA, FCA and the Bank in its FMI capacity. It introduced SS1/26, a revised SS2/21, and new Rulebook chapters.
None of it bites until 18 March 2027. Anything describing PS7/26 as a current obligation is a year early.
SS1/26 §3.2 sets three thresholds — risk to UK financial stability, to the firm's safety and soundness, or to "an appropriate degree of protection for those who are or may become the firm's policyholders."
The financial-stability limb reaches only "relevant Solvency II firms" — defined by gross written premiums above £15 billion or technical provisions above £75 billion, on a rolling three-year average. For most UK insurers that limb does not engage, and reporting turns on safety and soundness and policyholder protection.
Three phases, one incident:
| Report | Timing |
|---|---|
| Initial | "as soon as practicable" — expectation of within 24 hours of determining a threshold is met (§4.5) |
| Intermediate | "as soon as practicable after there has been a significant change in circumstances" (§§4.8–4.9) |
| Final | within 30 working days of resolution, or where impracticable "not exceeding 60 working days" (§4.14) |
Scope moves from material outsourcing to all material third party arrangements. Two new duties: notification before entering into or significantly changing an MTP, via FCA Connect; and an annual register of all MTPs via RegData.
SS2/21 (March 2026) §5.1 defines an MTP by whether disruption could "pose a risk to the firm's safety and soundness" or "cast serious doubt upon the firm's ability to satisfy the threshold conditions." Intragroup arrangements are generally outside the notification duty.
FCA PS26/2 creates SUP 15.18 and 15.19, and Solvency II firms are enhanced reporting firms under SUP 15.18.3R(5) — so the full three-phase cycle applies on the FCA side too. But the FCA threshold includes "causing intolerable levels of harm to consumers from which consumers cannot easily recover" — a consumer-harm limb absent from the PRA test.
The two tests are not co-extensive, both commence on the same day, and neither policy statement resolves whether a firm can operate a single trigger. This is the most practically significant unaddressed question in the 2027 package.
---
The CTP regime makes dominant providers more resilient. It does nothing about how dominant they are.
The regime's instrument is the resilience of each designated provider, one at a time. The regulators' approach document is explicit that, with one exception, "the regulators' rules only apply in relation to a CTP's provision of systemic third party services to firms" (§19). There are no caps, no diversification requirements, no substitutability mandate, and no power to refuse a concentration. And since PS16/24 §1.5 confirms no new duties fall on firms, the lever is not being pulled from that side either.
The Bank has diagnosed this in its own framing. The approach document records the FPC's position that "the greater the share of the financial sector relying on a third party, the greater the risk to the UK financial system in the event of a failure in, or disruption to, the services that the third party provides."
And it has named the population the regime does not reach. The Financial Stability Report of July 2026 — published three days before the CTP announcement — discusses the resilience expected of "other material third-party technology providers that may not meet the threshold for CTP designation."
The same report opens a newer front:
"Where multiple firms rely on the same providers, software components or essential services, a vulnerability, compromise or defensive shutdown at a common supplier could affect several institutions at once."
…and, on AI: "To the extent that firms come to rely on a handful of frontier AI providers to improve their defensive cyber capabilities, to identify vulnerabilities, and to fix processes, this could also represent a new channel of concentration risk."
Note "software components" — that reaches well beyond four cloud providers.
The honest statement of the position: the risk is identified in the Bank's own words; the regime built in response addresses provider resilience, not market structure. The PS7/26 material-third-party register is the closest thing to an answer, and it is a data-collection measure commencing in 2027, not a resilience obligation on the providers.
---
SS5/25 — the PRA's climate supervisory statement, published 3 December 2025 — brings climate drivers into the operational resilience machinery rather than building a parallel one.
§4.44 "Firms should assess the impact of climate-related risk drivers from the perspective of both their general operations and their ability to continue providing important business services, including those supported by outsourcing and third-party arrangements, in severe but plausible scenarios."
Read with §4.43, which lists the channels — "business continuity contingency planning and disaster recovery, infrastructure (both in the UK and globally), operations, and outsourcing and third-party arrangements" — and §4.45, on physical risk.
The drafting choice matters. §4.44 does not create a climate impact tolerance. It tells firms to run climate drivers through the existing important business services and the severe-but-plausible scenario testing they already do. Separately, §4.11 brings climate into board-level risk appetite for third-party arrangements and cross-refers expressly to SS2/21.
A citation trap: SS5/25's PDF is hosted under a filename reading ss425, and the Bank's page notes "Amended from SS4/25". The instrument is SS5/25. Anyone citing SS4/25 is citing the filename.
---
Do not cite them as live UK requirements. They are not.
PS15/24 — Review of Solvency II: Restatement of assimilated law (15 November 2024, implementation 31 December 2024) restated the governance and outsourcing provisions into the PRA Rulebook, "without material changes to the policy substance unless explicitly mentioned". The live references are Rulebook Parts.
The insurer governance rules now sit in Conditions Governing Business — including 2A.3, the business continuity rule and the closest analogue to a resilience obligation outside the dedicated Part:
"A firm must establish, implement and maintain a business continuity policy aimed at ensuring, in the case of an interruption to its systems and procedures, the preservation of essential data and functions and the maintenance of insurance and reinsurance activities, or, where that is not possible, the timely recovery of such data and functions and the timely resumption of their insurance or reinsurance activities."
Also 3.1(2)(c), which requires the risk-management system to cover operational risk, and 3.8(1), the ORSA. Outsourcing is Chapter 7.
This is one of the most frequently repeated errors in UK operational resilience commentary written since 2024.
---
Insurers are governed by the PRA Rulebook's Insurance – Operational Resilience Part, not the Operational Resilience Part that applies to CRR firms. It applies to UK Solvency II firms, the Society of Lloyd's and managing agents, has a dedicated Lloyd's chapter, and carries a policyholder protection limb the banking Part lacks. Rule 2.1 requires identification of important business services; 2.2 requires an impact tolerance for each; 5.1 requires regular scenario testing.
PS7/26 was published on 18 March 2026 but its requirements commence on 18 March 2027. It introduces SS1/26 on incident reporting, a revised SS2/21, and new Rulebook chapters on operational incident reporting and a register of material third party arrangements. Nothing in it binds firms until March 2027.
Four legal entities were designated with effect from 13 July 2026 under The Critical Third Parties (Designation) Regulations 2026 (SI 2026/777): Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. The instrument designates specific corporate entities rather than groups, and three of the four are not UK-incorporated.
No. The regime oversees the resilience of each designated provider's services. It contains no caps, diversification requirements or substitutability mandates, and PS16/24 confirms it imposes no additional requirements on firms. The Bank's July 2026 Financial Stability Report separately notes the resilience expected of material third-party technology providers that may not meet the threshold for designation.
SS1/21 §4.14 expected firms to be able to remain within their impact tolerances no later than 31 March 2025. That date has passed. As at August 2026 no PRA or FCA publication sets out a formal supervisory position on what was found; the FCA's insurance guidance, last updated December 2025, still refers to the deadline in expectation terms.
SS5/25 §4.44 requires firms to assess climate-related risk drivers against their ability to continue providing important business services, including those supported by outsourcing and third-party arrangements, in severe but plausible scenarios. It does not create a separate climate impact tolerance — it runs climate drivers through the existing operational resilience machinery. §4.11 separately brings climate into risk appetite for third-party arrangements, cross-referring to SS2/21.
Developments on this and related instruments are tracked in regulatory updates.
Discover how ABGALIS can unify your enterprise risk landscape into a single, living digital twin — with foresight across every domain.
Enter your details to access our peer-quality research from the Abgalis Risk Intelligence Lab.
Your data is handled in accordance with GDPR. We never share your information.