From 18 March 2027 a firm must report an operational incident (an event disrupting service to an external end user or affecting the availability, authenticity, integrity or confidentiality of their data) as soon as practicable once it reasonably believes the incident risks intolerable consumer harm, the safety and soundness of the firm or others, or market stability, integrity or confidence; the FCA expects this within 24 hours of that determination (payment service providers within 4 hours of detecting a major incident). Enhanced reporting firms (banks, building societies, designated investment firms, enhanced SMCR, Solvency II and CASS large firms, payment service providers, exchanges, trade repositories, credit rating agencies) must add an intermediate report on significant change and a final report within 30 working days of resolution (60 at the latest), using the prescribed fields and the FCA's online system.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.