From 18 March 2027 banks and insurers must report operational incidents to the PRA that meet its thresholds (risks to safety and soundness, policyholder protection or financial stability, weighing contagion, reputation, legal and regulatory obligations, service provision and data security) through initial, intermediate and final reports, with governance over classification and reporting; SS1/26 sets these expectations and the PRA rule text published with PS7/26 is not held.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.