UK FCA/PRA Operational Resilience Framework
The UK Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) operational resilience framework (effective March 2022, full compliance by March 2025) requires financial institutions to identify important business services, set impact tolerances, and ensure they can remain within those tolerances during severe but plausible disruptions. Applies to banks, building societies, PRA-designated investment firms, insurers, and recognised payment system operators.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Governance and Self-Assessment
| Code | Title |
|---|---|
| SYSC 15A.5.1 | Board Responsibility |
| SYSC 15A.5.2 | Self-Assessment Document |
| SYSC 15A.5.3 | Senior Management Accountability |
| SYSC 15A.5.4 | Internal Communication |
Impact Tolerances
| Code | Title |
|---|---|
| SYSC 15A.3.1 | Setting Impact Tolerances |
| SYSC 15A.3.2 | Tolerance Metrics |
| SYSC 15A.3.3 | Consumer and Market Impact Assessment |
| SYSC 15A.3.4 | Tolerance Review and Update |
Important Business Services
| Code | Title |
|---|---|
| SYSC 15A.2.1 | Identification of Important Business Services |
| SYSC 15A.2.2 | Service Mapping |
| SYSC 15A.2.3 | Third-Party Dependency Mapping |
| SYSC 15A.2.4 | Service Documentation |
Ongoing Compliance
| Code | Title |
|---|---|
| SYSC 15A.6.1 | Continuous Improvement |
| SYSC 15A.6.2 | Lessons Learned from Incidents |
| SYSC 15A.6.3 | Regulatory Reporting |
| SYSC 15A.6.4 | Outsourcing and Third-Party Risk |
Scenario Testing
| Code | Title |
|---|---|
| SYSC 15A.4.1 | Scenario Testing Programme |
| SYSC 15A.4.2 | Severe but Plausible Scenarios |
| SYSC 15A.4.3 | Vulnerability Identification |
| SYSC 15A.4.4 | Remediation Planning |
Maps to 481 other frameworks
Frequently Asked Questions
What is UK FCA/PRA Operational Resilience Framework?
UK FCA/PRA Operational Resilience Framework is a compliance framework from United Kingdom with 5 domains and 20 controls. The UK Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) operational resilience framework (effective March 2022, full compliance by March 2025) requires financial institutions to identify important business services, set impact tolerances, and ensure they can remain within those tolerances during severe but plausible disruptions. Applies to banks, building societies, PRA-designated investment firms, insurers, and recognised payment system operators. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does UK FCA/PRA Operational Resilience Framework have?
UK FCA/PRA Operational Resilience Framework has 20 controls organised across 5 domains. The largest domains are Governance and Self-Assessment (4 controls), Impact Tolerances (4 controls), Important Business Services (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does UK FCA/PRA Operational Resilience Framework map to?
UK FCA/PRA Operational Resilience Framework maps to 481 other compliance frameworks. The top mapping partners are TISAX — Trusted Information Security Assessment Exchange (30% coverage), Voluntary Principles on Security and Human Rights (VPs) (25% coverage), ILO Nursing Personnel Convention C149 (1977) (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with UK FCA/PRA Operational Resilience Framework compliance?
Start your UK FCA/PRA Operational Resilience Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK FCA/PRA Operational Resilience Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required