Skip to content
Financial services

Operational resilience software for UK financial services

One evidence base for UK operational resilience, the new incident and third-party reporting rules from 18 March 2027, and DORA. Built for banks, building societies, insurers, investment firms and payment firms.

Informational, not legal advice. Not an endorsement by, or statement on behalf of, any regulator. Regulatory detail verified 6 October 2026.

What UK financial firms must evidence on operational resilience

UK financial firms must keep their important business services within impact tolerances, a standing expectation since 31 March 2025 under FCA PS21/3 and PRA SS1/21. From 18 March 2027, PRA SS1/26 and FCA PS26/2 add operational incident reporting, with an initial report within 24 hours, and annual reporting of material third party arrangements. Firms with EU entities also sit under DORA, which has applied since 17 January 2025. STREAM®, from Acuity Risk Management, holds the services, risks, controls, third parties and incident evidence these rules ask for in one cyber GRC platform.

The deadlines that matter

  1. 31 March 2022
    In force

    UK operational resilience rules take effect: FCA PS21/3 and PRA SS1/21. Identify important business services, set impact tolerances, map and test.

  2. 1 January 2025
    In force

    UK Critical Third Parties regime takes effect. Its rules apply to third parties HM Treasury designates. Firms remain responsible for their own third-party risk.

  3. 17 January 2025
    In force

    DORA applies across EU financial entities: ICT risk management, incident reporting, resilience testing, ICT third party risk and information sharing.

  4. 31 March 2025
    Deadline

    End of the UK transition. Firms must be able to operate important business services within impact tolerances.

  5. 18 March 2027
    Effective date

    UK operational incident and third-party reporting: PRA PS7/26 and SS1/26 (with an updated SS2/21), and FCA PS26/2.

What changes on 18 March 2027: PS26/2 and SS1/26

Operational incident reporting

Report incidents that meet the thresholds: an initial report within 24 hours, as soon as reasonably practicable, updates as things change, and a final report within 30 working days of resolution, extendable to 60. One submission, updated across the phases, whichever regulator applies.

Material third-party reporting

Notify the regulator when you enter into, or significantly change, a material third-party arrangement, and submit a register of those arrangements each year.

Which rules apply to your firm?

RuleWho is in scope
UK operational resilienceBanks, building societies, PRA-designated investment firms, insurers, recognised investment exchanges, enhanced scope SM&CR firms, payment services entities, consolidated tape providers and qualifying cryptoasset firms.
UK incident reporting from 18 March 2027PRA: UK banks, building societies, PRA-designated investment firms, UK branches of overseas banks, UK Solvency II firms, the Society of Lloyd's and managing agents. FCA: firms with a Part 4A permission, plus payment service providers and certain market infrastructure.
UK material third-party reporting from 18 March 2027PRA: the firms above plus credit unions with assets of £50 million or more. FCA: enhanced SM&CR firms, banks, designated investment firms, building societies, Solvency II firms, CASS large firms, UK RIEs, e-money and payment institutions, and consolidated tape providers.
DORAEU financial entities, including EU subsidiaries of UK groups. UK ICT providers to EU financial entities, through contract terms.

Summarised from the PRA, FCA and EU texts listed below. Your permissions decide your scope: check them against the source.

How STREAM® supports operational resilience

Services and tolerances

Hold important business services, the risks, controls and assets behind them, and assessment against the impact tolerances your firm has set.

Incident readiness

Assess incidents against the classification criteria and assemble the evidence each report requires, so the 24-hour UK window and the 4-hour DORA notification start from the same decision.

One third-party record

Hold the cyber risk assessment, tiering and control evidence for each third party once, through Vendor Management Hub, and draw on it for the UK register and the DORA register of information.

Controls mapped once

Map controls once and evidence them against UK operational resilience, DORA and your other frameworks together, so continuous compliance replaces the annual scramble.

Ownership and audit trail

An owner for every control and action, with a record-level audit trail of who did what, and when.

Board-ready reporting

Dashboards and reports that answer the board, the auditor or the supervisor in the form they ask.

What STREAM® does not do

  • Set your impact tolerances. Your firm sets them; STREAM® supports assessing against them.
  • File regulatory reports on your behalf. It assembles the evidence; your firm submits.
  • Produce the ESA reporting templates for the DORA register of information.
  • Replace outsourcing governance, exit planning or sub-outsourcing oversight. Vendor Management Hub covers the cyber risk assessment layer.
  • Carry any endorsement or approval from a regulator.

Choose your edition

Mid-market firms

STREAM® Cloud

Cyber GRC for regulated mid-market firms that have outgrown spreadsheets. Live in days, run by a lean team, with qualitative 5×5 risk schemes and built-in reporting.

Explore STREAM® Cloud

Banks, insurers, large groups

STREAM® Classic

Adds quantitative risk modelling (Monte Carlo), deep configurability and automation, a custom report builder and reporting API, and on-premises deployment, including air-gapped.

Explore STREAM® Classic

Third parties

Vendor Management Hub

A central vendor registry, configurable assessment questionnaires with consistent scoring, and contract and renewal tracking.

Explore Vendor Management Hub

Not sure which fits? Take the STREAM® Editions Quiz →

Financial services operational resilience FAQ

Common questions about UK operational resilience, the 18 March 2027 incident and third-party reporting rules, DORA, and where STREAM fits.

Sources

  • FCA: Operational resilience (PS21/3), in force 31 March 2022; transition to 31 March 2025
  • Bank of England, PRA: PS7/26 Operational incident and third-party reporting, 18 March 2026
  • Bank of England, PRA: SS1/26 Operational resilience: Incident reporting, effective 18 March 2027
  • FCA: PS26/2 Operational incident and third party reporting, effective 18 March 2027
  • FCA: Critical third parties: strengthening UK financial services
  • Regulation (EU) 2022/2554 (DORA) and Commission Delegated Regulation (EU) 2025/301

See STREAM® run operational resilience

A 30-minute demo of services, tolerances, third parties and incident evidence in one place.

Request a demo