From 18 March 2027, firms must report material operational incidents within 24 hours of determining that a threshold has been met, or within four hours for payment service providers. That threshold is to be assessed against broad, outcome-based tests, rather than being confined to incidents affecting an important business service. Firms will also be required to maintain, and to submit annually, a register of material third-party (MTP) arrangements.
The FCA's approach, set out in PS26/2, sits alongside the PRA's PS7/26 and the Bank of England's parallel rules for market infrastructure, and responds to growing concerns over third-party risk management (TPRM) and operational resilience. The rules reflect a higher reporting standard than most firms currently meet. With a rapidly approaching implementation deadline, there's limited time for firms to achieve compliance, particularly in relation to the MTP register.
Operational resilience is a multi-faceted issue
Operational resilience aims to restore critical services following a service outage, to mitigate the risk of financial harm to individuals or the wider economy. These outages stem from a range of factors, from cyber-attacks to third-party failure to internal system failure – or often a combination, as seen in recent reviews and studies.
Over 40% of the cyber incidents reported to the FCA in 2025 involved a third party, and firms are expected to test scenarios around cloud outages and cyber-attacks. The first major report on ICT-related incidents under DORA, found that system failures were by far the largest cause of major incidents (51% of incidents, compared with 10% attributed to cyber security); of all these incidents almost a third originated at a third party. The UK's Treasury Select Committee's review painted a similar picture, finding that 803 hours of outages at nine major banks and building societies were due to third-party supplier problems, system change, and internal software malfunction.
The role of third-party risk
Third-party risk is a running theme throughout these findings and remains a top regulatory concern. This is reflected in the HM Treasury’s recent designation of four critical third parties, to give the regulators better oversight and assurance over how these providers manage risk and resilience. The new reporting regime should be viewed as a complement to firms' existing operational resilience and third-party risk management obligations, not a standalone compliance exercise. Accountability for third-party activity remains with the user organisation and firms need to understand how these risks can combine to increase both the likelihood and impact of significant incidents.
Outages can have a single root cause
Looking beyond third-party risk, outages can have more straightforward root causes. For instance, a leading automotive manufacturer suffered the UK's most damaging cyber-attack, with losses for thousands of smaller suppliers and a five-week production shutdown. Likewise, a major bank failed to execute 56% of its online payments over several days in 2025, due to degradation of its own mainframe. As such, firms need to embed effective oversight over a broad range of factors contributing to operational resilience and be prepared to report promptly on any outages.
Building effective incident reporting processes
From March, firms must classify incidents against the FCA's new thresholds, report within short timeframes and keep an accurate third-party register. Building this operational resilience capability will take time and four key areas consistently prove challenging, as outlined below.
Incident classification
Firms must judge, under a ‘reasonable belief’ standard (and frequently before they have the full picture), whether an incident is likely to meet the reporting threshold. Firms already reporting under DORA experienced this difficulty during its early, and by most accounts patchy, months of operation. Many firms don't currently capture the data needed to make that judgement quickly. Given the difference between DORA and UK thresholds, there is a risk that firms will operate parallel incident classification processes, while judgemental thresholds will require more senior leadership involvement in the incident process.
Group incident reporting
Reporting obligations apply entity-by-entity rather than at group level, so firms with several regulated entities that operate on a shared infrastructure will need to file multiple reports in respect of a single operational incident – but be clear on the specific impact on each regulated entity.
Third-party register compilation and upkeep
The information required for the MTP register will be derived from multiple sources – in systems, on spreadsheets, on paper and in people’s heads; some of it will need to be sourced from third parties. Some specific elements are also tricky to obtain in practice, including contracts, legal entity identifiers, materiality judgements, and agreements on substitutability. While the MTP reporting form is more straightforward than DORA's Register of Information, it still requires a lot of information, gathered through sequential planning and effective governance.
The FCA will notify firms when the annual MTP register submission window opens, after which they will have just 90 calendar days to submit.
Strengthening third-party risk management processes
Elements of the MTP submission have the potential to expose gaps in third-party risk management processes, given firms need to state the date and outcome of last audits and due diligence exercises, as well as whether contracts comply with regulatory requirements. TPRM policies, standards and processes may need to be strengthened to demonstrate the level of rigour over material third parties that the register implies; it cannot be treated as an annual compliance exercise.
Key actions for firms
With significant work still ahead before the March 2027 deadline, firms should ensure they have the people, processes, data and technology in place to support reporting. However, there is work to do now, and work to keep doing well beyond March 2027 – meeting the deadline is not the end point, and firms need to embed sustainable processes so that incident reporting and material third-party reporting keep working long after.
In the near term, firms should focus on:
- Taking the incident reporting thresholds and agreeing reasonable measures for them that can be adopted into incident management processes, to reduce the level of subjectivity in determining whether incidents are reportable.
- Ensuring incident detection capabilities are effective for legacy technologies, given the continued challenge they present around resilience.
- Revising incident management processes to incorporate incident reporting and ensure the roles required to support incident reporting are briefed on their responsibilities, confirming their understanding with a desktop exercise. This should consider both entity-level incident reporting and group-level incident management.
- Developing a common data model that supports both DORA and UK obligations (where applicable) to reduce the burden on teams.
- Managing the MTP reporting submission as a project, with clear activities and milestones. Prioritise determining material third parties and performing a gap assessment of the data available for each third-party in scope.
- Accelerating third-party risk assessments, audits and due diligence activities for those material third parties, to enable the demonstration of effective oversight before the register is submitted.
Looking further ahead, firms should treat this as more than a one-off project. The real test is whether the systems and habits built for March 2027 still hold up a year later. Third-party processes need to capture data as new suppliers are onboarded, not chase it down after the fact, and the same data model should keep pace for material third-party reporting. This may mean better use of existing systems, or agentic tools with proper human oversight. Teams also need to be resourced for the long haul rather than for a single push, with external tooling and AI capability considered before headcount is added. And firms should give the Board and senior management ongoing sight of near-misses and near-threshold incidents, not just reportable ones. Proactive management of recurring problems is what keeps future reporting volumes down.
Firms should not lose sight of the wider benefit here, though. Incident reporting can give firms richer, more consistent data on their own vulnerabilities and resilience priorities. Material third-party reporting can do the same for third-party risk, by forcing firms to centralise and standardise data that also supports incident response.
For further information, contact Danny Chamings, Robert Shaw, Priya Prakash or Chris Watson.