Description

Financial Conduct Authority adopted guidance on operational incident reporting (FG26/3)

On 18 March 2026, the Financial Conduct Authority (FCA) adopted the guidance on operational incident reporting for firms with Part 4A permission, payment service providers (PSPs), credit rating agencies, and other financial firms. The policy aims to establish a standardised process for reporting significant operational disruptions. The guidance defines an operational incident as a single event or series of linked events that disrupts service delivery to external end users or impacts the availability, authenticity, integrity, or confidentiality of their data. Firms must report incidents that meet specific thresholds, including those posing risks of intolerable harm to consumers, threats to the safety and soundness of the firm or market participants, and risks to market integrity or the UK financial system. The framework introduces two reporting tiers: standard and enhanced. Standard reporting requires basic information in a single report, while enhanced reporting for specific high-impact firms involves initial, intermediate, and final phases over the incident lifecycle. Firms are required to submit reports as soon as practicable, with a 24-hour limit for general firms and a 4-hour limit for PSPs following detection. The guidance clarifies that planned interruptions and "near misses" (such as potential incidents that were thwarted or contained/prevented crystallised incidents) do not require reporting under this specific mechanism unless they meet established thresholds. This unified framework replaces separate incident reporting systems previously used by PSPs and registered credit rating agencies to ensure a structured approach to thematic analysis and incident response.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
other service provider
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2026-03-18
adopted

On 18 March 2026, the Financial Conduct Authority (FCA) adopted the guidance on operational inciden…

2027-03-18
in force

On 18 March 2027, the guidance on operational incident reporting for firms with Part 4A permission,…