Operational Resilience and DORA Cover - Bratby Law Payments Regulation

Operational Resilience and DORA

A UK-authorised payment institution, e-money institution or other payment service provider must identify its important business services, set an impact tolerance for each of them and be able to stay within those tolerances when a service is disrupted, under SYSC 15A of the FCA Handbook, the operational resilience rules the FCA made in PS21/3, Building operational resilience. A firm with operations in the European Union must also comply with the Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, which took effect on 17 January 2025. DORA does not apply directly in the UK, so a UK payment firm with EU business meets both sets of requirements. Bratby Law advises payment institutions, e-money institutions and other payment service providers on operational resilience.

When operational resilience obligations apply

The FCA’s operational resilience rules apply to an electronic money institution, a payment institution and a registered account information service provider, whatever its size, under SYSC 15A.1.1R(3). They do not apply to a firm whose registered or head office is outside the United Kingdom (SYSC 15A.1.4R) or to a temporary permissions firm (SYSC 15A.1.3R), and for an institution caught only by SYSC 15A.1.1R(3) they apply only to its provision of payment services and issuance of electronic money (SYSC 15A.1.8R). A firm whose group includes an EU-authorised entity must comply with DORA for that entity, alongside the UK requirements that apply to the UK-authorised firm. A firm that outsources a critical function such as payment processing, settlement, data storage or customer authentication must secure operational resilience in the contract with the provider. A firm must also meet its operational incident reporting obligations: the FCA and the PRA published an incident and third-party reporting framework in March 2026. It reaches almost every FCA-regulated firm, adds notification of material third party arrangements and an annual register of them, and replaces the separate reporting regimes with a single submission. A provider designated as a Critical Third Party under the FCA, PRA and Bank of England regime, which took effect on 1 January 2025, must itself provide regular assurance, undertake resilience testing and report major incidents. A firm that relies on a designated provider takes on no new obligation on designation: it remains responsible for managing its own third-party risk under the existing operational resilience and outsourcing requirements, and the regulators have said the regime complements rather than replaces that responsibility. The Critical Third Party regime and the reporting framework change what a payment firm has to do about operational risk from 2026.

Why operational resilience matters now

A UK-authorised firm had to be able to remain within its impact tolerances for its important business services by 31 March 2025. In March 2026 the FCA and the PRA published PS26/2, an operational incident and third-party reporting framework that takes effect on 18 March 2027. From that date a payment service provider that detects an operational incident meeting a reporting threshold must submit its initial report within four hours of detection. That four-hour window is not new: it already applies to a payment service provider under regulation 99 of the PSRs 2017, SUP 15.14 and the EBA Guidelines on major incident reporting. What changes is that the FCA subsumes the PSRs reporting regime into a single framework and states the four hours as a rule rather than as an expectation drawn from guidelines. A payment institution has to design and test its detection, escalation and reporting procedures well before then, because four hours leaves no time to build them once an incident has started.

The Critical Third Party regime came into force on 1 January 2025. The FCA, the PRA and the Bank of England published final rules in November 2024. HM Treasury, not the regulators, decides whether to designate a provider, generally on a recommendation from the regulators, and it made the first designations on 13 July 2026: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. The regulators’ rules apply to a designated provider from the date its designation regulations come into force. A designated Critical Third Party is subject to regulatory oversight that goes beyond the outsourcing rules. A payment firm that uses a designated provider must be able to meet supervisory expectations on testing, incident reporting and information access. On 14 January 2026 the UK financial regulators (the Bank of England, the Prudential Regulation Authority and the FCA) announced that they had signed a Memorandum of Understanding with the European Supervisory Authorities (the EBA, EIOPA and ESMA), which sets a framework for supervisory cooperation and information sharing between the UK Critical Third Parties regime and the equivalent oversight of critical ICT third-party service providers under DORA, and is intended to reduce duplication for providers serving both markets.

DORA took effect on 17 January 2025 for financial entities authorised in the EU. A UK group is caught through its EU-authorised subsidiaries and, contractually, where it provides ICT services to EU financial entities. DORA also carries its own critical third party regime. Under Articles 31 to 44 the European Supervisory Authorities designate a critical ICT third-party service provider, appoint one of their number as Lead Overseer for it, and oversee it directly, with powers to require information, conduct investigations and inspections, make recommendations and impose periodic penalty payments. That regime is the counterpart of the UK Critical Third Party regime and is what the Memorandum of Understanding above connects. DORA and the UK operational resilience regime are broadly aligned but differ in scope, definitions and enforcement. A firm that treats UK compliance as sufficient for DORA is left with gaps in its European risk management. A payment firm with international operations must therefore work on the tighter UK reporting timelines, the first Critical Third Party designations and DORA at the same time.

Operational resilience governance, mapping and outsourcing requirements

A payment firm sets an impact tolerance for each of its important business services under SYSC 15A.2.5R, and must review that exercise no later than one year after it last carried it out and whenever its business or its market changes materially (SYSC 15A.2.6R). Its governing body must approve, and regularly review, the written self-assessment that records the tolerances and the firm’s compliance with the chapter (SYSC 15A.7.1R, read with SYSC 15A.6.1R). The firm must also carry out scenario testing of its ability to remain within each tolerance in a severe but plausible disruption (SYSC 15A.5.3R). A framework owned by the technology function and recorded in a compliance document does not meet that requirement, because the board must be able to demonstrate that the firm’s critical services survive stress.

A firm must map its important business services across the whole chain, not payment processing alone: customer onboarding, fraud detection, settlement, reporting and dispute resolution each carry the continuity of the service to the customer. A narrow mapping produces impact tolerances that do not match the risk to customers and to the market. The firm must understand the dependencies behind each tolerance before it sets one. A two-hour tolerance for settlement means nothing until the firm has tested whether it can isolate settlement from its other systems, and whether its providers can work at that speed when its own systems fail.

An outsourcing contract for a critical function must address operational resilience directly. Standard terms on availability and performance do not cover partial or total failure of the provider, or a regulator requiring rapid intervention in the provider’s systems. The contract must carry the firm’s impact tolerances and testing expectations, with penalties and termination rights to match. A firm must also test failure modes beyond cyber attack: provider insolvency, loss of a data centre, loss of key individuals at a provider, regulatory intervention in the provider’s jurisdiction, and failures of shared infrastructure that affect several providers at once.

UK operational resilience compliance does not satisfy DORA. The two regimes have similar objectives but define a critical function differently, impose different governance requirements and set different reporting obligations, so a firm that meets the UK requirements can still fail DORA on system redundancy, testing scope or incident notification timelines. A payment firm with EU operations must run a separate gap analysis and remediate what it finds. It must also rebuild its incident response for the four-hour reporting window, separating detection, escalation and regulatory notification, so that it can establish the nature and severity of an incident in four hours rather than 24.

An operational resilience framework that meets the requirements

A framework that works starts with the board. The board approves the operational resilience policy and the impact tolerances each year, receives reporting on whether the firm remains within them, and approves the testing scenarios and the results. That is a governance obligation of the same order as capital adequacy or liquidity management, and the documentation is short and decision-focused rather than a compliance binder. The firm identifies its important business services by mapping the payment chain from customer onboarding through settlement and reconciliation, and from that map it identifies the minimum operations it needs to serve customers without material disruption. It calibrates its impact tolerances to its customer base and its role in the market, so a wholesale payments hub sets different tolerances from a retail acquirer. It then tests whether it can operate within them under stress, by shutting systems down, disconnecting from providers and observing whether payments continue to be processed inside the tolerance.

The firm’s outsourcing agreements carry explicit operational resilience protections: incident notification, testing participation, access to data and systems, change control, and termination rights if the provider comes under material operational stress. Its incident response separates detection, investigation and reporting. Detection identifies the incident and establishes preliminary severity, investigation runs in parallel and gathers the detail the regulator needs, and reporting delivers it inside the four-hour window. A firm with EU operations documents how the UK requirements differ from DORA and how it addresses each difference, updates that analysis each year and puts it to the board. The firm can then tell the FCA what its risk profile is and show that it has tested the scenarios that matter.

When to instruct an operational resilience specialist

A payment firm needs specialist advice when it is designing or reviewing an operational resilience framework from first principles, and in particular where the framework has not been tested or was built for a smaller or simpler operation. A board-level review of the framework, including challenge to the impact tolerance assumptions and the scenario testing, benefits from a view from outside the firm. A firm that outsources critical functions needs its outsourcing agreements reviewed for operational resilience: gaps in notification obligations, testing access and termination rights leave the firm exposed. A firm with EU operations needs a gap analysis between its UK framework and DORA before its FCA supervisor or the competent authority of the EU Member State in which its subsidiary is authorised finds the gap first. A firm that relies on a provider likely to be designated a Critical Third Party, or that may be designated itself, needs advice on the supervisory expectations and the contractual protections that follow. A firm designing incident response procedures for the four-hour reporting window needs those procedures reviewed, so that the roles and escalation paths work when they are used.

How Bratby Law helps with operational resilience

Bratby Law advises payment institutions, e-money institutions and payment service providers on operational resilience. The work covers the design of a governance framework that meets FCA expectations and places ownership with the board, and the mapping of important business services across the payment chain from onboarding to settlement so that impact tolerances match real dependencies. It covers the setting and stress-testing of those tolerances against cyber attack, provider failure, loss of a data centre and key-person dependency, and the review of outsourcing and third-party risk arrangements, in particular the contractual protections for provider failure, regulatory intervention and shared infrastructure breakdown. It also covers the design of incident reporting procedures for the four-hour window under PS26/2, gap analysis between the UK requirements and DORA for firms with EU operations, and the supervisory expectations that apply to a firm relying on a designated Critical Third Party.

Advice on operational resilience and DORA compliance

Frequently asked questions about operational resilience

Does DORA apply to UK payment firms?

DORA is an EU regulation and does not apply directly to UK-regulated payment firms. DORA applies to financial entities authorised in the EU, so a UK payment group is caught through any EU-authorised subsidiary, which must comply in its own right; the location of customers is not itself the trigger. UK firms can also meet DORA contractually, where they provide ICT services to EU financial entities or where an EU group entity must flow DORA’s ICT third-party requirements into shared group arrangements. The right approach is an entity-by-entity scope analysis against Article 2, not an assumption either way.

What are the UK operational resilience requirements for payment firms?

A UK-authorised payment firm must identify its important business services, set an impact tolerance for each one (the maximum time the firm can operate outside normal parameters without breaching customer or market expectations), and test that it can remain within those tolerances under stress. The firm sets the impact tolerances under SYSC 15A.2.5R and reviews that exercise at least once a year under SYSC 15A.2.6R. Its governing body must approve and regularly review the written self-assessment that records them, under SYSC 15A.7.1R. Operational resilience is a board-level governance obligation and not an IT function.

What is the new incident reporting framework?

The FCA and the PRA published PS26/2 in March 2026, and it takes effect on 18 March 2027. A payment service provider must report an operational incident within four hours, while other categories of regulated firm have longer. An incident is reportable where it meets one or more of three thresholds: it poses a risk of causing intolerable levels of harm to consumers from which they cannot easily recover, a risk to the safety and soundness of the firm or of other market participants, or a risk to market stability, market integrity or confidence in the UK financial system. A cyber attack, a system change that does not go to plan and disruption to a third party are causes of an incident, not thresholds in themselves. The four-hour window runs from detection, so a payment firm needs its detection procedures, its incident investigation capacity and its regulatory reporting processes ready well before that date.

What is the Critical Third Parties regime?

HM Treasury designates a third-party service provider as a Critical Third Party, generally on a recommendation from the FCA, the PRA and the Bank of England, where disruption to or failure of its services could threaten the stability of, or confidence in, the UK financial system. The regime took effect on 1 January 2025 and applies to a provider from the date its designation regulations come into force. A designated Critical Third Party must provide regular assurance, undertake resilience testing and report major incidents to the regulators. The first designations were made on 13 July 2026 and cover Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. A firm that depends on a designated Critical Third Party keeps the same obligation it had before designation, which is to manage its own third-party risk under the FCA’s operational resilience and outsourcing requirements. The assurance, resilience testing and major incident reporting obligations fall on the designated provider.

How quickly must payment firms report operational incidents?

From 18 March 2027 a payment service provider must report a material operational incident to the FCA within four hours of detection. That applies to incidents involving ICT systems, cyber attacks, third-party failures or other events affecting important business services. The four-hour window carries across the existing position for a payment service provider under regulation 99 of the PSRs 2017, SUP 15.14 and the EBA Guidelines on major incident reporting, and states it as a rule. A payment firm must design its detection and escalation processes to meet that timeline, and must be able to give preliminary notification within four hours even where its investigation continues afterwards.

What is the difference between UK operational resilience and DORA?

Both regimes require a financial firm to survive operational stress, but they differ in scope, governance requirements and enforcement. DORA defines a critical function more broadly than the FCA defines an important business service, and imposes more detailed requirements on system redundancy, testing and documentation. Under DORA a firm must disclose its critical third-party dependencies each year and must test its outsourcing arrangements at least annually. Enforcement differs: a National Competent Authority in each EU Member State enforces DORA, and the FCA supervises the UK requirements. A payment firm subject to both must address the differences through a separate gap analysis and remediation.

Do outsourcing arrangements need to address operational resilience?

Yes. A firm’s outsourcing agreement for a critical function must include explicit operational resilience protections, under FCA expectations and regulatory good practice. It must address incident notification and escalation, access to systems and data for audit and scenario testing, change control, testing participation by the provider, and termination rights if the provider comes under material operational stress. Standard outsourcing agreements frequently lack those protections and must be amended to meet the operational resilience requirements.

When should I review my operational resilience framework?

Review the framework now if you have not tested your impact tolerances under realistic stress conditions, if it predates 2024, if you have substantially expanded your services or your third-party dependencies, or if you have not designed procedures for the four-hour incident reporting window under PS26/2. The board should reapprove the operational resilience policy and the impact tolerances each year, and testing results should go to the board at each review. A firm with EU operations should review its DORA position at the same time as its UK assessment.

Related payments regulation pages

These pages cover the other payments obligations that apply to the same firms: