The operational-resilience, BCDR, and crisis-handling obligations that most likely apply to registered investment advisers — by regulator, domain, and compliance status. Filter and search the full set below.
ria_small · 138 likely-applicable · 0 excluded by asset sizeNote: Adviser tiering is AUM-based (e.g. SEC vs state at $100M/$110M AUM); balance-sheet asset thresholds in rules rarely bind advisers.
How this persona’s 138 applicable obligations distribute across cross-cutting themes. For the full lens (what each requires), run python3 -m regwatch.theme <theme> --persona ria_small.
| Theme | Obligations | of which proposed |
|---|---|---|
| Third-Party / Vendor Risk Management | 68 | |
| Cybersecurity × Resilience | 29 | |
| Incident Reporting & Notification | 63 | |
| Resilience Testing & Exercises | 20 |
| ID | Country | Regulator | Domain | Size trigger | Obligation (with source quote) | Citation | Status | Suggested evidence to comply |
|---|---|---|---|---|---|---|---|---|
OBL-00755 | United States | SEC | cybersecurity | Develop, implement, and maintain written policies and procedures for an incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. “require covered institutions to develop, implement, and maintain written policies and procedures for an incident response program that is reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information” | 17 CFR 248.30(a)(3) | final | Written incident response program policies and procedures; version history; board/senior management approval documentation | |
OBL-00756 | United States | SEC | cybersecurity | Include in the incident response program procedures to assess the nature and scope of any incident and identify customer information systems and types of customer information that may have been accessed or used without authorization. “Assess the nature and scope of any incident involving unauthorized access to or use of customer information and identify the customer information systems and types of customer information that may have been accessed or used without authorization” | 17 CFR 248.30(a)(3)(i) | final | Written assessment procedures within IRP; completed incident assessment records; logs identifying affected systems and data types | |
OBL-00757 | United States | SEC | cybersecurity | Include in the incident response program procedures to take appropriate steps to contain and control an incident to prevent further unauthorized access to or use of customer information. “Take appropriate steps to contain and control the incident to prevent further unauthorized access to or use of customer information” | 17 CFR 248.30(a)(3)(ii) | final | Written containment and control procedures within IRP; incident records showing containment actions taken; periodic review documentation | |
OBL-00761 | United States | SEC | cybersecurity | Include incident response program procedures for notifying affected individuals whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. [adjacent] “Notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization in accordance with the notification obligations discussed below” | 17 CFR 248.30(a)(3)(iii) | final | Written notification procedures within IRP; notification decision trees; records of notifications issued per incident | |
OBL-00762 | United States | SEC | cybersecurity | Establish, maintain, and enforce written policies and procedures for oversight of service providers, including due diligence and monitoring, to ensure service providers safeguard customer information and that affected individuals receive required notices. [adjacent] “covered institutions will be required to establish, maintain, and enforce written policies and procedures reasonably designed to require oversight, including through due diligence and monitoring of service providers, including to ensure that affected individuals receive any required notices” | 17 CFR 248.30(a)(5) | final | Written vendor oversight policies; due diligence records; service provider contracts with security/notification obligations; monitoring logs | |
OBL-00763 | United States | SEC | cybersecurity | Require service providers to notify the covered institution of a breach as soon as possible, but no later than 72 hours after the service provider becomes aware that an applicable breach has occurred. “the final amendments require covered institutions to ensure that their service providers provide notification as soon as possible, but no later than 72 hours after becoming aware that an applicable breach has occurred” | 17 CFR 248.30(a)(5)(i) | final | Vendor contracts containing 72-hour breach notification clauses; records of notifications received from service providers; breach intake logs | |
OBL-00765 | United States | SEC | cybersecurity | Adopt written policies and procedures with administrative, technical, and physical safeguards to protect customer records and information (safeguards rule), now extended to transfer agents. [adjacent] “The safeguards rule requires brokers, dealers, investment companies, and registered investment advisers to adopt written policies and procedures that address administrative, technical, and physical safeguards to protect customer records and information” | 17 CFR 248.30(a) | final | Written safeguards policy covering administrative, technical, and physical controls; evidence of transfer agent compliance; periodic review records | |
OBL-00768 | United States | SEC | cybersecurity | Periodically review and update incident response assessment and containment procedures to ensure they remain reasonably designed. “covered institutions generally should consider reviewing and updating the assessment procedures periodically to ensure that the procedures remain reasonably designed” | 17 CFR 248.30(a)(3) | final | Documented periodic review cycle for IRP; change logs showing updates; board or senior management approval of updated procedures | |
OBL-00769 | United States | SEC | cybersecurity | Delay customer notification only upon receiving a written request from the Attorney General that notification poses a substantial risk to national security or public safety, consistent with the Public Company Cybersecurity Rules framework. [adjacent] “the final amendments will permit covered institutions to delay providing notice after the Commission receives a written request from the Attorney General that this notice poses a substantial risk to national security or public safety” | 17 CFR 248.30(a)(4) | final | Procedures for handling Attorney General delay requests; records of any delay requests received and actions taken | |
OBL-00885 | European Union | EU_ESA | business continuity | Establish and maintain a sound, comprehensive and well-documented ICT risk management framework as part of the overall risk management system. “Financial entities shall have in place a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system” | Art. 6(1) Regulation (EU) 2022/2554 | final | Board-approved ICT risk management framework document; annual review records; integration evidence within overall risk management system | |
OBL-00886 | European Union | EU_ESA | business continuity | Identify, classify and document all ICT-supported business functions, roles, dependencies, assets and information assets critical to operations. “Financial entities shall identify, classify and adequately document all ICT supported business functions, roles and responsibilities, the information assets and ICT assets supporting those functions” | Art. 8(1) Regulation (EU) 2022/2554 | final | Asset inventory and classification register; mapping of ICT assets to critical business functions; documented dependencies | |
OBL-00887 | European Union | EU_ESA | business continuity | Continuously monitor and manage all sources of ICT risk, including risks posed by third-party ICT service providers, and implement protection and prevention measures. “Financial entities shall continuously monitor and control the security and functioning of ICT systems and tools and shall minimise the impact of ICT risk” | Art. 9(1)-(2) Regulation (EU) 2022/2554 | final | Continuous monitoring logs; vulnerability management records; evidence of preventive controls; third-party risk monitoring reports | |
OBL-00888 | European Union | EU_ESA | business continuity | Implement ICT business continuity policy and plans to ensure continuity of critical or important functions through ICT disruptions. “As part of the ICT risk management framework referred to in Article 6(1), financial entities shall put in place a comprehensive ICT business continuity policy” | Art. 11(1) Regulation (EU) 2022/2554 | final | Board-approved ICT BCP document; list of critical functions covered; activation criteria; defined RTO/RPO; annual review records | |
OBL-00891 | European Union | EU_ESA | business continuity | Develop and implement crisis communication plans to ensure effective communication to staff, stakeholders and public during ICT-related crises. “Financial entities shall have in place crisis communication plans enabling a responsible disclosure of, at least, major ICT-related incidents or vulnerabilities to clients, counterparts and the public” | Art. 14(1) Regulation (EU) 2022/2554 | final | Documented crisis communication plan; defined roles and spokespersons; internal/external notification templates; activation records | |
OBL-00892 | European Union | EU_ESA | business continuity | Designate a crisis communication manager responsible for managing communications during ICT-related incidents. “Financial entities shall designate a person responsible for implementing the communication strategy for ICT-related incidents and fulfil the public and media function for that purpose” | Art. 14(2) Regulation (EU) 2022/2554 | final | Named crisis communication manager; role description; evidence of appointment; escalation pathway documentation | |
OBL-00893 | European Union | EU_ESA | business continuity | Establish and maintain an ICT-related incident management process to detect, manage and notify major ICT-related incidents, including classification criteria. “Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents” | Art. 17(1) Regulation (EU) 2022/2554 | final | Incident management process documentation; classification criteria; incident log; escalation procedures; evidence of regular review | |
OBL-00894 | European Union | EU_ESA | business continuity | Classify ICT incidents and cyber threats using prescribed criteria (clients affected, duration, data loss, criticality, economic impact) and report major incidents to competent authorities. “Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria: the number of clients, counterparts or financial transactions affected” | Art. 18(1) Regulation (EU) 2022/2554 | final | Classification methodology aligned to RTS criteria; incident registers with classification evidence; major incident reports submitted to authorities | |
OBL-00895 | European Union | EU_ESA | business continuity | Submit initial, intermediate and final reports on major ICT-related incidents to the relevant competent authority within prescribed timeframes. “Financial entities shall submit: an initial notification; an intermediate report after the initial notification, as soon as the status of the original incident has changed significantly; a final report” | Art. 19(3) Regulation (EU) 2022/2554 | final | Templates for initial/intermediate/final reports; submission records with timestamps; evidence of authority acknowledgement | |
OBL-00896 | European Union | EU_ESA | business continuity | Perform a basic digital operational resilience testing programme annually, covering ICT tools, systems and processes supporting critical or important functions. “Financial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework” | Art. 25(1) Regulation (EU) 2022/2554 | final | Annual resilience testing plan and results; coverage of critical/important functions; gap remediation records; sign-off by management | |
OBL-00897 | European Union | EU_ESA | business continuity | Conduct threat-led penetration testing (TLPT) at least every three years on critical or important live production systems. “Financial entities shall carry out at least every 3 years advanced testing by means of TLPT. Based on the risk profile of the financial entity and taking into account operational circumstances” | Art. 26(1) Regulation (EU) 2022/2554 | final | TLPT scope documentation; testers' credentials (TIBER or equivalent); test results and remediation plans; authority notification records | |
OBL-00898 | European Union | EU_ESA | business continuity | Adopt a strategy on ICT third-party risk, including a policy for use of ICT services supporting critical or important functions, and review it annually. “As part of their ICT risk management framework, financial entities shall adopt and regularly review a strategy on ICT third-party risk, taking into account the multi-vendor strategy” | Art. 28(1) Regulation (EU) 2022/2554 | final | Board-approved third-party ICT risk strategy; annual review records; multi-vendor strategy documentation; concentration risk assessment | |
OBL-00899 | European Union | EU_ESA | business continuity | Before entering into ICT third-party arrangements for critical or important functions, assess concentration risk and risks of ICT service provider failure or unavailability. “Prior to entering into a contractual arrangement on the use of ICT services, financial entities shall: identify and assess all relevant risks in relation to the ICT third-party service provider” | Art. 28(4) Regulation (EU) 2022/2554 | final | Pre-contract due diligence reports; concentration risk analysis; risk registers; sign-off documentation before contract execution | |
OBL-00900 | European Union | EU_ESA | business continuity | Maintain and update a register of all contractual arrangements with ICT third-party service providers and report it to competent authorities upon request. “Financial entities shall maintain and update at entity level, at sub-consolidated and at consolidated level, a register of information in relation to all contractual arrangements on the use of ICT services” | Art. 28(3) Regulation (EU) 2022/2554 | final | Centralised ICT third-party contract register; evidence of regular updates; submission records to competent authority | |
OBL-00901 | European Union | EU_ESA | business continuity | Ensure contractual arrangements with ICT third-party providers for critical/important functions include mandatory clauses on business continuity, availability, recovery and exit strategies. “Contractual arrangements on the use of ICT services shall include at minimum: the description of full service levels including updates and revisions thereof; the obligations of the ICT third-party service provider to provide assistance at no additional cost” | Art. 30(2) Regulation (EU) 2022/2554 | final | Contract clauses checklist aligned to Art. 30 requirements; contract review records; evidence of remediated legacy contracts | |
OBL-00902 | European Union | EU_ESA | business continuity | Establish exit strategies for ICT third-party arrangements on critical or important functions to ensure continuity if a provider fails or is discontinued. “Financial entities shall, taking into account the specificities of the ICT services to be provided, have exit strategies in order to be able to terminate, without detriment to their regulated activities, the relevant contractual arrangements” | Art. 28(8) Regulation (EU) 2022/2554 | final | Documented exit strategies per critical provider; portability assessments; alternative provider lists; transition plan templates | |
OBL-00903 | European Union | EU_ESA | business continuity | Include in ICT contracts with providers of critical/important functions rights to audit, access data, and require participation in incident response and recovery activities. “Contractual arrangements for the provision of ICT services supporting critical or important functions shall include: full cooperation of the ICT third-party service provider with the competent authorities and the resolution authorities of the financial entity” | Art. 30(3) Regulation (EU) 2022/2554 | final | Contract audit-right and cooperation clauses; evidence of audit execution; incident response cooperation records from providers | |
OBL-00904 | European Union | EU_ESA | business continuity | Implement protection measures including data integrity, encryption and access controls to safeguard ICT assets and ensure resilience of ICT infrastructure. “Financial entities shall develop, document and implement a policy on ICT security giving formal mandate to protect confidentiality, integrity, and availability of data” | Art. 9(3) Regulation (EU) 2022/2554 | final | ICT security policy; encryption and access control standards; evidence of implementation; penetration test results; periodic review records | |
OBL-00905 | European Union | EU_ESA | business continuity | Maintain backup systems and data restore procedures tested regularly, with backup systems physically and logically separate from primary systems. “Financial entities shall put in place backup policies and procedures. Financial entities shall have backup systems that can be activated without undue delay” | Art. 12(1) Regulation (EU) 2022/2554 | final | Backup policy; evidence of physical/logical separation; restore test records and success metrics; RTO/RPO alignment documentation | |
OBL-00906 | European Union | EU_ESA | business continuity | Detect anomalous activity, identify potential single points of failure, and implement measures to address ICT concentration risk in own infrastructure. “Financial entities shall identify all sources of ICT risk and shall assess cyber threats and ICT vulnerabilities relevant to their ICT supported business functions, information assets and ICT assets” | Art. 8(4) Regulation (EU) 2022/2554 | final | ICT risk assessment reports; single point of failure analysis; concentration risk register; remediation plans with target dates | |
OBL-00907 | European Union | EU_ESA | business continuity | Ensure the management body defines, approves, oversees and is accountable for the ICT risk management framework and digital operational resilience strategy. “The management body of the financial entity shall define, approve, oversee and be accountable for the implementation of all arrangements related to the ICT risk management framework” | Art. 5(1) Regulation (EU) 2022/2554 | final | Board resolution approving ICT risk framework; board-level oversight records; assigned accountability documentation; training completion records | |
OBL-00908 | European Union | EU_ESA | business continuity | Conduct post-incident reviews after major ICT incidents to identify root causes and implement corrective actions to prevent recurrence. “After a major ICT-related incident, financial entities shall perform a post-incident review to determine the root causes of disruptions and identify improvements to be applied to the ICT operations” | Art. 17(6) Regulation (EU) 2022/2554 | final | Post-incident review reports with root-cause analysis; corrective action plans with owners and deadlines; evidence of implementation | |
OBL-00909 | European Union | EU_ESA | business continuity | Share cyber threat intelligence and information on ICT vulnerabilities and incidents with other financial entities under appropriate confidentiality arrangements. [adjacent] “Financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques, and procedures, cyber alerts and configuration tools” | Art. 45(1) Regulation (EU) 2022/2554 | final | Information-sharing agreements; records of threat intelligence shared/received; confidentiality controls; participation in sector ISACs | |
OBL-01008 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must establish a quality management system ensuring the AI system meets robustness, accuracy and cybersecurity requirements throughout its lifecycle. [adjacent] “Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation.” | Art. 17(1) | final | Written QMS documentation covering robustness/cybersecurity controls; audit trail; version control records | |
OBL-01009 | European Union | EU_AI | artificial intelligence | High-risk AI systems must be designed and developed to achieve appropriate levels of accuracy, robustness and cybersecurity, and to perform consistently in those respects throughout their lifecycle. [adjacent] “High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.” | Art. 15(1) | final | Technical documentation showing robustness/cybersecurity design measures; test results; lifecycle maintenance records | |
OBL-01010 | European Union | EU_AI | artificial intelligence | High-risk AI systems must be resilient against attempts by third parties to alter their use or performance through adversarial attacks exploiting system vulnerabilities. “High-risk AI systems shall be resilient as regards attempts by unauthorised third parties to alter their use, outputs or performance by exploiting the system vulnerabilities.” | Art. 15(3) | final | Adversarial testing reports; penetration test results; vulnerability management log; incident response procedures | |
OBL-01011 | European Union | EU_AI | artificial intelligence | High-risk AI systems must have technical redundancy solutions, including backup or fail-safe plans, to ensure continuity of operation when failures occur. “The technical robustness and safety measures shall include redundancy solutions, which may include backup or fail-safe plans.” | Art. 15(4) | final | Documented backup/fail-safe architecture; failover test results; continuity runbooks | |
OBL-01012 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must establish post-market monitoring systems to proactively collect and review data on system performance and safety after deployment. [adjacent] “Providers of high-risk AI systems shall establish and document a post-market monitoring system in a manner that is proportionate to the nature of the AI technologies and the risks of the high-risk AI system.” | Art. 72(1) | final | Post-market monitoring plan; performance dashboards; incident/anomaly logs; periodic review reports | |
OBL-01013 | European Union | EU_AI | artificial intelligence | Providers must report serious incidents involving high-risk AI systems to market surveillance authorities immediately and in any event within prescribed timeframes. [adjacent] “Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred.” | Art. 73(1) | final | Incident reporting procedure; incident log with timestamps; regulatory notification records within required timeframes | |
OBL-01014 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must immediately take corrective actions, including withdrawal or recall, when the system presents a risk, and inform distributors, deployers and authorities accordingly. [adjacent] “Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity.” | Art. 20(1) | final | Corrective action log; recall/withdrawal procedures; communications to deployers and authorities | |
OBL-01015 | European Union | EU_AI | artificial intelligence | High-risk AI systems must enable human oversight including the ability to override, interrupt or shut down the system to prevent or minimise risks. [adjacent] “High-risk AI systems shall be designed and developed in such a way to enable the persons to whom human oversight is assigned to be able to … intervene on the operation of the high-risk AI system or interrupt the system through a 'stop' button or a similar procedure.” | Art. 14(4)(e) | final | Technical design documentation showing stop/override functionality; human oversight procedures; operator training records | |
OBL-01016 | European Union | EU_AI | artificial intelligence | High-risk AI systems must automatically detect and flag failures, faults, or inconsistencies that may result in risks, and be able to operate in a safe state in the event of such failures. “High-risk AI systems shall be resilient as regards … errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems.” | Art. 15(3) | final | Fault detection test records; safe-state design documentation; automated alerting configuration | |
OBL-01017 | European Union | EU_AI | artificial intelligence | Deployers of high-risk AI systems must monitor system operation on the basis of instructions of use and report to the provider any risks or incidents identified during use. [adjacent] “Deployers of high-risk AI systems shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers about serious incidents.” | Art. 26(5) | final | Operational monitoring logs; incident reports sent to providers; documented review cadence per instructions of use | |
OBL-01018 | European Union | EU_AI | artificial intelligence | Providers of general-purpose AI models with systemic risk must perform adversarial testing and red-teaming to identify and mitigate systemic risks including cybersecurity vulnerabilities. [adjacent] “Providers of general-purpose AI models with systemic risk shall … perform model evaluation in accordance with standardised protocols and tools … including adversarial testing of the model to identify and mitigate systemic risks.” | Art. 55(1)(a) | final | Red-team/adversarial test plans and results; risk mitigation records; model evaluation reports | |
OBL-01019 | European Union | EU_AI | artificial intelligence | Providers of general-purpose AI models with systemic risk must assess and mitigate systemic risks including risks to critical infrastructure and serious cyber threats. [adjacent] “Providers of general-purpose AI models with systemic risk shall … assess and mitigate possible systemic risks, including their sources, that may stem from the development, the placing on the market, or the use of general-purpose AI models with systemic risk.” | Art. 55(1)(b) | final | Systemic risk assessment report covering critical infrastructure and cyber threat scenarios; mitigation plan | |
OBL-01020 | European Union | EU_AI | artificial intelligence | Providers of general-purpose AI models with systemic risk must track, document and report serious incidents and possible corrective measures to the AI Office without undue delay. [adjacent] “Providers of general-purpose AI models with systemic risk shall … track, document and report, without undue delay, to the AI Office and, as applicable, to national competent authorities, relevant information about serious incidents and possible corrective measures.” | Art. 55(1)(c) | final | Incident tracking log; documented corrective measures; notification records to AI Office; timestamps of reports | |
OBL-01021 | European Union | EU_AI | artificial intelligence | Providers of general-purpose AI models with systemic risk must ensure adequate cybersecurity protection for the model and its physical infrastructure. [adjacent] “Providers of general-purpose AI models with systemic risk shall … ensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model.” | Art. 55(1)(d) | final | Cybersecurity policy; infrastructure hardening records; penetration test results; access control documentation | |
OBL-01022 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must keep automatically generated logs for the period appropriate to the intended purpose, to enable incident investigation and monitoring. [adjacent] “High-risk AI systems shall technically allow for the automatic recording of events ('logs') over the lifetime of the system.” | Art. 12(1) | final | Log retention policy; automated logging configuration; sample logs demonstrating traceability of events | |
OBL-01023 | European Union | EU_AI | artificial intelligence | Providers must ensure high-risk AI systems have automatic logging capabilities that enable reconstruction of events over the period of the AI system's use to support post-incident investigation. “The logging capabilities shall ensure a level of traceability of the AI system's functioning throughout its lifetime that is appropriate to the intended purpose of the system.” | Art. 12(2) | final | Logging architecture documentation; evidence that logs capture sufficient events for incident reconstruction; retention schedule | |
OBL-01024 | European Union | EU_AI | artificial intelligence | Deployers of high-risk AI systems must retain logs automatically generated by the system for a minimum period as applicable, to support incident investigation and regulatory oversight. [adjacent] “Deployers of high-risk AI systems shall retain the logs automatically generated by that high-risk AI system to the extent such logs are under their control.” | Art. 26(6) | final | Log retention records; access controls on logs; documented retention periods; log inventory | |
OBL-01025 | European Union | EU_AI | artificial intelligence | Providers must include instructions for use with high-risk AI systems specifying the expected lifetime and maintenance/servicing measures required to ensure continued safe and accurate operation. [adjacent] “The instructions for use shall include … where relevant, a description of the maintenance and care measures … to ensure that the AI system continues to comply with the requirements set out in this Chapter.” | Art. 13(3)(b)(v) | final | Instructions for use document containing maintenance schedules and servicing requirements; evidence of provision to deployers | |
OBL-01029 | European Union | EU_AI | artificial intelligence | National competent authorities must conduct market surveillance of AI systems to detect, investigate and remedy non-conformities that present risks, including operational and cybersecurity risks. [adjacent] “Market surveillance authorities shall perform market surveillance of AI systems made available on the market, put into service or used in the Union in accordance with this Regulation.” | Art. 74(1) | final | Market surveillance programme documentation; investigation records; risk-based inspection plans; corrective action orders | |
OBL-01031 | European Union | EU_AI | artificial intelligence | Providers and deployers of AI systems used by critical infrastructure operators must ensure those systems meet all high-risk AI system requirements including robustness and continuity of safe operation. “High-risk AI systems referred to in Article 6(2) are the AI systems listed in any of the following areas: … 2. AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.” | Annex III, point 2 | final | Classification assessment confirming critical infrastructure scope; conformity documentation; operational resilience test evidence | |
OBL-01032 | European Union | EU_AI | artificial intelligence | Providers of high-risk AI systems must systematically perform conformity assessments including evaluation of robustness and cybersecurity requirements before placing the system on the market or putting it into service. [adjacent] “For high-risk AI systems listed in Annex III, the conformity assessment shall be carried out by the provider … prior to placing it on the market or putting it into service.” | Art. 43(1) | final | Completed conformity assessment records; third-party audit reports where applicable; technical file cross-reference | |
OBL-01033 | United Kingdom | UK_FCA | business continuity | Identify important business services (IBS) — those whose disruption could cause intolerable harm to clients or risk to market integrity. “our rules only require firms to identify their important business services for the purposes of operational resilience” | SYSC 15A.2.1R–2R | final | Documented register of IBS with rationale; board or senior management sign-off; annual review records | |
OBL-01034 | United Kingdom | UK_FCA | business continuity | Review IBS at least annually or upon any material change to the business or market. “firms will need to review their important business services at least once per year, or whenever there is a material change to their business or the market in which they operate” | SYSC 15A.2.1R–2R | final | Annual review log with date, scope, and outcome; change-management trigger records | |
OBL-01035 | United Kingdom | UK_FCA | business continuity | Set an impact tolerance for each IBS at the first point at which disruption would cause intolerable harm to clients or risk to market integrity. “firms should set their impact tolerances at the first point at which a disruption to an important business service would cause intolerable levels of harm to consumers or risk to market integrity” | SYSC 15A.2.1R–2R; SYSC 15A.2.7G | final | Written impact tolerance statements per IBS, signed off by board; methodology documentation | |
OBL-01036 | United Kingdom | UK_FCA | business continuity | Use time/duration as a mandatory metric when measuring impact tolerances, supplemented by additional metrics as appropriate. “we are proceeding as consulted to require that firms use time/duration as a mandatory metric to measure their impact tolerances” | SYSC 15A.2.1R–2R | final | Impact tolerance documents specifying a time-based threshold (e.g. hours/days or end-of-day) per IBS, with any additional metrics | |
OBL-01037 | United Kingdom | UK_FCA | business continuity | Review impact tolerances at least annually or upon material change to the business or market. “firms should set and review their impact tolerances at least once per year or if there is a relevant change to the firm's business or the market in which it operates” | SYSC 15A.2.1R–2R | final | Annual tolerance review records; change-triggered review logs | |
OBL-01038 | United Kingdom | UK_FCA | business continuity | Remain within impact tolerances as soon as reasonably practicable, and no later than 31 March 2025. “Firms must be able to remain within their impact tolerances as soon as reasonably practicable, but no later than 3 years after the rules come into effect on 31 March 2022” | PS21/3 Chapter 1 para 1.32 | final | Board attestation that firm operates within all IBS tolerances; testing evidence; gap-closure roadmap | |
OBL-01039 | United Kingdom | UK_FCA | business continuity | Map each IBS by identifying and documenting the people, processes, technology, facilities and information that support it. “firms have a clear picture of the resources that enable an important business service to function... by identifying and documenting the people, processes, technology, facilities and information that support them” | SYSC 15A | final | IBS mapping artefacts (process maps, dependency registers, asset inventories) for each IBS | |
OBL-01040 | United Kingdom | UK_FCA | business continuity | Capture internal processes (e.g. payroll, IT services) that support IBS delivery within mapping exercises. “internal processes... which are necessary to the provision of important business services and should be captured by firms as part of their mapping exercises” | SYSC 15A | final | Mapping documentation that includes supporting internal processes with linkage to relevant IBS | |
OBL-01041 | United Kingdom | UK_FCA | business continuity | Conduct scenario testing of each IBS against severe but plausible scenarios to assess ability to remain within impact tolerances. “firms need to test their impact tolerances in a range of severe but plausible scenarios. This approach will give firms a clear idea when they initially test their impact tolerances of where such unexpected events may mean they cannot remain within tolerance” | SYSC 15A | final | Scenario testing plan; test results per IBS per scenario; remediation actions; board reporting | |
OBL-01042 | United Kingdom | UK_FCA | business continuity | Include cyber-attacks as a scenario category in scenario testing plans for IBS. “multiple important business services could be disrupted simultaneously due to an external factor directly affecting the service. For example, this could be due to a cyber-attack which hits a wide range of operational assets” | SYSC 15A; PS21/3 Chapter 3 para 3.12 | final | Scenario testing records explicitly including cyber-attack scenarios; test outcomes and remediation steps | |
OBL-01043 | United Kingdom | UK_FCA | business continuity | Consider the simultaneous disruption of multiple IBS in testing plans, including shared underlying systems, processes or people. “for substitute services which rely on the same systems, processes or people, firms should not assume, as part of their testing plans, that these services won't be affected in the event of disruption” | SYSC 15A; PS21/3 Chapter 3 para 3.12 | final | Multi-IBS disruption scenario plans; dependency analysis showing common assets; test results | |
OBL-01044 | United Kingdom | UK_FCA | business continuity | Identify key staff pivotal to delivering each IBS and maintain contingency plans for their incapacitation. “firms need to understand which staff are pivotal to delivering an important business service, with contingency plans if those staff become incapacitated” | SYSC 15A; PS21/3 Chapter 1 para 1.21 | final | Key-person register per IBS; documented contingency/succession plans; evidence of testing | |
OBL-01045 | United Kingdom | UK_FCA | business continuity | Report to the FCA any failure to remain within impact tolerances in line with SYSC 15A.2.11G. “if despite extensive scenario testing a firm finds itself not able to remain within impact tolerance for any reason, it should report the issue to the FCA in line with SYSC 15A.2.11G” | SYSC 15A.2.11G | final | Incident log; breach notification records submitted to FCA; internal escalation policy referencing SYSC 15A.2.11G | |
OBL-01046 | United Kingdom | UK_FCA | business continuity | Also report to the FCA where resuming a compromised service would cause further detriment (e.g. spreading a computer virus). “firms should consider such circumstances in their testing plans and report any issue with remaining in tolerance to the FCA in line with SYSC 15A.2.11G” | SYSC 15A.2.11G; PS21/3 Chapter 3 | final | Decision framework for safe resumption of compromised services; FCA notification records; board/SMF sign-off | |
OBL-01047 | United Kingdom | UK_FCA | business continuity | When outsourcing IBS to third parties, work effectively with those providers to set and remain within impact tolerances; responsibility remains with the firm. “When a firm is using a third-party provider in the provision of important business services, it should work effectively with that provider to set and remain within impact tolerances. Ultimately, the requirements... remain the responsibility of the firm” | SYSC 15A; PS21/3 Chapter 3 para 3.14 | final | Outsourcing contracts referencing impact tolerances; third-party assurance reports; joint testing records | |
OBL-01048 | United Kingdom | UK_FCA | business continuity | Identify and manage third-party dependencies (including cloud providers and technology vendors) within IBS mapping to address concentration and continuity risk. “the pandemic highlighted increasing dependence on third parties and outsourcing arrangements... some firms experienced challenges with offshore third-party providers... which affected continuity of service to UK consumers” | SYSC 15A; PS21/3 Chapter 1 para 1.19(b) | final | Third-party dependency register per IBS; concentration risk assessment; contingency plans for critical provider failure | |
OBL-01049 | United Kingdom | UK_FCA | business continuity | Ensure scenario testing incorporates third-party/outsourced service disruptions, including offshore provider lockdowns. “some firms experienced challenges with offshore third-party providers, particularly where providers were under lockdown in another geographical location, which affected continuity of service” | SYSC 15A; PS21/3 Chapter 1 para 1.19(b) | final | Testing scenarios covering third-party failure; offshore lockdown scenarios; test results and remediation plans | |
OBL-01050 | United Kingdom | UK_FCA | business continuity | Identify the users of each IBS so that impacts of disruption are clear and communications/alternative mechanisms can be targeted. “users of the service should be identifiable so that the impacts of disruption (through process, cyber security or technology failures) are clear” | SYSC 15A.2.4G(1); PS21/3 Chapter 2 para 2.21 | final | Service-user identification records per IBS; segmentation analysis including vulnerable consumers | |
OBL-01051 | United Kingdom | UK_FCA | business continuity | Consider the needs of vulnerable consumers when setting impact tolerances and design communications/alternative mechanisms to minimise their harm during disruptions. “Consideration of the needs of vulnerable consumers is central to a firm's setting of an impact tolerance, and firms should consider these groups when considering how much disruption could be tolerated. Firms should also construct communications and alternative mechanisms to minimise harms” | SYSC 15A.2.7G | final | Tolerance rationale documents referencing vulnerable consumer analysis; communications plan for disruption events | |
OBL-01052 | United Kingdom | UK_FCA | business continuity | Dual-regulated firms must set up to 2 impact tolerances per IBS — one aligned to FCA objectives and one aligned to PRA objectives. “For dual-regulated firms, we maintain the position that these firms should set up to 2 impact tolerances. This is to ensure that firms consider their impact tolerances in line with the statutory objectives of each authority” | SYSC 15A; PS21/3 Chapter 3 para 3.18–3.20 | final | Two documented impact tolerances per IBS with distinct FCA/PRA rationale; board approval records | |
OBL-01053 | United Kingdom | UK_FCA | business continuity | Dual-regulated firms' recovery and response arrangements must be viable for both shorter and longer impact tolerance periods. “its recovery and response arrangements are also appropriate for the longer tolerance (ie recovery and response arrangements must be viable for both shorter and longer time periods)” | SYSC 15A; PS21/3 Chapter 3 para 3.20 | final | Recovery/response plan documentation demonstrating viability across both tolerance periods; test evidence | |
OBL-01054 | United Kingdom | UK_FCA | business continuity | Where group-level impact tolerances differ from entity-level tolerances, the group Board must consider, approve and resource the entity's tolerance. “In situations where an entity sets an impact tolerance at a lower level than that set by the group, the group's Board should consider and approve... and ensure that the entity has appropriate resources to meet its identified tolerance” | PS21/3 Chapter 3 para 3.10 | final | Board minutes approving entity-level tolerances; resource allocation documentation; group vs entity tolerance comparison | |
OBL-01055 | United Kingdom | UK_FCA | business continuity | Assess, before resuming a degraded service, whether (a) it can safely resume without causing further detriment and (b) resumption benefits outweigh keeping the service unavailable. “firms should consider whether (a) the degraded service can safely resume without causing further detriment and (b) the benefits of resuming a degraded service outweigh the negatives of keeping the service unavailable until the issues have been remediated” | SYSC 15A.2.11G; PS21/3 Chapter 3 | final | Documented safe-resumption decision framework; incident records showing application of criteria; SMF sign-off | |
OBL-01057 | United Kingdom | UK_FCA | business continuity | Payments/e-money firms must apply operational resilience requirements only to their payments and/or e-money activities where other FSMA activities are not in scope. “payments firms only have to apply our operational resilience proposals to their payments and/or e-money activities. To clarify this, we have amended SYSC 15A.1 (Application)” | SYSC 15A.1 | final | Scoping documentation confirming which activities are subject to SYSC 15A; rationale for exclusion of any FSMA activities | |
OBL-01336 | United States | SEC | cybersecurity | Disclose any material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining the incident is material, describing nature, scope, timing, and impact. [adjacent] “An Item 1.05 Form 8-K must be filed within four business days of determining an incident was material.” | 17 CFR 249.308, Form 8-K Item 1.05; 17 CFR 240.13a-11 | final | Filed Form 8-K Item 1.05; internal materiality determination memo; incident log with determination date; description of nature, scope, timing, and impact | |
OBL-01337 | United States | SEC | cybersecurity | Make a materiality determination regarding a cybersecurity incident as soon as reasonably practicable after discovery of the incident. [adjacent] “a registrant shall make a materiality determination regarding a cybersecurity incident as soon as reasonably practicable after discovery of the incident.” | Form 8-K Item 1.05, Instruction 1 | final | Written incident response procedure specifying materiality assessment timeline; dated materiality determination records for each incident | |
OBL-01339 | United States | SEC | cybersecurity | Disclose in periodic reports (Form 10-K / Form 20-F) the registrant's processes for assessing, identifying, and managing material risks from cybersecurity threats. [adjacent] “Registrants must describe their processes, if any, for the assessment, identification, and management of material risks from cybersecurity threats.” | 17 CFR 229.106(b) | final | Annual report Item 106(b) disclosure; documented risk management framework; evidence of third-party assessor engagement if applicable | |
OBL-01342 | United States | SEC | cybersecurity | Disclose in periodic reports the board of directors' oversight of risks from cybersecurity threats. [adjacent] “Describe the board's oversight of risks from cybersecurity threats.” | 17 CFR 229.106(c); Form 20-F | final | Annual report board oversight disclosure; board committee charters; board meeting minutes referencing cybersecurity oversight activities | |
OBL-01344 | United States | SEC | cybersecurity | Foreign Private Issuers must describe in Form 20-F management's role in assessing and managing material cybersecurity risks. [adjacent] “FPIs must: Describe management's role in assessing and managing material risks from cybersecurity threats.” | 17 CFR 249.220f; Form 20-F | final | Form 20-F annual report cybersecurity governance section; management role descriptions; supporting internal governance documentation | |
OBL-01347 | United States | SEC | cybersecurity | A registrant may delay an Item 1.05 Form 8-K filing only where the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety. [adjacent] “A registrant may delay filing as described below, if the United States Attorney General determines immediate disclosure would pose a substantial risk to national security or public safety.” | Form 8-K Item 1.05; 17 CFR 240.13a-11 | final | Written Attorney General determination on file; documented delay justification; record of filing date relative to AG determination receipt | |
OBL-01625 | United States (CA) | CA_PRIVACY | cybersecurity | Establish and maintain a cybersecurity program consisting of policies, procedures, and practices that protect personal information from unauthorized access, destruction, use, modification, or disclosure, and protect against loss of availability of personal information. [adjacent] “"Cybersecurity program" means the policies, procedures, and practices that protect personal information from unauthorized access, destruction, use, modification, or disclosure; and protect against unauthorized activity resulting in the loss of availability of personal information.” | § 7001(k) | final | Written cybersecurity program documentation covering all enumerated protections; policies and procedures manual; evidence of implementation and periodic review. | |
OBL-01627 | United States (CA) | CA_PRIVACY | cybersecurity | Create a cybersecurity audit report documenting the required information for each completed annual cybersecurity audit. [adjacent] “"Cybersecurity audit report" means the document that every business must create as part of its cybersecurity audit. The cybersecurity audit report includes the information set forth in section 7123, subsection (e).” | § 7001(l) | final | Completed cybersecurity audit report containing all elements specified in § 7123(e); version history showing annual updates. | |
OBL-01629 | United States (CA) | CA_PRIVACY | cybersecurity | Conduct penetration testing of information systems by authorizing attempted circumvention or defeat of security features to identify vulnerabilities that could compromise availability or security of personal information. [adjacent] “"Penetration testing" means testing the security of an information system by attempting to circumvent or defeat its security features by authorizing attempted penetration of the information system.” | § 7001(bb) | final | Penetration testing authorization letters; test reports with findings and remediation tracking; schedule showing periodic conduct of testing. | |
OBL-01630 | United States (CA) | CA_PRIVACY | cybersecurity | Manage and control privileged accounts to prevent unauthorized configuration changes or unauthorized access that could affect availability and security of personal information. [adjacent] “"Privileged account" means any authorized user account or service account that can be used to perform functions that other user accounts are not authorized to perform, including but not limited to the ability to add, change, or remove other accounts, or make configuration changes to an information s” | § 7001(hh) | final | Privileged account inventory; access control policy; periodic access reviews/recertification records; audit logs for privileged account activity. | |
OBL-01631 | United States (CA) | CA_PRIVACY | cybersecurity | Scope the business's information system (including third-party-owned resources used for processing personal information) within the cybersecurity program and audit, addressing risks to all such resources. [adjacent] “"Information system" means the resources (e.g., network, hardware, and software) organized for the processing of personal information or that can provide access to personal information. The business's information system includes the resources organized for the business's processing of personal infor” | § 7001(t) | final | Asset inventory including third-party-hosted resources; contractual evidence of security requirements imposed on third-party providers; audit scope documentation. | |
OBL-01808 | United Kingdom | UK_FCA | business continuity | Establish sound, effective and comprehensive strategies, controls, processes and systems to enable compliance with all CTPS operational resilience rules. “A critical third party must have in place sound, effective and comprehensive strategies, controls, processes and systems that enable it to comply with the rules in CTPS.” | CTPS 4.1.1R | final | Written framework document; board/senior management approval; proportionality assessment per CTPS 4.1.2R; periodic review records. | |
OBL-01809 | United Kingdom | UK_FCA | business continuity | Establish governance arrangements that include a named regulator liaison, clear escalation channels, and an approach covering prevention, response, adaptation and recovery from CTP operational incidents. “A critical third party must ensure that its governance arrangements promote the resilience of any systemic third party service it provides, including by... establishing, overseeing and implementing an approach that covers... prevent, respond and adapt to, as well as recover from, any CTP operational” | CTPS 4.2.1R | final | Governance policy; named individual(s) with regulator contact details notified in writing; documented escalation and incident response governance structure. | |
OBL-01810 | United Kingdom | UK_FCA | business continuity | Implement lessons learned from CTP operational incidents and from testing and exercising into governance and operational arrangements. “implementing lessons learned from CTP operational incidents and any testing and exercising undertaken, including but not limited to that undertaken in accordance with CTPS 5.” | CTPS 4.2.1R(4) | final | Post-incident review logs; lessons-learned register; documented updates to playbooks, processes or controls with evidence of governance approval. | |
OBL-01811 | United Kingdom | UK_FCA | business continuity | Identify, monitor and manage risks to ability to deliver systemic third party services, and regularly update risk management processes using lessons from incidents, regulator engagement and testing. “A critical third party must manage effectively risks to its ability to deliver a systemic third party service including by: (1) identifying and monitoring relevant external and internal risks; (2) ensuring that it has in place risk management processes... (3) regularly updating its risk management p” | CTPS 4.3.1R | final | Risk register; risk management framework; evidence of regular reviews and updates; audit trail of changes triggered by incidents or testing. | |
OBL-01812 | United Kingdom | UK_FCA | business continuity | Identify and manage supply chain risks that could affect delivery of systemic third party services, including risks from key nth-party providers. “A critical third party must... identify and manage any risks to its supply chain that could affect its ability to deliver a systemic third party service.” | CTPS 4.4.1R | final | Supply chain risk register; documented mapping of key nth-party providers; risk assessments; contractual controls; periodic review records. | |
OBL-01813 | United Kingdom | UK_FCA | business continuity | Take reasonable steps to ensure key nth-party providers and connected persons in the supply chain are informed of CTP duties, cooperate in meeting them, and grant regulators access to relevant information. “A critical third party must take reasonable steps to ensure that its key nth-party providers and persons connected with a critical third party that are part of its supply chain: (1) are informed of the CTP duties... (2) cooperate... (3) provide the regulators with access to any information.” | CTPS 4.4.2R | final | Contractual clauses with nth-party providers; evidence of notifications issued; records of cooperation mechanisms; regulatory access provisions in contracts. | |
OBL-01814 | United Kingdom | UK_FCA | business continuity | Take reasonable steps to ensure the technology resilience of systemic third party services, including sound cyber resilience strategies and regular testing and exercising of those strategies. “A critical third party must... take reasonable steps to ensure the resilience of any technology that delivers, maintains or supports a systemic third party service, including by having: (1) sound, effective and comprehensive strategies... to adequately manage risks to its technology and cyber resili” | CTPS 4.5.1R | final | Technology and cyber resilience strategy; penetration test results; vulnerability management records; test schedules and outcomes; evidence of lessons-learned updates. | |
OBL-01815 | United Kingdom | UK_FCA | business continuity | Implement systematic change management for systemic third party services, including risk assessment, testing, verification and approval of all changes before implementation to minimise disruption risk. “A critical third party must ensure that it has a systematic and effective approach to dealing with changes to a systemic third party service... implementing any change... in a way that minimises appropriately the risk of any CTP operational incident occurring; and ensuring that prior to being implem” | CTPS 4.6.1R | final | Change management policy; change log with risk assessments, test results and approvals; evidence of pre-implementation verification for material changes. | |
OBL-01816 | United Kingdom | UK_FCA | business continuity | Within 12 months of Treasury designation, map and document all resources, persons, assets, supporting services, technology, and interdependencies used to deliver each systemic third party service; update regularly thereafter. “A critical third party must: (1) within 12 months of being designated by the Treasury, identify and document: (a) the resources... used to deliver, support and maintain each systemic third party service... and (b) any internal and external interconnections and interdependencies... and (2) thereafter” | CTPS 4.7.1R | final | Service mapping documentation per systemic service; asset and dependency register; dated version history showing regular updates. | |
OBL-01817 | United Kingdom | UK_FCA | business continuity | Implement measures to respond to and recover from CTP operational incidents, set a maximum tolerable level of disruption for each systemic service, and maintain an incident management playbook within 12 months of designation. “A critical third party must manage effectively CTP operational incidents including by: (1) implementing appropriate measures to respond to and recover from CTP operational incidents... (2) setting an appropriate maximum tolerable level of disruption... (3) maintaining and operating an incident manag” | CTPS 4.8.1R | final | Documented incident response and recovery measures; defined and documented maximum tolerable disruption level per service; completed incident management playbook with version control. | |
OBL-01818 | United Kingdom | UK_FCA | business continuity | The incident management playbook must set out plans and procedures to respond to and recover from CTP operational incidents and facilitate effective communication with regulators and affected firms. “maintaining and operating an incident management playbook... which sets out the plans and procedures to be followed by the critical third party in the event of a CTP operational incident in order to: (a) respond to and recover from the CTP operational incident; and (b) facilitate effective communica” | CTPS 4.8.1R(3) | final | Incident management playbook containing response/recovery procedures and communication protocols for regulators and affected firms; evidence of implementation. | |
OBL-01819 | United Kingdom | UK_FCA | business continuity | Cooperate and coordinate with regulators and affected firms in response to CTP operational incidents, including through collective incident response frameworks. “cooperating and coordinating with the regulators and affected firms in response to CTP operational incidents, including through collective incident response frameworks.” | CTPS 4.8.1R(4) | final | Records of participation in collective incident response frameworks; documented cooperation protocols; evidence of coordination during past incidents or exercises. | |
OBL-01820 | United Kingdom | UK_FCA | business continuity | Put in place measures for effective, orderly and timely termination of any systemic third party service, including transfer support and recovery/return of firm assets in an accessible format. “A critical third party must have in place appropriate measures to respond to a termination of any of its systemic third party services... including by putting in place: (1) arrangements to support the effective, orderly and timely termination of that service... (2) provision for ensuring access to, ” | CTPS 4.9.1R | final | Termination/exit plan per systemic service; data portability and return procedures; contractual provisions with firms covering asset recovery; evidence of testing. | |
OBL-01821 | United Kingdom | UK_FCA | business continuity | Be able to demonstrate to regulators the ability to comply with all CTPS requirements. [adjacent] “A critical third party must be able to demonstrate to the regulators its ability to comply with CTPS.” | CTPS 5.1.1R | final | Comprehensive compliance evidence pack; self-assessments; test results; governance sign-off; policies and procedures; records available for regulatory inspection. | |
OBL-01822 | United Kingdom | UK_FCA | business continuity | Carry out regular scenario testing of ability to continue providing each systemic third party service within its maximum tolerable disruption level under severe but plausible disruption scenarios covering varying nature, severity and duration. “a critical third party must carry out regular scenario testing of its ability to continue providing each systemic third party service within its appropriate maximum tolerable level of disruption... in the event of a severe but plausible disruption... identify an appropriate range of adverse circumst” | CTPS 5.2.1R, CTPS 5.2.2R | final | Scenario testing programme; test scenarios documented; test results reports; evidence of remediation actions taken; records showing frequency and coverage. | |
OBL-01823 | United Kingdom | UK_FCA | business continuity | Regularly assess effectiveness of the incident management playbook; conduct an incident management playbook exercise with a representative sample of firms within 12 months of designation and at least biennially thereafter. “a critical third party must assess the effectiveness of its incident management playbook regularly, including undertaking an appropriate incident management playbook exercise with a representative sample of the firms... within 12 months of the critical third party being designated by the Treasury an” | CTPS 5.3.1R | final | Playbook exercise schedule; exercise reports; list of participating firms; evidence of biennial frequency; post-exercise action plans. | |
OBL-01824 | United Kingdom | UK_FCA | business continuity | Prepare and submit to regulators a report of each incident management playbook exercise, including actions taken in light of results, as soon as practicable after the exercise. “A critical third party must, as soon as is practicable, prepare and submit to the regulators a report of the incident management playbook exercise undertaken under CTPS 5.3.1R (including any actions taken in the light of the results of that exercise).” | CTPS 5.3.2R | final | Submitted exercise reports to regulators; evidence of timely submission; records of follow-up actions. | |
OBL-01825 | United Kingdom | UK_FCA | business continuity | Provide regulators with an interim self-assessment within 3 months of designation and annual self-assessments thereafter on compliance with CTPS; retain copies for at least 3 years. [adjacent] “A critical third party must provide to the regulators: (1) within 3 months... an interim self-assessment; and (2) annually thereafter, an annual self-assessment, of the critical third party's compliance with CTPS... must keep a copy... for a period of at least 3 years.” | CTPS 6.1.1R, CTPS 6.1.2R | final | Submitted interim and annual self-assessments; regulator submission records; document retention logs showing 3-year retention. | |
OBL-01826 | United Kingdom | UK_FCA | business continuity | Maintain effective and secure processes to provide firms with sufficient and timely information—including test results, self-assessments and maximum tolerable disruption levels—to enable them to manage risks from using the CTP's systemic third party services. “A critical third party must have in place effective and secure processes and procedures to ensure sufficient and timely information is given to a firm... including... results of testing and exercising... the annual self-assessment... the appropriate maximum tolerable level of disruption.” | CTPS 7.1.1R, CTPS 7.1.2R | final | Information sharing framework/policy; evidence of information provided to each client firm; secure transmission records; disclosure logs. | |
OBL-01827 | United Kingdom | UK_FCA | business continuity | Submit an initial incident report to regulators and affected firms as soon as practicable after a CTP operational incident, covering nature/extent of disruption, detection time, affected services, geography, cause, recovery timeline and initial actions. “A critical third party must, as soon as is practicable after the occurrence of a CTP operational incident... submit the following information... (a) a description of the CTP operational incident... (d) the anticipated amount of time it will take to resolve the CTP operational incident, including the” | CTPS 8.1.1R | final | Initial incident report template; submitted reports to regulators and affected firms; submission timestamps; incident log. | |
OBL-01828 | United Kingdom | UK_FCA | business continuity | Submit intermediate incident reports to regulators and affected firms as soon as practicable after any significant change in circumstances, including when the incident is resolved. “A critical third party must, as soon as is practicable after any significant change in circumstances... provide the regulators and the affected firms with information further to that already disclosed in relation to the CTP operational incident, including... any steps taken to resolve the CTP operat” | CTPS 8.2.1R | final | Intermediate incident report records; submission logs to regulators and firms; documented triggers for issuing updates. | |
OBL-01829 | United Kingdom | UK_FCA | business continuity | Submit a final incident report to regulators and affected firms within a reasonable time of resolution, covering root causes, remedial actions, recurrence likelihood, long-term implications and improvement areas. “A critical third party must, within a reasonable time of the CTP operational incident being resolved, provide the regulators and the affected firms with the following information... (2) a description of the root causes... (3) a description of any remedial actions... (4) a description of the critical” | CTPS 8.3.1R | final | Final incident report template; submitted reports to regulators and affected firms; root cause analysis documentation; remediation action plans with timelines. | |
OBL-01830 | United Kingdom | UK_FCA | business continuity | Notify regulators immediately of any actual or potential circumstance that seriously and adversely impacts, or could impact, the CTP's ability to deliver systemic third party services or meet CTPS obligations. “A critical third party must notify the regulators immediately where there is an actual or potential circumstance or event that seriously and adversely impacts, or could seriously and adversely impact, the critical third party's ability to deliver any of its systemic third party services or meet any ” | CTPS 9.1.1R | final | Notification log; evidence of timely submissions; internal trigger criteria and escalation procedures for CTPS 9 notifications. | |
OBL-01831 | United Kingdom | UK_FCA | business continuity | Ensure all information provided to regulators and firms under CTP duties (including incident reports and notifications) is factually accurate, complete and fairly based; correct any inaccurate information immediately upon discovery. [adjacent] “A critical third party must take reasonable steps to ensure that all information it gives to the regulators and firms... is: (1) factually accurate or, in the case of estimates and judgements, fairly and properly based... (2) complete... If a critical third party becomes aware... that it has or may ” | CTPS 10.1.1R, CTPS 10.1.3R | final | Information quality control procedures; review and sign-off records for regulatory submissions; records of any corrective notifications made. | |
OBL-01832 | United Kingdom | UK_FCA | business continuity | When appointing a skilled person, contractually require and permit them to cooperate with regulators, report matters of material significance, comply with regulator instructions on reporting, and assist the skilled person with information and access. [adjacent] “When a critical third party appoints a skilled person, the critical third party must, in a contract with that person: (1) require and permit the skilled person during and after the course of their appointment: (a) to cooperate with the regulators in connection with the discharge of their oversight f” | CTPS 13.5.1R | final | Skilled person contracts containing required clauses; evidence of regulator cooperation and access provisions; records of skilled person engagements. | |
OBL-01868 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): All firms must submit a report to the FCA as soon as practicable (within 24 hours) after an operational incident meets any notification threshold (risk of intolerable consumer harm, safety/soundness, or market stability). “A firm must submit a report to the FCA in accordance with (2) or (3), as applicable, as soon as is practicable after the occurrence of an operational incident which the firm reasonably believes meets one or more of the notification thresholds” | SUP 15.18.6R(1) and SUP 15.18.7G | final | Incident log with timestamped detection and submission records; written threshold assessment; initial report submitted within 24 hours via FCA online portal | ||
OBL-01869 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Enhanced reporting firms must submit an initial phase report containing mandatory fields (Annex 15.1R cols 1 & 2) to the FCA as soon as practicable after an operational incident threshold is met. “For this initial phase of the report, an enhanced reporting firm must submit to the FCA, so far as it is aware, the information in accordance with columns (1) and (2) of the table in SUP 15 Annex 15.1R.” | SUP 15.18.6R(2) | final | Completed initial-phase report (SUP 15 Annex 15.1R cols 1&2) with all mandatory fields including incident description, detection time, recovery actions, third-party provider details | ||
OBL-01870 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Enhanced reporting firms must submit an intermediate phase report to the FCA as soon as practicable after any significant change in circumstances from those in the initial report, including resolution of the incident. “For the intermediate phase of the report, an enhanced reporting firm must, so far as it is aware, submit to the FCA the additional information in accordance with columns (1) and (3) of the table in SUP 15 Annex 15.1R, as soon as is practicable after any significant change in circumstances” | SUP 15.18.8R | final | Intermediate-phase update reports (Annex 15.1R cols 1&3) with timestamps showing submission promptly after material incident developments or resolution | ||
OBL-01871 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Enhanced reporting firms must submit a final phase report within 30 working days (or 60 working days if impracticable) of an operational incident being resolved. “For the final phase of the report, an enhanced reporting firm must submit to the FCA the additional information in accordance with columns (1) and (4) of the table in SUP 15 Annex 15.1R: (1) within 30 working days; or (2) where this is impracticable, as soon as is practicable but in any event within” | SUP 15.18.9R | final | Final-phase report (Annex 15.1R cols 1&4) including root cause, lessons learned, remedial actions, impact tolerance usage; dated within 30/60 WD of resolution | ||
OBL-01872 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Non-enhanced reporting firms must submit a standard report (Annex 15.2R) to the FCA as soon as practicable after an operational incident meets any notification threshold. “A firm other than an enhanced reporting firm must submit to the FCA, so far as it is aware, information in accordance with the table in SUP 15 Annex 15.2R.” | SUP 15.18.6R(3) | final | Completed standard report (Annex 15.2R) with mandatory fields including incident description, detection time, severity rating, recovery actions; submitted via FCA online portal | ||
OBL-01873 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): All firms required to report operational incidents must submit reports exclusively online through the appropriate systems accessible from the FCA's website. “A firm must submit the information required under this section to the FCA online through the appropriate systems accessible from the FCA's website.” | SUP 15.18.10R | final | Evidence of online portal registration; test submissions; documented escalation procedure if portal unavailable | ||
OBL-01874 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Payment service providers must submit the initial operational incident report to the FCA within 4 hours of first detecting a major operational or security incident. “A payment service provider must submit the report in SUP 15.18.6R to the FCA within 4 hours of first detecting a major operational or security incident.” | SUP 15.14.18DD | final | Incident log showing detection timestamp and FCA submission timestamp within 4 hours; 24/7 on-call escalation procedure | ||
OBL-01875 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Enhanced reporting firms must include in the final phase report the proportion of impact tolerance used, service downtime, number/percentage of affected customers, and transactions affected. “What proportion of an impact tolerance has been used?... Service downtime... Number of affected customers... Percentage of service users affected... Percentage of transactions affected... Value of transactions affected... Number of transactions affected” | SUP 15 Annex 15.1R (col 4, fields 24-30) | final | Final-phase report with populated impact tolerance, downtime, customer and transaction impact fields; internal methodology for calculating these metrics | ||
OBL-01876 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Enhanced reporting firms must include in the final phase report lessons identified and remedial actions being taken following an operational incident. “Describe the lesson identified... Not applicable... Not applicable... Mandatory... Describe the remedial action being taken... Not applicable... Not applicable... Mandatory” | SUP 15 Annex 15.1R (col 4, fields 41-42) | final | Post-incident review document; final-phase FCA report containing completed lessons learned and remedial action fields | ||
OBL-01877 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Where an operational incident originates from a third party, enhanced reporting firms must identify the third party provider name and LEI in both initial and intermediate phase reports. “Third party provider name (note 7)... Mandatory... Mandatory... -... Third party provider legal entity identifier (note 7)... Mandatory... Mandatory... -” | SUP 15 Annex 15.1R (fields 36-37) | final | Incident reports showing third-party provider name and LEI where origin is third party; internal register of critical third-party LEIs for rapid lookup | ||
OBL-01878 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): In-scope firms must notify the FCA before entering into, or making significant changes to, a material third party arrangement, at an early stage before internal or external commitments are made. ⚠ audit “A firm must give the FCA notice when entering into, or significantly changing, a material third party arrangement.” | SUP 15.19.6R and SUP 15.19.9G | final | Pre-commitment FCA notification records with submission timestamps; materiality assessment documentation; FCA online submission receipts | ||
OBL-01879 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): In-scope firms must submit material third party arrangement notifications to the FCA using the data fields in Annex 16.1R (cols 1 & 2), online via the FCA's website. ⚠ audit “A firm must submit the notice required in SUP 15.19.6R to the FCA: (1) by providing the information in accordance with columns (1) and (2) of the table in SUP 15 Annex 16.1R; and (2) online through the appropriate systems accessible from the FCA's website.” | SUP 15.19.8R | final | Completed Annex 16.1R notification templates with all mandatory fields; FCA portal submission confirmations; governance sign-off records (field 4.12) | ||
OBL-01880 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): In-scope firms must maintain a register of information relating to all their material third party arrangements and submit it annually to the FCA. [adjacent] “A firm must: (1) maintain a register of information relating to its material third party arrangements; and (2) submit the register of material third party arrangements annually to the FCA.” | SUP 16.33.6R | final | Live internal register with all Annex 16.1R fields populated; annual FCA submission records; evidence of ongoing register maintenance and updates | ||
OBL-01881 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): In-scope firms must submit the annual material third party arrangements register to the FCA using Annex 16.1R (cols 1 & 3) fields, online via the FCA's website. ⚠ audit “The firm must submit the register of material third party arrangements specified in SUP 16.33.6R(2) to the FCA: (1) by providing the information in accordance with columns (1) and (3) of the table in SUP 15 Annex 16.1R; and (2) online through the appropriate systems accessible from the FCA's website” | SUP 16.33.8R | final | Annual Annex 16.1R register submission via FCA portal; submission receipts; internal data governance records confirming completeness of mandatory fields | ||
OBL-01882 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms must record in the material third party register the substitutability of the service provider, ability to reintegrate the service, and impact of discontinuing the arrangement. “Substitutability of the service provider... Mandatory... Mandatory... Ability of reintegration of the service... Mandatory... Mandatory... The impact of discontinuing the contractual arrangement... Mandatory... Mandatory” | SUP 15 Annex 16.1R (fields 5.01-5.03) | final | Register entries with completed substitutability assessments; exit/reintegration analysis documentation; concentration risk assessments for critical providers | ||
OBL-01883 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms must record in the material third party register whether each arrangement supports an important business service and, if so, which service and whether the provider supports a core element of it. “Does the contractual arrangement support an important business service?... Mandatory... Mandatory... If yes, which important business service does the contractual arrangement support... Does the service provider support a core element of the important business service?” | SUP 15 Annex 16.1R (fields 3.04-3.06) | final | Register with mapped important business services per third-party arrangement; linkage to operational resilience important business service mapping documentation | ||
OBL-01884 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms must record FCA impact tolerances (client harm and market integrity) for each material third party arrangement in both the notification and the annual register. ⚠ audit “Impact tolerance - FCA - client harm... Mandatory... Mandatory... Impact tolerance - FCA - market integrity... Mandatory... Mandatory” | SUP 15 Annex 16.1R (fields 3.10-3.11) | final | Register and notification templates with impact tolerance fields completed; board-approved impact tolerance statements linked to third-party arrangements | ||
OBL-01885 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms must record the date and outcome of the most recent risk assessment and audit for each material third party arrangement in both the notification and annual register. ⚠ audit “Date of the most recent risk assessment... Mandatory... Mandatory... Outcome of the most recent risk assessment... Mandatory... Mandatory... Date of the most recent audit... Mandatory... Mandatory... Outcome of the most recent audit... Mandatory... Mandatory” | SUP 15 Annex 16.1R (fields 4.01-4.05) | final | Third-party risk assessment reports and audit reports with dates; register entries referencing these; schedule of upcoming reassessments | ||
OBL-01886 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms must record the date and outcome of cyber risk due diligence for each material third party arrangement in both the notification and annual register. ⚠ audit “Date of cyber risk due diligence... Mandatory... Mandatory... Outcome of cyber risk due diligence... Mandatory... Mandatory” | SUP 15 Annex 16.1R (fields 4.08-4.09) | final | Cyber risk due diligence reports for each material third party; register entries with dates and outcomes; evidence of periodic refresh | ||
OBL-01887 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms must record governance approval details (SMF/accountable-person sign-off or committee review) and the date of approval for each material third party arrangement. [adjacent] “Has this contractual arrangement been reviewed and signed off by an SMF holder or an accountable person of an FMI?... Mandatory... Mandatory... If not, which governance committee reviewed it?... Date of governance approval... Mandatory... Mandatory” | SUP 15 Annex 16.1R (fields 4.12-4.14) | final | Governance approval records (board/committee minutes or SMF sign-off) for each material third-party arrangement; dates recorded in register | ||
OBL-01888 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms must record where data is stored and where the service is delivered from for each material third party arrangement in both the notification and annual register. “Country where the data is stored... Mandatory... Mandatory... Country where the service is delivered from... Mandatory... Mandatory” | SUP 15 Annex 16.1R (fields 3.13-3.14) | final | Register entries showing data storage and service delivery countries; data flow mapping documentation; cloud deployment model records (field 2.06) | ||
OBL-01889 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms must maintain a permanent record of their material third party arrangements register (SUP 16.33.6R(1)) with no specified minimum retention period. ⚠ audit “SUP 16.33.6R(1) Material third party arrangements Register of information relating to material third party arrangements Not specified Not specified” | SUP 16.33.6R(1) and Sch 1.2G (SUP 16.33.6R(1) entry) | final | Documented register retention policy; version-controlled register records; audit trail of changes to register entries | ||
OBL-01890 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Enhanced reporting firms must report in the initial phase whether an affected service is classified as an important business service and, in the intermediate phase, must confirm this mandatorily. “Is the affected service classified as an important business service?... Optional (note 2)... Mandatory... -” | SUP 15 Annex 15.1R (field 23) | final | Incident reports with important business service classification; linkage to firm's important business service register under SYSC 15A | ||
OBL-01891 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms subject to both SUP 15.3.8G(1)(e) and SUP 15.19 notification requirements for material outsourcing must comply with SUP 15.19; a single notification satisfying SUP 15.19 discharges both obligations. [adjacent] “Any notification required under both SUP 15.3.8G(1)(e) and SUP 15.19 (Notification of material third party arrangements) must be made in accordance with SUP 15.19.” | SUP 15.3.10AR | final | Notification records showing SUP 15.19-compliant submissions for material outsourcing arrangements; policy documenting consolidation of dual notification obligations | ||
OBL-01892 | United Kingdom | UK_FCA | NOT YET IN FORCE (effective 2027-03-18): Firms must record in the material third party register the supply chain ranking and notice periods (for both firm and service provider) for each material third party arrangement. “Supply chain ranking... Mandatory... Mandatory... Notice period for the service provider... Mandatory... Mandatory... Notice period for the firm... Mandatory... Mandatory” | SUP 15 Annex 16.1R (fields 2.08, 2.12-2.13) | final | Register entries with supply chain tier/ranking, contractual notice periods for both parties; exit planning documentation referencing notice periods |
Knowing which rules bind you is step one. WSquare Advisory builds the operating capability behind compliance — the continuity, third-party, and recovery disciplines these regimes expect. If that's your challenge, let's talk.
Start with an Operating Survey · $5,000 →