Key Takeaways
- The March 2025 deadline was just the beginning; ongoing testing, investment, and governance are expected.
- CP24/28 sets the tone for a more structured and transparent incident and third-party reporting regime.
- Firms must learn from the CrowdStrike outage and test for comparable real-world disruption scenarios
- The FCA is removing three data collections from the Handbook, saving time and cost for around 16,000 firms.
- 'My FCA' platform launched. A new one-stop portal for regulatory tasks aims to streamline firm interactions with the FCA.
- From 30 April 2025, portfolio letters will be replaced by a smaller number of market reports. Historical portfolio letters and Dear CEO letters will be clearly marked as outdated.
As of 31 March 2025, the FCA’s operational resilience framework officially transitioned from its implementation phase into full compliance. But as the regulator makes clear: the journey doesn’t end with the deadline. Firms are now expected to demonstrate and maintain the ability to operate important business services within defined impact tolerances—before, during, and after disruption. This month, we break down what’s changed, the key lessons from realworld incidents like CrowdStrike, and what CP24/28 signals about the FCA’s next move.
What Was Due by March 31, 2025?
All in-scope firms—including banks, building societies, insurers, Recognised Investment Exchanges, EMIs, and PSPs—should now have:
- Identified Important Business Services (IBS) that could cause intolerable harm if disrupted.
- Set impact tolerances for how long and severe a disruption can be tolerated.
- Conducted scenario testing to validate resilience.
- Remediated key vulnerabilities identified through mapping and testing.
- Established internal and external communication plans for operational disruption.
- Documented governance arrangements and board accountability.
CrowdStrike Outage: A Sector-Wide Wake-Up Call
The July 2024 global CrowdStrike IT outage exposed how dependent many firms are on single providers. Key observations from the FCA included:
- Gaps in crisis communication protocols.
- Poorly defined backup procedures.
- Lack of contractual clarity on third-party failover responsibilities.
This incident is now seen as a benchmark for evaluating firms’ resilience testing. If you haven’t assessed how your operations would perform under a similar failure—now is the time.
CP24/28: New Reporting Requirements Incoming
With firms now expected to manage disruptions in real time, the FCA has proposed major reforms in how firms report operational incidents and thirdparty risks. In CP24/28, which closed in March, the regulator outlined:
- A consistent definition of ‘material incidents’ for timely reporting.
- Standardised reporting templates to reduce inconsistency.
- New third-party reporting obligations, including nonoutsourced but material relationships.
- More visibility into critical third parties (CTPs) and systemic vendor risks.
These changes aim to help regulators better assess cross-sector resilience and incident response readiness
FCA Proposes Data Reporting Simplification for 16,000 Firms
In a move to reduce regulatory burden and support economic growth, the FCA has proposed the removal of certain data reporting requirements affecting approximately 16,000 firms. The proposal includes:
- Elimination of three specific data collections from the FCA Handbook, simplifying reporting obligations.
- Introduction of ‘My FCA’ portal, offering a single signing for all regulatory tasks, streamlining the reporting process.
Firms are invited to provide feedback on these proposals by 14 May 2025. During the consultation period, firms currently required to submit these data returns may choose not to do so without incurring late payment fees.
FCA Streamlines Supervisory Communications
Effective 30 April 2025, the FCA will cease issuing and publishing portfolio letters. Instead, the regulator will:
- Publish a limited number of market reports, containing communications relevant to various firm types and insights from supervisory work.
- Retire historical portfolio and ‘Dear CEO’ letters, marking them as ‘historical’ and no longer current, though they will remain accessible via existing links.
This change is part of the FCA’s Consumer Duty Requirements Review, aiming to streamline supervisory priorities and enhance regulatory effectiveness.


