|
Supervisory Statement SS1/21 Operational ResiliencePRA
|
PRA-regulated firms within the statement’s scope |
Important business services, impact tolerances, mapping, scenario testing, remediation, lessons learned and board accountability. |
|
Source
|
|
Supervisory Statement SS2/21 Outsourcing and Third Party Risk ManagementPRA
|
PRA-regulated firms within the statement’s scope |
Materiality assessment, due diligence, contractual controls, concentration risk, continuity, exit planning, incident escalation and assurance. |
|
Source
|
|
Senior Management Arrangements, Systems and ControlsFCA
|
FCA-authorised firms subject to relevant SYSC provisions |
Risk-control arrangements, compliance, internal audit, operational-risk governance, responsibilities, escalation and documented assurance. |
|
Source
|
|
UK Corporate Governance Code 2024FRC
|
Companies reporting against the Code under applicable listing requirements |
Board responsibility, risk management, internal controls, audit committee oversight, effectiveness declarations and transparent reporting. |
|
Source
|
|
UK GDPR Personal Data Breach RequirementsICO
|
Controllers and processors handling personal data within the UK GDPR regime |
Breach logging, risk assessment, regulatory notification, affected-person communication, response evidence and corrective actions. |
|
Source
|
|
Network and Information Systems Regulations 2018UK Government and designated competent authorities
|
Operators of essential services and relevant digital service providers |
Security risk management, service continuity, incident response, significant-incident notification and regulator assurance. |
|
Source
|