UK Regulator FCA Introduces New Incident Reporting Framework

July 29, 2026

UK Regulator FCA Introduces New Incident Reporting Framework

United Kingdom financial regulators have introduced a unified incident reporting framework requiring authorized firms to report serious operational disruptions directly to the Financial Conduct Authority (FCA).

According to a Ropes & Gray article, this development represents a significant shift in how firms must respond to tech failures, cyberattacks, and other events that disrupt external clients and market participants.

The framework emerged from coordinated efforts among the FCA, the Prudential Regulation Authority, and the Bank of England, driven partly by growing concern over risks introduced by artificial intelligence.

Firms have nine months to prepare before the rules take effect on March 18, 2027. The new regime operates alongside, rather than replacing, existing UK General Data Protection Regulation (GDPR) data breach reporting obligations to the Information Commissioner’s Office (ICO).

Under the rules, an operational incident occurs when service delivery to an external end user is disrupted or the availability, integrity, or confidentiality of end-user data is compromised. Reporting is required if the incident crosses one of three reporting thresholds: consumer harm, market stability, or firm safety. The regime excludes near-misses, uncrystallized risks, and routine planned maintenance (unless a controlled interruption goes wrong and breaches a threshold).

Firms submit a single report per incident via the FCA Connect platform, though corporate groups must submit separate reports for each impacted FCA-regulated legal entity. Larger systemic firms face enhanced multi-stage reporting (intermediate and final reports). Reports must be submitted promptly, expected within 24 hours of determining a threshold is met—notably faster than the 72-hour window under UK GDPR.

Firms satisfying this new obligation will meet their existing FCA Principle 11 disclosure duties for that incident, though lower-impact issues and near-misses may still require separate internal escalation or standard Principle 11 reporting. Data-related incidents may trigger FCA and ICO obligations independently of one another.

Financial services counsel should prioritize updating incident response playbooks to reflect the differing thresholds, timelines, and disclosure obligations across the FCA, ICO, and Principle 11 regimes.

Critical intelligence for general counsel

Stay on top of the latest news, solutions and best practices by reading Daily Updates from Today's General Counsel.

Daily Updates

Sign up for our free daily newsletter for the latest news and business legal developments.

Scroll to Top