PRA SS1/21 & SS2/21 — Operational Resilience and Outsourcing
UK Prudential Regulation Authority requirements for operational resilience at PRA-regulated firms. PRA SS1/21 covers identification of important business services, impact tolerance setting, resource mapping, scenario testing, and self-assessment. PRA SS2/21 covers outsourcing governance, materiality assessment, due diligence, contractual requirements, sub-outsourcing chains, intra-group outsourcing, and exit strategies. Packaged under PRA Policy Statement PS6/21.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| PS6/21-1.1 | Transition period and compliance expectations | |
| PS6/21-2.1 | Proportionality and complexity | |
| SS1/21-3.1 | Identify important business services (IBS) | |
| SS1/21-3.2 | Board governance of operational resilience | |
| SS1/21-4.1 | Set impact tolerances for each IBS | |
| SS1/21-5.1 | Map resources supporting each IBS — people | |
| SS1/21-5.2 | Map resources supporting each IBS — technology and information | |
| SS1/21-5.3 | Map resources supporting each IBS — facilities and third parties | |
| SS1/21-6.1 | Scenario testing — severe but plausible scenarios | |
| SS1/21-6.2 | Scenario testing — lessons learned and remediation | |
| SS1/21-7.1 | Self-assessment and ongoing monitoring | |
| SS1/21-8.1 | Communication strategy during disruption | |
| SS1/21-9.1 | Interconnections and dependencies between IBS | |
| SS1/21-10.1 | Operational resilience and financial resilience linkage | |
| SS1/21-11.1 | Change management impact on operational resilience | |
| SS2/21-3.1 | Outsourcing governance framework | |
| SS2/21-4.1 | Materiality assessment of outsourcing arrangements | |
| SS2/21-5.1 | Pre-outsourcing due diligence | |
| SS2/21-6.1 | Contractual requirements — service levels and security | |
| SS2/21-6.2 | Contractual requirements — audit and access rights | |
| SS2/21-7.1 | Ongoing monitoring and oversight of outsourced providers | |
| SS2/21-8.1 | Sub-outsourcing chains | |
| SS2/21-9.1 | Intra-group outsourcing | |
| SS2/21-10.1 | Business continuity for outsourced services | |
| SS2/21-11.1 | Data protection and information security for outsourced services | |
| SS2/21-12.1 | Exit strategies and transition planning | |
| SS2/21-13.1 | Outsourcing register and record-keeping | |
| SS2/21-14.1 | Cloud outsourcing — specific considerations | |
| SS2/21-15.1 | PRA notification and regulatory reporting | |
| SS2/21-16.1 | Concentration risk across outsourcing portfolio | |
| SS2/21-17.1 | Skills and resources for outsourcing oversight |