← Frameworks / Regulatory

PRA SS1/21 & SS2/21 — Operational Resilience and Outsourcing

UK Prudential Regulation Authority requirements for operational resilience at PRA-regulated firms. PRA SS1/21 covers identification of important business services, impact tolerance setting, resource mapping, scenario testing, and self-assessment. PRA SS2/21 covers outsourcing governance, materiality assessment, due diligence, contractual requirements, sub-outsourcing chains, intra-group outsourcing, and exit strategies. Packaged under PRA Policy Statement PS6/21.

Clause Title SP 800-53 Controls
PS6/21-1.1 Transition period and compliance expectations
PS6/21-2.1 Proportionality and complexity
SS1/21-3.1 Identify important business services (IBS)
SS1/21-3.2 Board governance of operational resilience
SS1/21-4.1 Set impact tolerances for each IBS
SS1/21-5.1 Map resources supporting each IBS — people
SS1/21-5.2 Map resources supporting each IBS — technology and information
SS1/21-5.3 Map resources supporting each IBS — facilities and third parties
SS1/21-6.1 Scenario testing — severe but plausible scenarios
SS1/21-6.2 Scenario testing — lessons learned and remediation
SS1/21-7.1 Self-assessment and ongoing monitoring
SS1/21-8.1 Communication strategy during disruption
SS1/21-9.1 Interconnections and dependencies between IBS
SS1/21-10.1 Operational resilience and financial resilience linkage
SS1/21-11.1 Change management impact on operational resilience
SS2/21-3.1 Outsourcing governance framework
SS2/21-4.1 Materiality assessment of outsourcing arrangements
SS2/21-5.1 Pre-outsourcing due diligence
SS2/21-6.1 Contractual requirements — service levels and security
SS2/21-6.2 Contractual requirements — audit and access rights
SS2/21-7.1 Ongoing monitoring and oversight of outsourced providers
SS2/21-8.1 Sub-outsourcing chains
SS2/21-9.1 Intra-group outsourcing
SS2/21-10.1 Business continuity for outsourced services
SS2/21-11.1 Data protection and information security for outsourced services
SS2/21-12.1 Exit strategies and transition planning
SS2/21-13.1 Outsourcing register and record-keeping
SS2/21-14.1 Cloud outsourcing — specific considerations
SS2/21-15.1 PRA notification and regulatory reporting
SS2/21-16.1 Concentration risk across outsourcing portfolio
SS2/21-17.1 Skills and resources for outsourcing oversight