Menu Close

Blog

The Principle 11 threshold: When an operational glitch demands an FCA self-report

Compliance Consultant has observed that many mid-sized financial services firms struggle with the moving target of self-reporting operational failures under the revised Principle 11 rules. Following the June 1, 2026 guidance update, firms must immediately notify the Financial Conduct Authority (FCA) of systemic or recurring customer redress issues under the revised SUP 15.3.8(4) G rules. Compliance officers must establish clear internal triggers that isolate minor infrastructure friction from material disruptions to service delivery or data integrity before the new PS26/2 reporting regime takes effect on March 18, 2027.

On June 1, 2026, the FCA implemented updates to the supervision module of the FCA Handbook (SUP 15) that expanded the scope of Principle 11 notifications. For compliance officers at mid-sized firms, this regulatory update means that what was once handled as an internal IT issue or isolated customer complaint might now require an immediate self-report. The change, detailed in an Eversheds Sutherland analysis, introduces guidance under SUP 15.3.8(4) G that explicitly includes customer loss and redress issues within reportable events.

Historically, firms evaluated operational glitches under the broad language of SUP 15.3.1 R, which mandates immediate notification if an event has a significant adverse impact on the firm’s reputation or affects its ability to provide adequate services. The new guidance makes it clear that systemic or recurring issues leading to customer redress must be disclosed. As a specialist UK regulatory compliance firm, Compliance Consultant has observed that many compliance departments are unprepared for this lower notification threshold.

Instead of treating customer compensation as a post-incident cleanup task, the FCA expects active, immediate reporting as soon as a systemic pattern emerges. Failing to report these redress-generating events under Principle 11 exposes firms to severe penalties and reputational damage. To maintain a defensible position, compliance officers must re-engineer their internal reporting lines to connect the customer complaints team directly with the compliance function.

Evaluating material operational disruption against PS26/2 parameters

The upcoming PS26/2 policy statement establishes a unified reporting framework for operational incidents, taking effect on March 18, 2027. Under these rules, an operational incident is defined as any event that disrupts a firm’s operations to the point of impacting an external end-user or affecting data integrity. In our work with financial services businesses, Compliance Consultant emphasizes the necessity of building quantitative triggers to identify these events before the 2027 deadline.

Material disruption indicators

The current guidance on Reporting operational incidents | FCA outlines five primary indicators of materiality:

  • Material disruption to the provision of financial services
  • Incidents affecting a large number of customers
  • Unauthorised access to information systems
  • Significant loss of data
  • Unavailability or loss of control of IT systems

If an operational event meets any of these criteria, the firm must notify the FCA immediately. Firms often make the mistake of waiting for a complete platform blackout before considering a notification. Under the PS26/2 framework, even a partial degradation of service that results in client detriment must be logged and evaluated against your defined impact tolerances.

Implementing a practical assessment framework requires more than just high-level policy. Compliance teams must transition from passive oversight to active operational execution to manage these tight timelines. For detailed guidance on building these execution-focused frameworks, see our analysis on Evaluating FCA compliance partners: Why mid-market firms need execution over advisory.

Third-party vendor failures

Modern financial services rely heavily on external software vendors, cloud providers, and outsourced operations. When an external vendor suffers an outage, the regulated firm remains fully responsible for any disruption to its end users. Under PS26/2, any third-party service failure that breaches your operational impact tolerances requires a formal report to the FCA.

Compliance Consultant advises clients to map all material third-party arrangements and establish direct data feeds for service availability. A vendor’s failure to meet its service level agreement does not shield your firm from Principle 11 exposure if customers suffer. You must establish contractual obligations that require your vendors to notify you of incidents within minutes, allowing you to meet your own regulatory obligations.

To structure this oversight, firms can utilize templates like our Compliance Risk Register with Heat Mapping (£199 retail, or included within our Silver and Gold retainers). This tool allows you to map third-party risks and track the operational health of critical vendors. By formalizing these assessments, compliance officers can defend their decision-making process when determining whether a vendor outage requires an FCA notification.

Professional businesswomen engaged in a meeting discussing data on a screen.

The CASS factor: When resolution pack failures cross the notification line

For firms holding client money and assets, any operational glitch that impacts the integrity of the CASS Resolution Pack (CASS RP) is an immediate red flag. The CASS RP is a regulatory requirement designed to ensure that, in the event of insolvency, an insolvency practitioner can distribute client assets rapidly. An IT failure that prevents the daily update of CASS records or corrupts bank reconciliation data is not a minor operational issue; it is a direct threat to client asset safety.

The role of the CASS resolution pack

Compliance Consultant regularly reviews client asset governance, and we find that CASS record-keeping is often the first casualty of database synchronization errors. If your system fails to produce an accurate, up-to-date CASS RP within the regulatory deadline, this constitutes an operational breach. Under the current regime, you must assess whether this operational failure threatens your compliance with CASS rules and therefore demands a self-report.

To prevent these failures from escalating, firms must implement continuous, automated oversight of their reconciliation systems. Compliance officers can draw valuable lessons from adjacent sectors; for example, the structured approach to risk identification outlined in our guide on SRA COFA & COLP: Understanding Compliance Consultant highlights how robust monitoring systems prevent minor accounting errors from turning into systemic regulatory breaches.

Threshold condition breaches

Under FCA Handbook SUP 15.3.1 R(1), a firm must notify the regulator immediately if it has information suggesting it may fail to satisfy one or more of the threshold conditions. For financial services businesses, the “adequate resources” condition is highly sensitive to operational disruptions. If an IT outage, cyber event, or database failure prevents you from executing client transactions or calculating your financial positions, you are failing to maintain adequate operational resources.

A temporary glitch becomes a reportable threshold condition breach the moment it impacts your ability to operate in a sound and prudent manner. Compliance Consultant recommends setting clear quantitative parameters for what constitutes “adequate.” For instance, if your core transaction system is down for more than two hours during trading peaks, this should automatically trigger an assessment under SUP 15.3.1 R.

Documenting these decisions is vital. The FCA will scrutinize not only the incident itself but also your governance process during the outage. Keeping an audited decision log allows the compliance officer to prove that the firm acted in an open and cooperative way, even if the decision was made not to notify.

Businessman reviewing papers in office setting, highlighting analysis and attention to detail.

Categorising the firm: Standard vs. enhanced reporting

The administrative burden of complying with the upcoming operational resilience rules depends on your regulatory classification. Under the guidance in FG26/3: Operational Incident Reporting, the FCA splits authorised firms into two distinct reporting streams. This ensures that systemic, larger entities face closer scrutiny during an operational crisis, while smaller firms enjoy a more streamlined reporting process.

The following table outlines the key differences between these two categories under the new framework:

| Reporting Category | Firm Types In Scope | Reporting Requirements |
| :— | :— | :— |
| Standard Reporting Firms | All firms with Part 4A permission (excluding enhanced categories), such as mid-sized asset managers and corporate finance boutiques. | Submission of a single, standardized report upon the resolution of a material operational incident. |
| Enhanced Reporting Firms | Banks, building societies, designated investment firms, Solvency II insurers, CASS Large Firms, payment service providers, and enhanced-scope SMCR firms. | Submission of an initial notification, regular intermediate progress updates, and a detailed final report post-resolution. |

Compliance Consultant assists firms in identifying their classification and building appropriate incident response procedures. For enhanced reporting firms, a material operational incident requires dedicated resources to manage the ongoing stream of regulatory updates while simultaneously trying to resolve the technical root cause. This dual pressure makes pre-prepared templates and standby advisory support an absolute necessity.

Standard reporting firms must not become complacent. While they are only required to submit a single post-incident report, the criteria for what constitutes a “material operational incident” remain identical to those for enhanced firms. If a mid-sized asset manager suffers a data breach affecting client portfolios, they must still notify the FCA immediately under Principle 11, even if they do not have to provide intermediate progress updates.

Managing the shifting boundary of Principle 11 notifications demands continuous oversight and access to immediate, qualified expertise. Compliance Consultant offers tiered advisory retainers that provide mid-sized financial firms with predictable budgeting and senior-level support when critical incidents occur. Our retainers supply budget certainty and on-demand access to an extremely trustworthy compliance partner and a topic expert panel, ensuring you never have to make a difficult notification decision in isolation.

Our Silver Retainer (Compliance Professional) is priced at £795 per month for annual billing (representing an 11% saving) or £895 per month billed quarterly, and is designed for established firms wanting proactive compliance management and professional-grade templates. This tier includes 8 hours of dedicated advisory support per month, a 1 business day response SLA, priority helpline access, and quarterly compliance reviews. Silver clients also receive our complete digital template library, including the Compliance Risk Register with Heat Mapping (£199 retail), the Compliance Monitoring Programme Builder (£199 retail), and the Consumer Duty/Operational Resilience Toolkit (£199 retail) to systematically document incident assessments.

For firms requiring comprehensive board-level support, our Gold Retainer (Compliance Partner) at £1,345 per month for annual billing (save 10%) or £1,495 per month billed quarterly offers 16 hours of advisory support, a dedicated named compliance consultant, and a guaranteed 4-hour response SLA. Gold clients also receive monthly strategic calls, quarterly drafted board compliance reports, and advanced toolkits such as the Conduct Rules Breach Investigation Toolkit (£349 retail) and the FCA Query Response Pack (£199 retail).

Do not wait for a major system failure to test your reporting triggers. Contact Compliance Consultant today by emailing info@complianceconsultant.org with the subject “Retainer Discovery Call” or by calling our UK Freephone at 0800 689 0190 to book a free 30-minute discovery call to discuss your regulatory needs and identify the right retainer tier.

author avatar
Lee Werrell