PS26/2 will ask for structured incident and third-party reports. Can your register produce them?

From 18 March 2027 the FCA expects operational incidents and material third-party arrangements reported in set formats and timescales. If incidents live in one log, suppliers in another and risks in a third, the reporting becomes a manual exercise under deadline pressure. ERM+ keeps them in one linked register.

Who this page is for

  • Investment firms
  • Asset and wealth managers
  • Banks and building societies
  • Payment and e-money institutions
  • Insurers
  • Mortgage lenders and brokers
  • Consumer credit firms

Typically 100 to 1,000 employees, established and regulated, with the risk register, supplier oversight and resilience work still run largely by hand.

What you are asked to show, and where ERM+ holds it

PS21/3 Operational resilience

What it asks

Important business services identified, impact tolerances set, resources mapped, severe scenarios tested, and a self-assessment you can stand behind.

What ERM+ holds

Services, tolerances and the people, processes, systems and suppliers behind each one, with test results and breaches recorded against them.

PS26/2 Incident and third-party reporting

What it asks

Operational incidents and material third-party arrangements reported to the FCA in structured templates, from 18 March 2027.

What ERM+ holds

Incident records captured in a structured form as they happen, and a third-party register that shows which arrangements are in scope.

PS7/24 Critical third parties

What it asks

Tighter oversight of the suppliers your important services depend on, and evidence of that oversight.

What ERM+ holds

A supplier register linked to the services, risks and incidents each supplier touches, so concentration is visible.

SYSC and SM&CR

What it asks

Effective systems and controls, with named senior managers accountable for them.

What ERM+ holds

Owners on every risk, control and action, with testing and outcomes kept as an audit trail.

A summary to frame the conversation, not legal advice. The first call establishes exactly which requirements apply to your firm.

The rules are published. The data is the slow part.

The FCA has published the policy statement, final guidance and reporting templates. Documenting a process is quick. Discovering late that the information you need is not captured consistently is not.

Rule
OctONovNDecDJan 27JFebFMarMAprA
PS21/3 Operational resilience
Live and supervised
PS7/24 Critical third parties
Vendor oversight tightening
PS26/2 Incident and third-party reporting
In force 18 Mar 2027

164 days until PS26/2 takes effect on 18 March 2027.

Rate your firm against the rules first

Free assessments built requirement by requirement from the FCA and PRA policy statements. Rate each one red, amber or green and get a gap report in about fifteen minutes.

PS26/2 gap reportIllustrative ratings

17 of 48 requirements in place

  • 9 Not in place
  • 22 Partly in place
  • 17 In place
Rating by section
SectionRating
A1Scope and firm classificationIn place
A2Incident definitions and thresholdsPartly in place
A3Reporting process and timelinesNot in place
A4Governance and internal controlsPartly in place
B1Material third-party scopeIn place
B2Material third-party registerNot in place
B3Third-party notificationsPartly in place
B4Oversight and governancePartly in place
Regime A: incident reporting. Regime B: material third-party reporting.

How do you manage your risk register today: one spreadsheet or several?

  • Supervisors ask for evidence, not policies

    Supervisory visits increasingly ask to see the control framework working: tests, owners, outcomes. A policy document does not answer that.

  • Your supplier base keeps growing

    Every new outsourcing arrangement adds a row to a vendor list that nobody links back to the services it supports.

  • The deadline is fixed

    Documenting a reporting process is quick. Finding out late that the data behind it is not captured consistently is not.

Who usually owns this

Head of Risk / CRO

Also: Head of Operational Resilience, Risk Director

What you are dealing with
The risk register, third-party oversight and the resilience framework sit in separate spreadsheets. There is no single view of risk, and every board pack is assembled by hand.
What ERM+ gives you
One view of every risk type, with controls, incidents and suppliers linked to it. Risk committee reporting straight from live data.
Usually prompted by
A supervisory letter, a third-party incident, or the next board risk committee.

Built by practitioners, priced below enterprise GRC

More than 50 years of risk experience between the co-founders and over 500 with our senior associates. Implementation in weeks, not months.

Meet the team

Clients we have worked for or with

“ERM PLUS significantly reduced the time and resources for achieving regulatory compliance in risk and prudential management.”

Head of OpRisk · Asset Management Firm

“The expertise and professionalism of the ERM Plus team are unparalleled. Their strategic guidance and hands-on approach have been instrumental in achieving our business goals.”

Head of Risk · Retail Brokerage Firm

Twenty minutes will tell us both whether there is anything worth exploring.

We look at what you capture today, what your regulator will ask for, and whether there is a gap. If there is nothing there, no need to take it further.

A gap check, not a pitch. No project, no budget conversation, no access to sensitive data.

Not ready for a call?Run the free PS26/2 gap assessment(opens in a new tab)