PRA SS1/21 Operational Resilience: What Your Technology Function Must Be Able to Show

A reading of what PRA Supervisory Statement 1/21 actually requires of a technology function, written for the firms now past the March 2025 transition deadline.

The PRA’s operational resilience regime — PS6/21 and the supporting Supervisory Statement SS1/21 — completed its three-year transition on 31 March 2025. From that date, PRA-authorised firms have been expected to be able to remain within impact tolerances for important business services under severe but plausible scenarios. The transition is over. The supervisory engagement is now about how well firms meet the standard, not whether they are working towards it.

This is a reading of what SS1/21 substantively requires of the technology function, and where PRA scrutiny is most intense now that the transition deadline has passed.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

What SS1/21 says

The supervisory statement applies to PRA-authorised firms — banks, building societies, PRA-designated investment firms, and insurance and reinsurance undertakings. The requirements are structured around four obligations:

  • Identify important business services — the services that, if disrupted, would cause intolerable harm to clients or threaten financial stability.
  • Set impact tolerances — the maximum acceptable level of disruption for each important business service, expressed quantitatively where possible.
  • Map the resources supporting each important business service — technology, people, processes, facilities, third parties.
  • Test the ability to remain within impact tolerance under severe but plausible scenarios.

Each obligation must be documented in a self-assessment, reviewed at least annually, and made available to the PRA on request. Lessons learned from testing and from real incidents must feed back into the framework.

Who this is for

  • The CTO or COO at a PRA-authorised firm engaged in the post-transition supervisory cycle.
  • The head of operational resilience whose programme is now in steady-state and is being tested against the standard the PRA expects firms to meet.
  • The board member whose committee owns the operational resilience self-assessment and wants to read SS1/21 in plain English.

What “remain within impact tolerance” actually means

The phrase that does the most work in SS1/21 is “remain within impact tolerance under severe but plausible scenarios”. Four things are packed into it:

“Remain within” — not “minimise”. The firm has to be able to recover, restore service, or substitute service such that the disruption stays within the tolerance. A scenario that breaches the tolerance is a finding.

“Impact tolerance” — quantitative where possible. “Four hours of unavailability” is a tolerance. “Minimise disruption” is not. The tolerance has to be defensible — derived from the actual harm that would arise, not picked because it is achievable.

“Severe” — at the upper end of plausibility. Not asteroid impacts; loss of a critical cloud region, prolonged ransomware on the principal system, simultaneous failure of two critical third parties, loss of a single point of failure in payments processing.

“Plausible” — grounded in the firm’s actual circumstances. A scenario that ignores the firm’s specific architecture is not plausible. The scenario library has to be tailored.

Where PRA scrutiny is most intense post-transition

Now that the transition is complete, the supervisory engagement has shifted in character. The recurring focus areas:

Impact tolerance defensibility. The PRA challenges tolerances that look too generous and tolerances that look unrealistically tight. A four-hour tolerance for retail payments at a major retail bank is challenged because it is implausibly generous. A zero-tolerance for any disruption to any service is challenged because it is not credible.

Mapping completeness. The mapping of resources supporting an important business service is meant to be granular enough that the firm can identify single points of failure and concentration risks. Maps that stop at the level of “we use cloud” or “we have third parties” do not satisfy the requirement.

Scenario test depth. Scenarios that have been tested are evidence the firm’s resilience is what the firm believes it is. The PRA increasingly wants to see scenarios that actually exercise the recovery procedures — not desktop walkthroughs but technical exercises with measured recovery times.

Remediation tracking. When testing identifies a gap — a scenario that breaches the tolerance — the firm is expected to have a remediation plan with a target date. Findings without remediation plans, or with stale remediation plans, are now flagged.

Self-assessment quality. The self-assessment document is the artefact the PRA reads first. A self-assessment that reads as a marketing exercise — confident, free of identified weaknesses, dated months ago — does not match the supervisory expectation of an evidence-based document maintained under continuous improvement.

The interaction with operational continuity in resolution

For PRA-authorised banks subject to the Bank of England’s resolution regime, operational resilience under SS1/21 sits alongside operational continuity in resolution. The two regimes share many resource mappings and recovery considerations but have different framing: resilience is about staying within impact tolerance day-to-day; resolution continuity is about maintaining critical functions during and after resolution. Firms that have not aligned the two end up with duplicated effort and inconsistent documentation.

What “good” looks like

For a PRA-authorised firm now past the transition deadline, the technology function in a defensible position has:

  • A specific, defensible list of important business services.
  • Quantitative impact tolerances derived from harm analysis, board-approved.
  • Resource mappings at the granularity needed to identify single points of failure.
  • An annual scenario testing programme with technical exercises, not just desktops.
  • A self-assessment document updated within the last twelve months, with identified weaknesses and remediation plans.
  • Evidence that lessons learned from recent incidents — real or exercised — have fed back into the framework.

How we engage with this

We read operational resilience programmes against SS1/21. As part of a Technology Control Review scoped to PRA operational resilience, we identify gaps between current state and what the PRA expects post-transition, with specific recommendations on impact tolerances, mapping depth, scenario test design, and self-assessment quality.

We do not run scenario tests. We do not draft self-assessments. We do not act as operational resilience function. We read what is there, identify what is missing, and write it down for the technology function and the board.

Pricing is published at /pricing/. If your PRA-authorised firm is now in the post-transition supervisory cycle and the self-assessment needs an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.