Cyber security for financial services firms
FCA operational resilience requirements for cyber security, including the 31 March 2025 compliance deadline, SM&CR responsibilities for cyber …
This guidance is for the risk carriers and scheme operators themselves — insurers, reinsurers and occupational pension schemes. Insurers and reinsurers are dual-regulated: the Prudential Regulation Authority for prudential soundness and the Financial Conduct Authority for conduct. Trust-based occupational pension schemes follow a different regime under The Pensions Regulator. Work out which you are and follow the right guides — and if you broker or advise on insurance rather than carry the risk, different rules apply.
FCA operational resilience requirements for cyber security, including the 31 March 2025 compliance deadline, SM&CR responsibilities for cyber …
Audit-style yes/no checklist confirming your Part 4A application is ready before submission via FCA Connect. Covers business plan, …
How to apply to the Financial Conduct Authority for permission to carry on regulated activities under Part 4A …
A confirmation checklist for insurers, reinsurers and occupational pension schemes. Work through the duties every business in this …
Effecting and carrying out contracts of insurance are PRA-regulated activities: an insurer or reinsurer needs Part 4A permission, …
This division is the regulated heart of the insurance and pensions market: the businesses that carry the risk — life and general insurers, reinsurers — and the vehicles that fund pensions. The regimes differ sharply by what you are. Insurers and reinsurers need Part 4A permission and are dual-regulated by the PRA and FCA. Trust-based occupational pension schemes are not FCA-authorised at all — they are supervised by The Pensions Regulator. If you are not sure you need authorisation in the first place, start with do I need FCA authorisation.
Whatever you operate, start with the universal spine. Follow "Run a compliant insurance or pension business" for data protection and the ICO fee, employers' liability insurance, health and safety, fire safety and equality.
Effecting and carrying out contracts of insurance are PRA-regulated activities. You need Part 4A permission through the PRA, and you must meet the Solvency UK prudential regime and operational resilience requirements. Follow "Insurer authorisation and prudential rules".
Alongside the prudential regime, the FCA supervises your conduct: the Senior Managers and Certification Regime, the Consumer Duty for retail business, financial promotions, complaints handling, claims payment and pricing rules, and FSCS membership. Follow "Insurer conduct and accountability rules".
Trust-based schemes register with The Pensions Regulator and follow its regime: scheme funding for defined benefit schemes, trustee knowledge and understanding, pensions dashboards connection, and qualifying-scheme requirements where the scheme is used for automatic enrolment. Follow "Run an occupational pension scheme".
Finish with the insurance and pension compliance checklist to confirm every obligation that applies to you is in place.
Insurance intermediation — broking, advising, arranging — is a different set of FCA-regulated activities in a different SIC division. See FCA authorisation for insurance brokers and starting an insurance broking business.
Authoritative starting points for insurers and pension schemes.