top of page

PRA Compliance Support Consultancy 2026: Complete Guide for Banks and Insurers

Aug 8
14 min read
PRA Compliance Support Consultancy 2026: Complete Guide for Banks and Insurers

PRA compliance is fundamentally different from ordinary FCA conduct compliance because the Prudential Regulation Authority is concerned principally with the safety and soundness of firms, the protection of insurance policyholders and the resilience of the financial system. Banks, building societies, PRA-designated investment firms and insurers therefore need regulatory frameworks built around capital, liquidity, solvency, governance, risk management, recovery, operational resilience and the ability to withstand severe stress. Most PRA-authorised firms are also regulated by the FCA, so management needs to coordinate prudential and conduct obligations without confusing the roles of the two regulators.


The PRA's Business Plan 2026/27 places significant emphasis on implementation of Basel 3.1, the Strong and Simple framework, operational resilience, cyber risk, third-party dependencies and emerging risks including AI and geopolitical developments. For insurers, the supervisory agenda continues under Solvency UK with attention to risk management, funded reinsurance, bulk purchase annuity growth and operational resilience. A PRA compliance programme therefore needs to combine current business-as-usual controls with implementation of major prudential reforms taking effect during 2026 and 2027.


PRA compliance requirements at a glance

Firm type or area

Principal PRA requirements

Banks and building societies

Capital, liquidity, ICAAP, ILAAP, stress testing, recovery, governance and reporting

Basel 3.1 firms

New capital framework largely effective from 1 January 2027

Small Domestic Deposit Takers

Strong and Simple simplified capital regime effective from 1 January 2027

Insurers

Solvency UK, SCR, technical provisions, governance, ORSA and reporting

SMCR

Senior management accountability and fitness and propriety

Operational resilience

Important business services, impact tolerances, mapping, testing and remediation

Outsourcing and third-party risk

SS2/21 governance, due diligence, contracts, concentration and exit

Climate-related risk

Governance, risk management, scenario analysis and integration into decision-making

Recovery and resolution

Recovery plans, solvent exit or resolution requirements according to firm type

Regulatory reporting

Accurate prudential returns, data governance and timely submissions

Model risk

Governance and validation of internal models and material risk models where applicable

New firm authorisation

Capital, governance, business model, risk management and credible mobilisation or launch planning


The detailed rule set depends heavily on the entity. A small domestic bank entering the simplified SDDT regime has a different capital and reporting framework from a large internationally active bank, while a life insurer has materially different prudential risks from a general insurer. PRA compliance support should therefore begin with the specific Rulebook parts and supervisory statements applicable to the firm rather than a generic prudential checklist.


Basel 3.1 is the major banking implementation project

The PRA published final Basel 3.1 rules in PS1/26 in January 2026. The vast majority of the framework is scheduled to take effect on 1 January 2027, with the transitional period aligned so that full implementation remains targeted for 1 January 2030. Firms should therefore treat 2026 as the final implementation year rather than a period for initial impact assessment.


Implementation can affect credit risk, market risk, operational risk, output floors, reporting and the calculation of risk-weighted assets depending on the bank's model. Finance, risk, regulatory reporting and technology should use consistent data and assumptions because prudential calculations can fail where ownership is fragmented across functions. Change governance should also capture any related updates to pricing, limits or product strategy.


The PRA has delayed the Fundamental Review of the Trading Book Internal Models Approach to 1 January 2028, but this does not postpone the rest of Basel 3.1. Firms should distinguish delayed components from the wider framework and maintain a detailed obligations plan. Board reporting should identify implementation risks, capital impact and unresolved data or modelling issues.


ICAAP remains central to capital adequacy

The Internal Capital Adequacy Assessment Process is a core element of PRA banking supervision. A firm should assess the capital it needs for material risks that are not fully captured by Pillar 1, including stress and the specific characteristics of its business model. The ICAAP should therefore be a management process that informs capital planning rather than a document produced mainly for the regulator.


Risk identification, stress testing, capital projections and management actions should be internally coherent. If the bank's risk register identifies significant concentration, interest-rate or operational risk, the ICAAP should explain how that risk affects capital adequacy and what controls or buffers are appropriate. Scenario assumptions should be severe enough to provide useful insight rather than selected primarily to preserve comfortable headroom.


The PRA uses ICAAP information within its supervisory review and Pillar 2 assessment. Firms should therefore maintain evidence supporting methodologies and senior challenge. Material changes to strategy, portfolio composition or risk appetite should trigger consideration of whether the ICAAP remains current before the normal annual cycle.


ILAAP and liquidity risk need equivalent discipline

The Internal Liquidity Adequacy Assessment Process assesses whether a bank has sufficient liquidity and funding to survive stress. The firm should understand its funding profile, liquid asset buffer, collateral, intraday needs and vulnerabilities to deposit outflow or market disruption. Liquidity risk can become critical much faster than capital risk, so governance and data should support timely management decisions.


The PRA's approach to supervising liquidity and funding expects the ILAAP to explain the firm's risk appetite, stress assumptions, contingency funding and assessment of adequacy. Scenarios should reflect the business model and include idiosyncratic and market-wide pressures where relevant. The bank should also understand operational barriers to accessing liquidity during stress rather than assuming every balance-sheet resource can be monetised immediately.


Board and treasury governance should connect the ILAAP to limits and early-warning indicators. Where deposit concentration, wholesale funding or group dependency changes, the firm should reassess liquidity risk promptly. The document should reflect current strategy rather than last year's business with refreshed numbers.


Strong and Simple changes the regime for eligible SDDTs

The PRA finalised the Strong and Simple simplified capital regime for Small Domestic Deposit Takers in January 2026. The main simplified capital regime and additional liquidity simplifications take effect on 1 January 2027, while certain changes concerning the frequency of ICAAP, reverse stress testing and ILAAP updates took effect from 20 January 2026. Eligible firms should therefore ensure they understand which parts are already live and which apply from 2027.


The objective is to make prudential requirements more proportionate for smaller domestic banks and building societies without weakening resilience. Simplification does not mean the firm can reduce governance or risk understanding. Boards should still demonstrate that capital and liquidity are adequate for the business and that changes in risk are identified between formal assessment cycles.


Firms close to eligibility thresholds should monitor their status carefully. Growth, international activity, trading or other structural changes can affect whether the SDDT criteria continue to be met. Strategic planning should therefore consider the prudential consequences of moving outside the simplified regime.


Pillar 2 remains important after Basel reform

Pillar 2 allows the PRA to address risks not adequately captured through standard Pillar 1 requirements and to assess the quality of the firm's risk management. The PRA continued to update its Pillar 2A framework during 2026, including policy changes published in May. Firms should therefore ensure internal capital assessments and regulatory calculations remain aligned with the current supervisory methodology.


Pillar 2 should not be managed as a calculation owned solely by regulatory reporting. The drivers can include credit concentration, interest-rate risk, pension risk and other material exposures, with governance and controls influencing supervisory judgement. A bank should understand which risks drive its Pillar 2 requirement and how business changes could affect it.


Data quality is again central. Where internal models, risk systems and prudential reporting use inconsistent classifications, the bank can struggle to explain its capital position. Compliance support should therefore connect prudential policy with data lineage and control testing.


Recovery planning and solvent exit need credible execution

PRA-regulated banks need recovery planning proportionate to their size and systemic importance, while non-systemic firms can also be subject to solvent exit expectations. The objective is to identify credible actions that could restore viability or allow an orderly exit before the firm reaches failure. A list of theoretical options is not enough where management has never assessed execution time, dependencies or market capacity.


Recovery indicators should provide enough warning to act. Capital, liquidity, profitability, asset quality and operational indicators can all be relevant, and escalation thresholds should link to governance decisions. Management actions should identify ownership, expected impact and constraints rather than assuming a capital raise or asset sale will always be available during stress.


The plan should be updated when the business changes. Acquisitions, new funding structures, outsourcing or rapid growth can make old recovery options unrealistic. Scenario exercises can help management understand whether the governance process works under time pressure.


Solvency UK is the core prudential framework for insurers

For insurers, the domestic prudential regime is Solvency UK. It covers capital requirements, technical provisions, governance, risk management and reporting and has replaced the previous UK implementation of Solvency II terminology for current reporting reference dates. Insurers should therefore ensure policies and regulatory documentation reflect current Solvency UK rules rather than historic references where those are no longer accurate.


The Solvency Capital Requirement and Minimum Capital Requirement remain central quantitative measures, while the governance framework requires appropriate risk-management and control functions. Internal models, matching adjustment, transitional measures and other specialised areas can apply depending on the insurer. The exact compliance programme should therefore be tailored to the liability profile and business model.


PRA supervision is not limited to meeting the reported SCR. The regulator considers the quality of risk management, management actions, liquidity and whether the firm's strategy can create vulnerabilities not captured adequately by point-in-time solvency metrics. Boards should understand both regulatory ratios and the risks that could move them rapidly.


ORSA should drive insurer risk and solvency decisions

The Own Risk and Solvency Assessment is a central management process for insurers. It should assess the firm's risk profile, capital needs and ability to meet solvency requirements under normal and stressed conditions. The PRA's current insurer authorisation guidance expressly reviews draft ORSA material for firms within the Solvency UK framework, illustrating its importance from entry through ongoing supervision.


The ORSA should reflect strategy and material risk rather than duplicate the regulatory SCR calculation. Stress and scenario analysis should test how the insurer would respond to adverse experience, market movements, claims, liquidity pressure or operational disruption. Management actions should be credible and consistent with the wider business plan.


Board challenge should be visible. The ORSA is strongest when it influences risk appetite, capital allocation, reinsurance and business planning rather than being approved after strategic decisions have already been made. Changes to the product or investment strategy should be reflected promptly where material.


Funded reinsurance requires enhanced governance

Funded reinsurance has become an important PRA focus for life insurers, particularly in connection with bulk purchase annuity growth. The PRA's supervisory framework expects firms to understand counterparty, collateral, recapture and concentration risk and to maintain controls proportionate to the scale and complexity of arrangements. Commercial benefits should therefore be assessed alongside the stressed consequences of counterparty failure.


Due diligence should consider the reinsurer, collateral structure, legal enforceability, asset quality and the firm's ability to manage recapture. Board risk appetite and limits should prevent exposures from growing faster than the firm's capacity to understand and manage them. Internal stress testing should explore adverse combinations rather than assuming only one risk crystallises at a time.


The regulatory framework should also connect reinsurance with liquidity and investment risk. A transaction can affect capital, asset strategy and operational dependencies simultaneously. Governance should therefore involve actuarial, investment, risk and legal expertise rather than sit only within the reinsurance function.


SMCR remains a core PRA accountability framework

The Senior Managers and Certification Regime applies across relevant banks and insurers and is intended to reinforce personal accountability. The PRA published PS12/26 in April 2026, with Phase 1 changes effective from 24 April 2026. Firms should ensure approvals, Statements of Responsibilities, fitness and propriety and governance processes reflect the updated framework.


Senior management responsibilities should correspond with real decision-making. A formal allocation is ineffective where key risk or prudential decisions are made elsewhere in the group without the accountable Senior Manager's involvement. Governance maps, committee terms and reporting lines should therefore be consistent.


Fitness and propriety should also be evidence-based. Competence, conduct, reputation and performance should be assessed appropriately and material concerns escalated. The regime works best when it supports active accountability rather than annual documentation exercises.


Operational resilience is a continuing PRA supervisory priority

Banks and insurers within scope of the PRA operational resilience framework should maintain important business services, impact tolerances, mapping, testing and remediation. The transition deadline of 31 March 2025 has passed, so firms should now be able to demonstrate that they can remain within impact tolerances under severe but plausible disruption. The 2026 supervisory focus is therefore on effectiveness and continued improvement.


Cyber and third-party outages are particularly important. The PRA's Business Plan identifies operational resilience and cyber risk as continuing priorities and SIMEX26 focuses on an extended outage at a major third-party technology provider. Firms should therefore test scenarios that expose concentration and dependency rather than only failures they can recover from easily.


Resilience should influence change management. Cloud migrations, mergers, new core platforms and outsourcing can alter dependencies and recovery capability substantially. The important-business-service map should be updated when those changes occur, and boards should understand residual vulnerabilities.


SS2/21 governs outsourcing and third-party risk

The PRA's SS2/21 sets expectations for outsourcing and third-party risk management. Firms should assess materiality, conduct due diligence, maintain appropriate contractual protections, manage data and security risk and have credible business continuity and exit strategies. The PRA's 2026 Business Plan states that it will continue assessing how firms have implemented SS2/21.


Third-party concentration is a key issue because several firms can depend on the same cloud, data or technology provider. At firm level, different suppliers may also rely on one underlying infrastructure, creating hidden concentration. Dependency mapping should therefore go beyond the names on the contract register where material.


Outsourcing governance should remain active after onboarding. Financial deterioration, cyber incidents, sub-outsourcing or changes in service location can change risk materially. Firms should retain enough internal expertise to challenge and, where necessary, replace providers.


Critical third-party risk sits alongside firm responsibility

The UK has introduced a regulatory framework for designated critical third parties to the financial sector, allowing the regulators to oversee certain services whose disruption could threaten wider stability. This can improve sector-level resilience but does not transfer responsibility away from banks and insurers. Firms remain responsible for managing their own dependence on third parties.


Boards should therefore avoid treating designation as an assurance certificate. A critical provider can still fail or experience service disruption, and the firm needs contingencies capable of protecting its important business services. Contract, data portability and exit planning remain relevant.


Sector-wide exercises can provide valuable insight into common vulnerabilities. Firms should use lessons from regulatory exercises and real incidents to improve their own scenarios and remediation. Operational resilience should remain connected to the actual provider landscape.


Climate-related financial risk is now a more mature expectation

The PRA updated its approach to climate-related financial risk through PS25/25. Banks and insurers should integrate material climate-related risks into governance, risk management and decision-making rather than maintain climate as a standalone disclosure project. Scenario analysis should be proportionate to the firm's exposures and should inform strategy where material.


For banks, climate risk can affect credit, market, operational and liquidity risk through customers, collateral and sectors. For insurers, underwriting, investments and liabilities can each create distinct exposure. The firm should identify how climate risk manifests through established risk categories rather than invent a disconnected parallel risk framework.


Board oversight and data remain important. Limitations should be understood and addressed progressively, while material uncertainty should not become a reason to ignore the risk. The objective is decision-useful analysis rather than precision that the available data cannot support.


Regulatory reporting and data quality are prudential controls

PRA reporting can include extensive capital, liquidity, solvency and other prudential data depending on firm type. The data is used directly in supervision, so accuracy, lineage and governance are central compliance requirements. Returns should be reproducible from controlled source data and reviewed by people who understand the prudential meaning of the figures.


Insurers now report under Solvency UK for relevant reference dates, while banks are preparing reporting changes associated with Basel 3.1 and the Strong and Simple framework. Change programmes should therefore include regulatory reporting rather than treating it as a downstream consequence of policy implementation. New calculations often require new data fields and controls.


Errors should be assessed for significance and corrected appropriately. Repeated reporting problems can indicate weaknesses in systems, governance or prudential understanding and may attract supervisory attention. Senior management should receive information on material reporting issues and remediation.

Model risk and AI need governance proportionate to use

Banks and insurers increasingly use models for credit, pricing, capital, claims, fraud and operational decisions. The PRA expects material models to be governed appropriately, with validation, change control and clear understanding of limitations. The importance of the model should determine the depth of oversight rather than whether the underlying technology is labelled AI.


The PRA's 2026 Business Plan also identifies responsible AI adoption as an emerging risk area. Firms should therefore understand where AI is used within material prudential or customer processes and ensure responsibilities, testing and monitoring are appropriate. Black-box reliance on a vendor does not remove the need to understand material model risk.


Model inventories and risk classification can help management focus assurance resources. Changes to data, methodology or business use should trigger review where they can affect outcomes materially. Documentation should support internal challenge and regulatory explanation.


PRA and FCA obligations should be governed together where risks overlap

Dual-regulated firms need to satisfy both regulators, but duplicating governance is not always efficient. Capital decisions can affect product strategy, operational resilience can affect customer outcomes and financial crime remediation can affect liquidity or growth. Boards should therefore understand where prudential and conduct risks interact while preserving clear ownership of the different regulatory requirements.


A common obligations and governance architecture can improve consistency. The same incident can be assessed for PRA, FCA and other notification consequences without departments sending conflicting regulatory explanations. Regulatory engagement should be coordinated while respecting any specific regulator's information requirements.


This is particularly important during major change. Acquisitions, restructurings, new products and outsourcing can affect threshold conditions, capital, conduct and operational risk simultaneously. Regulatory impact assessment should occur before the commercial decision becomes difficult to reverse.


A practical PRA compliance framework

The first step is to identify the applicable PRA Rulebook parts, supervisory statements and current regulatory initiatives based on the firm's category. Those obligations should be mapped to policies, risk processes, data, owners and evidence. Banks and insurers should avoid using one generic prudential framework because the regulatory architecture differs substantially.


The second step is assurance. Capital, liquidity, solvency, ORSA or ICAAP, recovery, outsourcing, operational resilience and regulatory reporting should be tested according to risk, with independent challenge where appropriate. Material assumptions and management actions should be tested rather than accepted because they appeared in last year's submission.


The final step is governance and remediation. Senior management should receive information that explains current headroom, emerging risks, implementation projects and unresolved control weaknesses. A good PRA compliance programme supports safer business decisions rather than simply preparing the firm for the next supervisory meeting.


How Buckingham Capital Consulting can help

Buckingham Capital Consulting supports regulated financial institutions with governance, risk, compliance reviews, regulatory change and remediation. For PRA-regulated firms, engagements can include prudential obligations mapping, governance reviews, SMCR, operational resilience, outsourcing, regulatory reporting controls, recovery or wind-down governance and readiness assessments for major regulatory change. Work can be scoped to complement existing risk, finance and actuarial teams rather than duplicate specialist quantitative functions unnecessarily.


For banks, support can focus on implementation governance around Basel 3.1, Strong and Simple, ICAAP, ILAAP, reporting and supervisory readiness. For insurers, work can cover governance around Solvency UK, ORSA, operational resilience, outsourcing, conduct-prudential interaction and regulatory change. Where highly specialised quantitative modelling or formal legal advice is required, the project can be coordinated with relevant actuarial, model or legal specialists. To discuss PRA compliance support, an independent regulatory review or a prudential remediation programme, contact Buckingham Capital Consulting.


Frequently asked questions

What firms are regulated by the PRA?

The PRA regulates banks, building societies, credit unions, insurers and certain major investment firms and financial holding companies according to the statutory framework. Many PRA-authorised firms are also regulated by the FCA for conduct matters. The exact PRA rules depend on the entity and business model.


When does Basel 3.1 apply in the UK?

The PRA finalised the UK Basel 3.1 framework in January 2026, with the vast majority of requirements scheduled to take effect on 1 January 2027. The Fundamental Review of the Trading Book Internal Models Approach has a later implementation date of 1 January 2028. Firms should therefore distinguish the delayed component from the wider 2027 implementation.


What is the Strong and Simple regime?

Strong and Simple is the PRA's proportionate prudential framework for eligible Small Domestic Deposit Takers. The simplified capital regime takes effect on 1 January 2027, while certain changes concerning ICAAP and ILAAP update frequency took effect in January 2026. Eligibility should be monitored as the institution grows or changes its activities.


What is Solvency UK compliance for insurers?

Solvency UK is the domestic prudential framework for relevant UK insurers and covers capital, technical provisions, governance, risk management and reporting. Firms also maintain processes such as the ORSA and may be subject to additional requirements depending on business model, internal models, matching adjustment or other features. PRA compliance should therefore be tailored to the insurer's actual risk profile.


Does PRA operational resilience still require work after March 2025?

Yes. The March 2025 deadline marked the point by which in-scope firms were expected to be able to remain within impact tolerances, not the end of operational resilience obligations. Firms need to continue testing, mapping, remediating vulnerabilities and updating the framework as services and dependencies change. The PRA continues to treat operational resilience and third-party risk as active supervisory priorities in 2026.


#PRA Compliance Support Consultancy 2026: Complete Guide for Banks and Insurers

 
 
bottom of page