iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 consultants for financial services

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 8 min read
5 primary sources cited on this page. How we check what is on this site

Two different things get conflated here and the conflation is expensive. ISO 27001 certifies an information security management system. The FCA’s operational resilience rules ask a different question entirely, and holding the certificate does not answer it.

What the operational resilience rules ask for

The FCA’s operational resilience rules came into force on 31 March 2022, and firms were expected to have completed mapping and testing, and to be able to remain within their impact tolerances, by 31 March 2025. The framework runs through PS21/3.

The duties are structural and none of them is an information security duty:

  • Identify important business services. Those whose disruption could cause intolerable harm to consumers or to market integrity.
  • Set impact tolerances. The maximum tolerable disruption to each important business service.
  • Map and test. Map the people, processes, technology, facilities and information supporting each service, and test whether you can stay inside the tolerance.
  • Learn and invest. Lessons-learned exercises, and investment in response and recovery.
  • Plan communications. How you will communicate when an important business service is disrupted.

Where the certificate does and does not help

Read that list against the standard and the gap is clear. ISO 27001 asks you to identify and treat information security risk. It does not ask you to identify important business services, to set an impact tolerance, or to map and test against one. Those concepts do not appear in it, because it is a different instrument answering a different question.

Where the standard does real work is underneath. Asset and supplier information built for Annex A feeds the mapping exercise. Business continuity and ICT readiness controls feed the testing. Incident management feeds response. A firm with a functioning ISMS is materially better placed to do the resilience work than one starting cold — but it has not done it.

The reverse direction matters more commercially for most readers. If you are a supplier to regulated firms rather than a regulated firm yourself, ISO 27001 is very often exactly what the client’s third-party risk team asks for, because it is a recognised external attestation they can file. They will then ask resilience questions the certificate cannot answer, and the firms that handle that well have prepared for both.

Accountability does not transfer with the work

The rules are explicit that firms remain accountable for compliance with existing outsourcing and operational resilience rules, including when they rely on services provided by third parties. Separately, the Bank of England, the PRA and the FCA operate a critical third parties regime directed at services whose failure could threaten the stability of the financial system.

For a supplier, that accountability is why your client’s due diligence is as demanding as it is: they cannot delegate the consequence, so they interrogate the control. Anticipating it changes the shape of what you should build. The questions that come after the certificate are about concentration risk, substitutability, exit planning and recovery times — and A.5.23, the cloud services control introduced in the 2022 edition, covers exactly the exit question they will ask.

The date to plan around

New incident reporting and third-party notification requirements take effect on 18 March 2027. For regulated firms that is a change to what must be reported and when. For suppliers it is a change to what your clients will need from you, and on what timescale.

The practical consequence for a supplier is contractual and it is worth getting ahead of. Notification obligations flow down: if a client has to report an incident inside a window, your contract has to oblige you to tell them inside a shorter one. If your incident management process was built purely against Annex A, it probably has no external notification clock in it at all.

That is a concrete, dateable piece of work, and it is the kind of thing that is cheap to build into a management system now and expensive to retrofit under a contractual deadline.

What the questionnaire asks after the certificate

Suppliers to regulated firms often expect the certificate to end the due diligence conversation. It starts it. Because the firm remains accountable whether or not it outsources, its third-party team cannot stop at an external attestation, and the questions that follow are consistently about the same four things.

Concentration. How much of their important business service depends on you, and how much of you depends on one cloud region or one subprocessor. A certificate says nothing about this, and it is the first question a resilience-literate reviewer asks.

Substitutability. If you failed, what would they do, and how long would it take. They are required to have thought about it, so they will ask whether you have.

Exit. How they get their data out, in what format, over what period, and what happens to your copies afterwards. This one maps directly onto A.5.23 and A.8.10 in the 2022 edition, so a well-built ISMS has the answer already.

Recovery. Stated recovery time and recovery point objectives, and evidence that they have been tested rather than documented. “We have a business continuity policy” is not an answer to this; a dated test report is.

None of those four is difficult if they were considered while the management system was being built. All four are expensive to assemble under a deal deadline. If you sell into financial services, the sensible move is to treat this list as part of the scoping conversation with a consultant rather than as something to discover during a client’s review.

What this does not change

Whatever sits on top, the arithmetic underneath is the same for every sector. Audit days come from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) and are a function of the people inside your scope, your sites and your complexity. Surveillance is one third of the initial audit every year and recertification is two thirds in year three. Your certification body cannot be your consultant, and cannot do the internal audit clause 9.2 requires.

Work out the cost for your headcount, or see the full audit-day table.

Common questions

Does ISO 27001 make us operationally resilient under the FCA rules?

No, and treating it as though it does is the expensive mistake in this sector. The rules ask you to identify important business services, set impact tolerances, map the resources supporting each service and test whether you can stay within tolerance. None of those concepts appears in ISO 27001, which is about an information security management system. The certificate supplies useful inputs to the work — asset and supplier information, continuity arrangements, incident management — and it does not do the work.

We supply regulated firms. Do we need ISO 27001?

Nobody obliges you to hold it, and clients frequently do. A regulated firm remains accountable for its outsourcing and resilience obligations when it relies on you, so its third-party risk team needs external evidence it can rely on, and ISO 27001 is the most widely recognised form of it. Expect it to be the start of the conversation rather than the end: the questions that follow are about concentration, substitutability, exit and recovery times.

What is happening in March 2027?

New incident reporting and third-party notification requirements take effect on 18 March 2027. For a supplier the practical effect is contractual: notification obligations flow down, so clients will need to be told about incidents inside a window short enough for them to meet their own. If your incident process was built only against Annex A it probably has no external notification clock in it, and that is far cheaper to add now than under a contract deadline.

Our parent company is in the EU. Does that change anything?

Possibly, and it is a question for someone who can advise on your group structure rather than for a general guide. EU financial entities are subject to their own digital operational resilience regime, which is separate from the UK rules and has its own requirements for ICT third-party arrangements. Where a UK entity sits inside an EU group or contracts with EU entities, both can be in play. What is consistent across them is the direction: more scrutiny of third parties, not less.

Should the scope be the regulated entity or the group?

It depends on who is asking and what they will read. A client doing third-party due diligence wants the scope to cover the service they buy, which may be delivered by a different group entity from the one holding the certificate. Group-wide scope is cleaner to explain and costs more to audit, because the headcount driving the audit-day band is larger. Entity-level scope is cheaper and needs the schedule to be unambiguous about what it covers.

Sources cited on this page

  1. FCA, Operational resilience
  2. FCA PS21/3, Building operational resilience
  3. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  4. ISO/IEC 27002:2022, Information security controls

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Get a costed answer, not a call-back to discuss pricing

Five questions, all of them click-only. Your details are the last step, never the first.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now