Joint Standards 1 & 2 · Prudential Authority & FSCA

Compliance, with evidence attached.

Joint Standards 1 and 2 of 2024 make insurers answerable to the regulator for their outsourcing and for their suppliers’ cyber resilience. We build for both sides of that table — the insurer running due diligence, and the service provider being assessed.

joint standard 1 of 2024 · outsourcing by insurers

Legacy outsourcing arrangements must comply by 1 December 2026.

Insurers must complete due diligence on their material service providers. Joint Standard 2 — cybersecurity and cyber resilience — has been in force since 1 June 2025.

— days until the legacy-arrangement
compliance period ends
Who this touches

Who the standards apply to.

seat one

Insurers & UMAs

You must complete due diligence on every material service provider — on the Standard’s own terms, with evidence the Prudential Authority expects, re-assessed on schedule. Questionnaires in spreadsheets don’t survive a regulator’s visit.

seat two

Service providers

If you administer policies, collect premiums, or touch claims, you are in scope. Your clients now answer to the FSCA and Prudential Authority for your cyber resilience — and questionnaires are how that lands on your desk, again and again.

The pair

A product for each side.

The two connect: a supplier’s Evidently ISMS feeds live assurance into their clients’ Audit and Comply assessments — evidence, not promises, flowing both ways. Both are free to start.

Get in touch

Not sure where you fit?

Some firms sit in both — assessed by insurers, assessing their own suppliers. Tell us where you sit and we’ll point you at the right starting line.

Contact us →