joint standards 1 & 2 · 2024 the mandate prudential authority · fsca

Compliance, with evidence attached.

Joint Standards 1 and 2 of 2024 make insurers answerable to the regulator for their outsourcing and for their suppliers’ cyber resilience. We build for both sides of that table — the insurer running due diligence, and the service provider being assessed.

joint standard 1 of 2024 · outsourcing by insurers

Legacy outsourcing arrangements must comply by 1 December 2026.

Insurers must complete due diligence on their material service providers. Joint Standard 2 — cybersecurity and cyber resilience — has been in force since 1 June 2025.

days until the legacy-arrangement
compliance period ends
01 · Who this touches

One standard, two seats.

seat one

Insurers & UMAs

You must complete due diligence on every material service provider — on the Standard’s own terms, with evidence the Prudential Authority expects, re-assessed on schedule. Questionnaires in spreadsheets don’t survive a regulator’s visit.

seat two

Service providers

If you administer policies, collect premiums, or touch claims, you are in scope. Your clients now answer to the FSCA and Prudential Authority for your cyber resilience — and questionnaires are how that lands on your desk, again and again.

02 · The pair

A product for each seat.

The two connect: a supplier’s Evidently ISMS feeds live assurance into their clients’ Audit and Comply assessments — evidence, not promises, flowing both ways. Both are free to start.

03 · Begin

Not sure which seat is yours?

Some firms sit in both — assessed by insurers, assessing their own suppliers. Tell us where you sit and we’ll point you at the right starting line.

send a note ↗