TSB Bank plc
When the data migrated successfully, was the platform ready?
The FCA and PRA found that TSB's data migrated successfully in April 2018, but the new platform failed immediately; disruption affected all branches and a significant proportion of 5.2 million customers, with £48.65 million in combined penalties.
Documented impact
Authoritative findings
The documented event
Over the weekend of 20-22 April 2018, TSB migrated most corporate-system operations, customer services and customer data to a newly built platform. The FCA and PRA found that the data itself migrated successfully, but the platform immediately experienced technical failures. Branch, telephone, online and mobile banking were disrupted; all branches and a significant proportion of TSB's 5.2 million customers were affected, and the bank did not return to business as usual until 10 December 2018. TSB paid £32.7 million in customer redress. In December 2022, the FCA and PRA imposed combined penalties of £48.65 million for operational-risk-management and governance failures, including inadequate organisation and control of the migration programme and inadequate management of outsourcing risks arising from a critical third-party supplier.
Hypothetical institutional scenario
How might the same control pattern appear?
A migration reconciles every customer record successfully. The production platform, however, has not been demonstrated under realistic transaction volume, failure and recovery conditions, and key supplier-readiness evidence is largely self-attested. The successful data migration is treated as a proxy for end-to-end service readiness. Minutes after go-live, customers cannot reliably access the services that present and use the data.
Stress-test questions
Questions for challenge and assurance
-
Programme
Are data-migration integrity and live-platform readiness governed as two separate go-live decisions with separate accountable sign-offs?
-
Technology
Has the production platform been tested under realistic volume, dependency failure, recovery and customer-journey conditions?
-
Operations
Which critical supplier-readiness assertions have been independently verified rather than accepted through self-attestation?
-
Risk committee
Can governance stop go-live when reconciliation has passed but platform, resilience or supplier evidence remains incomplete?
NFRisk practitioner interpretation
Control implication
Completeness and correctness of migrated data and operational readiness of the platform serving that data are separate control decisions. A go-live gate should require independent evidence for each: reconciliation and integrity controls for the data; performance, capacity, recoverability, end-to-end service outcomes and supplier readiness for the platform. Passing one gate does not provide evidence that the other has passed.
Framework relevance
Explicitly labelled analytical mappings
Retrospective regulator-linked relevance: UK operational resilience
The FCA later used the TSB migration incident as an example in CP19/32, its consultation on operational resilience and impact tolerances. This establishes retrospective relevance; it does not mean the later framework applied to the 2018 event.
UK operational resilience · Financial Conduct Authority / Prudential Regulation Authority / Bank of EnglandEvidence register
Primary and supporting sources
-
Financial Conduct Authority / Prudential Regulation Authority
TSB fined £48.65m for operational resilience failings (opens in a new tab) 20 December 2022 · Authoritative primary source -
Financial Conduct Authority
Final Notice: TSB Bank plc (opens in a new tab) 20 December 2022 · Authoritative primary source -
Financial Conduct Authority
CP19/32: Building operational resilience (opens in a new tab) 5 December 2019 · Authoritative primary source
Publication note
A documented external event—not an NFRisk client engagement.
The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.
Return to the Risk Scenario LibraryFrom scenario to mandate
Test the equivalent control assumption in your environment.
NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.