Skip to main content
NFRisk Non-Financial Risk advisory Start a Conversation
NFR-0052 Approved reference implementation

Royal Bank of Scotland, NatWest and Ulster Bank

When overnight processing failed, could the numbers still be trusted?

A 2012 software compatibility failure disrupted core banking processes, affected at least 6.5 million UK customers and resulted in £56 million of combined FCA and PRA penalties.

Technology & Change Risk Operational Resilience Data & Control Integrity Payments Risk Change & release management Batch processing System & back-out testing Data integrity Operational resilience Payments & clearing Control assurance

Documented impact

£56m Combined FCA and PRA penalties
6.5m customers UK customers directly affected
Service disruption Core banking and payment disruption
Data integrity failure Out-of-date balances, incorrect interest and inaccurate statements
£70.3m Approximate redress paid to UK customers

Authoritative findings

The documented event

In June 2012, Technology Services, the banks' centralised group IT function, backed out an upgrade to batch-scheduler software. The upgraded and previous versions were incompatible. The incident disrupted core processing across RBS, NatWest and Ulster Bank. Customers experienced problems accessing accounts and payments; some ATMs showed out-of-date balances; incorrect credit and debit interest was applied; and inaccurate statements were produced. The FCA fined the banks £42 million and the PRA fined them £14 million in November 2014. The FCA Final Notice also records approximately £70.3 million of redress to UK customers.

Hypothetical institutional scenario

How might the same control pattern appear?

Imagine that an overnight scheduler is backed out after a change. Channels remain partly available, but account updates are incomplete. Customers see stale balances, interest is applied incorrectly, payments queue behind and different systems recover at different speeds. How quickly would the institution know which numbers can still be relied upon?

Stress-test questions

Questions for challenge and assurance

  1. Technology

    Would change and back-out testing expose version compatibility and downstream data effects before production?

  2. Operations

    Can monitoring distinguish late batch completion from incomplete, duplicated or misordered processing?

  3. Risk committee

    Who can declare customer balances trustworthy after recovery, and what evidence must support that decision?

  4. Board

    Are important business services tested through customer and clearing outcomes, rather than platform availability alone?

NFRisk practitioner interpretation

Control implication

The important control question is not only whether a system is available. It is whether balances, interest, statements and payment positions remain complete, current and trustworthy after change, back-out and recovery. Recovery evidence should therefore prove data integrity and business-service outcomes, not merely restoration of technical availability.

Framework relevance

Explicitly labelled analytical mappings

Retrospective relevance

Regulator-linked operational-resilience relevance

The FCA later used the incident as an example in CP19/32, its consultation on building operational resilience and impact tolerances.

UK operational resilience · Financial Conduct Authority / Prudential Regulation Authority / Bank of England
NFRisk analytical mapping

Business disruption and system failures

NFRisk analytical mapping: the primary Basel event-type lens is business disruption and system failures. Execution, delivery and process management is a secondary contributing lens for the failed processing and change controls. This is not a regulator determination.

Sound Practices for the Management and Supervision of Operational Risk · Basel Committee on Banking Supervision

Evidence register

Primary and supporting sources

  1. Financial Conduct Authority

    Final notice: Royal Bank of Scotland Plc, National Westminster Bank Plc, Ulster Bank Ltd (opens in a new tab) 19 November 2014 · Authoritative primary source
  2. Financial Conduct Authority

    FCA fines RBS, NatWest and Ulster Bank Ltd GBP 42 million for IT failures (opens in a new tab) 20 November 2014 · Authoritative primary source
  3. Bank of England / Prudential Regulation Authority

    PRA fines Royal Bank of Scotland, NatWest Bank and Ulster Bank GBP 14 million for IT failures (opens in a new tab) 20 November 2014 · Authoritative primary source
  4. Financial Conduct Authority

    CP19/32: Building operational resilience (opens in a new tab) 5 December 2019 · Authoritative primary source
  5. Basel Committee on Banking Supervision

    Sound Practices for the Management and Supervision of Operational Risk (opens in a new tab) 1 February 2003 · Authoritative primary source

Publication note

A documented external event—not an NFRisk client engagement.

The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.

Return to the Risk Scenario Library

From scenario to mandate

Test the equivalent control assumption in your environment.

NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.

Start a conversation