Fintech

A GBP 48.65m fine, eight years on: what TSB still teaches about migration governance

The FCA and PRA fined TSB GBP 48.65m for the 2018 IT migration failure. The final notices read as a delivery governance textbook. Here is what they say.

avanto.team·2026-08-04·As of 2026-08-04
in force

The fine

The FCA and PRA fined TSB GBP 48.65m in December 2022 for operational resilience and risk management failures related to the April 2018 IT migration. The FCA portion was GBP 29.75m. The PRA portion was GBP 18.9m. Both regulators applied 30% discounts for early settlement.

The fines are not the lesson. The final notices are the lesson.

What the notices say

The FCA final notice (reference FCA0018D) and PRA final notice (reference PRA0128) describe a migration governance failure with a specific anatomy. The failure is not technical. The failure is decision-making.

Five findings recur across both notices:

  1. The migration was treated as an IT project, not a business-critical event. TSB's board did not have a migration readiness criteria document. The CEO and CIO received go-live recommendations from the programme team without independent challenge. The regulators found that "the Firm did not manage the migration as a discrete, business-critical event requiring enhanced governance."

  2. Testing was insufficient and misread. The SABADell Protekt4 platform migration used data from a test environment that did not replicate production data volumes or edge cases. TSB's programme team reported green status on testing. The regulators found that "the testing approach was not sufficiently rigorous to provide assurance that the new platform would operate effectively at go-live."

  3. The decision to proceed was not evidence-based. On 18 April 2018, the programme steering committee recommended go-live. The board approved. Neither body had seen a production-equivalent test. Neither body had an independent readiness assessment. The regulators found that "the decision to proceed was taken without adequate assurance."

  4. Incident response was unprepared. When the migration failed on 20 April 2018, TSB had no rollback plan that could be executed within an acceptable timeframe. The bank could not process payments, could not access customer accounts, and could not quantify the scope of the failure for 12 days. The regulators found that "the Firm's incident response was inadequate and poorly prepared."

  5. Customer communication was absent. TSB customers were not informed of the migration risk before go-live. When the failure occurred, TSB's communication was delayed, inconsistent, and in some cases inaccurate. The regulators found that "the Firm failed to communicate effectively with its customers during and after the incident."

The design lesson

The lesson is not "do not migrate." The lesson is "do not migrate without governance that matches the risk."

A migration governance framework that would have prevented the TSB failure has three components:

  1. Independent readiness assessment. A party outside the programme team, with no career stake in the go-live decision, produces a written readiness assessment against defined criteria. The board sees both the programme team's recommendation and the independent assessment.

  2. Production-equivalent testing. Testing must use data volumes, edge cases, and integration points that replicate production. A test that passes in a synthetic environment with 10% of production volume is not a test. It is a rehearsal.

  3. Rollback and customer communication plans. The rollback plan must be tested, timed, and executable without programme team approval. The customer communication plan must be pre-drafted, pre-approved, and triggerable by the incident response team, not by the programme steering committee.

Why this still matters in 2026

Banks are migrating again. The 2027 instant payments deadlines, DORA operational resilience requirements, and the ongoing shift to cloud-native core banking platforms are driving a new wave of migrations. The TSB failure is eight years old. The governance failures it exposed are not.

Sources

  • FCA Final Notice, TSB Bank plc, 20 December 2022 (reference FCA0018D)
  • PRA Final Notice, TSB Bank plc, 20 December 2022 (reference PRA0128)
  • FCA/PRA Joint Investigation Report, 2019

EN draft. Public-record analysis. No client permission required. No SME quotes fabricated.