A successful data move can still produce a failed service
A banking migration has at least two finish lines. Records must reach their destination intact, and customers must be able to use the services those records support. TSB crossed the first without reliably crossing the second. The UK regulators’ December 20, 2022 announcement says the data migrated successfully in April 2018, while the new platform immediately encountered technical failures. Branch, telephone, online and mobile services were disrupted. Some problems persisted until December. This is therefore a case about operational continuity, rather than evidence that every customer’s money or account record disappeared. [1]
The distinction matters because a bank is a coordinated service, not simply a database. A correct balance has limited practical value if the customer cannot access it, make a payment or receive help. Conversely, temporary unavailability does not by itself establish that the underlying deposit has been lost. The incident illustrates how technology, service capacity and governance can combine to impair access without being the same kind of event as insolvency or a trading loss.
What the bank was trying to change
TSB had been separated from Lloyds Banking Group and continued to use its technology. After Sabadell acquired TSB in 2015, the migration programme sought a UK-adapted version of Sabadell’s Proteo platform. The new platform was called Proteo4UK; SABIS, a Sabadell subsidiary, was the principal provider. The main migration took place over April 20–22, 2018. A platform already used elsewhere was a starting point, not proof that a newly adapted UK implementation was ready. [2]
There is an understandable commercial logic to replacing an inherited technology dependency. A bank may want more control over product development, lower recurring costs or a common platform within its group. Those benefits arrive over time. Migration risk is concentrated around the point when customers begin relying on the replacement. That asymmetry makes the approval decision important: expected future savings cannot answer whether the service can safely operate on Monday morning.
The relevant comparison is also broader than change versus no change. Maintaining a legacy system has costs and risks of its own. A disciplined decision compares the proposed migration with realistic alternatives, including a delay, a different scope or additional preparation. The TSB findings do not establish that banks should never modernize their infrastructure. They establish why a commercially attractive destination does not eliminate the need for evidence about the journey.
The regulatory outcome, with the numbers separated
The FCA imposed a £29.75 million penalty and the PRA imposed £18.9 million, for a combined £48.65 million. Both authorities announced the outcome on December 20, 2022. TSB qualified for a 30% early-settlement discount; the combined undiscounted figure was £69.5 million. The regulators separately reported £32.7 million in customer redress. The fine was not a compensation fund added to a second, independent £48.65 million penalty. [1, 3]
These categories answer different questions. A penalty is an enforcement consequence. Redress addresses customer detriment through the remediation process. Technology expenditure purchases or repairs operating capability. Lost revenue, staff time and customer departures can be economically important but cannot be inferred by adding the disclosed fine and redress. Even an accurately calculated sum of the two would be an incomplete measure of the incident’s total cost.
The timing differs as well. Customer disruption began in 2018, while the joint institutional enforcement outcome arrived in 2022. It would be misleading to present the penalty date as the date of the outage, or to imply that customers waited until the enforcement announcement before any remediation occurred. A case chronology needs separate dates for the operational event, customer response and regulatory resolution.
Testing is evidence about a particular configuration
The FCA identified shortcomings in planning, testing, risk management and outsourcing. Its final notice describes a curtailed form of non-functional testing involving the data centres’ active-active configuration. It considered that the omitted testing would likely have exposed a configuration problem. That is a specific finding about evidence missing before migration, not a claim that any conceivable test would have prevented every subsequent problem. [2]
Functional testing asks whether an operation produces the right result. Capacity and resilience testing ask whether it still does so under realistic demand and failure conditions. A system might process one customer’s request correctly while struggling when many customers log in together. It might work with one component isolated but fail when components interact. A meaningful approval therefore needs the test conditions, their relationship to production and the exceptions, not merely a percentage of test scripts marked complete.
Scheduling creates a further problem. If defects emerge late, there may be too little time to repair and retest them before a promised date. Parallel work is not inherently wrong, but it can reduce the evidentiary value of an earlier result when later changes alter the tested system. The analytical question is whether the final service configuration has been demonstrated to meet requirements, rather than whether enough activity has occurred to fill a project dashboard.
A supplier inside the group is still a dependency
The PRA’s final notice focuses on the bank’s control of its outsourcing arrangement and the operational risks surrounding the migration. Using a group provider did not remove the bank’s responsibility for understanding what that provider could deliver. The notice also explains the background commercial and prudential incentives for moving away from the Lloyds arrangement. Those incentives explain the project’s importance; they do not establish readiness. [3]
An affiliated provider may offer closer access to management and shared objectives. It can also create false comfort if familiarity substitutes for a documented assessment. A bank needs to distinguish confidence in a relationship from evidence about a service. The provider’s intentions, experience in another market and commitment to a deadline are relevant, but none is identical to demonstrated capacity in the implementation being approved.
Outsourcing also produces an information chain. The bank relies on a provider, which may rely on other suppliers. An assurance passed through that chain can lose its qualifications. A statement that a supplier expects to finish a task can become, in a summary, a statement that it is ready. The general governance lesson is to preserve the original scope, outstanding conditions and accountable owner as information travels upward. A concise report is useful only if it remains a faithful report.
Why fallback channels are not automatically independent
The FCA describes a cascade: customers encountering problems with digital services tried telephone banking, increasing pressure on that channel, while branches also faced demand and technology problems. The bank did not return to business-as-usual until December 10, 2018. These findings make the case more informative than a simple uptime statistic. [2]
A fallback is valuable when it can actually absorb the displaced activity. A telephone service sized for normal demand may not be able to replace a digital channel used by a large customer population. Branch staff may also rely on the affected infrastructure. Counting the number of channels can therefore overstate resilience if their dependencies and peak loads are correlated.
An illustrative capacity exercise makes the point without estimating TSB’s actual traffic. Suppose an online service normally handles 100,000 daily interactions and a call centre handles 5,000. If only one in ten displaced online interactions becomes a call, the call centre faces 10,000 additional requests, three times its normal total workload when combined with the existing calls. Redirection is not the same as recovery. The assumptions are hypothetical; the mechanism is why contingency planning needs demand scenarios.
Accountability without treating one person as the entire cause
A later PRA action, announced April 13, 2023, fined former chief information officer Carlos Abarca £81,620. The authority found that he had failed to take reasonable steps to ensure adequate management and supervision of the outsourcing arrangement. It identified assurance given to the board without sufficient underlying assurance having been obtained. The penalty was a separate individual enforcement action, not part of the £48.65 million institutional total. [4]
This additional outcome sharpens the accountability question without reducing a complex programme to a single individual. Effective oversight depends on responsibilities being assigned, evidence being available and concerns being escalated. A named executive’s assurance is most valuable when it rests on a process that can be examined. Personal accountability and organizational controls complement one another; either can be weakened if the other is treated as a substitute.
It is equally important not to expand the finding into unsupported allegations about motives. A regulatory conclusion that reasonable steps were not taken does not require an assertion that a manager intended customer harm. Explaining what assurance was missing is both more precise and more useful than attributing a state of mind that the cited outcome does not establish.
Historical rules and the lasting operating lesson
The Bank of England explicitly notes that the PRA’s overarching operational-resilience framework was introduced in 2021, after this migration, while the case drew on longstanding requirements already applicable during the relevant period. The 2018 conduct should not be described as a breach of a framework that did not yet exist. Nor should UK enforcement be presented as a U.S. regulatory action. [5]
The broader analytical questions concern evidence: which configuration was tested, which exceptions remained, who understood the supplier chain, what would happen if several customer channels were impaired together, and who had the authority to delay. These are analytical questions, not a claim that a particular checklist guarantees success or that a later incident proves negligence.
TSB’s case ultimately separates execution milestones from service outcomes. Copying data, completing a project phase and obtaining a supplier letter can each be real achievements while leaving the bank exposed to a consequential failure. The durable lesson is to judge readiness in terms of the customer’s usable banking service and the evidence supporting that judgment. That perspective preserves the value of modernization while making its concentrated transition risk visible.
Sources
- FCA, joint penalty announcement, December 20, 2022SourceBack to text: ↑1↑2
- FCA, TSB final notice, December 20, 2022, especially summary and programme findingsSource · PDFBack to text: ↑1↑2↑3
- PRA, TSB final notice, December 20, 2022Source · PDFBack to text: ↑1↑2
- PRA, Carlos Abarca penalty announcement, April 13, 2023SourceBack to text: ↑
- Bank of England, institutional penalty and historical framework clarification, December 20, 2022SourceBack to text: ↑