Which Financial Firms Get ORQUEST? Where Penetration Testing Sits in Your Answers

Which Financial Firms Get ORQUEST? Where Penetration Testing Sits in Your Answers

By EJN Labs · 4 Aug 2026 · 8 min read

ORQUEST is the Bank of England and PRA operational resilience questionnaire. It goes to financial firms, payment participants, market infrastructure and their critical suppliers, and is mandatory when the regulator requests it. ORQUEST does not name penetration testing as a required control, but it asks for assessment and scenario testing evidence, and a recent pen test is the strongest evidence most firms can attach. Typical UK cost: £4,800 to £16,800.

Which firms receive ORQUEST, and where ORQUEST penetration testing evidence fits

ORQUEST goes to firms the Bank of England and the PRA choose to ask, when they ask. It is an operational resilience questionnaire, not a standing annual return filed on a fixed date, and your penetration testing evidence fits as the proof behind the answers you give when it lands.

That “mandatory when requested” character is what catches teams out: there is no long lead time, and the quality of your answers depends entirely on the evidence you already hold. Firms searching for ORQUEST penetration testing guidance are usually asking two things. Am I in scope, and will my current testing evidence stand up when the questionnaire arrives?

The scope is broad. Banks and insurers supervised by the PRA sit at the centre, but the questionnaire also reaches payment participants, financial market infrastructure and the critical outsourced providers that sit behind them. If your organisation runs an important business service for the UK financial system, or supplies one, you should assume you can be asked.

The regulatory driver: operational resilience, not a checkbox

ORQUEST sits inside the Bank of England and PRA operational resilience agenda. The supervisory question behind it is simple: can your important business services stay within impact tolerances when something goes wrong, including when the something is a cyber attack? The questionnaire probes how you have assessed that question and what testing sits behind your answer.

Two points matter for honest planning. First, ORQUEST is mandatory when requested. You cannot decline it, and you cannot generate evidence retrospectively without that being visible. Second, the questionnaire does not contain a clause that says “commission a penetration test”. What it expects is assessment and scenario testing evidence: proof that you have identified vulnerabilities in the technology underpinning important business services, tested realistic disruption scenarios, and acted on the findings. In practice, an independent penetration test from a CREST-accredited firm is the cleanest way to evidence the vulnerability side of that expectation, and scenario-led testing such as red teaming maps directly onto the scenario side. We are being precise here deliberately: firms that claim a framework mandates testing when it does not tend to write weaker questionnaire answers than firms that explain exactly what evidence they hold and why it is proportionate.

What each type of firm should be able to evidence

The right evidence pack differs by where you sit in the financial system. The table below reflects how we see UK firms scope testing when an operational resilience questionnaire is on the horizon.

Firm typeTypical important business servicesTesting evidence that answers ORQUEST well
Banks and building societiesPayments, lending, customer account accessExternal and internal infrastructure tests, application tests on customer channels, scenario exercises
InsurersClaims handling, policy administrationApplication and API testing on claims platforms, cloud configuration review
Payment participants and processorsPayment initiation, clearing, settlement connectivityAPI and external infrastructure testing, segmentation checks around payment flows
Market infrastructureTrading, clearing, settlement servicesInfrastructure testing, resilience-focused scenario testing, red team exercises
Critical suppliers and fintech vendorsHosted platforms and services consumed by regulated firmsPlatform penetration test reports that regulated customers can reference in their own returns

Note the last row. Suppliers are pulled into ORQUEST indirectly: when a regulated firm answers questions about the resilience of an outsourced service, it needs evidence from you. A current, well-scoped penetration test report is often the single document that keeps a supplier relationship out of the remediation column of a customer’s questionnaire response.

How an ORQUEST-driven engagement runs

When we scope testing for a financial firm preparing for or responding to an operational resilience questionnaire, the sequence looks like this:

  1. Map testing scope to important business services. We start from your service map, not your asset register, so the report speaks the same language as the questionnaire.
  2. Agree the test types. Usually a blend of external infrastructure testing, API testing where payment or platform integrations exist, and cloud testing for hosted estates.
  3. Test under controlled conditions. UK-based testers work to an agreed window and escalation route, which matters when the estate carries live payment traffic.
  4. Report with resilience framing. Findings are tied to the business services they threaten, with severity, exploitability and remediation guidance.
  5. Retest and evidence closure. A retest letter showing fixes verified is materially stronger questionnaire evidence than an open findings list.

If you want a fuller picture of preparation steps before any engagement, our penetration testing checklist covers scoping, access and evidence handling in detail.

What it costs and how scope drives the price

Penetration testing for financial firms is priced by effort, and effort is driven by scope. UK day rates for CREST-accredited testing typically run £1,100 to £1,400 per day, so the total depends on how many external services, applications, APIs and cloud accounts sit behind your important business services.

The ranges below are typical for ORQUEST-relevant scopes.

ScopeTypical effortTypical UK cost
Single scope: external infrastructure or one application4 to 6 days£4,400 to £8,400
Blended scope: external, API and cloud around one business service6 to 9 days£6,600 to £12,600
Broad scope: multiple business services or supplier platform estate8 to 12 days£8,800 to £16,800

These are typical UK ranges rather than a quote. An exact price for your estate comes from a short scoping conversation via our quote form. For a wider view of what drives testing prices in the UK market, see our guide to penetration testing cost in the UK.

How EJN Labs approaches ORQUEST evidence for financial firms

EJN Labs is a UK firm delivering CREST-accredited penetration testing, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we understand what it is like to sit on the answering side of an assurance questionnaire. When we test for financial firms, we scope from the important business service down: we ask which services the regulator would care about, trace the systems that carry them, and test those paths first. That ordering shows up in the report, which means the document drops straight into a questionnaire response without translation work.

All testing is carried out by UK-based testers under UK contracts, which removes the data residency questions that offshore testing can create for regulated firms. Where a firm needs scenario testing evidence as well as vulnerability evidence, we design objective-led exercises against the disruption scenarios your resilience team has already documented. Our broader work with regulated finance clients is covered in our overview of cyber security for financial services.

Frequently Asked Questions

Which firms receive the ORQUEST questionnaire?

Financial firms, payment participants and market infrastructure receive ORQUEST from the Bank of England and the PRA, and its questions also reach the critical suppliers behind those firms. Any organisation running or supplying an important business service for the UK financial system should be prepared to answer it.

The questionnaire is mandatory when requested rather than a fixed annual return.

Does ORQUEST require a penetration test?

No, no ORQUEST clause mandates a penetration test by name. The questionnaire asks for assessment and scenario testing evidence around your important business services, and in practice an independent test from a CREST-accredited firm is the clearest way to evidence the technical assessment side.

Scenario-led exercises evidence the resilience testing side, and firms without recent testing usually find this the hardest section of the questionnaire to answer.

What does penetration testing for ORQUEST evidence cost?

Expect £4,400 to £8,400 for a single scope such as external infrastructure or one application, based on UK day rates of £1,100 to £1,400 for CREST-accredited testing and 4 to 6 days of effort. Larger blended scopes cost more, and exact pricing follows a free scoping call.

A blended scope runs 6 to 9 days, £6,600 to £12,600, and a broad multi-service scope 8 to 12 days, £8,800 to £16,800.

We are a supplier to regulated firms. Does ORQUEST affect us?

Yes, indirectly. ORQUEST covers the resilience of important business services, including the outsourced and supplier components behind them. When a regulated customer answers, it needs evidence from you. A current penetration test report on your platform, scoped to the service your customers consume, is often the document that keeps your relationship out of their remediation list.

How recent does testing evidence need to be for ORQUEST?

Test important business services at least annually and after significant change. ORQUEST publishes no fixed validity window, but evidence loses weight as it ages and as your estate changes, so most financial firms keep a current report and a retest letter confirming fixes rather than relying on older evidence.

Because ORQUEST arrives when requested rather than on a schedule, keeping evidence current matters more than it does for scheduled returns.

Get testing evidence in place before the questionnaire arrives

ORQUEST gives no comfortable run-up. If your firm or your regulated customers could be asked, the time to build assessment evidence is before the request lands. Tell us about your important business services and estate through our CREST penetration testing quote form and we will return a scoped proposal with fixed effort and pricing, usually within one working day.

Leave a Reply

Your email address will not be published. Required fields are marked *