Skip to main content

What Procurement, Risk and Compliance Need Before Approving a New Supplier

A practical guide to the evidence, judgements and sequencing required before onboarding a new third party in a regulated firm. After reading, you will know what to demand from the business sponsor, what each control function must verify, and where approvals typically fail.

Approving a new supplier in a regulated firm is not a procurement exercise with risk and compliance bolted on. It is a joint decision about whether the firm can safely extend part of its operation, data, or customer experience to a third party, and still answer for the outcome. The question most senior sponsors underestimate is not "can this supplier do the work?" but "can we evidence, on day one and every day after, that we remain in control of what they do for us?" This guide sets out what procurement, risk and compliance each need in hand before signing.

Key Executive Takeaways

  • Supplier approval requires a shared evidence pack covering criticality, financial resilience, data handling, operational resilience, and exit, not three parallel reviews that never meet.
  • The hardest judgements are about concentration, subcontracting chains, and whether the supplier can genuinely support your regulatory obligations, including SYSC 8, PRA SS2/21, and DORA where in scope.
  • Approvals fail most often because the business sponsor cannot articulate the service in terms of important business services, data flows, and exit triggers, not because due diligence was thin.

Start with the service, not the supplier

Before any questionnaire goes out, the sponsoring business must define what is actually being bought: the process, the data involved, the customers affected, and whether this supports an important business service. Procurement should refuse to progress a request that cannot answer these on one page. This classification drives everything downstream: tier, due diligence depth, contract clauses, board visibility, and regulatory notification thresholds.

Most firms get this wrong by letting the supplier's sales deck define the scope. The scope must be defined internally first, in your language, mapped to your service catalogue and your operational resilience framework.

What procurement needs

Procurement owns commercial integrity and the contracting pathway. Before approval, they need: a validated business case with alternatives considered, confirmation the service is not already provided elsewhere in the group, a competitive process or a documented single-source justification, pricing benchmarked against market, and a draft contract containing the regulatory clauses the firm requires as standard (audit rights, sub-outsourcing consent, data location, termination for regulatory cause, cooperation with regulators, service levels tied to the business service).

What good looks like: procurement can show the paper trail from business need to supplier selection without gaps, and the contract template was not weakened in negotiation on any clause risk or compliance flagged as non-negotiable.

What risk needs

Risk is assessing whether the firm can absorb what could go wrong. Before approval, risk needs: a completed inherent and residual risk assessment across operational, financial, information security, concentration, country, and conduct dimensions; evidence of the supplier's financial standing over at least three years; a clear view of the subcontracting chain, including any fourth parties handling material data or processing; an operational resilience assessment covering impact tolerance alignment, tested recovery capability, and dependency on shared infrastructure; and a credible, costed exit plan with triggers and a stressed timeline.

The judgement call risk teams most often duck is concentration. If three critical services sit with the same provider, or the same cloud region, say so and escalate. Do not let tiering hide it.

What compliance needs

Compliance confirms the arrangement meets regulatory expectations and does not transfer accountability the firm cannot transfer. Before approval, compliance needs: confirmation of the applicable regime (SYSC 8, PRA SS2/21, EBA outsourcing guidelines, DORA, GDPR, consumer duty implications); a data protection impact assessment where personal data is involved, with lawful basis and international transfer mechanisms documented; sanctions, anti-bribery and modern slavery screening on the supplier and its beneficial owners; conflicts of interest check against the sponsor and decision-makers; and, for material or critical arrangements, the register entry drafted and regulator notification pathway identified.

Where approvals break down

The common failure modes are predictable: the sponsor cannot describe the service in resilience terms, the exit plan is theoretical, the subcontracting chain is unknown past tier one, audit rights were traded away, and no one owns the supplier post-signature. Fix these before approval, not after.

The decision point

Before the approval committee meets, ask one question: if the regulator called tomorrow and asked us to walk them through this arrangement end to end, could we do it from the pack in front of us? If not, the file is not ready. Send it back.

Frequently Asked Questions

When should the board or a board committee see a supplier approval?

When the arrangement supports an important business service, involves material customer data, creates group concentration, or meets your internal materiality threshold. The board should see the decision, the exit plan, and the residual risk, not the questionnaire.

How deep should due diligence go into fourth parties?

At minimum, identify every fourth party that touches material data or supports a critical process, and understand the supplier's own controls over them. For critical arrangements under DORA, this extends further and must be documented in the register.

What is a credible exit plan?

One that names the trigger events, the alternative provider or in-house capability, the data return and deletion process, the stressed timeline, and the cost. If it has not been pressure-tested against a real scenario, it is not credible.

How do we handle a supplier the business urgently wants but due diligence is incomplete?

Do not approve conditionally on diligence being completed later. Either narrow the scope so the arrangement is non-material and approve on that basis, or hold the decision. Retrofitting controls after go-live rarely works.

Who owns the supplier after approval?

A named accountable executive in the first line, with defined review cadence, performance monitoring, and responsibility for triggering reassessment on material change. Without this, the approval pack becomes the last serious look at the relationship.

Frequently asked questions

When should the board or a board committee see a supplier approval?

When the arrangement supports an important business service, involves material customer data, creates group concentration, or meets your internal materiality threshold. The board should see the decision, the exit plan, and the residual risk, not the questionnaire.

How deep should due diligence go into fourth parties?

At minimum, identify every fourth party that touches material data or supports a critical process, and understand the supplier's own controls over them. For critical arrangements under DORA, this extends further and must be documented in the register.

What is a credible exit plan?

One that names the trigger events, the alternative provider or in-house capability, the data return and deletion process, the stressed timeline, and the cost. If it has not been pressure-tested against a real scenario, it is not credible.

How do we handle a supplier the business urgently wants but due diligence is incomplete?

Do not approve conditionally on diligence being completed later. Either narrow the scope so the arrangement is non-material and approve on that basis, or hold the decision. Retrofitting controls after go-live rarely works.

Who owns the supplier after approval?

A named accountable executive in the first line, with defined review cadence, performance monitoring, and responsibility for triggering reassessment on material change. Without this, the approval pack becomes the last serious look at the relationship.

Related guides

Regulation & Regulatory Change

How to Structure a Change in Control Application That Holds Its Timeline

A practical guide to preparing Section 178 Change in Control notifications that give the FCA and PRA what they need to assess without triggering clarification cycles that stall completion. Readers will learn how to sequence evidence, pre-empt supervisory questions, and build an application pack that supports a clean 60-working-day assessment.

Regulatory submissionAcquisitionRegulators
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Recovery Plan Regulators Will Accept as Executable

A practical guide to building a Recovery Plan that supervisors treat as a credible operational document rather than a compliance artefact. Readers will learn how to sequence stress calibration, option design, governance triggers, and management actions so the plan holds up under both desktop review and live stress.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Write an ICAAP Narrative That Shows Real Capital Judgement

This guide sets out how to construct an ICAAP document that evidences genuine board-level thinking about capital adequacy, not formulaic compliance. After reading, you will know how to sequence the narrative, where to place judgement, and how to make the document defensible under supervisory challenge.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Build a Climate Transition Plan That Withstands Investor and Regulatory Scrutiny

This guide sets out how senior leaders in regulated firms can construct a transition plan that holds up under both investor interrogation and prudential supervision. After reading, you will know how to sequence the plan's build, where credibility usually breaks down, and what evidence base you need to defend it.

Sustainability transitionRegulatory submissionRegulators
4 min readRead guide →
Regulation & Regulatory Change

How to Prepare a Credible Response to a Section 165 Request

This guide explains how to respond to an FCA or PRA Section 165 information request with the rigour, accuracy and timeliness regulators expect. After reading it, you will know how to mobilise the right people, control the production process, and engage credibly with the supervisor throughout.

Regulatory submissionRegulatorsBoards
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity