Critical third parties: supervision moves up the stack
The FCA and PRA have confirmed the first designated critical third parties under the new oversight regime, extending direct regulatory reach beyond authorised firms to the technology and data providers they depend on. For senior leaders, this reshapes accountability for concentration risk and forces a rethink of how operational resilience is evidenced at board level.
The UK has just crossed a threshold in operational resilience supervision. On 28 July, the FCA and PRA confirmed that the Bank of England, PRA and FCA will jointly oversee the first designated critical third parties (CTPs), giving regulators direct visibility into the providers that sit beneath the regulated perimeter (FCA). The framing from Mark Francis, FCA director of specialists, and Simon Dixon, PRA director of supervisory risk specialists, is unambiguous: resilience is no longer just about your own individual organisation (FCA).
From firm-level to system-level accountability
The existing operational resilience regime placed the burden squarely on regulated firms to manage outsourcing risk. That has not gone away. What has changed is the addition of a parallel supervisory track over the providers themselves, targeting the concentration that emerges when banks, insurers, payment firms and FMIs rely on the same handful of cloud, technology and data specialists (FCA). The regulators cite the 2024 CrowdStrike outage and the cyber incidents at Marks & Spencer and Jaguar Land Rover as evidence that disruption at a single provider can propagate simultaneously across many organisations (FCA).
For boards, this creates an awkward dynamic. Direct oversight of CTPs does not transfer responsibility away from the firm. It layers a new information source on top: regulators will now have their own view of provider resilience, and they will expect firms to reconcile that view with their own third party risk assessments. Where a firm's due diligence diverges from the supervisory picture, the gap becomes a governance problem.
The concentration question moves to the top of the agenda
The CTP regime does not resolve concentration risk. It makes it visible. Once regulators formally designate a provider as critical, the firms depending on that provider inherit a labelled exposure. That has consequences for capital planning conversations with the PRA, for recovery and resolution assumptions, and for the way exit and substitutability are evidenced. Andrew Bailey's recent public warning that frontier AI may make cyber-attacks faster and easier to perpetrate, outages more disruptive, and scams by criminals more convincing sits directly alongside this (Bank of England). The regulatory posture is that resilience must be demonstrated through stress tests and penetration testing, not asserted (Bank of England).
Stakeholder dynamics shift too. CTPs themselves are now direct counterparties to supervisors, which changes the commercial conversation with client firms. Contract terms, incident disclosure protocols, and the granularity of assurance reporting will all come under pressure. Providers that historically pushed back on bespoke financial services requirements have less room to do so when the Bank, PRA and FCA are on the other side of the table.
What senior leaders should do next
Three items deserve immediate board attention. First, a mapping exercise: which of the firm's material third parties are now, or are likely to be, designated CTPs, and what does that mean for the current risk register. Second, a reconciliation protocol: how will the firm compare its own provider assessments against supervisory findings, and who owns the gap. Third, a concentration statement: what is the firm's tolerance for shared dependency on a designated provider, and how is that being tested.
The CTP regime is a supervisory instrument, but its real effect is on internal governance. Boards that treat it as a procurement matter will find themselves explaining why to their regulator.
Sources
Polar Insight helps senior leaders in financial services understand what their key stakeholders actually think before significant decisions are made.
Book a conversation