Skip to main content

Critical third parties: supervision moves up the stack

The FCA and PRA have confirmed the first designated critical third parties under the new oversight regime, extending direct regulatory reach beyond authorised firms to the technology and data providers they depend on. For senior leaders, this reshapes accountability for concentration risk and forces a rethink of how operational resilience is evidenced at board level.

The UK has just crossed a threshold in operational resilience supervision. On 28 July, the FCA and PRA confirmed that the Bank of England, PRA and FCA will jointly oversee the first designated critical third parties (CTPs), giving regulators direct visibility into the providers that sit beneath the regulated perimeter (FCA). The framing from Mark Francis, FCA director of specialists, and Simon Dixon, PRA director of supervisory risk specialists, is unambiguous: resilience is no longer just about your own individual organisation (FCA).

From firm-level to system-level accountability

The existing operational resilience regime placed the burden squarely on regulated firms to manage outsourcing risk. That has not gone away. What has changed is the addition of a parallel supervisory track over the providers themselves, targeting the concentration that emerges when banks, insurers, payment firms and FMIs rely on the same handful of cloud, technology and data specialists (FCA). The regulators cite the 2024 CrowdStrike outage and the cyber incidents at Marks & Spencer and Jaguar Land Rover as evidence that disruption at a single provider can propagate simultaneously across many organisations (FCA).

For boards, this creates an awkward dynamic. Direct oversight of CTPs does not transfer responsibility away from the firm. It layers a new information source on top: regulators will now have their own view of provider resilience, and they will expect firms to reconcile that view with their own third party risk assessments. Where a firm's due diligence diverges from the supervisory picture, the gap becomes a governance problem.

The concentration question moves to the top of the agenda

The CTP regime does not resolve concentration risk. It makes it visible. Once regulators formally designate a provider as critical, the firms depending on that provider inherit a labelled exposure. That has consequences for capital planning conversations with the PRA, for recovery and resolution assumptions, and for the way exit and substitutability are evidenced. Andrew Bailey's recent public warning that frontier AI may make cyber-attacks faster and easier to perpetrate, outages more disruptive, and scams by criminals more convincing sits directly alongside this (Bank of England). The regulatory posture is that resilience must be demonstrated through stress tests and penetration testing, not asserted (Bank of England).

Stakeholder dynamics shift too. CTPs themselves are now direct counterparties to supervisors, which changes the commercial conversation with client firms. Contract terms, incident disclosure protocols, and the granularity of assurance reporting will all come under pressure. Providers that historically pushed back on bespoke financial services requirements have less room to do so when the Bank, PRA and FCA are on the other side of the table.

What senior leaders should do next

Three items deserve immediate board attention. First, a mapping exercise: which of the firm's material third parties are now, or are likely to be, designated CTPs, and what does that mean for the current risk register. Second, a reconciliation protocol: how will the firm compare its own provider assessments against supervisory findings, and who owns the gap. Third, a concentration statement: what is the firm's tolerance for shared dependency on a designated provider, and how is that being tested.

The CTP regime is a supervisory instrument, but its real effect is on internal governance. Boards that treat it as a procurement matter will find themselves explaining why to their regulator.

What this reveals

The CTP regime exposes a governance blind spot most boards have not yet reckoned with: operational resilience has been treated as a firm-level compliance exercise, evidenced through the firm's own due diligence on providers, while the actual risk sits in system-level concentration the firm cannot see on its own. Once regulators publish their own view of provider resilience, any gap between that view and the firm's internal assessment becomes a governance problem, not a procurement one. Other leadership teams may wrongly assume that a green-rated third party register, SOC reports and contractual rights are sufficient evidence, when what is now required is a reconciled position between internal assumptions and the supervisory picture. This matters beyond the designated CTPs because every regulated firm dependent on shared infrastructure now inherits a labelled concentration exposure it must be able to explain at board level.

Questions accountable leaders should ask

  • 01If a regulator published its own resilience assessment of your top ten providers tomorrow, would it reconcile with the picture your third party risk function currently presents to the board?
  • 02Can you evidence, with tested data rather than contractual assertion, how a simultaneous outage at a designated CTP would propagate through your important business services and those of your peers?
  • 03Who on your board actually owns concentration risk as a standing item, and when was it last stress-tested against a live scenario rather than reviewed as a register?
  • 04Have your exit and substitutability plans been pressure-tested against the realistic time, cost and regulatory tolerance for switching, or do they rely on assumptions no one has revisited since they were written?
  • 05How would you demonstrate to a supervisor that your board challenged, rather than merely received, the last third party resilience assessment?

What accountable leaders should do now

  1. 1Commission a reconciliation exercise between your internal third party risk view and the emerging supervisory picture on designated CTPs, and identify explicitly where the two diverge before a regulator does it for you.
  2. 2Reframe concentration risk as a board-owned governance topic with a named accountable executive, standing agenda time, and a documented tolerance, rather than as a line item in the operational risk report.
  3. 3Stress-test exit, substitutability and simultaneous-outage scenarios against your important business services using live evidence from recent incidents (CrowdStrike, M&S, JLR), and record the assumptions that failed.
  4. 4Update the board's evidence standard for operational resilience so that assertions are replaced by tested outputs, including penetration testing, scenario walkthroughs and independent challenge of provider claims.
  5. 5Establish a mechanism to track supervisory signals on CTP oversight and AI-enabled cyber risk continuously, so board conversations are informed by what regulators are saying now, not by the last annual review.

Explore the practical guide

This guide identifies where board-level strategic thinking typically diverges from what supervisors actually care about in financial services, and how to spot and close those gaps before they become enforcement problems. After reading, you will be able to audit your own board papers and strategy documents for the specific blind spots regulators notice.

Read the guide

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity

Stakeholder Signals

Consequential developments in financial services and other regulated markets, with one implication for accountable leaders.