The External Dependencies Boards Discover Too Late
Authorisation, contracts and longstanding relationships create a persuasive sense of control over intermediaries. They tell a board much less than it may assume about what will happen to customers, complaints, redress, distribution or reputation when one of those intermediaries fails. That gap between the internal dependency map and external reality is where many recent incidents may be lurking unseen.
Key Executive Takeaways
- Intermediaries are frequently treated as commercial relationships when they are, in fact, operational, conduct and reputational infrastructure.
- Standard third-party risk processes typically focus on contracts, controls and financial resilience. They are less well equipped to predict how customers, regulators and distributors would behave following a failure.
- The useful board question is not only whether a partner is well governed, but which external organisation, if it failed tomorrow, would make current customer, regulatory or growth assumptions untrue.
The recent cases are not identical, but their differences make the pattern more instructive. Amplifi exposed the dependence that can accumulate around an origination and broker channel. Halo showed how quickly customer access, claims and the treatment of safeguarded funds can change when an authorised payments firm enters special administration. Prosper showed how complaints arising through an appointed representative can crystallise at the authorised principal. The FCA's scrutiny of vertically integrated insurance businesses shows the regulator examining comparable questions before failure occurs: where responsibility sits, whether conflicts are genuinely controlled and whether the structure supports good customer outcomes.
Taken together, they expose the same underlying weakness. The formal classification of a relationship often reveals less about its real importance than the customer, operational and regulatory consequences that would follow if it stopped functioning.
The assumption underneath many board conversations about these relationships is simple and often wrong. It runs: this is a regulated commercial partner, so the material risks are contained by the contract, the regulatory perimeter and our oversight regime.
That framing survives because it is often adequate for the routine risks supplier assessments are designed to catch. It becomes less reliable when stakeholder behaviour and operational consequences become decisive: when customers need answers, regulators need evidence, distributors need alternative arrangements and complaints need resolution.
Four forms of hidden dependency recur.
Customer acquisition and distribution, where a single intermediary quietly accounts for a disproportionate share of new business and cannot be replaced at short notice.
Servicing and operational continuity, where the intermediary sits between the firm and the customer at the moments that define the relationship.
Complaints, remediation and Consumer Duty, where the regulated firm may remain responsible for outcomes it does not directly observe, and where failure can expose redress liabilities that were incompletely modelled or located elsewhere in the risk framework.
Regulatory and reputational transfer, where the intermediary's conduct, or its collapse, can be attributed by regulators, the press and customers to the firm whose name is attached to the product or customer relationship.
These dependencies are visible across recent incidents, although not every one is present in every case. Conventional third-party risk processes are not always designed to identify them.
The reason is structural. Supplier assessments typically test contracts, controls and financial resilience. They rarely test how customers, regulators, distributors and counterparties would actually behave following a failure.
That requires a different form of enquiry. It means speaking to the people outside the organisation whose reactions would determine the cost and trajectory of the event, then treating their likely behaviour as a risk input in its own right. The question is no longer simply whether the intermediary can withstand failure. It is whether the organisation understands what would happen around it if the intermediary did not.
This evidence rarely appears in a conventional risk pack because the process assesses the resilience of the organisation, rather than the likely behaviour of the surrounding stakeholder system.
The board-level test is therefore blunt:
Which external organisation, if it failed tomorrow, would make our current customer, regulatory or growth assumptions untrue?
An executive team can often name the likely candidates quickly. The harder question is whether it can show the board independent evidence about what the customers, regulators and distributors attached to those dependencies would actually do.
Responsible proximity means closing that gap around the two or three relationships that matter most, before an incident closes it for you.
Sources
- FCA: Amplifi Capital (U.K.) Limited enters administration
- FCA: Halo Financial Limited enters administration
- FCA: Prosper Capital LLP enters creditors' voluntary liquidation
- FCA: General insurance and vertically integrated business models
Which external dependency would matter most to your firm if it failed tomorrow?
A Proximity Sprint independently tests the assumptions attached to that relationship, showing where internal confidence and external reality align, and where they may have diverged before events expose the gap.
Polar Insight helps senior leaders in financial services understand what their key stakeholders actually think before significant decisions are made.
Book a conversation