About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

UK Regulators Consult on Proposals to Strengthen Resilience of Services Provided by Critical Third Parties

Subscribe to our newsletter

The Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) are consulting on proposals to oversee and strengthen the resilience of services provided by critical third parties (CTPs) to UK regulated financial services firms and financial market infrastructure entities.

The proposals set out in the consultation paper follow Parliament’s adoption of the Financial Services and Markets Act 2023, which gave HM Treasury power to designate certain third-party service providers to UK firms and infrastructure entities as CTPs, and regulators power to make rules for, and oversee, designated CTPs.

The UK regulators acknowledge that CTPs provide benefits, including greater operational resilience and innovation, but note that if they are disrupted or fail, there are potential risks to financial stability that are beyond the ability of any individual firm to manage and require an appropriate but proportionate level of direct regulatory oversight.

“Third-party service providers often play a vital role in the delivery of important services by banks and insurers. These arrangements bring benefits, but also potential risks,” says Sam Woods, deputy governor of prudential regulation and CEO at the PRA. “We are consulting on proposals to implement new powers given to us by Parliament to manage these risks for those providers who could present risks to financial stability in an effective and proportionate way.”

Nikhil Rathi, chief executive at the FCA adds: “These proposals will improve the resilience of the critical third-party services that financial firms and their customers depend on, support market integrity and enhance UK competitiveness and growth.”

Proposals in the CP include: a set of fundamental rules that would apply to all the services CTPs provide to UK firms and FMIs; more granular operational risk and resilience requirements to apply only to CTPs’ material services to firms and FMIs; requirements for CTPs to provide certain information and assurance to the regulators, including submitting an annual self-assessment, and conducting regular testing of their ability to provide material services in severe but plausible disruption; requirements for CTPs to notify the regulators, the firms and FMIs they provide services to of specific disruptions that may adversely impact the services provided. CTPs will not be authorised or overseen in their entirety by the regulators, but the third-party services they provide will be overseen against these proposals once they are finalised.

Feedback to the CP is open until 15 March 2024. Subject to feedback, the regulators propose to publish final requirements and expectations for CTPs in the second half of 2024.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Managing Non-Financial Misconduct Under SMCR

Non-financial misconduct – encompassing behaviours such as bullying, sexual harassment, and discrimination is a key focus of the Senior Managers and Certification Regime (SMCR). The Financial Conduct Authority (FCA) has underscored that such misconduct is not only unethical but also poses significant risks to a firm’s culture and operational integrity. Recognizing the profound impact on...

BLOG

A-Team Insight Announces RegTech Award Winners as APAC Navigates Compliance Complexity

A-Team Group is proud to reveal the winners of our inaugural Capital Markets Technology APAC Awards 2025, recognising the firms and solutions demonstrating exceptional innovation across the Asia Pacific region. Alongside this announcement, we have launched our in-depth annual report, “The State of Capital Markets Technology in Asia Pacific 2025”, which examines the key trends...

EVENT

RegTech Summit New York

Now in its 9th year, the RegTech Summit in New York will bring together the RegTech ecosystem to explore how the North American capital markets financial industry can leverage technology to drive innovation, cut costs and support regulatory change.

GUIDE

The DORA Implementation Playbook: A Practitioner’s Guide to Demonstrating Resilience Beyond the Deadline

The Digital Operational Resilience Act (DORA) has fundamentally reshaped the European Union’s financial regulatory landscape, with its full application beginning on January 17, 2025. This regulation goes beyond traditional risk management, explicitly acknowledging that digital incidents can threaten the stability of the entire financial system. As the deadline has passed, the focus is now shifting...