About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

UK Regulators Consult on Proposals to Strengthen Resilience of Services Provided by Critical Third Parties

Subscribe to our newsletter

The Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) are consulting on proposals to oversee and strengthen the resilience of services provided by critical third parties (CTPs) to UK regulated financial services firms and financial market infrastructure entities.

The proposals set out in the consultation paper follow Parliament’s adoption of the Financial Services and Markets Act 2023, which gave HM Treasury power to designate certain third-party service providers to UK firms and infrastructure entities as CTPs, and regulators power to make rules for, and oversee, designated CTPs.

The UK regulators acknowledge that CTPs provide benefits, including greater operational resilience and innovation, but note that if they are disrupted or fail, there are potential risks to financial stability that are beyond the ability of any individual firm to manage and require an appropriate but proportionate level of direct regulatory oversight.

“Third-party service providers often play a vital role in the delivery of important services by banks and insurers. These arrangements bring benefits, but also potential risks,” says Sam Woods, deputy governor of prudential regulation and CEO at the PRA. “We are consulting on proposals to implement new powers given to us by Parliament to manage these risks for those providers who could present risks to financial stability in an effective and proportionate way.”

Nikhil Rathi, chief executive at the FCA adds: “These proposals will improve the resilience of the critical third-party services that financial firms and their customers depend on, support market integrity and enhance UK competitiveness and growth.”

Proposals in the CP include: a set of fundamental rules that would apply to all the services CTPs provide to UK firms and FMIs; more granular operational risk and resilience requirements to apply only to CTPs’ material services to firms and FMIs; requirements for CTPs to provide certain information and assurance to the regulators, including submitting an annual self-assessment, and conducting regular testing of their ability to provide material services in severe but plausible disruption; requirements for CTPs to notify the regulators, the firms and FMIs they provide services to of specific disruptions that may adversely impact the services provided. CTPs will not be authorised or overseen in their entirety by the regulators, but the third-party services they provide will be overseen against these proposals once they are finalised.

Feedback to the CP is open until 15 March 2024. Subject to feedback, the regulators propose to publish final requirements and expectations for CTPs in the second half of 2024.

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: Sponsored by FundGuard: NAV Resilience Under DORA, A Year of Lessons Learned

Date: 25 February 2026 Time: 10:00am ET / 3:00pm London / 4:00pm CET Duration: 50 minutes The EU’s Digital Operational Resilience Act (DORA) came into force a year ago, and is reshaping how asset managers, asset owners and fund service providers think about operational risk. While DORA’s focus is squarely on ICT resilience and third-party...

BLOG

From London to New York: How Regulators and Firms Are Re-Drawing the AI Compliance Map

As artificial intelligence (AI) reshapes financial services, regulators and industry leaders are converging on a shared challenge: how to balance innovation with accountability. At A-Team Group’s recent RegTech Summit London, the conversation moved beyond theory into practice, with the Financial Conduct Authority (FCA) and leading firms outlining how principle-based regulation, collaborative testing, and emerging “agentic...

EVENT

Data Management Summit New York City

Now in its 15th year the Data Management Summit NYC brings together the North American data management community to explore how data strategy is evolving to drive business outcomes and speed to market in changing times.

GUIDE

Regulatory Data Handbook 2025 – Thirteenth Edition

Welcome to the thirteenth edition of A-Team Group’s Regulatory Data Handbook, a unique and practical guide to capital markets regulation, regulatory change, and the data and data management requirements of compliance across Europe, the UK, US and Asia-Pacific. This year’s edition lands at a moment of accelerating regulatory divergence and intensifying data focused supervision. Inside,...