About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

UK Regulators Consult on Proposals to Strengthen Resilience of Services Provided by Critical Third Parties

Subscribe to our newsletter

The Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) are consulting on proposals to oversee and strengthen the resilience of services provided by critical third parties (CTPs) to UK regulated financial services firms and financial market infrastructure entities.

The proposals set out in the consultation paper follow Parliament’s adoption of the Financial Services and Markets Act 2023, which gave HM Treasury power to designate certain third-party service providers to UK firms and infrastructure entities as CTPs, and regulators power to make rules for, and oversee, designated CTPs.

The UK regulators acknowledge that CTPs provide benefits, including greater operational resilience and innovation, but note that if they are disrupted or fail, there are potential risks to financial stability that are beyond the ability of any individual firm to manage and require an appropriate but proportionate level of direct regulatory oversight.

“Third-party service providers often play a vital role in the delivery of important services by banks and insurers. These arrangements bring benefits, but also potential risks,” says Sam Woods, deputy governor of prudential regulation and CEO at the PRA. “We are consulting on proposals to implement new powers given to us by Parliament to manage these risks for those providers who could present risks to financial stability in an effective and proportionate way.”

Nikhil Rathi, chief executive at the FCA adds: “These proposals will improve the resilience of the critical third-party services that financial firms and their customers depend on, support market integrity and enhance UK competitiveness and growth.”

Proposals in the CP include: a set of fundamental rules that would apply to all the services CTPs provide to UK firms and FMIs; more granular operational risk and resilience requirements to apply only to CTPs’ material services to firms and FMIs; requirements for CTPs to provide certain information and assurance to the regulators, including submitting an annual self-assessment, and conducting regular testing of their ability to provide material services in severe but plausible disruption; requirements for CTPs to notify the regulators, the firms and FMIs they provide services to of specific disruptions that may adversely impact the services provided. CTPs will not be authorised or overseen in their entirety by the regulators, but the third-party services they provide will be overseen against these proposals once they are finalised.

Feedback to the CP is open until 15 March 2024. Subject to feedback, the regulators propose to publish final requirements and expectations for CTPs in the second half of 2024.

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: Sponsored by FundGuard: NAV Resilience Under DORA, A Year of Lessons Learned

Date: 25 February 2026 Time: 10:00am ET / 3:00pm London / 4:00pm CET Duration: 50 minutes The EU’s Digital Operational Resilience Act (DORA) came into force a year ago, and is reshaping how asset managers, asset owners and fund service providers think about operational risk. While DORA’s focus is squarely on ICT resilience and third-party...

BLOG

World Federation of Exchanges Urges Regulators to Balance Quantum Risk with Near-Term Cyber and AI Threats

The World Federation of Exchanges (WFE) has called on regulators to balance long-term quantum computing risks against more immediate operational challenges in the financial sector. The association’s press release highlights a substantial gap between regulatory expectations for early preparation and the industry’s current prioritisation of nearer-term threats such as generative artificial intelligence (GenAI) and cyber...

EVENT

TradingTech Summit New York

Our TradingTech Briefing in New York is aimed at senior-level decision makers in trading technology, electronic execution, trading architecture and offers a day packed with insight from practitioners and from innovative suppliers happy to share their experiences in dealing with the enterprise challenges facing our marketplace.

GUIDE

The DORA Implementation Playbook: A Practitioner’s Guide to Demonstrating Resilience Beyond the Deadline

The Digital Operational Resilience Act (DORA) has fundamentally reshaped the European Union’s financial regulatory landscape, with its full application beginning on January 17, 2025. This regulation goes beyond traditional risk management, explicitly acknowledging that digital incidents can threaten the stability of the entire financial system. As the deadline has passed, the focus is now shifting...