About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

UK Regulators Consult on Proposals to Strengthen Resilience of Services Provided by Critical Third Parties

Subscribe to our newsletter

The Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) are consulting on proposals to oversee and strengthen the resilience of services provided by critical third parties (CTPs) to UK regulated financial services firms and financial market infrastructure entities.

The proposals set out in the consultation paper follow Parliament’s adoption of the Financial Services and Markets Act 2023, which gave HM Treasury power to designate certain third-party service providers to UK firms and infrastructure entities as CTPs, and regulators power to make rules for, and oversee, designated CTPs.

The UK regulators acknowledge that CTPs provide benefits, including greater operational resilience and innovation, but note that if they are disrupted or fail, there are potential risks to financial stability that are beyond the ability of any individual firm to manage and require an appropriate but proportionate level of direct regulatory oversight.

“Third-party service providers often play a vital role in the delivery of important services by banks and insurers. These arrangements bring benefits, but also potential risks,” says Sam Woods, deputy governor of prudential regulation and CEO at the PRA. “We are consulting on proposals to implement new powers given to us by Parliament to manage these risks for those providers who could present risks to financial stability in an effective and proportionate way.”

Nikhil Rathi, chief executive at the FCA adds: “These proposals will improve the resilience of the critical third-party services that financial firms and their customers depend on, support market integrity and enhance UK competitiveness and growth.”

Proposals in the CP include: a set of fundamental rules that would apply to all the services CTPs provide to UK firms and FMIs; more granular operational risk and resilience requirements to apply only to CTPs’ material services to firms and FMIs; requirements for CTPs to provide certain information and assurance to the regulators, including submitting an annual self-assessment, and conducting regular testing of their ability to provide material services in severe but plausible disruption; requirements for CTPs to notify the regulators, the firms and FMIs they provide services to of specific disruptions that may adversely impact the services provided. CTPs will not be authorised or overseen in their entirety by the regulators, but the third-party services they provide will be overseen against these proposals once they are finalised.

Feedback to the CP is open until 15 March 2024. Subject to feedback, the regulators propose to publish final requirements and expectations for CTPs in the second half of 2024.

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: Sponsored by FundGuard: NAV Resilience Under DORA, A Year of Lessons Learned

Date: 25 February 2026 Time: 10:00am ET / 3:00pm London / 4:00pm CET Duration: 50 minutes The EU’s Digital Operational Resilience Act (DORA) came into force a year ago, and is reshaping how asset managers, asset owners and fund service providers think about operational risk. While DORA’s focus is squarely on ICT resilience and third-party...

BLOG

SEC’s 2026 Examination Priorities – 10 Notable Changes

The U.S. Securities and Exchange Commission (SEC) has released its Examination Priorities for 2026, and while many supervisory themes continue from 2025, the tone and structure of the new document reflect a decisive pivot. After years of rapid organisational expansion and broadening remit, the Division of Examinations is now emphasising consistency, prioritisation and the effective...

EVENT

AI in Capital Markets Summit London

Now in its 3rd year, the AI in Capital Markets Summit returns with a focus on the practicalities of onboarding AI enterprise wide for business value creation. Whilst AI offers huge potential to revolutionise capital markets operations many are struggling to move beyond pilot phase to generate substantial value from AI.

GUIDE

The DORA Implementation Playbook: A Practitioner’s Guide to Demonstrating Resilience Beyond the Deadline

The Digital Operational Resilience Act (DORA) has fundamentally reshaped the European Union’s financial regulatory landscape, with its full application beginning on January 17, 2025. This regulation goes beyond traditional risk management, explicitly acknowledging that digital incidents can threaten the stability of the entire financial system. As the deadline has passed, the focus is now shifting...