← News
July 24, 2026
UK Regulators Activate Oversight Regime for Critical Third Parties to Bolster Financial Resilience
The FCA, Bank of England, and PRA have activated a joint oversight regime directly supervising designated Critical Third Parties to mitigate systemic operational risks.
The Financial Conduct Authority (FCA), the Bank of England, and the Prudential Regulation Authority (PRA) have initiated joint direct oversight of newly designated Critical Third Parties (CTPs), marking a major step in the UK's operational resilience framework.
The regulatory regime targets key third-party vendors—such as cloud platforms, technology suppliers, and data providers—whose failure or disruption could threaten the stability of the broader UK financial system and financial market infrastructures (FMIs). The government recently designated the first cohort of critical service providers under statutory powers designed to manage concentration risks across the financial sector.
According to regulatory data highlighted by the FCA, third-party dependencies have become a substantial source of operational vulnerabilities. In 2025, 27% of all operational disruption incidents reported to the FCA were attributed to third-party issues, with 37% of those involving cyber-related incidents. High-profile global disruptions, including major cloud and software outages, have underscored how technical failures at a single vendor can impact multiple institutions simultaneously.
Under the newly active regime, designated CTPs are required to identify and manage risks associated with their critical services, rigorously test and improve resilience arrangements, and maintain open communication channels with supervisors and client firms during major incidents. The framework also facilitates joint resilience testing and information-sharing to speed up recovery when widespread disruptions occur.
Regulators emphasized that the regime is designed to address systemic, market-wide vulnerabilities and does not regulate every supplier or relieve individual financial institutions of their ongoing obligations to manage their own operational resilience, outsourcing, and third-party risk arrangements.