The Financial Conduct Authority and Prudential Regulation Authority outlined how the UK’s critical third-party oversight regime will operate following the government’s designation of the first critical third parties. The Bank of England, PRA and FCA will jointly oversee the resilience of services these providers supply to UK financial firms and financial market infrastructures, focusing on systemwide risks arising from reliance on common providers. Designated critical third parties must identify and manage risks to their critical services, test and improve resilience arrangements, and engage openly with regulators and firms, particularly during incidents. The regime also promotes joint testing, information-sharing and greater transparency, but does not replace regulated firms’ responsibility for managing their own operational resilience and third-party dependencies. In 2025, third-party issues accounted for 27% of incidents reported to the FCA, of which 37% were cyber-related.
Financial Conduct Authority2026-07-28
Financial Conduct Authority and Prudential Regulation Authority outline expectations as critical third-party oversight regime goes live
The Financial Conduct Authority and Prudential Regulation Authority outlined expectations under the UK’s now-live critical third-party oversight regime. Designated providers must manage and test the resilience of critical services and support coordination during incidents, while regulated firms remain responsible for their own operational resilience and third-party risks.