Ok
logo_outline-1
CheckCircle

Author: Priscilla Gaudoin - Head of Risk & Compliance. First published in December 2021

CheckCircle

Topics: Third Party, Operational Resilience, Managing Risks

CheckCircle

Regions and Regulators: UK: FCA, PRA. USA: SEC, EU: EBA, DORA.

Recognised CPD Badge (transparent) 24 (1)

 

Strengthening Resilience: How to Build Robust
Third Party Risk Management Chains

 

Both the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA) require firms to identify and manage their risks. Over the years we’ve seen both regulators focus on outsourced and third party arrangements. Current efforts to build a more resilient financial services sector continue this theme both in the UK and overseas.
 

Regulatory Expectations for Operational Resilience

The regulators have been clear that operational resilience requires firms to adopt an holistic view of their operations. 

In May 2021, Deputy CEO of the PRA, Lyndon Nelson delivered a speech focusing on the outcomes of the operational resilience work, where he stated:

Firms have a variety of stakeholders including investors, employees, regulators, government, society and customers. The aim of building a resilient financial services sector requires thought to be given to the inter-firm dependencies.

Firms cannot afford to work in silos as building a more robust financial services sector needs wider consideration.
 

As alluded to earlier, the financial services sector already has existing requirements relating to outsourced arrangements. In addition to the overarching Principles for Businesses, there are also specific rules set out in PRA’s Supervisory Statements and Outsourcing part of the PRA rulebook as well as FCA’s outsourcing chapters in the Senior Managers Systems and Controls sourcebook. 

What Counts as a Third-Party Arrangement?

We tend to refer to outsourcing arrangements in a general manner. Outsourcing is usually where firms could conduct an activity inhouse, but choose to contract with another organisation to leverage their expertise or manage costs and resources. In regulatory terms, it is usually the material outsourcing parties that gain attention. 

However, it is possible to have key third party relationships that may not be classified as outsourcing for example, arrangements between firms and financial market infrastructures, or strategic partnerships with non-financial third parties. These third party providers could support the delivery of important business services.

The focus for regulated firms now is to ensure that they identify these relationships and manage the associated third party risks to their operational resilience frameworks.
 

Whilst this may sound obvious, from FCA’s own research, it appears that not all firms have thought about this. FCA’s survey findings indicated 50% of firms surveyed did not have a comprehensive list of their third party providers. (See our Blog Operational Resilience: Is Outsourcing on your Radar?)

Points for firms to note include that: 

  • The new operational resilience rules are meant to complement existing requirements.
  • Firms are reminded of their accountability regarding any outsourced or third-party arrangements. 

This links with the regulatory focus on governance and accountability within firms and the basis for the Senior Managers and Certification Regime (SM&CR). 

Steps for Managing Third-Party Risk

Managing exposure to external risks requires collaboration and early engagement. Firms need to identify (a) third party relationships and (b) those deemed to be material outsourcing arrangements and complete the following steps: 

 
  • Demonstrate that they are following the relevant rules and guidance within their firms
  • Assess any third party arrangements and identify those that meet the definition of outsourcing
  • Apply regulatory obligations appropriate to the risk management of third party relationships (outsourced or not)
  • Apply the rules and guidance through the extended supply chain 

Assessing Third-Party Arrangements

As part of the Operational Resilience workstreams, firms will have identified their important business services. Further consideration is needed to: 

  • Assess due diligence process for third party providers to align with materiality and risk assessment. Ensure this process also includes any sub-contracted providers
  • Manage relationships with the providers by clear ownership of the relationship, with good, open communication
  • Review the outcome of any monitoring or audits. Address any weaknesses and consider lessons from past events
  • Maintain an issues log and report timely and accurate data to management 

Firms will need to think about the specifics of the operational resilience. Maintaining a good dialogue with third parties is key to better understanding their perception of operational resilience and how it affects both parties. Early engagement benefits firms’ understanding of what each other is doing and helps coordinate work to avoid duplicating efforts or avoid delays where there might be dependencies.

Regulated firms face the challenges of gaining assurance from outsourced and third party arrangements. For some firms, this will mean that they need to explain the regulatory requirements to non-financial providers. 

Legacy Contracts: Where Things Stand Now

The PRA’s guidance required legacy outsourcing agreements entered into before 31 March 2021 to be reviewed and updated by 31 March 2022. That transition window has now closed, and firms should already be operating under the finalised requirements. The current focus for third-party risk management has moved on to the Critical Third Parties regime and the incoming Material Third-Party rules, covered above.

International Approaches: US, EBA and Basel

Looking further afield, we need to consider what is happening in other jurisdictions that might impact regulated entities.

Earlier in July, the US banking regulators issued its proposed guidance for public comment on third party risk management. Its proposals are similar to the UK. Highlighting the need for: risk identification; governance and oversight of third parties; due diligence on third parties; contractual arrangements; ongoing monitoring and contingency planning to terminate relationships. 

EBA Guidelines are echoed in the PRA’s supervisory statements relating to third party risk management. Principle 5 states: 

Principle 5: Banks should manage their dependencies on relationships, including those of, but not limited to, third parties or intragroup entities, for the delivery of critical operations. 

EBA also encourages risk assessment and due diligence of third party providers and requires banks to verify that the provider has at least equivalent level of operational resilience to safeguards a bank’s critical operations. It too encourages contingency and exit planning. 

Action required:

Early engagement is required by firms, not just to identify and review their third party arrangements, but to discuss vulnerabilities in processes. Building a good relationship with third parties will help with contractual renegotiations. It also aids understanding of impacts upon Important Business Services and identification of collective actions to respond to any issues. 

If you’d like to learn more about our Client Assurance Portal Solution or Supplier Oversight Solution, please contact us for further information on: Tel: 0800 408 3845 or hello@ruleguard.com.

The Critical Third Parties Regime: Live From July 2026

The financial sector's third-party risk landscape shifted decisively on 13 July 2026, when the Bank of England, PRA and FCA began jointly overseeing the first Critical Third Parties (CTPs) designated by HM Treasury: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited.

The regime, introduced under the Financial Services and Markets Act 2023, gives the regulators direct oversight of the resilience of services that underpin the UK financial system, though designation is not the same as full authorisation and does not extend to a provider's wider business. For regulated firms, this does not remove the obligation to manage their own third-party risk; it adds a further layer of oversight above the largest, most systemically important providers.

See our on-demand webinar on third-party risk for a deeper look at what the CTP regime means for firms relying on these providers.

Useful Resources:

This white paper delves into the intricacies of Third Party Risk Management (TPRM) and explores the evolving regulatory landscape surrounding it.

Gain in-depth insights into the evolving landscape of operational resilience in the UK financial services sector, in our free white paper.

typ-lp-frame

Genuine oversight. From first to third parties.

Book a discovery call with our RegTech Consultants to see how you can effortlessly demonstrate your adherence to global regulations with our Client Assurance Portal Solution.
 
Keep track of your third-party providers directly with Ruleguard’s Supplier Oversight Solution. Ensure protection against foreseeable harm to retail customers in line with cross-cutting rules.
 
Arrange a personalised discovery session

About the author

In a career spanning almost 30 years, Priscilla has worked as a consultant, CCO and MLRO providing regulatory oversight and advice to firms across the financial services industry. She is responsible for our thought leadership programme, writing regular articles and white papers, and hosting webinars on a variety of regulatory matters.
 
She is a Fellow of the International Compliance Association, a certified GRC practitioner, and a member of the Institute of Risk Management. 
 
 
Contact Priscilla
Priscilla photo-1