This checklist is for compliance, risk, financial crime, surveillance and governance leaders at banks, insurers, pensions, hedge funds, asset and wealth managers, e-money and payment firms, and other FCA-regulated businesses. If you own third-party oversight, supplier risk or operational resilience and need to know where your evidence gaps are before your regulator or board finds them, this is for you.
Regulators' concerns: whether you know how exposed you are to concentration risk, whether your due diligence rests on tested evidence rather than vendor assertions, and whether your exit and incident-reporting arrangements would hold up under real pressure.
Due diligence and evidenced oversight: whether control expectations are agreed with suppliers up front rather than discovered at renewal, and whether the evidence you hold is continuous, tested and reported to the board as a metric rather than a narrative.
Connecting the dots: whether continuous monitoring, named accountability, enterprise risk integration and operational resilience testing are actually joined up, or running as four separate exercises that never meet.
The new model: whether your supplier population, including fourth parties, is tiered and mapped, tested evidence has replaced assertion for top-tier suppliers, and concentration risk is tracked as a standing board metric rather than raised once and forgotten.
Already fairly confident in your answers? Skip ahead and book a discovery call with our team to pressure-test them directly.