The UK's Financial Conduct Authority (FCA), Bank of England, and Prudential Regulation Authority (PRA) have implemented a new oversight regime for Critical Third Parties (CTPs) that provide essential services to UK financial firms. This regime, now live, aims to strengthen operational resilience across the interconnected financial system by directly overseeing CTPs. CTPs are expected to identify and manage risks, test resilience, and engage openly with regulators and firms, particularly during incidents, while firms must continue managing their dependencies on these critical services.
Action required
Firms must review and update their processes for identifying, testing, and managing dependencies on Critical Third Parties. Designated CTPs must implement and demonstrate robust risk management, resilience testing, and communication protocols with regulators and financial firm clients.
Binding status
binding
Governing body
FCA
Direction
expanding scope
Innovation impact
mixed
Compliance requirements
Transparency requirements
- Promote greater transparency and stronger communication between CTPs and UK financial services clients.
- Share self-assessments where appropriate.
Affected industries
Affected roles
"As the regime is now live, firms should continue to consider how they identify, test and manage dependencies on critical services. Designated CTPs should engage openly with regulators and firms, including through testing and information-sharing."
Enriched 2026-07-29
Stay informed
Get daily intelligence briefs on this and related regulatory developments.