Critical Third Parties: A UK Risk Committee Checklist for 2026
The UK’s Critical Third Parties regime — overseen by the Bank of England, PRA and FCA — took effect 13 July 2026, putting oversight on risk committees.
FSMA 2023 gives the Bank of England, PRA and FCA new statutory powers to directly oversee “critical third parties” — providers whose failure could disrupt the UK financial system. HM Treasury made its first designations in mid-2026, naming Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited. For firms that depend on these providers, the regime does not remove existing outsourcing obligations — it adds direct regulatory scrutiny of the supplier, and boards are expected to show they understand what that means for their own resilience planning.
What is the UK’s Critical Third Parties regime, and who does it cover?
According to the Bank of England, the Bank, the PRA and the FCA began formally overseeing the first Critical Third Parties on 13 July 2026, following HM Treasury’s initial designation of four global cloud and technology providers. Designation is not decided by firms or by the providers themselves — HM Treasury designates a third party as critical based on regulator recommendations, typically where concentration risk means a large number of regulated firms rely on the same supplier for the same critical function. Once designated, the CTP itself takes on direct regulatory obligations around resilience, testing and incident reporting to the regulators — obligations that sit alongside, not instead of, the outsourcing due diligence regulated firms already owe under existing PRA and FCA rules.
The practical effect for a regulated firm’s board is indirect but real: your resilience is only as strong as your weakest critical dependency, and regulators now have a direct line into your key suppliers’ own resilience posture. That changes what “sufficient oversight” looks like at board level.
Executive Action:
- Map which of your critical operational functions depend on a designated CTP, directly or through a sub-outsourcing chain.
- Confirm your risk register distinguishes CTP-designated suppliers from ordinary third parties.
- Ask your resilience lead for a one-page summary of each designated CTP’s regulatory status and reporting obligations.
Why is critical third-party oversight now a risk committee responsibility?
Operational resilience has been a board-level accountability since the FCA and PRA’s 2021 operational resilience rules required firms to identify important business services and set impact tolerances for disruption. The CTP regime sharpens that accountability rather than replacing it: firms remain fully responsible for their own resilience even where a critical function depends on a designated supplier. That is a governance point, not a technical one, and it belongs with the risk committee because it concerns risk appetite, concentration risk and regulatory accountability under the Senior Managers regime — not day-to-day vendor management.
According to the FCA, oversight of CTPs is limited to the resilience of the services they provide to UK financial firms and market infrastructures — regulators are not underwriting the supplier’s overall business, only the specific services regulated firms rely on. That distinction matters for how a risk committee frames its own questions: the board’s job is not to second-guess a hyperscaler’s engineering, but to satisfy itself that the firm’s own contingency and exit planning holds up if a designated CTP is disrupted.
Executive Action:
- Add CTP concentration risk as a standing line item on the risk committee agenda, separate from general cyber risk reporting.
- Require evidence that impact tolerances for important business services reflect realistic CTP outage scenarios.
- Assign clear Senior Managers regime accountability for CTP-related resilience reporting.
How should risk committees assess exposure to designated CTPs?
Start with concentration, not compliance paperwork. A risk committee should be able to answer, in plain terms, which important business services would be disrupted if any single designated CTP suffered an extended outage, and how long the firm could operate before breaching its own impact tolerances. Where the answer is unclear or where substitutability is genuinely limited — as it often is with cloud infrastructure — that is itself the finding to escalate, not a gap to quietly note.
Firms should expect more, not less, information flowing from CTPs over time, since designated providers now have direct reporting obligations to regulators on their own resilience testing. Risk committees should ask whether the firm has a mechanism to receive and act on CTP incident disclosures, rather than learning about a material outage from the news. INFORMD’s DORA oversight checklist covers similar ground for firms with EU exposure under the parallel DORA regime, worth reading alongside this one.
Executive Action:
- Request a substitutability assessment for each designated CTP underpinning a critical function.
- Confirm exit and contingency plans have been tested, not just documented, in the past 12 months.
- Establish a defined escalation path for CTP-related incident disclosures reaching the risk committee.
How does the UK’s CTP regime differ from DORA, and does that matter?
DORA, the EU’s Digital Operational Resilience Act, designates and supervises critical ICT third parties across the EU financial sector under broadly similar logic. The UK regime is a distinct domestic framework under FSMA 2023, not a DORA equivalence arrangement, so a UK firm with EU operations may need to track two separate designation lists and timelines. Boards should not assume alignment between the two regimes without compliance confirming it directly.
That divergence is manageable, but it is a governance risk in its own right if left unowned. Firms operating across both jurisdictions should nominate a single accountable owner for tracking both CTP and DORA designation lists, since the underlying suppliers — the large cloud and technology providers — are often designated under both frameworks at different times and on different terms.
Executive Action:
- Confirm whether the firm falls under UK CTP oversight, DORA, or both, and document the basis for that assessment.
- Nominate one accountable owner for cross-regime third-party designation tracking.
- Brief the board annually on any change to either regime’s designated provider list.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
Risk committees preparing board papers on this topic may also find INFORMD’s technology strategy review template useful for structuring supplier resilience reporting, or can get in touch with specific questions.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
A regulatory framework under FSMA 2023 letting the Bank of England, PRA and FCA directly oversee technology and service providers designated by HM Treasury as critical to UK financial stability. It went live on 13 July 2026 with four initial designations: AWS, Google Cloud, Microsoft and Oracle’s UK/EMEA entities.
No. Regulated firms remain fully accountable for their own operational resilience and outsourcing due diligence under existing PRA and FCA rules. The CTP regime adds direct regulatory oversight of the supplier itself — it does not transfer or reduce the firm’s own responsibility.
DORA is the EU’s equivalent framework for critical ICT third parties. The UK regime is a separate domestic framework under FSMA 2023, not a DORA equivalence arrangement, so firms operating in both jurisdictions may face two distinct designation lists and reporting timelines.
The risk committee, not IT or procurement alone, because CTP exposure concerns concentration risk, risk appetite and Senior Managers regime accountability. Firms should assign a named senior manager to own CTP-related resilience reporting to the board.
