Critical Third Parties: A UK Risk Committee Checklist for 2026
UK risk committees must now oversee Critical Third Parties like AWS, Google and Microsoft under BoE, PRA and FCA rules live since July 2026.
UK risk committees must now oversee Critical Third Parties like AWS, Google and Microsoft under BoE, PRA and FCA rules live since July 2026.
How should UK audit committees oversee DORA compliance in 2026? Board-level ICT risk oversight now demands independent assurance, not just a CISO report.
UK CFOs must now model BNPL regulation impact before FCA authorisation lands on 15 July 2026 — provisioning, systems and reporting all change.
The FCA’s £9.1bn motor finance redress scheme is in legal limbo. Here’s what UK boards must prepare before the tribunal ruling lands.
UK ransomware payment ban legislation is advancing. CISOs in CNI and financial services must act now to build resilience that removes the payment option.
From 1 September 2026, FCA non-financial misconduct rules extend to 37,000 SMCR firms. Here is what boards must govern and act on now.
UK SRS S1 and S2 were published in February 2026. UK CFOs must prepare now ahead of the FCA’s January 2027 mandatory reporting deadline.
Gartner says only 10% of large enterprises will have mature zero trust by end of 2026. UK CISOs with NCSC, DORA, and Cyber Resilience Bill obligations cannot wait.
HM Treasury’s landmark reforms to the FCA AR regime create a new permission gateway for principal firms. Here’s what compliance leaders must plan for now.
FCA Consumer Duty board reports are due 31 July 2026. Here is what UK financial services boards must evidence to satisfy active FCA supervision now.