A reading of the UK Critical Third Party regime — what it does to designated providers, and the six technology implications for the financial firms that depend on them.
The Financial Services and Markets Act 2023 introduced the UK Critical Third Party regime — the UK’s equivalent of DORA’s CTPP framework, with its own designation criteria, supervisory architecture, and substantive requirements. Designations have been under way since 2024, with the first wave of designated CTPs published. For UK financial services firms, the regime fundamentally changes how the most material technology dependencies are supervised and contracted.
This is a reading of what the regime substantively does, and the six technology implications affected firms now have to address.
Free · 4 minutes
Do you know what could take the business down — and have you priced it?
Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.
What the regime is
The Bank of England, the PRA, and the FCA jointly designate certain ICT and other service providers as Critical Third Parties — providers whose failure would pose risks to the stability of, or confidence in, the UK financial system. Once designated, a CTP comes under direct supervision by the regulators with powers to:
- Set minimum operational resilience standards.
- Require information and conduct on-site inspections.
- Commission skilled person reviews.
- Issue directions on remediation.
The first wave of designations published by the regulators in 2024–2025 includes the major hyperscaler cloud providers and several specialised infrastructure firms. The list continues to expand.
For the financial services firms that depend on these providers, the regime does not directly change their existing outsourcing obligations under SYSC 8, SS2/21, or the broader operational resilience framework — but it raises the supervisory bar substantially on how those dependencies are managed.
Who this is for
- The CTO or CISO at a UK financial services firm whose principal technology providers are designated or likely to be designated as CTPs.
- The head of operational resilience translating CTP designations into specific changes to the firm’s resilience programme.
- The general counsel or chief procurement officer reviewing or renewing contracts with material providers in light of CTP designation.
The six technology implications
1. Know which of your providers are (or are likely to be) designated. The list of designated CTPs is public. The firm must maintain a clear view of which of its providers are designated, which are not, and which sit on the boundary. This needs to be in the firm’s outsourcing register with a specific field for designation status.
2. Understand the obligations the CTP itself now has. Once designated, the CTP is subject to operational resilience standards set by the regulators. These standards affect the service the firm receives — incident notification, transparency on changes, audit and inspection cooperation. The firm benefits from these obligations indirectly, and should reflect them in its own supervisory engagement.
3. Strengthen the contractual position. Contracts with designated CTPs need to reflect the regime’s expectations. Audit rights, sub-outsourcing controls, exit plans, incident notification — these need to align with the CTP regime alongside SYSC 8 and DORA requirements (for firms also in EU scope). Standard cloud terms of service do not satisfy this; addenda and enterprise agreements with specific provisions do.
4. Build operational resilience that does not assume the CTP is risk-free. Designation does not eliminate risk. A designated CTP that fails — through cyber attack, operational error, or third-party cascade — still affects the firm’s important business services. Operational resilience scenarios should include CTP-level failure.
5. Plan for CTP-level incidents and the cascade through your operations. When a designated CTP has a material incident, the impact reaches multiple financial firms simultaneously. Coordinated response with peers, with the CTP, and with the supervisory authorities becomes part of the playbook.
6. Update outsourcing registers and governance documentation. The firm’s outsourcing register, its board reporting, and its operational resilience self-assessment should all reflect which of its dependencies are designated CTPs and what additional considerations that brings. Auditors and supervisors will ask.
Differences from the EU CTPP regime
For firms operating in both the UK and the EU, the two regimes overlap heavily but diverge in specifics:
- The designation lists are not identical. A provider designated in the EU may or may not be designated in the UK.
- The supervisory architecture differs: UK regulators jointly supervise, EU has Lead Overseers among the three ESAs.
- The substantive standards converge but are expressed differently in supervisory guidance.
- Incident notification and reporting expectations differ in detail.
Firms in both regimes need to maintain a view that satisfies both rather than assuming compliance with one carries the other.
Where firms get this wrong
Treating designation as the CTP’s problem. The firm remains accountable for its operations regardless of who supervises the CTP. The regime does not transfer accountability.
Outsourcing register not updated. The register needs a designation status field. Many firms have not added it.
Operational resilience scenarios assume CTPs do not fail. Designation is not a guarantee. Scenarios that exclude CTP failure are deficient.
Exit plans are paper exercises. The most common deficiency. An exit from a designated CTP is hard. Documented, costed, time-bound exit paths — actually rehearsed in at least desktop form — are the supervisory expectation.
How we engage with this
We read CTP exposure and the firm’s response to it. As part of a Supplier and Dependency Review scoped to UK CTP and operational resilience expectations, we read the outsourcing register, the contracts with material providers, the operational resilience scenarios, and the exit plans, and identify where the firm’s position would not satisfy the regulators’ reading.
We do not represent firms to the regulators. We do not negotiate contracts. We do not run scenario tests. We read what is there, identify what is missing, and write it down.
Pricing is published at /pricing/. If your firm is preparing for the next supervisory engagement on third-party risk, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.