A reading of what SYSC 8 in the FCA Handbook actually demands of a technology function, and how the rule interacts with the wider operational resilience regime.
SYSC 8 is the FCA Handbook chapter on outsourcing. It looks, on first reading, like a short and unremarkable section. In practice it is the foundation of how UK-regulated firms manage their relationship with technology providers, and it has been read with increasing strictness since the operational resilience regime came into full effect in March 2025.
This is a reading of what SYSC 8 substantively requires, how the FCA interprets it in supervisory engagement, and where firms get this wrong.
Free · 4 minutes
Do you know what could take the business down — and have you priced it?
Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.
What SYSC 8 says
SYSC 8 has two substantive parts:
- SYSC 8.1 sets the general outsourcing requirements. A firm that outsources critical or important operational functions must take reasonable steps to avoid undue additional operational risk. Outsourcing must not result in delegation by senior management of their responsibility, or alter the firm’s regulatory obligations.
- SYSC 8.2 sets the requirements for outsourcing of important operational functions specifically. Documented arrangements, due diligence on providers, ability to terminate without harm, adequate resources to monitor performance, ability of the FCA to obtain information.
The principle: a firm remains responsible for outsourced functions. The mechanics: documentation, oversight, and exitability.
Who this is for
- The CTO or CIO at an FCA-authorised firm — bank, asset manager, fund manager, payment institution, EMI, broker — whose outsourcing arrangements are being reviewed in light of the post-March 2025 operational resilience regime.
- The compliance officer at a firm preparing for an FCA thematic review or a supervisory engagement that touches on third-party risk.
- The board member whose committee is approving the firm’s outsourcing arrangements and wants to read SYSC 8 in plain English.
“Important operational function” — the classification that does the work
SYSC 8’s stricter provisions in 8.2 apply specifically to outsourcing of “important operational functions”. The classification matters because it determines which contractual provisions are mandatory and which oversight expectations apply.
An operational function is “important” if a defect or failure would materially impair compliance with regulatory obligations, the firm’s financial performance, or the soundness or continuity of investment services. In practice, for technology providers, this catches the cloud platforms hosting client-facing services, the core systems processing client transactions, the custody systems, the principal market connectivity, and the providers of regulated activities done on the firm’s behalf.
The classification needs to be performed and documented. Firms that have not formally classified their outsourcing arrangements end up applying the same level of rigour to everything, or — worse — applying important-function rigour only to the obvious cases and missing the long tail.
What the contracts actually need to contain
For an outsourced important operational function, SYSC 8.2 and the surrounding FCA guidance require contractual provisions covering:
- The rights and obligations of each party, including service levels.
- Audit rights — both for the firm’s internal audit and for the FCA.
- Confidentiality and data protection.
- Termination rights, including step-in rights where appropriate.
- Sub-outsourcing — what the provider can and cannot delegate, and on what notice.
- The location of data and services, and notification of any change in location.
- Business continuity and disaster recovery arrangements, including the firm’s right to participate in testing.
Standard cloud-provider terms of service do not contain most of these. A firm that outsources an important operational function to a hyperscaler on standard terms has a compliance gap. The remediation is usually a specific addendum, an enterprise agreement with additional schedules, or — for some providers — participation in a regulated cloud framework.
The operational resilience overlay
Since 31 March 2025 — the end of the FCA’s operational resilience transition period — firms in scope of PS21/3 (the FCA’s operational resilience policy statement) must be able to remain within impact tolerances for important business services under severe but plausible scenarios. SYSC 8 outsourcing arrangements are downstream of this. A firm cannot meet its impact tolerance for an important business service if it has not understood how its outsourcing arrangements support — or undermine — that resilience.
The practical effect is that SYSC 8 is now read alongside SYSC 15A (operational resilience) and the FCA’s guidance on operational resilience. Firms that treat them separately produce policies that pass paper review but fail scenario testing.
The UK Critical Third Party regime
Sitting above SYSC 8 is the UK Critical Third Party regime, established by the Financial Services and Markets Act 2023 and implemented by the FCA and Bank of England. Like DORA’s CTPP regime in the EU, the UK CTP regime allows direct supervision of designated providers. From a SYSC 8 perspective, firms relying on designated CTPs need contracts and oversight arrangements that take account of the regime’s expectations.
Where firms get this wrong
The classification is informal. Important operational functions are not formally classified. Everything looks the same; everything gets the same treatment; the important ones get under-controlled and the non-important ones get over-controlled.
The register is incomplete. The big cloud provider is on it. The CRM is on it. The intra-day reconciliation vendor, the market data feed, the chain-analytics provider, the email security gateway are not.
Cloud is treated as procurement, not outsourcing. A multi-year IaaS or PaaS arrangement hosting client-facing services is outsourcing. Treating it as routine procurement misses the SYSC 8 obligations entirely.
Exit plans are theoretical. “If our cloud provider failed we would migrate to another provider” is not an exit plan. The FCA expects documented, tested, time-bound exit paths for important operational functions.
How we engage with this
We read outsourcing arrangements against SYSC 8 and the operational resilience overlay. As part of a Supplier and Dependency Review, we identify the gaps between current state and what the FCA reads SYSC 8 to require, with specific recommendations on contract amendments, exit plans, and oversight arrangements.
We do not negotiate contracts. We do not implement controls. We do not act as outsourcing oversight function. We read what is there, identify what is missing, and write it down for the people who have to act on it.
Pricing is published at /pricing/. If your firm is preparing for an FCA review of outsourcing arrangements, or has been told by the relationship manager that this is an area of focus, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.