The UK’s Critical Third Parties (CTP) regime, created by Part 5 of the Financial Services and Markets Act 2023, comes into force today.
HM Treasury can designate third parties, such as major cloud and technology providers, whose failure or disruption could threaten UK financial stability. Designated CTPs must meet Fundamental Rules and Operational Risk and Resilience Requirements set by the Bank of England, PRA and FCA, covering:
- Governance and risk management
- Dependency and supply chain risk
- Technology and cyber resilience
- Incident management and incident reporting to regulators
- Resilience testing and incident management playbook exercises
Regulated firms remain fully responsible for managing their own third-party risk, so expect continued scrutiny of outsourcing and cloud arrangements.
Source: PS24/16 Critical third parties to the UK financial sector (FCA)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.