Don’t do SECURITY. Do business SECURELY.

UK critical third parties regime comes into force

The Bank of England, PRA and FCA’s regime for critical third parties to the financial sector is now in force.

The UK’s Critical Third Parties (CTP) regime, created by Part 5 of the Financial Services and Markets Act 2023, comes into force today.

HM Treasury can designate third parties, such as major cloud and technology providers, whose failure or disruption could threaten UK financial stability. Designated CTPs must meet Fundamental Rules and Operational Risk and Resilience Requirements set by the Bank of England, PRA and FCA, covering:

  • Governance and risk management
  • Dependency and supply chain risk
  • Technology and cyber resilience
  • Incident management and incident reporting to regulators
  • Resilience testing and incident management playbook exercises

Regulated firms remain fully responsible for managing their own third-party risk, so expect continued scrutiny of outsourcing and cloud arrangements.

Source: PS24/16 Critical third parties to the UK financial sector (FCA)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights