| Link(s): | Strengthening resilience across an increasingly interconnected financial system | FCA Critical Third Parties: Strengthening UK Financial Services | FCA |
Context
In an article written by the FCA director of specialists Mark Francis and Simon Dixon, director of supervisory risk specialists at the Prudential Regulation Authority (PRA), it
highlights that as firms increasingly rely on common third-party service providers, delivering operational resilience is no longer just about your own individual organisation. It’s about strengthening resilience across the wider network that supports the UK financial system. It explains the UK’s new Critical Third Parties (CTP)oversight regime is designed to strengthen the operational resilience of financial services by directly overseeing key technology, data and service providers that many firms depend on.
Key points to note and next actions
- Financial services increasingly rely on a small number of common third-party providers, such as cloud, technology and data firms.
- Disruption at one provider can affect many firms and consumers at the same time, as shown by incidents like the CrowdStrike outage and major cyber disruptions.
- The Bank of England, PRA and FCA will jointly oversee designated CTPs to manage system-level risks and improve coordination during incidents.
- The regime does not replace firms’ own responsibility for managing resilience or outsourcing risks.
- CTPs will be expected to identify risks, test resilience, share information and engage openly with regulators and firms.
- The overall aim is to make critical financial services more resilient, reduce the spread of disruption and support confidence, innovation and growth in the UK financial system.
