When a cloud platform suffers an outage, a payments processor stalls, or a software update ships a fault, your customers don’t see your third party. They see you. And when the regulator asks what happened, “our vendor let us down” has never been an acceptable answer.
In our experience, the challenge is rarely a lack of policy or governance. Most firms have those in place. The real challenge is maintaining a clear view of which third parties support critical services, how those dependencies connect together, and what happens when one of them fails.
Why This Has Moved To The Top Of The Agenda
Lately financial services firms have become more dependent on third parties, in critical areas such as core banking, cloud infrastructure, KYC and onboarding, data and analytics, and customer communications. Much of the value chain now runs through outsourced service providers, and often through the third parties of these third party. These dependencies buy real efficiency but also concentrates risk in places where firms often don’t have enough visibility and control.
In the UK, regulators have spent years tightening their expectations, and the pace has picked up in recent years. The key regulations:
- SS2/21 relating to Outsourcing and third-party risk management is probably the one most compliance teams know well. The PRA’s rule sets the expectation that firms apply adequate governance and controls to all third-party dependencies, not just formal outsourcing arrangements. Importantly, accountability stays with the firm throughout the relationship, it is not transferred to the third party.
- The operational resilience regime (FCA PS21/3 and PRA SS1/21) requires firms to identify their important business services, set impact tolerances, and stay within them.
- The Critical Third Parties (CTP) regime, created under the Financial Services and Markets Act 2023, gave the Bank of England, PRA and FCA direct oversight of the most important providers. HM Treasury made its first designations in July 2026, and the regulators have begun overseeing an initial set of cloud and technology providers.
- And from March 2027, new reporting rules (FCA PS26/2 and PRA PS7/26) will require firms to maintain and submit an annual register of third-party arrangements, notify regulators of new or changed arrangements, and report serious operational incidents.
Regulators want to know who the firms depend on, how much, and what happens when a third party fails.
What “Third-party Risk” Actually Covers
Third-party risk usually gets reduced to a procurement checkbox exercise – a one-off, due diligence exercise at onboarding, with nothing further happening until contract renewal. In reality, it should span across distinct exposures of risk, each with its own way of landing on your customers and in front of your regulator.
- Operational and resilience risk is the most visible: for example, when a third party suffers an outage or a degraded service, and an important business service goes down with it.
- Concentration risk shows up when large parts of the sector rely on the same handful of providers, as with the major cloud platforms, so a single incident can affect many firms at once. It also shows up inside your own estate, when one third party quietly underpins several of your critical services.
- Fourth-party and sub-outsourcing risk is trickier to see. A material service may depend on a chain of subcontractors you’ve never assessed and can’t easily get visibility of. Resilience is only as strong as the weakest link in that chain, and firms are often surprised how many links there are once they go looking.
- Cyber and data risk, and financial and viability risk round out the picture. Third parties are a leading route for breaches and ransomware, and where a third– party processes personal or sensitive data, a failure at their end becomes a data protection incident at yours, including UK GDPR obligations. Meanwhile a third party in financial distress may cut corners or degrade service quietly – often with little warning until it’s already happened.
An Approach That Treats Third-party Risk As Your Own
Managing third-party risk well isn’t an initial stage gate at the start of the contract, it’s a discipline that runs across the life cycle of the relationship.
Our pragmatic approach:
1. Start with current inventory, mapped to important business services that third parties support. Assess them consistently, using regulators’ guidance
2. Match due diligence to the risk. A critical cloud dependency warrants scrutiny of resilience, security, sub-outsourcing chains and exit feasibility. A low-risk, easily substitutable third party doesn’t need the same treatment. Tailor the questions asked, and information required, to the level of risk and the nature of the service.
3. Get the contract right, because clauses you didn’t negotiate up front are impossible to enforce once something has gone wrong. Contracts should have relevant resilience and service-level commitments, security and data obligations, and appropriate exit provisions.
4. Monitor periodically, not once a year. Track supplier performance, resilience, financial health and security risk on an ongoing basis, with triggers that prompt reassessment when something changes.
5. Build capability, not just process. The strongest controls still depend on the teams running them. Firms need the individuals managing each supplier to be genuinely risk-aware and proactive about the service in front of them – noticing drift, questioning assurances, and escalating early rather than relying solely on due diligence, contract terms and supplier self-disclosure. Invest in these skills, and make supplier risk a real part of the role, not a form to file.
6. Ensure suppliers disclose their own critical dependencies and factor concentration and fourth-party risk into your assessment. If several of your important services trace back to the same underlying provider, that’s a concentration exposure the regulator will expect you to understand and manage.
7. Maintain an exit and continuity plan for critical arrangement and test it. Knowing how you’d sustain the service through a substitute provider or a period of degraded operation is what turns a third-party failure from a crisis into a managed event.
None of this works in a procurement silo. Third-party risk belongs inside your end-to-end supplier management approach, operational resilience and enterprise risk frameworks, with clear ownership, board level visibility of your most critical dependencies, and management information that informs leadership where the exposures sit.
Where This Leaves Firms
The dust has settled on the regulatory direction. SS2/21, the operational resilience rules, the CTP regime, and the reporting obligations landing in 2027 all pull the same way. What isn’t settled is how many firms will treat this as genuine risk management versus paperwork to satisfy an annual return.
The firms that get caught out won’t be the ones without a policy document. They’ll be the ones whose register was accurate on the day it was submitted, and stale within a month, because nobody owned it after that. When the next major provider has a bad day and one will – the question won’t be whether you had a third-party risk framework. It’ll be whether anyone had looked at it since it was written and managed the risk effectively.
How 4C Associates can help
Knowing that third-party risk is your risk is the easy part. Getting on top of it across hundreds of third parties, tangled sub-contracting chains and a rulebook that keeps moving is the difficult part. That is where we come in.
4C Associates is a commercial, supply chain and operations consultancy. We are not armchair advisors; we are hands-on doers who build the frameworks and then help you run them.
Third-party risk is your risk. Let’s make it a managed one.
Talk to us today: Andy Hemsley, Rohit Namdeo, Agnieszka Abbott.
