Night time view of the City of London
Think of the last time you made a payment, transferred money, used a banking app or logged on to online financial services. Did you give much thought to the infrastructure that makes those essential everyday transactions possible?
Let’s be honest, you probably didn’t. Most people don’t – until something goes wrong.
Financial services rely on a network of providers working behind the scenes – including technology, data and operational service providers.
These are so important to the resilience of the financial system that the government granted us powers[1] to implement a new oversight regime[2], and has now designated[3] the first critical third parties (CTPs).
That means, the Bank of England, PRA and FCA will together directly oversee these providers[4], with a targeted, proportionate focus on ensuring the services they provide to UK financial firms and financial market infrastructures (FMIs) are resilient.
Our oversight aims to address system level risks, where many firms rely on the same services from common service providers. And improve coordination and information-sharing across the sector, particularly during major incidents. This complements the existing rules in place for regulated firms to manage the risks they individually face.
Operational resilience has evolved
The primary focus of our operational resilience[5] regulatory framework has been on the ability of individual firms to prevent, respond to and recover from disruption to maintain financial stability and confidence – including from risks arising from their outsourcing and third party arrangements.
That remains vital.
What's changed is the environment in which those firms operate.
Banks, insurers, payment firms and FMIs increasingly rely on a relatively small number of common third party service providers. These may be cloud providers, technology firms, data providers or other specialist service providers.
The benefits of this approach are obvious: it can support innovation, boost efficiency, help firms improve the services they offer to millions of consumers and businesses, and contributes to the competitiveness and growth of UK financial services.
But what happens if there’s a failure or disruption to the services that one of these third parties offer?
Recent events have demonstrated how interconnected such modern services have become. The CrowdStrike outage[6] in 2024 affected a wide range of organisations around the world, while cyber incidents affecting retailers such as Marks & Spencer and Jaguar Land Rover showed how disruption can quickly extend beyond a single organisation.
These incidents starkly illustrate how operational disruption at one provider can affect many organisations simultaneously, including financial services.
Taking a system-wide view
Having more visibility across the system is becoming increasingly important, as the financial services landscape has changed.
The numbers speak for themselves.
In 2025, 27% of incidents reported to the FCA by firms were attributed to a third party issue, and 37% of those were cyber-related.
Operational resilience can't solely be about understanding risks within individual firms. It is also about understanding how disruption at commonly used critical service providers could affect the wider system.
The CTP regime adds this essential system-wide perspective. It’s not about replacing firms' responsibilities for managing their own operational resilience and third party arrangements. Nor is it about regulating every third party provider that firms use.
Put simply, it's about making sure our oversight reflects the way the system actually works today.
What this means in practice
This regime can’t and won’t end all disruptions. But it is designed to make a practical difference, particularly when disruption occurs.
For critical third parties, the expectations are clear. They must identify and manage risks relating to the critical services they provide. They need to test and improve their resilience arrangements, and engage openly with regulators and firms, especially during incidents.
The regime also aims to promote greater transparency and stronger communication between critical third parties and their UK financial services clients, including through activities such as joint testing exercises and the sharing of self-assessments where appropriate.
For firms, the regime should support better visibility of risks and improved communication during major incidents. When many firms are affected by the same disruption, timely information and effective coordination become even more important.
And for consumers and businesses, the services they rely on every day should be more resilient to disruption and, where disruption does occur, be restored quickly.
No framework can eliminate operational incidents entirely. But strengthening resilience across the wider system that supports financial services can help reduce the likelihood that disruption escalates or spreads unnecessarily.
Building resilience together
One of the clearest lessons from recent years is that the operational resilience of the financial system is a shared mission. A more resilient system helps create the conditions for firms to innovate, invest and grow with confidence.
Firms, regulators and third party providers all play an important role in maintaining the services that consumers, businesses and markets rely upon. The CTP regime reflects our connected reality. It recognises how the financial system operates today and ensures our approach to resilience evolves, so that the financial system can continue to safely serve businesses and consumers now and in the future.
As the regime is now live, firms should continue to consider how they identify, test and manage dependencies on critical services. Designated CTPs should engage openly with regulators and firms, including through testing and information-sharing.
You can find more information on critical third parties on the FCA and PRA’s website: