FCA highlights operational resilience of critical third parties
FCA published commentary emphasising resilience risks from interconnected technology, data and operational service providers to financial services.
The FCA underscores growing dependence on shared technology and data providers, reinforcing the critical third parties (CTP) supervisory framework. Firms should expect intensified scrutiny of concentration risk, exit planning and incident response for outsourced infrastructure.
Signals continued FCA priority on operational resilience and CTP oversight, driving supervisory expectations for third-party risk management.
Action Required
Map critical third party dependencies and align to the CTP regime resilience expectations.
Reinforces the CTP regime as a strategic supervisory priority with implications across all regulated firms.
Refresh third-party dependency mapping, concentration analysis and exit strategies. Ensure incident playbooks address CTP disruption and align with FCA/PRA/BoE operational resilience expectations.
“FCA blog emphasises financial services reliance on technology, data and operational service providers that underpin resilience of the financial system.”
Published: 2026-08-02