Critical Third Parties Regime: What You Need to Know
March 31, 2025
-
Blog

Critical Third Parties Regime: What You Need to Know

By 
Tilly Niven - Head of Marketing & Growth

The UK's Critical Third Party (CTP) regime is how regulators keep an eye on the outside providers that financial firms depend on, the ones whose failure could cause real trouble for the wider financial system. It's been in force since 1st January 2025, and it's overseen jointly by the Bank of England, the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA).

The regime came out of the regulators' joint policy statement, PRA Policy Statement PS16/24 and FCA Policy Statement PS24/16.

In short, it gives regulators direct oversight of certain providers that deliver services to regulated financial institutions and market infrastructures. The goal is to reduce the risk that comes from so much of the financial sector leaning on a small handful of tech, infrastructure and outsourcing providers.

Being in force doesn't mean it applies to everyone, though. A provider only comes under the regime once HM Treasury has formally designated it as a Critical Third Party.

What Is a Critical Third Party?

A CTP is a provider that HM Treasury has designated because a disruption to its services could threaten the stability of, or confidence in, the UK financial system.

A provider might be seen as critical because of how many (or which) financial institutions rely on it, how important its services are, or how hard it would be for firms to replace it. Think cloud infrastructure, data, technology, payments and similar operational services.

The detailed rulebook that designated CTPs must follow sits in the FCA Handbook, in the Critical Third Parties Sourcebook, or CTPS for short.

Put simply: CTP is the provider, CTPS is the rulebook it has to follow.

How Does the UK's CTP Regime Compare to the EU's DORA?

The main difference: the UK regime is broader and technology-neutral, focused on keeping services running and resilient. The EU's Digital Operational Resilience Act (DORA) is more prescriptive and tech-specific.

DORA has applied since 17th January 2025. It manages ICT risk across the EU financial sector and lets critical ICT providers be brought under direct oversight by European supervisory authorities.

The UK regime isn't limited to ICT providers, it can apply to any provider whose disruption could pose a systemic risk to the UK financial system. It focuses on resilience and continuity, whereas DORA goes further into ICT risk management, incident reporting, resilience testing and provider contracts.

If you operate across both the UK and EU, you may need to comply with both. Meeting one doesn't automatically satisfy the other, though there's often room to align governance, testing and reporting processes.

Who Does the Regime Apply To?

It applies directly to providers designated as CTPs because of how systemically important their services are to the UK financial sector. These services might go to:

• PRA-regulated firms, including banks and insurers

• FCA-regulated firms, including investment firms and other authorised businesses

• Financial market infrastructures, like clearing houses and certain payment systems overseen by the Bank of England

Regulators can identify and recommend potential CTPs, but HM Treasury makes the final call on designation.

Each regulator has its own legally binding rules, though these are designed to line up with each other, and the regulators are required to coordinate their oversight. The Bank of England also has emergency powers it can use in certain circumstances.

Importantly, this regime doesn't take responsibility away from regulated firms. Financial institutions, market infrastructures and their senior management are still accountable for managing the risks in their third-party arrangements. A provider being designated a CTP isn't regulators giving it a stamp of approval or vouching for its suitability.

What Powers Do Regulators Have?

The PRA, FCA and Bank of England can:

• Identify potential CTPs and recommend them to HM Treasury for designation

• Set compliance rules for CTPs

• Direct CTPs in writing to take (or avoid) specific actions

• Gather information, investigate, and appoint skilled persons to review compliance

• Take enforcement action against non-compliant CTPs

Some of these powers can also reach people or businesses connected to a CTP, including other companies in the same group.

The Fundamental Rules

Designated CTPs must stick to six Fundamental Rules. A CTP must:

1. Conduct its business with integrity.

2. Conduct its business with due skill, care and diligence.

3. Act in a prudent manner.

4. Maintain effective risk strategies and risk management systems.

5. Organise and control its affairs responsibly and effectively.

6. Deal with regulators openly and cooperatively, including flagging anything regulators would reasonably expect to know about.

The first five apply to how a CTP delivers its systemic services to financial firms. The sixth, working openly with regulators, applies more broadly across all the services a CTP provides.

These sit above the more detailed rules in the Critical Third Parties Sourcebook.

Operational Risk and Resilience Requirements

The CTPS requires CTPs to have solid systems in place for preventing, responding to and recovering from disruption. That means:

Strong governance and risk management: clear responsibilities, proper oversight, and ways to spot and manage risk.

Oversight of dependencies and supply chains: including risks from subcontractors and other "nth-party" providers.

Robust cyber resilience and tech safeguards: protecting the systems behind these services.

Change management, service mapping and incident response: so CTPs understand how their services work and can respond fast when things go wrong.

In full, there are eight requirements:

1. Governance

2. Risk management

3. Dependency and supply-chain risk management

4. Technology and cyber resilience

5. Change management

6. Mapping

7. Incident management

8. Termination of services

CTPs need to show they're meeting these, through self-assessments, scenario testing and incident-management exercises. They're also expected to map out the people, tech, assets, suppliers and support behind each service, and have a plan for winding down or transferring services if needed.

When Do CTPs Need to Comply?

A CTP's obligations kick in on the date set out in its HM Treasury designation order.

The rules have applied since 1st January 2025, but they only bite once a provider has actually been designated. HM Treasury's approach to designating CTPs involves regulator recommendations, engagement with the provider, weighing up the evidence, and publishing a formal designation order.

Once designated, a CTP must give regulators an interim self-assessment within three months, then an annual one after that. Other requirements phase in over time. For example, certain mapping and incident-management rules usually need to be in place within 12 months.

If you think your business could be a candidate for designation, it's worth getting ahead of it, start reviewing your governance, services, supply chain and resilience now.

How Founders Law Can Help

The CTP regime creates obligations for designated providers, but it matters for the firms relying on them too. Regulated firms still need to assess their outsourcing arrangements, do proper due diligence, and manage the risks that come with important third-party relationships.

Our financial services regulatory team helps regulated firms and providers navigate the UK CTP regime, DORA, and operational resilience more broadly, from regulatory scoping and governance to supplier contracts, gap analyses, incident-response planning and getting ready for potential CTP designation.

Want to talk through how this regime might affect your business? Get in touch.

Fintech
Legal Updates
Payments
Regulation Updates
UK
EU
Next
Previous