Understanding the Bank of England’s New Policy PS16/24 on Critical Third Parties and Its Implications for the Financial Sector
- Julien Haye

- Nov 13, 2024
- 26 min read
Updated: 2 days ago

In November 2024, the Bank of England, in collaboration with the Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA), released PS16/24 – Operational resilience: Critical third parties to the UK financial sector. The policy establishes a new regulatory framework for the direct oversight of third-party providers whose services are considered critical to the stability of the UK financial system.
Traditionally, operational resilience regulation has focused on banks, insurers, payment firms and financial market infrastructures. PS16/24 represents a significant evolution by recognising that the resilience of the financial sector increasingly depends on a relatively small number of highly interconnected technology and service providers. Rather than relying solely on financial institutions to manage these dependencies through outsourcing and third-party risk management, the new regime enables UK regulators to supervise designated Critical Third Parties (CTPs) directly.
The UK's approach complements similar international initiatives, most notably the European Union's Digital Operational Resilience Act (DORA), although the two regimes differ in scope, governance and supervisory arrangements. Together, they reflect a growing recognition that digital infrastructure, cloud computing and other shared services have become systemically important to modern financial markets.
This guide explains the PS16/24 framework, including how Critical Third Parties are designated, the Operational Risk and Resilience Requirements they must meet, the six Fundamental Rules that underpin the regime, and the responsibilities that remain with regulated financial institutions. It also examines the relationship between PS16/24 and DORA, the implications for third-party risk management and operational resilience, and what organisations should do to prepare for an increasingly interconnected regulatory environment.
Executive Takeaways
For readers scanning rather than reading in full, five strategic insights capture the significance of the UK's Critical Third Party regime:
Operational resilience now extends beyond regulated financial institutions.
PS16/24 recognises that the resilience of the UK financial system increasingly depends on a relatively small number of shared technology and service providers. Direct regulatory oversight of Critical Third Parties reflects a significant shift from supervising individual firms to strengthening resilience across the wider financial ecosystem.
Critical Third Party designation is based on systemic importance, not organisational size.
Providers are designated because disruption to the services they deliver could threaten the stability of, or confidence in, the UK financial system. The focus is therefore on the criticality of the services provided and the dependencies they create, rather than the provider's scale or market share.
Direct oversight complements rather than replaces firms' responsibilities.
Financial institutions remain fully accountable for managing their operational resilience, outsourcing arrangements and third-party risks. The new regime strengthens regulatory oversight of designated providers but does not reduce firms' responsibility to understand, monitor and manage their own dependencies.
Resilience depends on understanding concentration and interconnectedness.
Cloud computing, payments infrastructure, cybersecurity, market data and other shared services have become foundational to modern financial services. Organisations should look beyond individual supplier risks and assess how concentration, substitutability and common dependencies could affect the resilience of important business services.
The UK regime reflects a broader international shift towards ecosystem resilience.
PS16/24 complements international initiatives such as the EU's Digital Operational Resilience Act (DORA), recognising that financial stability increasingly depends on resilient digital infrastructure operating across multiple jurisdictions. As technology ecosystems continue to evolve, organisations that proactively understand and manage third-party dependencies will be better positioned to meet regulatory expectations and strengthen long-term operational resilience.
What Is PS16/24?
PS16/24 – Operational resilience: Critical third parties to the UK financial sector – establishes the UK's regulatory framework for the direct oversight of Critical Third Parties (CTPs) whose disruption could threaten the stability of the UK financial system. Introduced jointly by the Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA), the regime strengthens operational resilience by applying supervisory requirements directly to designated service providers while preserving the accountability of regulated firms for managing their own third-party risks.
Why Was PS16/24 Introduced?
Modern financial services rely on a relatively small number of highly interconnected third-party providers. Cloud computing platforms, payment infrastructure, market data providers, telecommunications networks and other technology services now underpin many of the UK's critical financial services.
While these providers enable innovation, scalability and operational efficiency, they also create systemic dependencies. A significant disruption affecting a single provider may simultaneously impact multiple banks, insurers, payment firms and financial market infrastructures, potentially threatening market confidence and financial stability.
Recognising these growing interdependencies, the Bank of England, PRA and FCA introduced Policy Statement PS16/24 alongside Supervisory Statement SS6/24 to establish a regulatory framework for the direct oversight of designated Critical Third Parties (CTPs).
Unlike traditional outsourcing or third-party risk requirements, which focus on how regulated firms manage their suppliers, the CTP regime enables UK regulators to supervise certain systemic service providers directly where their disruption could have wider consequences for the financial sector.
The Purpose of the CTP Regime
The primary objective of PS16/24 is to strengthen the operational resilience of the UK financial system by reducing the systemic risks arising from critical third-party dependencies.
The policy seeks to ensure that designated CTPs can continue delivering services that are essential to the operation of regulated financial firms and financial market infrastructures, even during severe but plausible disruption events.
To achieve this, designated CTPs are expected to demonstrate robust operational resilience capabilities across areas including:
governance and accountability
operational risk management
dependency mapping
technology and cyber resilience
scenario testing
incident management
regulatory notifications
continuous improvement.
The regime therefore focuses on protecting the resilience of the wider financial ecosystem rather than supervising the commercial activities of third-party providers.
How Does PS16/24 Support Operational Resilience?
Operational resilience aims to ensure that organisations can prevent, adapt to, respond to and recover from operational disruptions while continuing to deliver their critical business services.
Historically, regulatory expectations focused primarily on the resilience of individual financial institutions. However, as financial services have become increasingly dependent on shared technology providers, operational resilience can no longer be achieved solely within the boundaries of a single organisation.
PS16/24 extends this approach by recognising that the resilience of the financial sector increasingly depends on the resilience of critical external providers. The regime therefore complements existing operational resilience requirements by strengthening oversight of the systemic services on which multiple regulated firms rely.
Importantly, direct supervision of designated CTPs does not transfer responsibility away from regulated firms. Banks, insurers, payment firms and financial market infrastructures remain fully accountable for identifying, assessing, monitoring and managing the third-party risks within their own operational resilience frameworks.
How Does PS16/24 Address Systemic Risk?
A key distinction between the CTP regime and traditional outsourcing regulation is its focus on systemic risk rather than individual firm risk.
An operational disruption affecting a single financial institution may have limited consequences for the wider financial system. However, disruption affecting a shared technology or infrastructure provider could simultaneously impact numerous regulated firms, amplifying operational, financial and reputational consequences across the sector.
The CTP regime therefore focuses on providers whose services are considered sufficiently important that their failure could threaten financial stability, market integrity or confidence in the UK financial system.
Rather than replacing firms' existing responsibilities for third-party risk management, PS16/24 introduces an additional layer of regulatory oversight designed to strengthen the resilience of these critical ecosystem dependencies.

PS16/24 and SS6/24 Explained
The UK's Critical Third Party (CTP) regime is established through two complementary regulatory documents. Policy Statement PS16/24 sets out the final regulatory framework, while Supervisory Statement SS6/24 explains the regulators' supervisory expectations for designated Critical Third Parties. Together, they define both the legal framework and the operational standards expected to strengthen the resilience of systemic third-party providers.
What Is the Difference Between PS16/24 and SS6/24?
The UK Critical Third Party regime is built on two closely related regulatory publications issued jointly by the Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA).
Although frequently referenced together, they serve different purposes.
PS16/24 – Operational resilience: Critical Third Parties to the UK financial sector
-> Establishes the final regulatory framework, Fundamental Rules and Operational Risk and Resilience Requirements applicable to designated Critical Third Parties.
SS6/24 – Supervisory Statement: Operational resilience of Critical Third Parties
-> Explains how the Bank of England, PRA and FCA expect designated CTPs to comply with those requirements in practice and how supervisory oversight will be exercised.
Put simply, PS16/24 defines what the regulatory requirements are, while SS6/24 explains how regulators expect those requirements to be implemented and demonstrated.
How PS16/24 and SS6/24 Work Together
The two documents should be read together rather than in isolation.
PS16/24 establishes the regulatory obligations that apply once an organisation has been formally designated as a Critical Third Party by HM Treasury. These include the Fundamental Rules, Operational Risk and Resilience Requirements, and powers available to the regulators to oversee designated providers.
SS6/24 complements the policy by providing practical supervisory guidance on how regulators will assess compliance. It sets out their expectations regarding governance, operational resilience, dependency mapping, incident management, scenario testing, self-assessments and ongoing engagement with supervisors.
Together, the documents create a principles-based regulatory framework that provides both regulatory certainty and supervisory flexibility. Rather than prescribing a single operating model, they enable regulators to assess whether designated CTPs have implemented effective and proportionate resilience capabilities that reflect the nature, scale and complexity of the systemic services they provide.
Do Financial Institutions Need to Understand Both PS16/24 and SS6/24?
Understanding the distinction between PS16/24 and SS6/24 is important for both designated Critical Third Parties and the financial institutions that rely on them.
PS16/24 establishes the legal framework that underpins the UK's CTP regime, while SS6/24 provides insight into how regulators are likely to interpret compliance during supervisory engagement.
For organisations preparing for increased regulatory scrutiny, reading the two documents together provides a more complete understanding of both the regulatory requirements and the supervisory expectations that support the UK's operational resilience framework.
Is Your Organisation Prepared for the New Operational Resilience Standards?
At Aevitium LTD, we guide financial services firms and their suppliers through the complexities of regulatory compliance and operational resilience. From building robust risk management frameworks to implementing scenario testing and incident response plans, our experts are here to help you navigate the demands of the Bank of England’s PS16/24 policy and strengthen your resilience against systemic risks.
What Is a Critical Third Party?
A Critical Third Party (CTP) is a service provider formally designated by HM Treasury because disruption to the services it provides could threaten the stability or confidence of the UK financial system. Unlike traditional outsourcing arrangements, designation reflects the provider's systemic importance across the financial sector rather than the significance of an individual contractual relationship.
Defining a Critical Third Party
A Critical Third Party is an external service provider that delivers one or more services to regulated financial institutions or financial market infrastructures and has been formally designated by HM Treasury under the Financial Services and Markets Act 2023.
Designation is not based on the size of the provider or the value of individual contracts. Instead, it reflects the systemic importance of the services the provider delivers to the UK financial sector and the potential consequences if those services were disrupted.
Examples may include providers of cloud computing, payment infrastructure, market data, telecommunications, technology platforms or other shared services that support the delivery of critical financial services across multiple regulated organisations.
How Is a Critical Third Party Designated?
An organisation does not become a Critical Third Party automatically.
Designation is made by HM Treasury, following recommendations from the Bank of England, PRA and FCA, after considering whether disruption to the services provided could threaten the stability or confidence of the UK financial system.
When making this assessment, regulators consider factors such as:
the criticality of the services provided
the number and type of financial institutions relying on those services
the level of market concentration and substitutability
the potential impact of disruption on financial stability
broader systemic dependencies across the financial sector.
Only organisations formally designated through this process become subject to the UK's Critical Third Party regime.
Why Are Critical Third Parties Systemically Important?
The financial services sector has become increasingly dependent on a relatively small number of shared technology and infrastructure providers.
While these providers deliver significant efficiencies, they also create concentration risk. A major operational disruption affecting a single provider may simultaneously impact multiple banks, insurers, payment firms and financial market infrastructures.
This interconnectedness means that the resilience of the financial system increasingly depends not only on the resilience of individual firms, but also on the resilience of the critical third-party providers that support them.
The CTP regime recognises this shift by extending regulatory oversight beyond regulated firms to include those providers whose disruption could have wider systemic consequences.
How Is a Critical Third Party Different from a Traditional Outsourcing Provider?
A common misconception is that all outsourced service providers are Critical Third Parties. This is not the case.
Traditional outsourcing regulation focuses on the relationship between an individual regulated firm and its suppliers. The responsibility for managing outsourcing risk remains with the regulated firm through governance, due diligence, contractual arrangements and ongoing oversight.
The CTP regime has a different objective. It focuses on providers whose services are sufficiently important that disruption could affect multiple regulated firms simultaneously and create wider financial stability risks.
The key distinction is summarised below.

Importantly, designation as a Critical Third Party does not replace existing outsourcing or third-party risk management requirements. Financial institutions remain fully accountable for identifying, assessing, managing and monitoring their third-party risks, regardless of whether a supplier is subject to direct regulatory oversight.
Which Critical Third Parties Have Been Designated?
HM Treasury designated the first four Critical Third Parties under the UK regime with effect from 13 July 2026. All four are major cloud and technology providers whose services support a significant number of banks, insurers, payment firms and financial market infrastructures across the UK financial system.
The designated legal entities are:

The statutory designation applies to the named legal entities. Regulatory oversight is more focused: it applies to the systemic third-party services they provide to the UK financial sector, rather than to every aspect of their global operations. The relevant provider is notified at designation of the services considered systemic.
Why Were These Providers Designated as Critical Third Parties?
The first designations reflect the financial sector's growing dependence on a small number of major cloud and technology providers. Banks, insurers and financial market infrastructures increasingly use shared cloud infrastructure to host applications, process data and support critical business services. A severe disruption at one widely used provider could therefore affect multiple regulated organisations simultaneously.
HM Treasury stated that the designations followed evidence gathering and collaborative engagement with the providers. The decision reflects the potential systemic consequences of disruption, rather than the commercial scale or importance of any single outsourcing contract.
The selection of these organisations is consistent with the three factors used by the regulators when identifying potential Critical Third Parties:
Concentration: the number and type of regulated firms relying on the provider.
Materiality: the importance of the services to essential financial activities, services or operations.
Other drivers of systemic impact: factors that could cause disruption to spread, amplify risk or undermine confidence in the financial system.
The four designations do not create a closed list. The regime is intended to operate on a rolling basis, and HM Treasury may designate additional providers where the statutory criteria are met. There is no statutory limit on the number of Critical Third Parties that may ultimately fall within the regime.
Important distinction: designation does not mean that every service delivered by AWS, Google Cloud, Microsoft or Oracle is directly overseen under the CTP regime. The regulators oversee the services identified as systemically important to the UK financial sector.
How Are Critical Third Parties Designated?
HM Treasury has the legal authority to designate a service provider as a Critical Third Party. In practice, the Bank of England, Prudential Regulation Authority and Financial Conduct Authority identify potential providers, assess their systemic importance and may recommend designation. HM Treasury then undertakes its own assessment, consults the relevant parties and makes the final decision through secondary legislation.
Who Designates a Critical Third Party?

The final designation decision belongs to HM Treasury.
Under section 312L of the Financial Services and Markets Act 2000, as amended by the Financial Services and Markets Act 2023, HM Treasury may designate a provider where, in its opinion, failure or disruption to the services it provides could threaten the stability of, or confidence in, the UK financial system.
HM Treasury must consult the Bank of England, PRA and FCA before making a designation. In most cases, the regulators are expected to identify potential CTPs and submit a recommendation supported by regulatory data and analysis. However, HM Treasury may also designate a provider without first receiving a formal recommendation from the regulators.
How Do Regulators Identify Potential Critical Third Parties?
The Bank of England, PRA and FCA assess whether a provider's services could create systemic risk if they failed or were severely disrupted.
Their assessment considers three principal areas.
1. Concentration
The regulators consider how many regulated firms use the provider and the types of organisations that depend on its services.
This includes both:
the total number of firms relying on the provider; and
the systemic importance of those firms within the UK financial system.
A provider used by many firms may create concentration risk, but concentration alone does not automatically justify designation. The regulators also assess the importance of the services and the potential channels through which disruption could spread.
2. Materiality
Materiality concerns the importance of the provider's services to essential financial activities, services or operations.
The regulators assess whether disruption could:
interrupt critical financial services;
affect consumers or market participants;
amplify operational or financial stress;
undermine market integrity; or
weaken confidence in the UK financial system.
3. Other Drivers of Systemic Impact
The regulators may also consider additional factors that influence the scale or transmission of disruption.
These may include:
limited substitutability;
complex supply-chain dependencies;
common technology architecture;
geographic or operational concentration;
reliance on shared platforms;
the speed at which disruption could spread; and
the difficulty firms would face in migrating to an alternative provider.
These considerations help distinguish an important supplier from one whose disruption could create broader financial stability consequences.
What Is the Critical Third Party Recommendation Process?
Once a potential CTP has been identified, the regulators analyse available information and determine whether the statutory test appears to be met.
This analysis may draw on:
regulatory returns and third-party registers;
information supplied by regulated firms;
market intelligence;
supervisory data;
information from the provider;
incident and resilience information; and
engagement with domestic or international authorities.
Where the regulators conclude that a provider may meet the statutory threshold, they may recommend designation to HM Treasury. HM Treasury then conducts its own assessment and considers the evidence before making a final decision.
What Happens Before HM Treasury Makes a Designation?
Before reaching a decision, HM Treasury engages with the provider, the financial regulators and other relevant organisations. This gives the proposed provider an opportunity to understand the basis for potential designation and provide relevant evidence.
HM Treasury then considers whether failure or disruption to the provider's services could threaten the stability of, or confidence in, the UK financial system.
Where the statutory test is satisfied, the designation is made through regulations identifying the relevant legal entity. The provider is also notified of the services considered to be systemic third-party services for regulatory oversight purposes.
What Happens After a Provider Is Designated?
Following designation, the Bank of England, PRA and FCA jointly oversee the provider's systemic third-party services.
The designated CTP becomes subject to applicable requirements covering areas such as:
governance;
operational risk management;
dependency mapping;
incident management;
scenario testing;
information sharing;
resilience assurance; and
regulatory notifications.
Designation does not make the provider a regulated financial institution and does not place all its business activities under financial regulation. Oversight remains focused on the systemic services it provides to firms and financial market infrastructures
Who Does PS16/24 Apply To?
PS16/24 applies directly to designated Critical Third Parties (CTPs), but its implications extend well beyond those organisations. Financial institutions, financial market infrastructures (FMIs), service providers and other third parties all have different responsibilities within the UK's operational resilience framework. Understanding these distinctions is essential to avoiding common misunderstandings about the scope of the regime.
Designated Critical Third Parties
Designated Critical Third Parties are organisations formally designated by HM Treasury under the Financial Services and Markets Act 2023 because disruption to the services they provide could threaten the stability of, or confidence in, the UK financial system.
Once designated, they become subject to direct oversight by the Bank of England, PRA and FCA and must comply with the Fundamental Rules and Operational Risk and Resilience Requirements established by PS16/24.
Importantly, only the systemic services identified by regulators fall within the scope of supervision. Designation does not extend financial regulation to all aspects of the provider's business.
Regulated Financial Institutions
Banks, building societies, insurers, investment firms and payment firms are not directly subject to PS16/24 unless they themselves become designated as a Critical Third Party.
However, the regime has significant implications for regulated firms because many rely on designated providers to support critical business services.
Financial institutions remain responsible for:
identifying critical third-party dependencies;
undertaking due diligence;
managing outsourcing risk;
maintaining operational resilience;
monitoring supplier performance; and
complying with existing outsourcing and operational resilience requirements.
The designation of a supplier does not transfer these responsibilities to the regulators.
Financial Market Infrastructures (FMIs)
Financial Market Infrastructures, including payment systems, central counterparties (CCPs) and central securities depositories (CSDs), are among the organisations most likely to depend on designated Critical Third Parties.
Given their systemic role within the financial system, FMIs may rely heavily on cloud infrastructure, data services and shared technology platforms to support critical operations.
Although FMIs are not directly regulated under the CTP regime, their operational resilience frameworks should consider dependencies on designated providers alongside their existing resilience obligations.
Other Service Providers
Many technology providers, software vendors, managed service providers and infrastructure suppliers support regulated firms without being designated as Critical Third Parties.
These organisations continue to operate under contractual arrangements with their clients and remain outside the scope of direct supervision unless HM Treasury formally designates them.
They remain subject to commercial obligations and, where relevant, sector-specific regulatory requirements, but PS16/24 does not automatically apply to them.
Non-Designated Third Parties
Most outsourcing providers will never become Critical Third Parties.
Professional advisers, consultants, facilities providers, telecommunications suppliers, payroll providers and countless other service organisations continue to be managed through traditional outsourcing, supplier management and operational resilience arrangements. The existence of the CTP regime does not alter these relationships.

What Are the PS16/24 Requirements?
PS16/24 establishes a comprehensive operational resilience framework for designated Critical Third Parties. Rather than prescribing detailed technical controls, the policy sets principles-based expectations across governance, operational risk management, technology resilience and regulatory engagement. Together, these requirements are intended to reduce the likelihood that disruption at a single provider could threaten the stability of the UK financial system.
Governance Expectations
The Bank of England, PRA and FCA expect governance arrangements to provide effective oversight of operational resilience from board level through to day-to-day operations.
Although the framework remains principles based, designated providers should be able to demonstrate:
clearly defined governance arrangements;
senior management accountability;
effective challenge and oversight;
escalation procedures for material issues;
regular management information and resilience reporting; and
governance that supports timely and informed decision-making during disruption.
Governance should also support continuous review as services, technologies and dependencies evolve.
Operational Risk Expectations
The framework should enable organisations to understand:
operational risks affecting critical services;
key dependencies;
control effectiveness;
emerging vulnerabilities;
escalation triggers; and
residual risk.
Rather than treating resilience separately from operational risk management, PS16/24 expects resilience considerations to be embedded throughout the operational risk lifecycle.
Mapping Critical Services and Dependencies
Providers should maintain sufficient visibility over:
critical services;
supporting technology;
infrastructure;
operational processes;
key personnel;
third-party suppliers; and
fourth-party dependencies where relevant.
Effective mapping supports scenario testing, incident response and resilience planning.
Technology, Cyber and Supply Chain Resilience
Providers should demonstrate resilience across:
ICT infrastructure;
cyber security;
availability and recovery capabilities;
change management;
cloud operations;
supplier resilience;
subcontractor oversight; and
concentration risk.
Operational resilience should continue throughout periods of significant organisational or technological change.
Testing and Incident Response
Scenario testing should consider severe but plausible events, including:
cyber attacks;
technology failures;
cloud service disruption;
data corruption;
third-party failures; and
multiple concurrent events where appropriate.
Incident management arrangements should support:
timely detection;
effective escalation;
crisis coordination;
communications;
service recovery; and
post-incident learning.
For further guidance, refer to our resource on Crisis Management and Response: Best Practices and Strategies to develop robust response frameworks that align with regulatory expectations.
Regulatory Engagement and Continuous Improvement
Designated providers should maintain processes supporting:
regulatory notifications;
self-assessments;
information sharing;
supervisory engagement;
resilience reporting;
lessons learned;
internal assurance; and
ongoing framework improvement.
Operational resilience is viewed as a continuously evolving capability rather than a one-time compliance exercise.
What Are the Six PS16/24 Fundamental Rules for Critical Third Parties?
The PS16/24 framework includes six Fundamental Rules that establish the overarching standards designated Critical Third Parties must meet. They cover how a CTP conducts its business, manages risk, organises its affairs and engages with the Bank of England, PRA and FCA.
The first five rules apply to the CTP’s provision of systemic third-party services. Fundamental Rule 6 has a wider application and also covers other services the CTP provides to firms.
The Six Critical Third Party Fundamental Rules

The rules are intentionally principles-based. They do not specify every control that a CTP must operate. Instead, they establish the standards against which the regulators can assess the organisation’s conduct, governance, risk management and regulatory engagement.
They should therefore be read alongside the more detailed Operational Risk and Resilience Requirements, which explain the capabilities a CTP must establish in relation to its material services. These include requirements covering governance, risk management, dependency management, technology and cyber resilience, change management, mapping, incident management and termination of services.
Key point: The Fundamental Rules establish how a designated CTP is expected to behave and organise itself. The Operational Risk and Resilience Requirements provide the more detailed framework through which that standard is implemented.
Which Third-Party Providers Could Be Designated as Critical Third Parties Under PS16/24?
Designation under the UK Critical Third Party regime is not restricted to a predetermined list of industries. HM Treasury may designate a provider where a failure in, or disruption to, the services it provides to financial firms or financial market infrastructures could threaten the stability of, or confidence in, the UK financial system.
The assessment therefore focuses on the services provided and the systemic dependency they create, rather than the provider’s industry classification alone.
Types of Critical Providers That Could Be Considered for Future Designation

What Does PS16/24 Mean for Financial Institutions?
The regime is intended to strengthen system-wide resilience by allowing the Bank of England, PRA and FCA to oversee providers whose disruption could affect multiple firms at the same time. It complements, rather than replaces, the operational resilience, outsourcing and third-party risk obligations that already apply to regulated firms.
For financial institutions, the practical implication is clear: designation may improve regulatory visibility over a major provider, but it does not remove the need to understand, manage and test the institution’s own dependencies.
Regulated Firms Remain Accountable
A regulated firm cannot assume that using a designated Critical Third Party makes the underlying service resilient by default.
The CTP regime focuses on the systemic risks arising from the provider’s services across the wider financial sector. The firm remains responsible for understanding how it uses those services, how disruption could affect its important business services and what measures are required to remain within its own impact tolerances.
This creates a shared but distinct accountability model:
the CTP is accountable for complying with the rules and expectations applying to its systemic third-party services;
regulators oversee the systemic resilience of the designated provider; and
each regulated firm remains accountable for managing the risks arising from its own use of the service.
The designation of a provider should therefore strengthen a firm’s third-party risk management, not replace it.
Third Party Dependency Mapping
Financial institutions should maintain a clear view of how designated CTP services support their important business services, critical processes and customer outcomes.
Effective dependency mapping should identify:
the specific services obtained from the CTP;
the systems, applications and data that rely on those services;
internal processes and teams dependent on them;
material subcontractors and fourth parties where relevant;
interdependencies with other external providers; and
the important business services that could be disrupted.
This mapping should extend beyond the name of the provider. Large CTPs often deliver multiple products through different legal entities, regions, data centres and service configurations. The relevant dependency is therefore the specific service architecture used by the firm, not merely the fact that the provider has been designated.
Critical Third Party Concentration Risk
PS16/24 places greater regulatory attention on concentration and common-dependency risks across the financial system. Firms should conduct the same analysis at institutional level.
Concentration can arise where:
several important business services depend on the same provider;
different providers rely on the same underlying infrastructure;
multiple group entities use the same platform;
a material subcontractor supports several of the firm’s suppliers; or
alternative providers exist in theory but migration would be difficult or slow.
Firms should assess both direct concentration and hidden concentration within the wider supply chain. Diversifying contracts across several providers offers limited protection where those providers depend on the same cloud platform, network, data source or cybersecurity service.
Contracts and Information Rights
Existing contracts should be reviewed to determine whether they provide the rights and information required to manage resilience effectively.
Relevant provisions may include:
access to resilience and assurance information;
incident notification requirements;
cooperation during investigations and regulatory engagement;
audit and access rights;
participation in testing;
subcontracting controls;
data access, portability and return;
recovery and continuity commitments; and
termination and transition assistance.
Designation does not automatically improve the contractual position of every customer. Firms still need arrangements that reflect the materiality of the service, their regulatory obligations and the practical information needed to assess resilience.
Resilience and Scenario Testing
The direct oversight of CTPs should not lead firms to reduce their own testing.
Firms should continue to test how disruption at a designated provider would affect their important business services, including whether they could remain within impact tolerances. Scenario Testing should cover more than the provider’s technical recovery capabilities.
Relevant scenarios may examine:
regional or prolonged service failure;
cyber compromise;
loss or corruption of data;
failure of a critical subcontractor;
restricted access to the provider’s personnel or systems;
simultaneous disruption across several services; and
the failure of recovery or migration arrangements.
Where appropriate, firms should seek coordinated testing with the CTP and other relevant participants. However, they should also be able to test their own response independently, particularly where joint participation is unavailable or restricted.
Exit and Substitutability Planning
Exit planning remains essential even where a provider has been designated and is subject to direct supervision.
A credible exit plan should consider:
the trigger for initiating exit;
the availability and capability of alternative providers;
data extraction and portability;
system reconfiguration;
regulatory approvals;
customer and operational impacts;
transition resources and governance; and
the time required to complete migration safely.
The existence of an alternative supplier does not, by itself, demonstrate substitutability. Firms should assess whether they could move the service in practice, within an acceptable timeframe and without creating further operational risk.
For highly concentrated services, immediate substitution may be unrealistic. In those cases, resilience planning should also consider service degradation, alternative operating procedures, workload prioritisation and recovery within the existing environment.
Incident Coordination
A significant incident at a CTP may affect many firms simultaneously. Effective coordination is therefore central to the regime.
Financial institutions should establish clear arrangements covering:
notification and escalation between the firm and the CTP;
internal crisis management and decision-making;
communications with customers and counterparties;
regulatory reporting;
participation in sector-wide coordination arrangements;
access to accurate and timely incident information; and
recovery priorities where several services or firms are affected.
The firm should understand how its own incident management process connects with the provider’s response structure. This includes knowing who has authority to make decisions, what information will be shared and how competing recovery priorities will be managed.
Key point: Direct regulatory oversight of CTPs strengthens system-wide resilience. It does not reduce the accountability of financial institutions for their own dependency management, operational resilience and customer outcomes.
PS16/24 vs DORA: What Is the Difference?
The two regimes share common objectives around operational resilience, regulatory cooperation and the management of concentrated third-party dependencies. Their legal scope, terminology, designation process and supervisory architecture remain distinct.
PS16/24 and DORA Comparison

PS16/24 should therefore not be described simply as the UK version of DORA.
DORA is broader in its direct application to financial entities and more specifically focused on digital and ICT resilience. PS16/24 is primarily a systemic third-party oversight regime. It gives UK regulators powers to oversee designated providers directly while leaving firms’ own regulatory responsibilities in place.
UK–EU Cooperation on Critical Third-Party Oversight
In January 2026, the Bank of England, PRA and FCA entered into a Memorandum of Understanding with the European Supervisory Authorities: the EBA, EIOPA and ESMA. The agreement supports cooperation, information exchange and coordination of oversight activities relating to providers that operate across the UK and EU regimes.
The cooperation arrangements are particularly relevant where:
a provider is designated under both PS16/24 and DORA;
an EU-designated CTPP uses premises in the UK to serve EU financial entities;
a UK-designated CTP uses premises in the EU to serve UK financial institutions;
regulators require information about cross-border ICT dependencies;
coordinated oversight could reduce duplication; or
authorities need to cooperate during an incident or emergency.
The MoU provides a framework for:
exchanging relevant supervisory information;
coordinating oversight activities where appropriate;
supporting cooperation in emergency situations;
sharing approaches to ICT risk management and controls;
considering mitigation measures and incident response; and
supporting the oversight of providers designated in both jurisdictions.
The arrangement reflects the practical reality that many large technology providers operate through integrated global infrastructures. A significant disruption may therefore affect firms in several jurisdictions at the same time.
Cooperation Does Not Merge the Two Regimes
The UK and EU frameworks remain legally separate.
The MoU supports cooperation between the authorities, but it does not create a single designation process, common rulebook or automatic recognition of compliance. A provider subject to both regimes must continue to meet the applicable UK and EU requirements.
The UK supervisory statement confirms that the CTP regime is intended to be interoperable with regimes such as DORA, but only where that interoperability does not conflict with or undermine the UK regime’s overall objective.
For financial institutions operating in both jurisdictions, this means that third-party risk management should identify where the same provider or service falls within both frameworks. Governance, assurance and testing processes should be coordinated where possible, while preserving the distinct legal and regulatory requirements of each regime.
Key point: PS16/24 and DORA are complementary cross-border resilience regimes, not interchangeable standards. The UK–EU cooperation arrangements should improve information sharing and supervisory coordination, but firms and providers remain responsible for complying with each regime separately.
What Implementation Challenges Will Critical Third Parties Face?
The first wave of Critical Third Party designations demonstrates that many organisations outside the traditional regulatory perimeter will now be expected to meet supervisory standards comparable to those applied to major financial institutions. For some providers, this will require strengthening governance, operational resilience capabilities and regulatory engagement rather than simply implementing new technical controls.
Operational Risk Management Frameworks: Many CTPs may not currently possess comprehensive frameworks that align with the stringent regulatory standards for risk assessment, control, and management.
Scenario Testing and Incident Response: Some organisations may lack experience in conducting advanced scenario tests or have limited resources to meet the required testing intensity and frequency. In addition to be effective, such scenarios should operate jointly with their clients.
Governance and Accountability Structures: Clear governance structures with defined accountability—particularly at senior management levels—may be underdeveloped, leading to challenges in aligning management practices with resilience goals.
Technological and Cyber Resilience: CTPs may need to enhance their cybersecurity and IT resilience to prevent and respond to disruptions effectively, requiring additional investment and expertise.
Resource Allocation and Capacity: Smaller CTPs may lack the financial and human resources needed to comply with these requirements while continuing to serve their financial sector clients effectively. Effective resource allocation includes understanding exit triggers for third-party vendors. Our resource on Monitoring Triggers for Third-Party Vendor Exit provides insight into identifying and acting on these critical signals.
Regulatory and Compliance Awareness: Non-financial service providers that are new to these regulations might lack familiarity with the stringent requirements, necessitating further education and training to build a compliance-oriented culture.
Cross-Functional Collaboration: Organisations may face challenges in achieving cross-functional collaboration, with responsibilities for operational resilience often dispersed across departments, leading to siloed implementation efforts.
Conclusion
The designation of the first Critical Third Parties represents a significant evolution in the UK's approach to operational resilience.
Rather than focusing solely on the resilience of individual financial institutions, PS16/24 recognises that the stability of the financial system increasingly depends on a relatively small number of highly interconnected technology and service providers. As digital transformation, cloud adoption and shared infrastructure continue to reshape financial services, the resilience of these providers has become a matter of public interest rather than simply a contractual issue between firms and their suppliers.
The UK Critical Third Party regime addresses this challenge by introducing direct regulatory oversight of providers whose disruption could have systemic consequences. At the same time, it preserves the long-established principle that regulated firms remain accountable for managing their own operational resilience, outsourcing arrangements and third-party risks.
For designated providers, the regime introduces a comprehensive framework covering governance, operational risk management, technology resilience, testing, incident management and regulatory engagement. For financial institutions, it reinforces the importance of understanding dependencies, managing concentration risk, maintaining effective contractual arrangements and ensuring credible contingency and exit planning.
The UK's approach is also designed to operate alongside international initiatives such as the European Union's Digital Operational Resilience Act (DORA). As many critical providers support financial institutions across multiple jurisdictions, effective cooperation between regulators will become increasingly important in strengthening cross-border operational resilience while avoiding unnecessary duplication.
PS16/24 is therefore more than a new supervisory framework. It reflects a broader shift in financial regulation towards recognising that resilience is no longer determined solely within individual organisations, but across the complex network of third-party providers that underpin today's financial ecosystem.
Organisations that understand and actively manage these dependencies will be better positioned to strengthen operational resilience, support regulatory compliance and maintain confidence in an increasingly interconnected financial system.
For a deeper dive into the regulatory landscape, watch our Webinar Recap: Navigating the Intersection of Operational Resilience, Consumer Duty, and Regulatory Compliance to explore how these elements align under the new policy.
Frequently Asked Questions
Why did the UK introduce the Critical Third Party regime?
The UK's operational resilience framework initially focused on regulated financial institutions. However, as banks, insurers, payment firms and financial market infrastructures became increasingly dependent on a relatively small number of external technology providers, regulators recognised that disruption at one provider could affect many firms simultaneously. The Critical Third Party regime extends regulatory oversight to those providers whose services could create systemic risk.
Does designation mean a provider has failed to manage risk?
No. Designation is not a supervisory finding or enforcement action. It reflects the systemic importance of the services provided rather than the quality of the provider's controls. A provider may be designated simply because many financial institutions depend on its services.
Can a provider refuse to become a Critical Third Party?
No. Designation is made by HM Treasury under the statutory framework. Once designated, the provider becomes subject to the applicable oversight regime and regulatory requirements.
Does designation apply to every service provided by a CTP?
No. The regime focuses on the systemic third-party services identified during the designation process. A provider may offer hundreds of products and services, but only those falling within the designation are subject to the Operational Risk and Resilience Requirements.
Does using a designated CTP reduce a firm's regulatory obligations?
No. Regulated firms remain fully responsible for managing operational resilience, outsourcing and third-party risk. Designation strengthens regulatory oversight of the provider but does not transfer accountability from the firm.
Could the same provider be designated under both PS16/24 and DORA?
Yes. Many large technology providers operate across multiple jurisdictions. A provider may therefore fall within both the UK Critical Third Party regime and the EU DORA oversight framework, requiring engagement with both supervisory regimes.
Can a provider be removed from the Critical Third Party regime?
Potentially. If the statutory designation criteria are no longer met, HM Treasury could revoke a designation. This might occur if the provider no longer delivers services that create systemic dependencies within the UK financial sector.
Does PS16/24 introduce new contractual requirements for financial institutions?
Not directly. The regime primarily regulates designated providers rather than customer contracts. However, many financial institutions are expected to review contractual arrangements to ensure they continue to support operational resilience, testing, information sharing and exit planning.
Will more organisations be designated in the future?
Almost certainly. The legislation was designed to accommodate future designations as technology evolves and systemic dependencies change. Cloud providers represent the first wave rather than the final scope of the regime.
What should boards ask about Critical Third Party risk?
Boards should understand:
which designated CTPs support important business services;
where concentration risk exists;
whether alternative providers are genuinely viable;
how disruption would affect impact tolerances; and
whether exit plans have been tested rather than simply documented.
How does PS16/24 affect third-party risk management programmes?
For many organisations, the regime reinforces existing good practice rather than creating an entirely new discipline. Third-party risk management is increasingly expected to integrate operational resilience, cyber resilience, supplier governance, concentration risk and business continuity into a single governance framework.
What does success look like under the CTP regime?
Successful implementation is unlikely to be measured solely by compliance with documented requirements. Regulators will expect designated providers to demonstrate that resilience is embedded within governance, operational decision-making and day-to-day management of systemic services.
.png)
