top of page

Understanding the Bank of England’s New Policy PS16/24 on Critical Third Parties and Its Implications for the Financial Sector

  • Writer: Julien Haye
    Julien Haye
  • Nov 13, 2024
  • 26 min read

Updated: 2 days ago

Hero image for a blog post about Bank of England PS16/24 on Critical Third Parties. A hand positions an orange cogwheel within a network of interconnected gears against a dark background, symbolising the interconnected technology and service providers that underpin the UK financial system. A white title panel displays the article heading, "Bank of England's New Policy PS16/24 on Critical Third Parties", with the subtitle, "How New Resilience Standards for Critical Third Parties Could Reshape Financial Stability and Service Delivery." The image represents operational resilience, systemic dependencies and regulatory oversight of critical third-party providers.

In November 2024, the Bank of England, in collaboration with the Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA), released PS16/24 – Operational resilience: Critical third parties to the UK financial sector. The policy establishes a new regulatory framework for the direct oversight of third-party providers whose services are considered critical to the stability of the UK financial system.


Traditionally, operational resilience regulation has focused on banks, insurers, payment firms and financial market infrastructures. PS16/24 represents a significant evolution by recognising that the resilience of the financial sector increasingly depends on a relatively small number of highly interconnected technology and service providers. Rather than relying solely on financial institutions to manage these dependencies through outsourcing and third-party risk management, the new regime enables UK regulators to supervise designated Critical Third Parties (CTPs) directly.


The UK's approach complements similar international initiatives, most notably the European Union's Digital Operational Resilience Act (DORA), although the two regimes differ in scope, governance and supervisory arrangements. Together, they reflect a growing recognition that digital infrastructure, cloud computing and other shared services have become systemically important to modern financial markets.


This guide explains the PS16/24 framework, including how Critical Third Parties are designated, the Operational Risk and Resilience Requirements they must meet, the six Fundamental Rules that underpin the regime, and the responsibilities that remain with regulated financial institutions. It also examines the relationship between PS16/24 and DORA, the implications for third-party risk management and operational resilience, and what organisations should do to prepare for an increasingly interconnected regulatory environment.


Executive Takeaways


For readers scanning rather than reading in full, five strategic insights capture the significance of the UK's Critical Third Party regime:


  1. Operational resilience now extends beyond regulated financial institutions.

    PS16/24 recognises that the resilience of the UK financial system increasingly depends on a relatively small number of shared technology and service providers. Direct regulatory oversight of Critical Third Parties reflects a significant shift from supervising individual firms to strengthening resilience across the wider financial ecosystem.

  2. Critical Third Party designation is based on systemic importance, not organisational size.

    Providers are designated because disruption to the services they deliver could threaten the stability of, or confidence in, the UK financial system. The focus is therefore on the criticality of the services provided and the dependencies they create, rather than the provider's scale or market share.

  3. Direct oversight complements rather than replaces firms' responsibilities.

    Financial institutions remain fully accountable for managing their operational resilience, outsourcing arrangements and third-party risks. The new regime strengthens regulatory oversight of designated providers but does not reduce firms' responsibility to understand, monitor and manage their own dependencies.

  4. Resilience depends on understanding concentration and interconnectedness.

    Cloud computing, payments infrastructure, cybersecurity, market data and other shared services have become foundational to modern financial services. Organisations should look beyond individual supplier risks and assess how concentration, substitutability and common dependencies could affect the resilience of important business services.

  5. The UK regime reflects a broader international shift towards ecosystem resilience.

    PS16/24 complements international initiatives such as the EU's Digital Operational Resilience Act (DORA), recognising that financial stability increasingly depends on resilient digital infrastructure operating across multiple jurisdictions. As technology ecosystems continue to evolve, organisations that proactively understand and manage third-party dependencies will be better positioned to meet regulatory expectations and strengthen long-term operational resilience.


What Is PS16/24?

PS16/24 – Operational resilience: Critical third parties to the UK financial sector – establishes the UK's regulatory framework for the direct oversight of Critical Third Parties (CTPs) whose disruption could threaten the stability of the UK financial system. Introduced jointly by the Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA), the regime strengthens operational resilience by applying supervisory requirements directly to designated service providers while preserving the accountability of regulated firms for managing their own third-party risks.

Why Was PS16/24 Introduced?


Modern financial services rely on a relatively small number of highly interconnected third-party providers. Cloud computing platforms, payment infrastructure, market data providers, telecommunications networks and other technology services now underpin many of the UK's critical financial services.


While these providers enable innovation, scalability and operational efficiency, they also create systemic dependencies. A significant disruption affecting a single provider may simultaneously impact multiple banks, insurers, payment firms and financial market infrastructures, potentially threatening market confidence and financial stability.


Recognising these growing interdependencies, the Bank of England, PRA and FCA introduced Policy Statement PS16/24 alongside Supervisory Statement SS6/24 to establish a regulatory framework for the direct oversight of designated Critical Third Parties (CTPs).


Unlike traditional outsourcing or third-party risk requirements, which focus on how regulated firms manage their suppliers, the CTP regime enables UK regulators to supervise certain systemic service providers directly where their disruption could have wider consequences for the financial sector.


The Purpose of the CTP Regime


The primary objective of PS16/24 is to strengthen the operational resilience of the UK financial system by reducing the systemic risks arising from critical third-party dependencies.


The policy seeks to ensure that designated CTPs can continue delivering services that are essential to the operation of regulated financial firms and financial market infrastructures, even during severe but plausible disruption events.


To achieve this, designated CTPs are expected to demonstrate robust operational resilience capabilities across areas including:


  • governance and accountability

  • operational risk management

  • dependency mapping

  • technology and cyber resilience

  • scenario testing

  • incident management

  • regulatory notifications

  • continuous improvement.


The regime therefore focuses on protecting the resilience of the wider financial ecosystem rather than supervising the commercial activities of third-party providers.


How Does PS16/24 Support Operational Resilience?


Operational resilience aims to ensure that organisations can prevent, adapt to, respond to and recover from operational disruptions while continuing to deliver their critical business services.


Historically, regulatory expectations focused primarily on the resilience of individual financial institutions. However, as financial services have become increasingly dependent on shared technology providers, operational resilience can no longer be achieved solely within the boundaries of a single organisation.


PS16/24 extends this approach by recognising that the resilience of the financial sector increasingly depends on the resilience of critical external providers. The regime therefore complements existing operational resilience requirements by strengthening oversight of the systemic services on which multiple regulated firms rely.


Importantly, direct supervision of designated CTPs does not transfer responsibility away from regulated firms. Banks, insurers, payment firms and financial market infrastructures remain fully accountable for identifying, assessing, monitoring and managing the third-party risks within their own operational resilience frameworks.


How Does PS16/24 Address Systemic Risk?


A key distinction between the CTP regime and traditional outsourcing regulation is its focus on systemic risk rather than individual firm risk.


An operational disruption affecting a single financial institution may have limited consequences for the wider financial system. However, disruption affecting a shared technology or infrastructure provider could simultaneously impact numerous regulated firms, amplifying operational, financial and reputational consequences across the sector.


The CTP regime therefore focuses on providers whose services are considered sufficiently important that their failure could threaten financial stability, market integrity or confidence in the UK financial system.


Rather than replacing firms' existing responsibilities for third-party risk management, PS16/24 introduces an additional layer of regulatory oversight designed to strengthen the resilience of these critical ecosystem dependencies.


Figure 1. How Systemic Third-Party Dependencies Create Financial Stability Risks. A professional vertical flowchart illustrating how systemic third-party dependencies can create risks to UK financial stability. The diagram begins with the UK financial system, followed by critical business services (payments, trading, banking and insurance), multiple regulated financial firms (banks, insurers, payment firms and financial market infrastructures), a critical third-party provider (cloud, payments, data and infrastructure), a severe disruption event (cyberattack, outage or technology failure), simultaneous disruption across multiple firms, reduced service availability, customer impact, market disruption and financial stability concerns, culminating in regulatory oversight under PS16/24 to strengthen resilience. A side callout explains that disruption to a single critical third-party provider can simultaneously affect many financial firms, amplifying operational, financial and reputational risks across the financial system. The infographic uses Aevitium's black, white, grey and gold branding, includes supporting icons for each stage, a caption explaining how the UK Critical Third Party regime differs from traditional third-party risk management, and a footer containing the Aevitium LTD logo, copyright notice and professional disclaimer.


PS16/24 and SS6/24 Explained


The UK's Critical Third Party (CTP) regime is established through two complementary regulatory documents. Policy Statement PS16/24 sets out the final regulatory framework, while Supervisory Statement SS6/24 explains the regulators' supervisory expectations for designated Critical Third Parties. Together, they define both the legal framework and the operational standards expected to strengthen the resilience of systemic third-party providers.

What Is the Difference Between PS16/24 and SS6/24?


The UK Critical Third Party regime is built on two closely related regulatory publications issued jointly by the Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA).


Although frequently referenced together, they serve different purposes.


PS16/24 – Operational resilience: Critical Third Parties to the UK financial sector


-> Establishes the final regulatory framework, Fundamental Rules and Operational Risk and Resilience Requirements applicable to designated Critical Third Parties.


SS6/24 – Supervisory Statement: Operational resilience of Critical Third Parties


-> Explains how the Bank of England, PRA and FCA expect designated CTPs to comply with those requirements in practice and how supervisory oversight will be exercised.


Put simply, PS16/24 defines what the regulatory requirements are, while SS6/24 explains how regulators expect those requirements to be implemented and demonstrated.


How PS16/24 and SS6/24 Work Together


The two documents should be read together rather than in isolation.


PS16/24 establishes the regulatory obligations that apply once an organisation has been formally designated as a Critical Third Party by HM Treasury. These include the Fundamental Rules, Operational Risk and Resilience Requirements, and powers available to the regulators to oversee designated providers.


SS6/24 complements the policy by providing practical supervisory guidance on how regulators will assess compliance. It sets out their expectations regarding governance, operational resilience, dependency mapping, incident management, scenario testing, self-assessments and ongoing engagement with supervisors.


Together, the documents create a principles-based regulatory framework that provides both regulatory certainty and supervisory flexibility. Rather than prescribing a single operating model, they enable regulators to assess whether designated CTPs have implemented effective and proportionate resilience capabilities that reflect the nature, scale and complexity of the systemic services they provide.


Do Financial Institutions Need to Understand Both PS16/24 and SS6/24?


Understanding the distinction between PS16/24 and SS6/24 is important for both designated Critical Third Parties and the financial institutions that rely on them.

PS16/24 establishes the legal framework that underpins the UK's CTP regime, while SS6/24 provides insight into how regulators are likely to interpret compliance during supervisory engagement.


For organisations preparing for increased regulatory scrutiny, reading the two documents together provides a more complete understanding of both the regulatory requirements and the supervisory expectations that support the UK's operational resilience framework.


Is Your Organisation Prepared for the New Operational Resilience Standards?


At Aevitium LTD, we guide financial services firms and their suppliers through the complexities of regulatory compliance and operational resilience. From building robust risk management frameworks to implementing scenario testing and incident response plans, our experts are here to help you navigate the demands of the Bank of England’s PS16/24 policy and strengthen your resilience against systemic risks.



Businesswoman looking at a colorful lightbulb sketch symbolizing resilience strategy, with the headline "Operational Resilience Solutions – Adapt. Respond. Lead with confidence." promoting Aevitium LTD’s services in crisis response, governance, and third-party risk.

What Is a Critical Third Party?


A Critical Third Party (CTP) is a service provider formally designated by HM Treasury because disruption to the services it provides could threaten the stability or confidence of the UK financial system. Unlike traditional outsourcing arrangements, designation reflects the provider's systemic importance across the financial sector rather than the significance of an individual contractual relationship.

Defining a Critical Third Party


A Critical Third Party is an external service provider that delivers one or more services to regulated financial institutions or financial market infrastructures and has been formally designated by HM Treasury under the Financial Services and Markets Act 2023.


Designation is not based on the size of the provider or the value of individual contracts. Instead, it reflects the systemic importance of the services the provider delivers to the UK financial sector and the potential consequences if those services were disrupted.

Examples may include providers of cloud computing, payment infrastructure, market data, telecommunications, technology platforms or other shared services that support the delivery of critical financial services across multiple regulated organisations.


How Is a Critical Third Party Designated?


An organisation does not become a Critical Third Party automatically.


Designation is made by HM Treasury, following recommendations from the Bank of England, PRA and FCA, after considering whether disruption to the services provided could threaten the stability or confidence of the UK financial system.


When making this assessment, regulators consider factors such as:

  • the criticality of the services provided

  • the number and type of financial institutions relying on those services

  • the level of market concentration and substitutability

  • the potential impact of disruption on financial stability

  • broader systemic dependencies across the financial sector.


Only organisations formally designated through this process become subject to the UK's Critical Third Party regime.


Why Are Critical Third Parties Systemically Important?


The financial services sector has become increasingly dependent on a relatively small number of shared technology and infrastructure providers.


While these providers deliver significant efficiencies, they also create concentration risk. A major operational disruption affecting a single provider may simultaneously impact multiple banks, insurers, payment firms and financial market infrastructures.


This interconnectedness means that the resilience of the financial system increasingly depends not only on the resilience of individual firms, but also on the resilience of the critical third-party providers that support them.


The CTP regime recognises this shift by extending regulatory oversight beyond regulated firms to include those providers whose disruption could have wider systemic consequences.


How Is a Critical Third Party Different from a Traditional Outsourcing Provider?


A common misconception is that all outsourced service providers are Critical Third Parties. This is not the case.


Traditional outsourcing regulation focuses on the relationship between an individual regulated firm and its suppliers. The responsibility for managing outsourcing risk remains with the regulated firm through governance, due diligence, contractual arrangements and ongoing oversight.


The CTP regime has a different objective. It focuses on providers whose services are sufficiently important that disruption could affect multiple regulated firms simultaneously and create wider financial stability risks.


The key distinction is summarised below.


Figure 2. Comparison: Traditional Outsourcing vs Critical Third Party (CTP). A professional two-column comparison table contrasting traditional outsourcing with the UK's Critical Third Party (CTP) regime. The left column, titled Traditional Outsourcing, explains that outsourcing applies to individual outsourcing arrangements, focuses on firm-level operational risk, leaves regulated firms responsible for supplier oversight, and is governed by outsourcing and operational resilience rules. The right column, titled Critical Third Party (CTP), explains that CTP designation applies only to providers formally designated by HM Treasury, focuses on systemic financial stability risk, subjects designated providers to direct regulatory oversight, and is governed by PS16/24 and SS6/24. An information callout beneath the table emphasises that designation as a Critical Third Party does not replace existing outsourcing or third-party risk management requirements, and that regulated firms remain fully accountable for managing their own third-party risks. The infographic uses Aevitium's black, white, grey and gold corporate branding with supporting icons, and includes the Aevitium LTD logo, copyright notice and professional disclaimer in the footer.

Importantly, designation as a Critical Third Party does not replace existing outsourcing or third-party risk management requirements. Financial institutions remain fully accountable for identifying, assessing, managing and monitoring their third-party risks, regardless of whether a supplier is subject to direct regulatory oversight.


Which Critical Third Parties Have Been Designated?


HM Treasury designated the first four Critical Third Parties under the UK regime with effect from 13 July 2026. All four are major cloud and technology providers whose services support a significant number of banks, insurers, payment firms and financial market infrastructures across the UK financial system. 

The designated legal entities are:


Figure 3. Designated Critical Third Parties. A professionally designed table summarising the first organisations designated as Critical Third Parties (CTPs) under the UK regime with effect from 13 July 2026. The three-column table lists the organisation, designation date and primary relevant services. The designated entities are Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. The first three organisations are identified as providers of cloud infrastructure and technology services, while Oracle Corporation UK Limited is identified as providing cloud infrastructure, database and technology services. An information callout explains that designation applies to the named legal entities and that regulatory oversight focuses on the systemic third-party services they provide to the UK financial sector rather than their wider global operations. The infographic uses Aevitium's black, white, grey and gold branding and includes the Aevitium LTD logo, copyright notice and professional disclaimer in the footer.

The statutory designation applies to the named legal entities. Regulatory oversight is more focused: it applies to the systemic third-party services they provide to the UK financial sector, rather than to every aspect of their global operations. The relevant provider is notified at designation of the services considered systemic.


Why Were These Providers Designated as Critical Third Parties?


The first designations reflect the financial sector's growing dependence on a small number of major cloud and technology providers. Banks, insurers and financial market infrastructures increasingly use shared cloud infrastructure to host applications, process data and support critical business services. A severe disruption at one widely used provider could therefore affect multiple regulated organisations simultaneously.


HM Treasury stated that the designations followed evidence gathering and collaborative engagement with the providers. The decision reflects the potential systemic consequences of disruption, rather than the commercial scale or importance of any single outsourcing contract.


The selection of these organisations is consistent with the three factors used by the regulators when identifying potential Critical Third Parties:


  • Concentration: the number and type of regulated firms relying on the provider.

  • Materiality: the importance of the services to essential financial activities, services or operations.

  • Other drivers of systemic impact: factors that could cause disruption to spread, amplify risk or undermine confidence in the financial system.


The four designations do not create a closed list. The regime is intended to operate on a rolling basis, and HM Treasury may designate additional providers where the statutory criteria are met. There is no statutory limit on the number of Critical Third Parties that may ultimately fall within the regime.

Important distinction: designation does not mean that every service delivered by AWS, Google Cloud, Microsoft or Oracle is directly overseen under the CTP regime. The regulators oversee the services identified as systemically important to the UK financial sector.

How Are Critical Third Parties Designated?


HM Treasury has the legal authority to designate a service provider as a Critical Third Party. In practice, the Bank of England, Prudential Regulation Authority and Financial Conduct Authority identify potential providers, assess their systemic importance and may recommend designation. HM Treasury then undertakes its own assessment, consults the relevant parties and makes the final decision through secondary legislation. 

Who Designates a Critical Third Party?


Figure 4. How a Critical Third Party Is Designated. A vertical process flow illustrating the UK's Critical Third Party (CTP) designation process. The diagram begins with Regulatory Data and Market Intelligence, including third-party registers, supervisory information, firm dependency data and incidents. It progresses to Potential CTP Identified by the Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA), followed by Systemic Assessment based on concentration, materiality and other drivers of systemic impact. The next stages show Recommendation to HM Treasury, where regulators submit analysis and supporting evidence, followed by HM Treasury Review and Consultation, including provider engagement, regulator consultation and evidence assessment. The process concludes with Formal Designation, where designation regulations identify the legal entity, before Joint Regulatory Oversight Begins, with the Bank of England, PRA and FCA overseeing the designated provider's systemic third-party services. An information callout highlights that HM Treasury makes the final designation decision, while the financial regulators identify, assess and recommend potential Critical Third Parties and supervise designated providers once the regime applies. The infographic is presented in Aevitium's black, white, grey and gold corporate style and includes the Aevitium LTD logo, copyright notice and professional disclaimer in the footer.

The final designation decision belongs to HM Treasury.


Under section 312L of the Financial Services and Markets Act 2000, as amended by the Financial Services and Markets Act 2023, HM Treasury may designate a provider where, in its opinion, failure or disruption to the services it provides could threaten the stability of, or confidence in, the UK financial system.


HM Treasury must consult the Bank of England, PRA and FCA before making a designation. In most cases, the regulators are expected to identify potential CTPs and submit a recommendation supported by regulatory data and analysis. However, HM Treasury may also designate a provider without first receiving a formal recommendation from the regulators.


How Do Regulators Identify Potential Critical Third Parties?


The Bank of England, PRA and FCA assess whether a provider's services could create systemic risk if they failed or were severely disrupted.


Their assessment considers three principal areas.


1. Concentration

The regulators consider how many regulated firms use the provider and the types of organisations that depend on its services.

This includes both:

  • the total number of firms relying on the provider; and

  • the systemic importance of those firms within the UK financial system.

A provider used by many firms may create concentration risk, but concentration alone does not automatically justify designation. The regulators also assess the importance of the services and the potential channels through which disruption could spread.


2. Materiality

Materiality concerns the importance of the provider's services to essential financial activities, services or operations.

The regulators assess whether disruption could:

  • interrupt critical financial services;

  • affect consumers or market participants;

  • amplify operational or financial stress;

  • undermine market integrity; or

  • weaken confidence in the UK financial system.


3. Other Drivers of Systemic Impact

The regulators may also consider additional factors that influence the scale or transmission of disruption.


These may include:

  • limited substitutability;

  • complex supply-chain dependencies;

  • common technology architecture;

  • geographic or operational concentration;

  • reliance on shared platforms;

  • the speed at which disruption could spread; and

  • the difficulty firms would face in migrating to an alternative provider.

These considerations help distinguish an important supplier from one whose disruption could create broader financial stability consequences.


What Is the Critical Third Party Recommendation Process?


Once a potential CTP has been identified, the regulators analyse available information and determine whether the statutory test appears to be met.


This analysis may draw on:

  • regulatory returns and third-party registers;

  • information supplied by regulated firms;

  • market intelligence;

  • supervisory data;

  • information from the provider;

  • incident and resilience information; and

  • engagement with domestic or international authorities.


Where the regulators conclude that a provider may meet the statutory threshold, they may recommend designation to HM Treasury. HM Treasury then conducts its own assessment and considers the evidence before making a final decision.


What Happens Before HM Treasury Makes a Designation?


Before reaching a decision, HM Treasury engages with the provider, the financial regulators and other relevant organisations. This gives the proposed provider an opportunity to understand the basis for potential designation and provide relevant evidence.


HM Treasury then considers whether failure or disruption to the provider's services could threaten the stability of, or confidence in, the UK financial system.


Where the statutory test is satisfied, the designation is made through regulations identifying the relevant legal entity. The provider is also notified of the services considered to be systemic third-party services for regulatory oversight purposes.


What Happens After a Provider Is Designated?


Following designation, the Bank of England, PRA and FCA jointly oversee the provider's systemic third-party services.


The designated CTP becomes subject to applicable requirements covering areas such as:

  • governance;

  • operational risk management;

  • dependency mapping;

  • incident management;

  • scenario testing;

  • information sharing;

  • resilience assurance; and

  • regulatory notifications.


Designation does not make the provider a regulated financial institution and does not place all its business activities under financial regulation. Oversight remains focused on the systemic services it provides to firms and financial market infrastructures


Who Does PS16/24 Apply To?


PS16/24 applies directly to designated Critical Third Parties (CTPs), but its implications extend well beyond those organisations. Financial institutions, financial market infrastructures (FMIs), service providers and other third parties all have different responsibilities within the UK's operational resilience framework. Understanding these distinctions is essential to avoiding common misunderstandings about the scope of the regime.

Designated Critical Third Parties


Designated Critical Third Parties are organisations formally designated by HM Treasury under the Financial Services and Markets Act 2023 because disruption to the services they provide could threaten the stability of, or confidence in, the UK financial system.


Once designated, they become subject to direct oversight by the Bank of England, PRA and FCA and must comply with the Fundamental Rules and Operational Risk and Resilience Requirements established by PS16/24.


Importantly, only the systemic services identified by regulators fall within the scope of supervision. Designation does not extend financial regulation to all aspects of the provider's business.


Regulated Financial Institutions


Banks, building societies, insurers, investment firms and payment firms are not directly subject to PS16/24 unless they themselves become designated as a Critical Third Party.


However, the regime has significant implications for regulated firms because many rely on designated providers to support critical business services.


Financial institutions remain responsible for:

  • identifying critical third-party dependencies;

  • undertaking due diligence;

  • managing outsourcing risk;

  • maintaining operational resilience;

  • monitoring supplier performance; and

  • complying with existing outsourcing and operational resilience requirements.


The designation of a supplier does not transfer these responsibilities to the regulators.


Financial Market Infrastructures (FMIs)


Financial Market Infrastructures, including payment systems, central counterparties (CCPs) and central securities depositories (CSDs), are among the organisations most likely to depend on designated Critical Third Parties.


Given their systemic role within the financial system, FMIs may rely heavily on cloud infrastructure, data services and shared technology platforms to support critical operations.


Although FMIs are not directly regulated under the CTP regime, their operational resilience frameworks should consider dependencies on designated providers alongside their existing resilience obligations.


Other Service Providers


Many technology providers, software vendors, managed service providers and infrastructure suppliers support regulated firms without being designated as Critical Third Parties.


These organisations continue to operate under contractual arrangements with their clients and remain outside the scope of direct supervision unless HM Treasury formally designates them.


They remain subject to commercial obligations and, where relevant, sector-specific regulatory requirements, but PS16/24 does not automatically apply to them.


Non-Designated Third Parties


Most outsourcing providers will never become Critical Third Parties.

Professional advisers, consultants, facilities providers, telecommunications suppliers, payroll providers and countless other service organisations continue to be managed through traditional outsourcing, supplier management and operational resilience arrangements. The existence of the CTP regime does not alter these relationships.




What Are the PS16/24 Requirements?


PS16/24 establishes a comprehensive operational resilience framework for designated Critical Third Parties. Rather than prescribing detailed technical controls, the policy sets principles-based expectations across governance, operational risk management, technology resilience and regulatory engagement. Together, these requirements are intended to reduce the likelihood that disruption at a single provider could threaten the stability of the UK financial system.


Governance Expectations


The Bank of England, PRA and FCA expect governance arrangements to provide effective oversight of operational resilience from board level through to day-to-day operations.

Although the framework remains principles based, designated providers should be able to demonstrate:

  • clearly defined governance arrangements;

  • senior management accountability;

  • effective challenge and oversight;

  • escalation procedures for material issues;

  • regular management information and resilience reporting; and

  • governance that supports timely and informed decision-making during disruption.

Governance should also support continuous review as services, technologies and dependencies evolve.


Operational Risk Expectations


The framework should enable organisations to understand:

  • operational risks affecting critical services;

  • key dependencies;

  • control effectiveness;

  • emerging vulnerabilities;

  • escalation triggers; and

  • residual risk.

Rather than treating resilience separately from operational risk management, PS16/24 expects resilience considerations to be embedded throughout the operational risk lifecycle.


Mapping Critical Services and Dependencies


Providers should maintain sufficient visibility over:

  • critical services;

  • supporting technology;

  • infrastructure;

  • operational processes;

  • key personnel;

  • third-party suppliers; and

  • fourth-party dependencies where relevant.

Effective mapping supports scenario testing, incident response and resilience planning.


Technology, Cyber and Supply Chain Resilience


Providers should demonstrate resilience across:

  • ICT infrastructure;

  • cyber security;

  • availability and recovery capabilities;

  • change management;

  • cloud operations;

  • supplier resilience;

  • subcontractor oversight; and

  • concentration risk.

Operational resilience should continue throughout periods of significant organisational or technological change.


Testing and Incident Response


Scenario testing should consider severe but plausible events, including:

  • cyber attacks;

  • technology failures;

  • cloud service disruption;

  • data corruption;

  • third-party failures; and

  • multiple concurrent events where appropriate.

Incident management arrangements should support:

  • timely detection;

  • effective escalation;

  • crisis coordination;

  • communications;

  • service recovery; and

  • post-incident learning.


For further guidance, refer to our resource on Crisis Management and Response: Best Practices and Strategies to develop robust response frameworks that align with regulatory expectations.


Regulatory Engagement and Continuous Improvement


Designated providers should maintain processes supporting:

  • regulatory notifications;

  • self-assessments;

  • information sharing;

  • supervisory engagement;

  • resilience reporting;

  • lessons learned;

  • internal assurance; and

  • ongoing framework improvement.

Operational resilience is viewed as a continuously evolving capability rather than a one-time compliance exercise.


What Are the Six PS16/24 Fundamental Rules for Critical Third Parties?


The PS16/24 framework includes six Fundamental Rules that establish the overarching standards designated Critical Third Parties must meet. They cover how a CTP conducts its business, manages risk, organises its affairs and engages with the Bank of England, PRA and FCA.


The first five rules apply to the CTP’s provision of systemic third-party services. Fundamental Rule 6 has a wider application and also covers other services the CTP provides to firms.


The Six Critical Third Party Fundamental Rules


Figure 6. The Six Critical Third Party Fundamental Rules under PS16/24. A two-column table summarising the six Fundamental Rules that apply to designated Critical Third Parties under the UK Critical Third Party regime. The left column lists each rule: (1) conduct business with integrity; (2) conduct business with due skill, care and diligence; (3) act in a prudent manner; (4) maintain effective risk strategies and risk management systems; (5) organise and control affairs responsibly and effectively; and (6) deal with regulators in an open and co-operative way, including appropriate regulatory disclosures. The right column explains the practical meaning of each rule, highlighting governance, operational resilience, risk management, accountability and regulatory engagement. The infographic uses Aevitium's black, white, grey and gold branding, with the company logo, copyright notice and disclaimer.

The rules are intentionally principles-based. They do not specify every control that a CTP must operate. Instead, they establish the standards against which the regulators can assess the organisation’s conduct, governance, risk management and regulatory engagement.


They should therefore be read alongside the more detailed Operational Risk and Resilience Requirements, which explain the capabilities a CTP must establish in relation to its material services. These include requirements covering governance, risk management, dependency management, technology and cyber resilience, change management, mapping, incident management and termination of services.


Key point: The Fundamental Rules establish how a designated CTP is expected to behave and organise itself. The Operational Risk and Resilience Requirements provide the more detailed framework through which that standard is implemented.

Which Third-Party Providers Could Be Designated as Critical Third Parties Under PS16/24?


Designation under the UK Critical Third Party regime is not restricted to a predetermined list of industries. HM Treasury may designate a provider where a failure in, or disruption to, the services it provides to financial firms or financial market infrastructures could threaten the stability of, or confidence in, the UK financial system.


The assessment therefore focuses on the services provided and the systemic dependency they create, rather than the provider’s industry classification alone.


Types of Critical Providers That Could Be Considered for Future Designation


Figure 7. Types of Providers That Could Be Considered for Future Designation under the UK Critical Third Party Regime. A three-column table summarising the types of third-party providers that could potentially be designated as Critical Third Parties (CTPs) under PS16/24. The table groups providers into eight categories: cloud services, payments, technology and communications infrastructure, data services, financial market infrastructure technology, cybersecurity services, artificial intelligence services, and digital identity services. For each category, the table outlines the potentially relevant services and explains why they could become systemically important due to concentration risk, common dependencies or their role in supporting critical financial services. The infographic uses Aevitium's black, white, grey and gold branding and includes the company logo, copyright notice and disclaimer.

What Does PS16/24 Mean for Financial Institutions?


The regime is intended to strengthen system-wide resilience by allowing the Bank of England, PRA and FCA to oversee providers whose disruption could affect multiple firms at the same time. It complements, rather than replaces, the operational resilience, outsourcing and third-party risk obligations that already apply to regulated firms.


For financial institutions, the practical implication is clear: designation may improve regulatory visibility over a major provider, but it does not remove the need to understand, manage and test the institution’s own dependencies.


Regulated Firms Remain Accountable


A regulated firm cannot assume that using a designated Critical Third Party makes the underlying service resilient by default.


The CTP regime focuses on the systemic risks arising from the provider’s services across the wider financial sector. The firm remains responsible for understanding how it uses those services, how disruption could affect its important business services and what measures are required to remain within its own impact tolerances.


This creates a shared but distinct accountability model:

  • the CTP is accountable for complying with the rules and expectations applying to its systemic third-party services;

  • regulators oversee the systemic resilience of the designated provider; and

  • each regulated firm remains accountable for managing the risks arising from its own use of the service.


The designation of a provider should therefore strengthen a firm’s third-party risk management, not replace it.


Third Party Dependency Mapping


Financial institutions should maintain a clear view of how designated CTP services support their important business services, critical processes and customer outcomes.


Effective dependency mapping should identify:

  • the specific services obtained from the CTP;

  • the systems, applications and data that rely on those services;

  • internal processes and teams dependent on them;

  • material subcontractors and fourth parties where relevant;

  • interdependencies with other external providers; and

  • the important business services that could be disrupted.


This mapping should extend beyond the name of the provider. Large CTPs often deliver multiple products through different legal entities, regions, data centres and service configurations. The relevant dependency is therefore the specific service architecture used by the firm, not merely the fact that the provider has been designated.


Critical Third Party Concentration Risk


PS16/24 places greater regulatory attention on concentration and common-dependency risks across the financial system. Firms should conduct the same analysis at institutional level.


Concentration can arise where:

  • several important business services depend on the same provider;

  • different providers rely on the same underlying infrastructure;

  • multiple group entities use the same platform;

  • a material subcontractor supports several of the firm’s suppliers; or

  • alternative providers exist in theory but migration would be difficult or slow.


Firms should assess both direct concentration and hidden concentration within the wider supply chain. Diversifying contracts across several providers offers limited protection where those providers depend on the same cloud platform, network, data source or cybersecurity service.


Contracts and Information Rights


Existing contracts should be reviewed to determine whether they provide the rights and information required to manage resilience effectively.


Relevant provisions may include:

  • access to resilience and assurance information;

  • incident notification requirements;

  • cooperation during investigations and regulatory engagement;

  • audit and access rights;

  • participation in testing;

  • subcontracting controls;

  • data access, portability and return;

  • recovery and continuity commitments; and

  • termination and transition assistance.


Designation does not automatically improve the contractual position of every customer. Firms still need arrangements that reflect the materiality of the service, their regulatory obligations and the practical information needed to assess resilience.


Resilience and Scenario Testing


The direct oversight of CTPs should not lead firms to reduce their own testing.

Firms should continue to test how disruption at a designated provider would affect their important business services, including whether they could remain within impact tolerances. Scenario Testing should cover more than the provider’s technical recovery capabilities.


Relevant scenarios may examine:

  • regional or prolonged service failure;

  • cyber compromise;

  • loss or corruption of data;

  • failure of a critical subcontractor;

  • restricted access to the provider’s personnel or systems;

  • simultaneous disruption across several services; and

  • the failure of recovery or migration arrangements.


Where appropriate, firms should seek coordinated testing with the CTP and other relevant participants. However, they should also be able to test their own response independently, particularly where joint participation is unavailable or restricted.


Exit and Substitutability Planning


Exit planning remains essential even where a provider has been designated and is subject to direct supervision.


A credible exit plan should consider:

  • the trigger for initiating exit;

  • the availability and capability of alternative providers;

  • data extraction and portability;

  • system reconfiguration;

  • regulatory approvals;

  • customer and operational impacts;

  • transition resources and governance; and

  • the time required to complete migration safely.


The existence of an alternative supplier does not, by itself, demonstrate substitutability. Firms should assess whether they could move the service in practice, within an acceptable timeframe and without creating further operational risk.


For highly concentrated services, immediate substitution may be unrealistic. In those cases, resilience planning should also consider service degradation, alternative operating procedures, workload prioritisation and recovery within the existing environment.


Incident Coordination


A significant incident at a CTP may affect many firms simultaneously. Effective coordination is therefore central to the regime.


Financial institutions should establish clear arrangements covering:

  • notification and escalation between the firm and the CTP;

  • internal crisis management and decision-making;

  • communications with customers and counterparties;

  • regulatory reporting;

  • participation in sector-wide coordination arrangements;

  • access to accurate and timely incident information; and

  • recovery priorities where several services or firms are affected.


The firm should understand how its own incident management process connects with the provider’s response structure. This includes knowing who has authority to make decisions, what information will be shared and how competing recovery priorities will be managed.

Key point: Direct regulatory oversight of CTPs strengthens system-wide resilience. It does not reduce the accountability of financial institutions for their own dependency management, operational resilience and customer outcomes.

PS16/24 vs DORA: What Is the Difference?


The two regimes share common objectives around operational resilience, regulatory cooperation and the management of concentrated third-party dependencies. Their legal scope, terminology, designation process and supervisory architecture remain distinct.


PS16/24 and DORA Comparison


Figure 8. PS16/24 and DORA Comparison. A three-column comparison table outlining the similarities and differences between the UK's PS16/24 Critical Third Party regime and the European Union's Digital Operational Resilience Act (DORA). The table compares jurisdiction, primary regulatory framework, provider terminology, scope of provider designation, designation authority, oversight authorities, primary objective, focus of oversight, application to financial institutions, service coverage, regulatory approach and cross-border coordination. It highlights that PS16/24 establishes a UK oversight regime for designated Critical Third Parties to protect financial stability, while DORA creates an EU framework for digital operational resilience and oversight of Critical ICT Third-Party Service Providers. The infographic uses Aevitium's black, white, grey and gold branding and includes the company logo, copyright notice and disclaimer.

PS16/24 should therefore not be described simply as the UK version of DORA.

DORA is broader in its direct application to financial entities and more specifically focused on digital and ICT resilience. PS16/24 is primarily a systemic third-party oversight regime. It gives UK regulators powers to oversee designated providers directly while leaving firms’ own regulatory responsibilities in place.


UK–EU Cooperation on Critical Third-Party Oversight


In January 2026, the Bank of England, PRA and FCA entered into a Memorandum of Understanding with the European Supervisory Authorities: the EBA, EIOPA and ESMA. The agreement supports cooperation, information exchange and coordination of oversight activities relating to providers that operate across the UK and EU regimes.


The cooperation arrangements are particularly relevant where:

  • a provider is designated under both PS16/24 and DORA;

  • an EU-designated CTPP uses premises in the UK to serve EU financial entities;

  • a UK-designated CTP uses premises in the EU to serve UK financial institutions;

  • regulators require information about cross-border ICT dependencies;

  • coordinated oversight could reduce duplication; or

  • authorities need to cooperate during an incident or emergency.


The MoU provides a framework for:

  • exchanging relevant supervisory information;

  • coordinating oversight activities where appropriate;

  • supporting cooperation in emergency situations;

  • sharing approaches to ICT risk management and controls;

  • considering mitigation measures and incident response; and

  • supporting the oversight of providers designated in both jurisdictions.


The arrangement reflects the practical reality that many large technology providers operate through integrated global infrastructures. A significant disruption may therefore affect firms in several jurisdictions at the same time.


Cooperation Does Not Merge the Two Regimes


The UK and EU frameworks remain legally separate.


The MoU supports cooperation between the authorities, but it does not create a single designation process, common rulebook or automatic recognition of compliance. A provider subject to both regimes must continue to meet the applicable UK and EU requirements.


The UK supervisory statement confirms that the CTP regime is intended to be interoperable with regimes such as DORA, but only where that interoperability does not conflict with or undermine the UK regime’s overall objective.


For financial institutions operating in both jurisdictions, this means that third-party risk management should identify where the same provider or service falls within both frameworks. Governance, assurance and testing processes should be coordinated where possible, while preserving the distinct legal and regulatory requirements of each regime.

Key point: PS16/24 and DORA are complementary cross-border resilience regimes, not interchangeable standards. The UK–EU cooperation arrangements should improve information sharing and supervisory coordination, but firms and providers remain responsible for complying with each regime separately.

What Implementation Challenges Will Critical Third Parties Face?


The first wave of Critical Third Party designations demonstrates that many organisations outside the traditional regulatory perimeter will now be expected to meet supervisory standards comparable to those applied to major financial institutions. For some providers, this will require strengthening governance, operational resilience capabilities and regulatory engagement rather than simply implementing new technical controls.


  • Operational Risk Management Frameworks: Many CTPs may not currently possess comprehensive frameworks that align with the stringent regulatory standards for risk assessment, control, and management.

  • Scenario Testing and Incident Response: Some organisations may lack experience in conducting advanced scenario tests or have limited resources to meet the required testing intensity and frequency. In addition to be effective, such scenarios should operate jointly with their clients.

  • Governance and Accountability Structures: Clear governance structures with defined accountability—particularly at senior management levels—may be underdeveloped, leading to challenges in aligning management practices with resilience goals.

  • Technological and Cyber Resilience: CTPs may need to enhance their cybersecurity and IT resilience to prevent and respond to disruptions effectively, requiring additional investment and expertise.

  • Resource Allocation and Capacity: Smaller CTPs may lack the financial and human resources needed to comply with these requirements while continuing to serve their financial sector clients effectively. Effective resource allocation includes understanding exit triggers for third-party vendors. Our resource on Monitoring Triggers for Third-Party Vendor Exit provides insight into identifying and acting on these critical signals.

  • Regulatory and Compliance Awareness: Non-financial service providers that are new to these regulations might lack familiarity with the stringent requirements, necessitating further education and training to build a compliance-oriented culture.

  • Cross-Functional Collaboration: Organisations may face challenges in achieving cross-functional collaboration, with responsibilities for operational resilience often dispersed across departments, leading to siloed implementation efforts.


Conclusion


The designation of the first Critical Third Parties represents a significant evolution in the UK's approach to operational resilience.


Rather than focusing solely on the resilience of individual financial institutions, PS16/24 recognises that the stability of the financial system increasingly depends on a relatively small number of highly interconnected technology and service providers. As digital transformation, cloud adoption and shared infrastructure continue to reshape financial services, the resilience of these providers has become a matter of public interest rather than simply a contractual issue between firms and their suppliers.


The UK Critical Third Party regime addresses this challenge by introducing direct regulatory oversight of providers whose disruption could have systemic consequences. At the same time, it preserves the long-established principle that regulated firms remain accountable for managing their own operational resilience, outsourcing arrangements and third-party risks.


For designated providers, the regime introduces a comprehensive framework covering governance, operational risk management, technology resilience, testing, incident management and regulatory engagement. For financial institutions, it reinforces the importance of understanding dependencies, managing concentration risk, maintaining effective contractual arrangements and ensuring credible contingency and exit planning.


The UK's approach is also designed to operate alongside international initiatives such as the European Union's Digital Operational Resilience Act (DORA). As many critical providers support financial institutions across multiple jurisdictions, effective cooperation between regulators will become increasingly important in strengthening cross-border operational resilience while avoiding unnecessary duplication.


PS16/24 is therefore more than a new supervisory framework. It reflects a broader shift in financial regulation towards recognising that resilience is no longer determined solely within individual organisations, but across the complex network of third-party providers that underpin today's financial ecosystem.

Organisations that understand and actively manage these dependencies will be better positioned to strengthen operational resilience, support regulatory compliance and maintain confidence in an increasingly interconnected financial system.


For a deeper dive into the regulatory landscape, watch our Webinar Recap: Navigating the Intersection of Operational Resilience, Consumer Duty, and Regulatory Compliance to explore how these elements align under the new policy.


Frequently Asked Questions


Why did the UK introduce the Critical Third Party regime?

The UK's operational resilience framework initially focused on regulated financial institutions. However, as banks, insurers, payment firms and financial market infrastructures became increasingly dependent on a relatively small number of external technology providers, regulators recognised that disruption at one provider could affect many firms simultaneously. The Critical Third Party regime extends regulatory oversight to those providers whose services could create systemic risk.


Does designation mean a provider has failed to manage risk?

No. Designation is not a supervisory finding or enforcement action. It reflects the systemic importance of the services provided rather than the quality of the provider's controls. A provider may be designated simply because many financial institutions depend on its services.


Can a provider refuse to become a Critical Third Party?

No. Designation is made by HM Treasury under the statutory framework. Once designated, the provider becomes subject to the applicable oversight regime and regulatory requirements.


Does designation apply to every service provided by a CTP?

No. The regime focuses on the systemic third-party services identified during the designation process. A provider may offer hundreds of products and services, but only those falling within the designation are subject to the Operational Risk and Resilience Requirements.


Does using a designated CTP reduce a firm's regulatory obligations?

No. Regulated firms remain fully responsible for managing operational resilience, outsourcing and third-party risk. Designation strengthens regulatory oversight of the provider but does not transfer accountability from the firm.


Could the same provider be designated under both PS16/24 and DORA?

Yes. Many large technology providers operate across multiple jurisdictions. A provider may therefore fall within both the UK Critical Third Party regime and the EU DORA oversight framework, requiring engagement with both supervisory regimes.


Can a provider be removed from the Critical Third Party regime?

Potentially. If the statutory designation criteria are no longer met, HM Treasury could revoke a designation. This might occur if the provider no longer delivers services that create systemic dependencies within the UK financial sector.


Does PS16/24 introduce new contractual requirements for financial institutions?

Not directly. The regime primarily regulates designated providers rather than customer contracts. However, many financial institutions are expected to review contractual arrangements to ensure they continue to support operational resilience, testing, information sharing and exit planning.


Will more organisations be designated in the future?

Almost certainly. The legislation was designed to accommodate future designations as technology evolves and systemic dependencies change. Cloud providers represent the first wave rather than the final scope of the regime.


What should boards ask about Critical Third Party risk?

Boards should understand:

  • which designated CTPs support important business services;

  • where concentration risk exists;

  • whether alternative providers are genuinely viable;

  • how disruption would affect impact tolerances; and

  • whether exit plans have been tested rather than simply documented.


How does PS16/24 affect third-party risk management programmes?

For many organisations, the regime reinforces existing good practice rather than creating an entirely new discipline. Third-party risk management is increasingly expected to integrate operational resilience, cyber resilience, supplier governance, concentration risk and business continuity into a single governance framework.


What does success look like under the CTP regime?

Successful implementation is unlikely to be measured solely by compliance with documented requirements. Regulators will expect designated providers to demonstrate that resilience is embedded within governance, operational decision-making and day-to-day management of systemic services.


 
 
bottom of page