top of page

What the UK’s new critical third-party rules signify for TPRM - With great visibility comes great resilience

  • 6 days ago
  • 4 min read

Updated: 1 day ago

For decades, financial regulation focused solely on financial institutions. Banks, insurers, credit unions, and investment firms were responsible for managing their own risks and the risks posed by third-party vendors. The UK's latest cloud regulation signals a shift in that thinking. Rather than regulating only financial institutions, UK regulators are extending their oversight to critical financial technology providers. This isn't just another outsourcing rule. It's recognition that today's financial system extends far beyond banks themselves, and that the regulatory perimeter needs to expand along with it.  Which begs an all-important question: Is your TPRM also evolving to reflect this new reality?


A man interacting with cloud infrastructure with a critical banner in the foreground

What’s happening and why


The UK has formally designated four major cloud providers (AWS, Google Cloud, Microsoft, and Oracle) as Critical Third Parties (CTPs) to the financial system. These CTPs will now be directly monitored by the Bank of England, the Prudential Regulatory Authority (PRA), and the Financial Conduct Authority (FCA). By bringing major cloud providers under direct regulatory oversight, the UK is basically acknowledging that some technology providers have become so deeply embedded in the financial system that their resilience can affect the stability of the entire sector.


In other words, the aim is to reduce systemic risks.


What triggered this response? Like many countries, the UK's public and private sectors have become heavily dependent on a small number of cloud hyperscalers. According to HM Treasury, more than 65% of UK firms rely on the same quartet of cloud service providers, while the figure rises to around 95% across the public sector. This level of concentration means that a disruption at a single provider can quickly ripple across critical services. Last year's AWS outage brought these fears to life. The outage disrupted services at several UK banks and government tax portals and reinforced calls from lawmakers for stronger regulatory oversight.


The move also comes on the heels of the EU's Digital Operational Resilience Act (DORA), which designates 19 major technology firms as critical and subjects them to direct regulatory oversight. Together, these developments showcase that regulators are now viewing technology providers as more than just vendors.


What’s changing


Perhaps the biggest change is ideological. Large cloud providers were once treated much like other technology vendors, such as CRM or marketing platforms. The new rules signal a fundamental shift in regulatory ideology where cloud providers are now being viewed as critical financial infrastructure, much like payment systems and central counterparties (CCPs).


What does this mean in practice? Regulators can now engage directly with these CTPs, rather than relying solely on the financial institutions that use their services. They can require CTPs to strengthen stress testing and scenario planning, identify critical dependencies, and improve their resilience measures. Most importantly, CTPs will have to directly report major incidents, such as cyberattacks or power outages, to regulators. This gives regulators greater visibility into risks that can spread across multiple financial institutions.


And to paraphrase a popular superhero saying: with greater visibility comes greater resilience.


What’s not


For banks and other financial institutions, not much changes. Direct regulatory oversight of critical third parties does not reduce an FI’s responsibility for managing its third-party risk. Banks are still expected to conduct thorough vendor due diligence, continuously monitor their third-party providers, maintain effective exit strategies, and demonstrate strong outsourcing governance.


At the end of the day, the brunt of the responsibility remains with the FI. If a third-party failure disrupts critical services or creates a regulatory breach, the financial institution can still be held accountable and face the resulting penalties.


The regulatory perimeter is expanding. Is your TPRM?


While the new rules apply only in the UK, the broader trend it reinforces is global. Financial regulation is moving beyond the bank itself. That’s no surprise given that today's financial ecosystem stretches across cloud providers, payment platforms, fintechs, AI providers, data companies, cybersecurity firms, and other critical third parties. As banks become more dependent on these organizations, the risks they need to manage are changing too.


This explains why, over the past few years, US regulators have increasingly looked beyond the traditional financial sector and sharpened their focus on areas such as operational resilience, cloud risk, cyber resilience, and third-party oversight.


And if the regulatory perimeter is expanding, TPRM needs to expand with it.


For many financial institutions, third-party monitoring still revolves around periodic assessments, annual reviews, questionnaires, and financial disclosures. These provide an important baseline, but they offer only a snapshot of a vendor at a particular point in time. However, a vendor can be financially stable when its annual review is completed and become distressed six months later. Similarly, a critical supplier can maintain strong financials while facing operational, regulatory, or reputational issues. These non-financial signals can emerge long before they show up in financial statements and can provide important clues about where a vendor’s risk profile might be heading.


In today’s environment, FIs need greater visibility into what is happening between formal assessments. That means continuously monitoring both financial and non-financial signals. This proactive approach can help with early risk detection. For example, it could help detect a cyber weakness before the next scheduled review, identify regulatory or legal issues as they emerge, spot a pattern of customer complaints or adverse media, or recognize operational and business changes that may eventually affect a vendor’s ability to deliver critical services. The aim isn’t to collect more data points. It's to gain earlier visibility into a vendor's changing risk profile and have enough time to act. 


After all, if expanding regulation is intended to create greater visibility and resilience, TPRM should also move in the same direction. It should enable earlier visibility, faster action, and ultimately, greater resilience.       


Want to dive deeper into this subject? Explore our take on how continuous risk intelligence can strengthen a bank’s Three Lines of Defense and give each line greater visibility into emerging third-party risk. And discover why the future of TPRM goes beyond questionnaires to continuous, AI-led monitoring.


A man holding a laptop with a schedule a demo button in the foreground

 
 
final1.png
Subscribe to the TRaiCE blog
Get our posts delivered straight to your inbox

Thanks for subscribing

bottom of page