Skip to main content
Welcome to Deloitte
If we have selected the wrong experience for you, please change it above.

Beyond Compliance: Strategic Approaches to Operational Incident and Third-Party Reporting by March 2027 - Part - 2

Part 2: Material Third-Party (MTP) Reporting: What Financial Services Firms Need to Do Now

The UK regulators have introduced a new reporting regime for material third-party arrangements, with the aim of giving supervisors greater oversight over the external services that support firms’ operations.

The regulatory focus is shifting from "material outsourcing" to a more expansive view of significant risks and materiality across all third-party relationships, encompassing technology, data, and other service dependencies. This new framework is designed to provide a more integrated perspective on concentration and systemic risks within the sector, reflecting international standards like the Financial Stability Board toolkit, the Basel Committee on Banking Supervision principles, and the EU’s Digital Operational Resilience Act (DORA).

Many financial services firms have already broadened their view of third-party risk, in line with current PRA SS2/21 requirements to assess non-outsourcing populations. This trend is reinforced by global regulatory developments, including the OFSI Third-Party Risk Management Guideline1, EBA Consultation Paper2 being updated to cover non-ICT outsourcing and non-outsourcing (given DORA's comprehensive coverage of the ICT third-party supply chain), and the Monetary Authority of Singapore (MAS) also expanding its scope beyond traditional outsourcing in its March 2026 Consultation Paper3. Therefore, for firms regulated by the PRA the requirement to assess materiality and perform due diligence on non-outsourcing relationships is not new, however, the main implications are:

  • Greater reporting scope to the UK regulators of all material third-party relationships;
  • Evolution from maintaining an outsourcing register to now submission of an annual MTP register;
  • Additional data points to capture across the material third-party template in advance of March 2027 e.g. critical nodes in the supply chain.

Key Changes and Their Impact

The new reporting regime introduces several critical changes, expanding the scope of reportable third-party arrangements and standardising how firms notify regulators and maintain internal records.

  • Broader Regulatory Visibility: Regulators will now receive more comprehensive information on a wider portfolio of third-party arrangements. This shift from material outsourcing to material third-party arrangements equips them with incremental data points to better understand both firm-specific risks and sector-wide systemic concentration risks and dependencies.
  • Standardised MTP Reporting: The regime introduces distinct templates for the MTP register and notifications4 which are broadly aligned, with the intention of providing firms with greater flexibility over the number of data points associated with each template. Submissions will be made via FCA Connect for notifications and RegData for the annual MTP register.
  • Annual MTP Register Requirements: In-scope firms must now maintain and submit an annual register of their material third-party arrangements into RegData. This replaces the previous outsourcing register with a more comprehensive and granular MTP register, particularly in the context of the data points required for supply chain mapping, operational resilience, due diligence/risk management, and governance.
  • Incremental Materiality Criteria: Firms will need to re-evaluate their materiality assessment criteria proportionately. There is a refreshed emphasis on data sensitivity, privileged systems access, operational resilience, and internal governance indicators.

Defining a Third-Party Arrangement

As mentioned, a key feature of the new regime is the breadth of its definition. Both the PRA and FCA define a third-party arrangement broadly as any arrangement under which another person provides a product or service to the firm. This applies regardless of whether the product or service:

  • Would otherwise be provided by the firm itself.
  • Is provided directly or through a sub-contractor.
  • Is provided by an entity within the same group.

This matters because the new regime is not limited to traditional outsourcing. Material outsourcing remains a subset of material third-party arrangements, but firms are now expected to consider a wider range of non-outsourcing services where disruption could still create significant operational, prudential or consumer harm. In practice, that means arrangements involving technology platforms, data services or other externally provided capabilities may need to be assessed more carefully than before.

Regulators have also clarified that some services are generally not expected to be material, such as basic utilities, certain data purchases, and support services without privileged access (e.g., general consultancy or legal services).

What are the key additions to the materiality criteria?

Under the FCA approach, a third-party arrangement is deemed material if its disruption or failure could:

  • Cause intolerable harm to clients.
  • Pose a risk to the soundness, stability, resilience, confidence, or integrity of the UK financial system.
  • Cast serious doubt on the firm’s ability to meet the threshold conditions or comply with the Principles or SYSC 15A (Operational Resilience).

FCA FG26/4 also outlines additional factors for materiality, such as direct connections to the firm’s performance of regulated and ancillary activities, data reporting services, and collective portfolio management.

The PRA’s March 2026 update largely maintains existing materiality criteria but adds emphasis in areas where firms may need to revisit the classifications. The template now requires a "reason for materiality" with a list of options, which firms should embed into their assessment processes for consistency. Notably, there is a sharper focus on data sensitivity, privileged systems access, operational resilience, and the level of internal governance as key materiality indicators.

What are the challenges with the new materiality criteria under PRA SS2/21?

A common challenge for firms is the potential blurring of risk and materiality. Materiality and risk should be independent but complementary concepts, and firms should consider the links between the two, but it is important that both of these elements are independently assessed, where the former focuses more on its dependency and impact of failure if the service were to be impaired/unavailable and the latter focuses more on the inherent risk of the service. Determining a third-party relationship as “material” solely because of the transferring of confidential data would likely increase the number of top tier/material relationships, thereby undermining proportionality, a core principle of the regulatory framework. Careful consideration of the impact associated with data sharing is required to determine materiality, avoiding an unnecessary increase in reported material arrangements. There should be an objective to reduce the risk of a service but not necessarily its materiality, so blurring these concepts impacts the ability to evidence risk imitation and provide oversight at board level and below.

Both materiality and Important Business Services (IBS) assessments focus on impact. Crucially, any third-party service deemed important (i.e., vital for an IBS) will always be material. However, the reverse is not true: not all material TPs will be classified as important, as some may relate primarily to internal obligations like regulated activities or portfolio management. The PRA also expects firms to classify an arrangement as material if the timely delivery of the third-party service is fundamental to the firm delivering an Important Business Service (IBS) within its impact tolerance. Firms should already be mapping third-party dependencies to IBSs, testing failure scenarios, and maintaining continuity, substitution, and exit options for material third-party relationships. Where a contractual arrangement supports an IBS, the template mandates population of the impact tolerance in hours based on different regulatory scenarios (e.g., PRA safety and soundness, PRA financial stability, FCA client harm).

The incorporation of the "level of internal governance" as a materiality indicator is particularly noteworthy. This refers to the governance required before entering into a proposed arrangement or making significant changes to it, such as requiring senior management or board attention, enhanced due diligence, intensive monitoring, or specific continuity planning. This could prove challenging for firms, as their TPRM frameworks typically determine materiality upfront to inform the subsequent level of due diligence and approvals, rather than the other way around, potentially proving impractical for many organisations.

Firms are also expected under the latest PRA SS2/21 to revisit materiality when an arrangement changes meaningfully. Triggers include significant changes in scope, data handling, location, ownership, financial standing, or sub-outsourcing structure. Materiality should not be a static, one-off assessment. Instead it should be revisited periodically and as the service evolves. With the underlying risk profile influencing the Materiality assessment, it will make the outcome more susceptible to change.

The Annual Register: More Than Administration

In-scope firms must maintain and annually submit a register of their material third-party arrangements. Under the FCA process, firms will be notified when the submission window opens and will have 90 calendar days to file. This is not merely a record-keeping exercise; it provides supervisors with a structured view of firms' reliance on external providers, how those dependencies are organised, and where sector-wide concentration may be building.

The Register collects data across several groups5:

  • Primary data on regulated firms.
  • Primary data on third parties, including intra-group arrangements.
  • Function Category: Data on types of products or services performed by a third-party.
  • Data on products and/or services used.
  • Information on the supply chain (including a ranking of third-party providers for each service based on the firm’s tiering in the supply chain).
  • Data on assessments (including information on firms’ due diligence conducted, details on risk assessments, recent audits etc.).

This approach, as noted in the Policy Statement, is designed to align with DORA principles as much as possible. For firms already navigating the intricacies of DORA, particularly those maintaining a Register of Information (ROI) on ICT Third-Party Providers, there will be a degree of familiarity with the underlying principles of the UK MTP template. Both frameworks demand an understanding of third-party dependencies, their materiality/criticality, and potential impact on operational resilience. While DORA's ROI focuses specifically on ICT services and is primarily made available upon request, the UK MTP template extends to all material third-party arrangements and requires annual submission of a standardised dataset.

For firms not already required to submit the DORA ROI, one of the most significant new requirements will be the supply chain ranking. Given the lack of direct contractual relationships with fourth parties and beyond, achieving supply chain visibility has historically been challenging for financial services firms. Firms might explore supply chain visualisation tools or mandate greater transparency from their third parties to address this. The incremental data required in the template requires firms to identify the most critical elements of a supply chain, not every element, and will provide regulators with a clearer view of third-party dependencies throughout the ecosystem also informing designation of Critical Third Parties (CTPs) for oversight.

A key distinction lies in the MTP register's explicit focus on UK-specific regulatory compliance (FCA, PRA, FMI rules) and detailed impact tolerance metrics, alongside specific due diligence outcomes (financial, cyber risk) and governance approvals. In contrast, DORA provides a more granular framework for entity and group information, and a distinct separation of function identification from service types.

However, by identifying the common data points and shared objectives firms can develop a common, integrated approach to data collection and risk assessment. This strategic alignment can significantly streamline compliance efforts, avoiding duplication and fostering a more holistic view of third-party risk across both regulatory landscapes.

Notification Requirements: Earlier Regulatory Visibility

Firms will need to notify the relevant regulator(s) of their material third-party arrangements before entering into them, and when making significant changes to existing arrangements (excluding third-country branches, Non-Directive Firms, and credit unions with less than £50 million in total assets). The objective is to give regulators earlier visibility of changes that could affect firms’ risk profiles, not to create a formal approval process. However, there is no official view of specifically how early in the process a notification is required and from our experience, this significantly varies in approach taken across Financial Services organisations.

Intragroup Arrangements

Intragroup arrangements are treated distinctly within the new MTP regime. With the exception of ring-fenced bodies, an intragroup arrangement is only excluded from third-party notification and reporting requirements if it is provided without any dependency on an external third-party provider. This external provider, in effect, functions as a fourth party in the broader supply chain supporting the intragroup service, presenting the same visibility challenges discussed previously. This distinction makes it more critical than ever for firms to thoroughly understand the materiality of their intragroup arrangements and identify any underlying external dependencies within their supply chains, particularly for pass-through services.

What Should Firms Do Now?

For most firms, the immediate priority extends beyond simply preparing a template submission. These activities represent an opportunity to enhance operational resilience, improve risk management, and gain strategic insights into your third-party ecosystem, rather than just meeting a compliance deadline. Our view is that this requires a structured approach in four key areas:

1. Review and Re-evaluate existing Materiality Criteria:

  • Firms should consider whether any updates are required to their existing materiality methodology to reflect the new emphasis on data sensitivity, systems access, Important Business Services (IBS), and governance indicators, whilst maintaining proportionality.
  • Ensure there are clear triggers in the TPRM process for reassessment when arrangements change.

2. Reassess Third-Party Arrangements:

  • Where changes have been made to the materiality criteria or where the non-outsourcing portfolio has not been assessed for materiality (e.g., for solo FCA-regulated firms), reassess third-party arrangements to ensure appropriate materiality classification and completion of appropriate downstream activities.

Accurately classifying third-party arrangements ensures that oversight and due diligence efforts are proportionate to the actual risk and impact, thereby preventing the misallocation of resources and guaranteeing that truly material services receive the necessary attention. This classification also underpins the need for the development and testing of robust business continuity and exit plans, enabling firms to effectively manage severe but plausible disruptions by simulating and understanding their potential impact, thus enhancing preparedness for future events.

3. Perform a Gap Analysis for Data Points:

  • Conduct a gap analysis of the incremental data points and format required for the MTP template.
  • Assess whether the necessary data can be captured consistently across procurement, legal, risk, operational resilience, and supplier management processes. This is often the most challenging aspect of implementation.
  • A harmonised data model will be critical to ensure golden source datasets link to enterprise processes and services, providing accurate data fields for the register. Firms also submitting DORA ROIs or other templates must consider the differences and aim to transpose data into the required regulatory reporting format for ease of submission at different submission timeframes.

Establishing a harmonised data model and consistent data capture across functions is not just about reporting; it creates a single source of truth for third-party information. This significantly improves operational efficiency, enhances the accuracy of risk assessments, enables faster and more informed decision-making during incidents, and reduces the burden of redundant data collection for various regulatory submissions, ultimately saving time and resources. This is also a foundational activity for firms looking to explore the benefits of technology such as AI for TPRM activities.

4. Enhance Supply Chain Visualisation:

  • Develop the ability to visualise dependencies and interdependencies. This provides valuable insights for Board and Executive Committee levels that a simple register cannot. Comprehensive supply chain mapping helps identify single points of failure across the third-party portfolio, enterprise, and IBS delivery, highlighting concentration risk. This enables proactive planning and mitigation strategies for disruption.
  • Consider exploring supply chain visualisation tools and integrating AI to enhance understanding and mapping of the supply chain.

Moving beyond a static register to dynamic supply chain visualisation transforms risk management from a reactive to proactive activity. It provides a holistic view of your ecosystem, uncovering hidden vulnerabilities and interdependencies, identifying single points of failure and overreliance that could otherwise lead to significant operational disruptions. This strategic insight empowers leadership to make informed decisions about concentration, risk appetite, investment in resilience, and business continuity, safeguarding the firm's reputation and financial stability in the face of uncertainty.

For more information about how we can support you with our Third Party Resilience, Operational Resilience, or TPRM services, please reach out to the team.

References:

1. Third-Party Risk Management Guideline - Office of the Superintendent of Financial Institutions
2. The EBA launches consultation on its draft Guidelines on third-party risk management with regard to non-ICT related services | European Banking Authority
3. Consultation Paper on Proposed Guidelines on Third-Party Risk Management
4. PS7/26 – Operational resilience: Operational incident and third-party reporting | Bank of England
5. bankofengland.co.uk/-/media/boe/files/prudential-regulation/supervisory-statement/2026/ss221-march-2026-update.pdf