The UK regulators have introduced a new reporting regime for material third-party arrangements, with the aim of giving supervisors greater oversight over the external services that support firms’ operations.
The regulatory focus is shifting from "material outsourcing" to a more expansive view of significant risks and materiality across all third-party relationships, encompassing technology, data, and other service dependencies. This new framework is designed to provide a more integrated perspective on concentration and systemic risks within the sector, reflecting international standards like the Financial Stability Board toolkit, the Basel Committee on Banking Supervision principles, and the EU’s Digital Operational Resilience Act (DORA).
Many financial services firms have already broadened their view of third-party risk, in line with current PRA SS2/21 requirements to assess non-outsourcing populations. This trend is reinforced by global regulatory developments, including the OFSI Third-Party Risk Management Guideline1, EBA Consultation Paper2 being updated to cover non-ICT outsourcing and non-outsourcing (given DORA's comprehensive coverage of the ICT third-party supply chain), and the Monetary Authority of Singapore (MAS) also expanding its scope beyond traditional outsourcing in its March 2026 Consultation Paper3. Therefore, for firms regulated by the PRA the requirement to assess materiality and perform due diligence on non-outsourcing relationships is not new, however, the main implications are:
The new reporting regime introduces several critical changes, expanding the scope of reportable third-party arrangements and standardising how firms notify regulators and maintain internal records.
As mentioned, a key feature of the new regime is the breadth of its definition. Both the PRA and FCA define a third-party arrangement broadly as any arrangement under which another person provides a product or service to the firm. This applies regardless of whether the product or service:
This matters because the new regime is not limited to traditional outsourcing. Material outsourcing remains a subset of material third-party arrangements, but firms are now expected to consider a wider range of non-outsourcing services where disruption could still create significant operational, prudential or consumer harm. In practice, that means arrangements involving technology platforms, data services or other externally provided capabilities may need to be assessed more carefully than before.
Regulators have also clarified that some services are generally not expected to be material, such as basic utilities, certain data purchases, and support services without privileged access (e.g., general consultancy or legal services).
Under the FCA approach, a third-party arrangement is deemed material if its disruption or failure could:
FCA FG26/4 also outlines additional factors for materiality, such as direct connections to the firm’s performance of regulated and ancillary activities, data reporting services, and collective portfolio management.
The PRA’s March 2026 update largely maintains existing materiality criteria but adds emphasis in areas where firms may need to revisit the classifications. The template now requires a "reason for materiality" with a list of options, which firms should embed into their assessment processes for consistency. Notably, there is a sharper focus on data sensitivity, privileged systems access, operational resilience, and the level of internal governance as key materiality indicators.
A common challenge for firms is the potential blurring of risk and materiality. Materiality and risk should be independent but complementary concepts, and firms should consider the links between the two, but it is important that both of these elements are independently assessed, where the former focuses more on its dependency and impact of failure if the service were to be impaired/unavailable and the latter focuses more on the inherent risk of the service. Determining a third-party relationship as “material” solely because of the transferring of confidential data would likely increase the number of top tier/material relationships, thereby undermining proportionality, a core principle of the regulatory framework. Careful consideration of the impact associated with data sharing is required to determine materiality, avoiding an unnecessary increase in reported material arrangements. There should be an objective to reduce the risk of a service but not necessarily its materiality, so blurring these concepts impacts the ability to evidence risk imitation and provide oversight at board level and below.
Both materiality and Important Business Services (IBS) assessments focus on impact. Crucially, any third-party service deemed important (i.e., vital for an IBS) will always be material. However, the reverse is not true: not all material TPs will be classified as important, as some may relate primarily to internal obligations like regulated activities or portfolio management. The PRA also expects firms to classify an arrangement as material if the timely delivery of the third-party service is fundamental to the firm delivering an Important Business Service (IBS) within its impact tolerance. Firms should already be mapping third-party dependencies to IBSs, testing failure scenarios, and maintaining continuity, substitution, and exit options for material third-party relationships. Where a contractual arrangement supports an IBS, the template mandates population of the impact tolerance in hours based on different regulatory scenarios (e.g., PRA safety and soundness, PRA financial stability, FCA client harm).
The incorporation of the "level of internal governance" as a materiality indicator is particularly noteworthy. This refers to the governance required before entering into a proposed arrangement or making significant changes to it, such as requiring senior management or board attention, enhanced due diligence, intensive monitoring, or specific continuity planning. This could prove challenging for firms, as their TPRM frameworks typically determine materiality upfront to inform the subsequent level of due diligence and approvals, rather than the other way around, potentially proving impractical for many organisations.
Firms are also expected under the latest PRA SS2/21 to revisit materiality when an arrangement changes meaningfully. Triggers include significant changes in scope, data handling, location, ownership, financial standing, or sub-outsourcing structure. Materiality should not be a static, one-off assessment. Instead it should be revisited periodically and as the service evolves. With the underlying risk profile influencing the Materiality assessment, it will make the outcome more susceptible to change.
In-scope firms must maintain and annually submit a register of their material third-party arrangements. Under the FCA process, firms will be notified when the submission window opens and will have 90 calendar days to file. This is not merely a record-keeping exercise; it provides supervisors with a structured view of firms' reliance on external providers, how those dependencies are organised, and where sector-wide concentration may be building.
The Register collects data across several groups5:
This approach, as noted in the Policy Statement, is designed to align with DORA principles as much as possible. For firms already navigating the intricacies of DORA, particularly those maintaining a Register of Information (ROI) on ICT Third-Party Providers, there will be a degree of familiarity with the underlying principles of the UK MTP template. Both frameworks demand an understanding of third-party dependencies, their materiality/criticality, and potential impact on operational resilience. While DORA's ROI focuses specifically on ICT services and is primarily made available upon request, the UK MTP template extends to all material third-party arrangements and requires annual submission of a standardised dataset.
For firms not already required to submit the DORA ROI, one of the most significant new requirements will be the supply chain ranking. Given the lack of direct contractual relationships with fourth parties and beyond, achieving supply chain visibility has historically been challenging for financial services firms. Firms might explore supply chain visualisation tools or mandate greater transparency from their third parties to address this. The incremental data required in the template requires firms to identify the most critical elements of a supply chain, not every element, and will provide regulators with a clearer view of third-party dependencies throughout the ecosystem also informing designation of Critical Third Parties (CTPs) for oversight.
A key distinction lies in the MTP register's explicit focus on UK-specific regulatory compliance (FCA, PRA, FMI rules) and detailed impact tolerance metrics, alongside specific due diligence outcomes (financial, cyber risk) and governance approvals. In contrast, DORA provides a more granular framework for entity and group information, and a distinct separation of function identification from service types.
However, by identifying the common data points and shared objectives firms can develop a common, integrated approach to data collection and risk assessment. This strategic alignment can significantly streamline compliance efforts, avoiding duplication and fostering a more holistic view of third-party risk across both regulatory landscapes.
Firms will need to notify the relevant regulator(s) of their material third-party arrangements before entering into them, and when making significant changes to existing arrangements (excluding third-country branches, Non-Directive Firms, and credit unions with less than £50 million in total assets). The objective is to give regulators earlier visibility of changes that could affect firms’ risk profiles, not to create a formal approval process. However, there is no official view of specifically how early in the process a notification is required and from our experience, this significantly varies in approach taken across Financial Services organisations.
Intragroup arrangements are treated distinctly within the new MTP regime. With the exception of ring-fenced bodies, an intragroup arrangement is only excluded from third-party notification and reporting requirements if it is provided without any dependency on an external third-party provider. This external provider, in effect, functions as a fourth party in the broader supply chain supporting the intragroup service, presenting the same visibility challenges discussed previously. This distinction makes it more critical than ever for firms to thoroughly understand the materiality of their intragroup arrangements and identify any underlying external dependencies within their supply chains, particularly for pass-through services.
For most firms, the immediate priority extends beyond simply preparing a template submission. These activities represent an opportunity to enhance operational resilience, improve risk management, and gain strategic insights into your third-party ecosystem, rather than just meeting a compliance deadline. Our view is that this requires a structured approach in four key areas:
1. Review and Re-evaluate existing Materiality Criteria:
2. Reassess Third-Party Arrangements:
Accurately classifying third-party arrangements ensures that oversight and due diligence efforts are proportionate to the actual risk and impact, thereby preventing the misallocation of resources and guaranteeing that truly material services receive the necessary attention. This classification also underpins the need for the development and testing of robust business continuity and exit plans, enabling firms to effectively manage severe but plausible disruptions by simulating and understanding their potential impact, thus enhancing preparedness for future events.
3. Perform a Gap Analysis for Data Points:
Establishing a harmonised data model and consistent data capture across functions is not just about reporting; it creates a single source of truth for third-party information. This significantly improves operational efficiency, enhances the accuracy of risk assessments, enables faster and more informed decision-making during incidents, and reduces the burden of redundant data collection for various regulatory submissions, ultimately saving time and resources. This is also a foundational activity for firms looking to explore the benefits of technology such as AI for TPRM activities.
4. Enhance Supply Chain Visualisation:
Moving beyond a static register to dynamic supply chain visualisation transforms risk management from a reactive to proactive activity. It provides a holistic view of your ecosystem, uncovering hidden vulnerabilities and interdependencies, identifying single points of failure and overreliance that could otherwise lead to significant operational disruptions. This strategic insight empowers leadership to make informed decisions about concentration, risk appetite, investment in resilience, and business continuity, safeguarding the firm's reputation and financial stability in the face of uncertainty.
For more information about how we can support you with our Third Party Resilience, Operational Resilience, or TPRM services, please reach out to the team.
References:
1. Third-Party Risk Management Guideline - Office of the Superintendent of Financial Institutions
2. The EBA launches consultation on its draft Guidelines on third-party risk management with regard to non-ICT related services | European Banking Authority
3. Consultation Paper on Proposed Guidelines on Third-Party Risk Management
4. PS7/26 – Operational resilience: Operational incident and third-party reporting | Bank of England
5. bankofengland.co.uk/-/media/boe/files/prudential-regulation/supervisory-statement/2026/ss221-march-2026-update.pdf