Invest1 distinct publisher3 min readPublished
The first critical third parties have been designated, putting technology, data and operations suppliers under direct UK supervision. Firm-level responsibility does not move an inch.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Take the two percentages the supervisors put in the same paragraph and multiply them. If 27% of incidents firms reported to the FCA in 2025 were attributed to a third party [5], and 37% of those were cyber-related [6], then roughly one in ten reported incidents was a cyber failure that occurred somewhere other than the reporting firm [7]. That is the number the regime is built on: not a catastrophe, but a steady tithe of outages that a firm's own controls could not have prevented because the failure was not on its premises.
The supervisory logic follows from concentration rather than severity. The post says banks, insurers, payment firms and FMIs increasingly depend on a relatively small number of common providers, among them cloud providers, technology firms and data providers [4], and that oversight is aimed at system-level risk where many firms rely on the same service, plus coordination and information-sharing during major incidents [3]. Designation is what converts a line in a supplier register into a counterparty the Bank of England, PRA and FCA oversee directly and jointly [2], under powers the government granted for this purpose [1].
What the designated providers owe is specified: identify and manage the risks in the critical services they supply, test and improve their resilience arrangements, and engage openly with regulators and firms during incidents [10]. What clients get is described more softly, as better visibility of risk and better communication when something large breaks [16], delivered partly through joint testing exercises and the sharing of self-assessments where appropriate [11].
Read the caveats as carefully as the powers. The regulators state plainly that the regime does not replace firms' responsibility for their own operational resilience and third party arrangements, and does not extend to every provider a firm uses [12]; the existing firm-level rules stand and are complemented, not superseded [14]; and the regime cannot and will not end all disruptions [13]. A firm whose critical vendor is now supervised has gained an information channel and lost no accountability.
One practical gap sits in the source itself: it does not name the designated providers or say how many were designated [15]. Until that list is in hand, nobody can reconcile it against a supplier register, which is the only exercise that tells an operator whether this regime touches them at all. It is also worth noticing where the contagion evidence comes from. The examples offered are the 2024 CrowdStrike outage, which hit organisations worldwide [8], and cyber incidents at Marks & Spencer and Jaguar Land Rover [9] - retailers and a carmaker, cited to a financial services audience. The regulators are arguing from other people's outages because the shared-dependency failure they are supervising against has mostly happened elsewhere so far.
Ranked by verification strength, evidence, and original report placement.
The government granted the Bank of England, PRA and FCA powers to implement a new oversight regime, and has now designated the first critical third parties (CTPs).
The Bank of England, PRA and FCA will together directly oversee the designated providers, with a targeted, proportionate focus on ensuring the services they provide to UK financial firms and financial market infrastructures are resilient.
The oversight aims to address system level risks, where many firms rely on the same services from common service providers, and to improve coordination and information-sharing across the sector, particularly during major incidents.
Banks, insurers, payment firms and FMIs increasingly rely on a relatively small number of common third party service providers, which may be cloud providers, technology firms, data providers or other specialist service providers.
In 2025, 27% of incidents reported to the FCA by firms were attributed to a third party issue.
37% of those third-party-attributed incidents reported to the FCA in 2025 were cyber-related.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-party regulator statement, no independent corroboration
The regime's existence, scope and obligations come directly from the authorities implementing it, which is authoritative for what the rules are, and the post carries specific first-party incident statistics. But the cluster holds a single item from a single publisher republishing that post, the designated providers are neither named nor counted, and no independent reporting, provider response or supervisory documentation is present to test the claims.
Regime in force, implementation depth unobserved
Adoption is real at the regulatory layer: powers are granted, the first designations have been made and the regime is described as live, which is a binding change of status for the designated providers. What is not observed is depth, no provider count, no named designations, no completed joint testing exercise, no self-assessments shared and no firm-side implementation evidence, so measured adoption stays below the midpoint.
Measured regulator framing, key specifics withheld
The source actively suppresses overclaim: it says the regime cannot and will not end all disruptions, that it does not replace firm responsibilities and that it does not regulate every provider. That pulls the gap toward zero. A small positive residue remains because a milestone framed as system-strengthening is announced without disclosing which providers were designated or how many, leaving readers unable to size the change against the concentration risk described.
Regulator self-presentation republished without scrutiny
The only cluster item is a regulator communications post carried verbatim by a trade publication. The authoring institutions have a direct interest in presenting newly granted oversight powers as necessary and proportionate, and the supporting statistics and incident examples are selected by the same parties. No adversarial or provider-side voice appears, so incentive alignment between author and message is high.
Facts reliable, consequences unresolved
Confidence is moderate. What the regime says and requires is high-reliability information because it comes from the bodies that wrote it, and the arithmetic derivation from the disclosed percentages is straightforward. Confidence is held down by single-source, single-publisher coverage, undisclosed designations, and the absence of any evidence about how oversight will operate in practice or what it will cost firms and providers.
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
invest
The bond selloff the Fed cannot fix: $90 Brent, sovereign supply, AI capex1 distinct publisher
invest
Central banks concede the CBDC answer, and the stablecoin fight moves to issuers1 distinct publisher
invest
Nvidia's Perplexity talks move its money one layer further from its own chips1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026