InvestNot yet confirmed elsewhere1 publisher3 min readPublished
Designation day: your cloud vendor now answers to three regulators, and you still answer for it
The first critical third parties have been designated, putting technology, data and operations suppliers under direct UK supervision. Firm-level responsibility does not move an inch.
The Investor · Invest desk

What happened
- The government's new oversight regime is live and the first critical third parties have been formally designated.
- The Bank of England, PRA and FCA will supervise those providers jointly and directly, covering the services they sell to UK firms and market infrastructures.
- The regulators say the regime neither replaces firms' own resilience duties nor extends to every supplier a firm uses.
Why it matters
- exposure A concentrated dependency is no longer a private entry in an outsourcing file: three authorities are now looking at the same provider from the other side, and can see how many of their firms sit...
- constraint Supervision of the vendor buys a firm no relief from its own obligations, so resilience work now has to be done twice over: once inside the firm and once in coordination with a supervised supplier.
- decision Vendor selection acquires a question it did not have, because a designated provider comes with joint testing and shareable self-assessments that an undesignated one does not.
- cost Joint exercises and self-assessment sharing consume engineering and risk hours on both sides of the contract, and the post is silent on who funds them.
Take the two percentages the supervisors put in the same paragraph and multiply them. If 27% of incidents firms reported to the FCA in 2025 were attributed to a third party [5], and 37% of those were cyber-related [6], then roughly one in ten reported incidents was a cyber failure that occurred somewhere other than the reporting firm [16]. That is the number the regime is built on: not a catastrophe, but a steady tithe of outages that a firm's own controls could not have prevented because the failure was not on its premises.
The supervisory logic follows from concentration rather than severity. The post says banks, insurers, payment firms and FMIs increasingly depend on a relatively small number of common providers, among them cloud providers, technology firms and data providers [4], and that oversight is aimed at system-level risk where many firms rely on the same service, plus coordination and information-sharing during major incidents [3]. Designation is what converts a line in a supplier register into a counterparty the Bank of England, PRA and FCA oversee directly and jointly [2], under powers the government granted for this purpose [1].
What the designated providers owe is specified: identify and manage the risks in the critical services they supply, test and improve their resilience arrangements, and engage openly with regulators and firms during incidents [9]. What clients get is described more softly, as better visibility of risk and better communication when something large breaks [15], delivered partly through joint testing exercises and the sharing of self-assessments where appropriate [10].
Read the caveats as carefully as the powers. The regulators state plainly that the regime does not replace firms' responsibility for their own operational resilience and third party arrangements, and does not extend to every provider a firm uses [11]; the existing firm-level rules stand and are complemented, not superseded [13]; and the regime cannot and will not end all disruptions [12]. A firm whose critical vendor is now supervised has gained an information channel and lost no accountability.
One practical gap sits in the source itself: it does not name the designated providers or say how many were designated [14]. Until that list is in hand, nobody can reconcile it against a supplier register, which is the only exercise that tells an operator whether this regime touches them at all. It is also worth noticing where the contagion evidence comes from. The examples offered are the 2024 CrowdStrike outage, which hit organisations worldwide [7], and cyber incidents at Marks & Spencer and Jaguar Land Rover [8] - retailers and a carmaker, cited to a financial services audience. The regulators are arguing from other people's outages because the shared-dependency failure they are supervising against has mostly happened elsewhere so far.
What to watch
- Publication of the designated cohort by name, which is what lets a firm reconcile the list against its own supplier register.
- Whether the FCA's next incident data moves the third-party share off 27%, and the cyber share off 37% of that.
- The first joint testing exercise between a designated provider and its UK clients: scope, who runs it, and who absorbs the cost.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption47
- Hype gap+6
- Incentives66
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The government granted the Bank of England, PRA and FCA powers to implement a new oversight regime, and has now designated the first critical third parties (CTPs).
ReportedSupportedSource: Post written in the voice of the Bank of England, PRA and FCA, published by Crowdfund InsiderView cited source - [2]
The Bank of England, PRA and FCA will together directly oversee the designated providers, with a targeted, proportionate focus on ensuring the services they provide to UK financial firms and financial market infrastructures are resilient.
- [3]
The oversight aims to address system level risks, where many firms rely on the same services from common service providers, and to improve coordination and information-sharing across the sector, particularly during major incidents.
- [4]
Banks, insurers, payment firms and FMIs increasingly rely on a relatively small number of common third party service providers, which may be cloud providers, technology firms, data providers or other specialist service providers.
- [5]
In 2025, 27% of incidents reported to the FCA by firms were attributed to a third party issue.
- [6]
37% of those third-party-attributed incidents reported to the FCA in 2025 were cyber-related.
- [7]
The CrowdStrike outage in 2024 affected a wide range of organisations around the world.
- [8]
Cyber incidents affecting retailers such as Marks & Spencer and Jaguar Land Rover showed how disruption can quickly extend beyond a single organisation.
- [9]
Critical third parties must identify and manage risks relating to the critical services they provide, test and improve their resilience arrangements, and engage openly with regulators and firms, especially during incidents.
- [10]
The regime aims to promote greater transparency and stronger communication between critical third parties and their UK financial services clients, including through joint testing exercises and the sharing of self-assessments where appropriate.
- [11]
The regulators state the regime is not about replacing firms' responsibilities for managing their own operational resilience and third party arrangements, nor about regulating every third party provider that firms use.
- [12]
The regulators state the regime cannot and will not end all disruptions, but is designed to make a practical difference particularly when disruption occurs.
- [13]
The regime complements the existing rules in place for regulated firms to manage the risks they individually face.
- [14]
The published post does not name the designated critical third parties and does not state how many were designated.
- [15]
For firms, the regime should support better visibility of risks and improved communication during major incidents.
- [16]
Roughly 10% of all incidents firms reported to the FCA in 2025 were third-party incidents that were cyber-related.
Sources
1 independent publisher whose own reporting we read for this story.
- crowdfundinsider.comStrengthening resilience across an increasingly interconnected financial system
1 article · August 25, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- Financial Conduct AuthorityFollow
- Bank of EnglandFollow
- Prudential Regulation AuthorityFollow
- Critical Third Parties (CTP) RegimeFollow
- CrowdStrikeFollow
- Marks & SpencerFollow
- Jaguar Land RoverFollow
- Crowdfund InsiderFollow