HeadlinesBriefing favicon HeadlinesBriefing.com

UK, EU Strengthen Oversight of Critical Third Parties

All News •
×

UK regulators, including the Financial Conduct Authority (FCA), Bank of England, and Prudential Regulation Authority, have signed a Memorandum of Understanding (MoU) with European Supervisory Authorities to enhance cooperation on critical third party (CTP) oversight. This agreement establishes a framework for coordinating and sharing information about CTPs under the UK regime and critical third party providers (CTPPs) under the EU’s Digital Operational Resilience Act (DORA).

The MoU aims to reduce regulatory duplication and burden on service providers while managing potential risks to financial stability and market confidence. It underscores the UK regulators’ commitment to cross-border cooperation and strengthening operational resilience. The UK’s CTP regime, introduced in 2024, complements similar international standards and is designed to be compatible with the EU’s DORA framework.

Under the new regulations, designated CTPs will be required to provide regular assurance, undertake resilience testing, and report major incidents. The Treasury is responsible for deciding which third-party service providers fall under the new CTP regime, and the designation process has already begun. This move ensures that financial firms and Financial Market Infrastructures remain responsible for managing their own operational resilience and third-party risks in accordance with existing outsourcing rules.

This enhanced oversight is a response to growing concerns about potential disruptions from third-party service providers, such as power outages or cyber-attacks. By working together, UK and EU regulators aim to create a more robust system for managing risks and maintaining financial stability in an increasingly interconnected global market.