The UK financial regulators (the Financial Conduct Authority, the Bank of England, and the Prudential Regulation Authority) have jointly published a policy statement which provides clarity on how they will regulate the resilience of technology and other third parties providing key services to financial firms.
The new rules, set out in the document ‘PS24/16: Operational resilience: Critical third parties to the UK financial sector’, align closely with international standards and similar regimes, such as the EU’s Digital Operational Resilience Act (DORA).
The final rules and policy will come into effect on 1 January 2025 and the UK Government (HM Treasury) will determine which third parties will fall under the new regime, based on advice from the regulators.
Critical third parties once designated will not be overseen in their entirety by the regulators, but the third-party services they specifically provide to the financial services sector will be overseen.
Amongst other things, the final rules will require designated critical third parties to:
- Provide regular assurance, information, and notifications to the financial regulators on their services,
- Undertake various forms of resilience testing and scenario-based exercises,
- Report major incidents.
More information






