FCA tells third parties to ‘test and improve’

Mark Francis detailed FCA's digital resilience policy this week

Britain’s Financial Conduct Authority is intensifying its scrutiny of the technology providers underpinning UK financial services, as regulators move from supervising operational resilience institution by institution to testing risks across the wider financial system.

With banks, insurers, payment companies and financial market infrastructures increasingly dependent on a small group of cloud, data and technology providers, the FCA, Bank of England and Prudential Regulation Authority have begun directly overseeing the UK’s first designated critical third parties.

The new regime places testing, incident coordination and evidence-sharing at the centre of regulatory oversight.

Critical third parties will be expected to identify risks affecting their services, test their resilience arrangements and demonstrate how they can contain and recover from disruption.

The development extends the testing perimeter well beyond the bank itself. Firms must now understand whether critical services can withstand disruption across shared infrastructure, while also testing their own ability to detect, escalate and report failures originating elsewhere in the supply chain.

“Digital resilience is being tested like never before, with firms facing growing online threats and increasing reliance on third parties to deliver the essential financial services consumers rely on,” wrote Mark Francis, director at the FCA, in a blog post this week.

Testing ‘the system’

Operational resilience regulation has traditionally focused on whether individual institutions can prevent, respond to and recover from disruption. That remains important, but the FCA believes it no longer reflects the full concentration of risk within financial services technology.

Banks and other regulated firms increasingly depend on common providers for cloud infrastructure, data, software and operational services. These arrangements can support innovation and efficiency, but they also create the possibility that a single failure affects numerous institutions simultaneously.

“Operational resilience can’t solely be about understanding risks within individual firms,” Francis stressed. “It is also about understanding how disruption at commonly used critical service providers could affect the wider system.”

The scale of the issue is becoming clearer through regulatory reporting. In 2025, 27% of incidents reported to the FCA were attributed to third-party issues, with 37% of those incidents classified as cyber-related.


“Digital resilience is being tested like never before.”

– Mark Francis

Recent large-scale technology and cyber incidents have demonstrated how disruption can spread between otherwise unrelated organisations. The 2024 CrowdStrike outage affected businesses worldwide, while incidents involving Marks & Spencer and Jaguar Land Rover illustrated the operational consequences of interconnected technology environments.

“These incidents starkly illustrate how operational disruption at one provider can affect many organisations simultaneously, including financial services,” Francis explained.

The critical third-party regime is intended to add a system-wide layer of supervision without removing the responsibility of regulated firms to manage their own outsourcing arrangements and technology dependencies.

“Put simply, it’s about making sure our oversight reflects the way the system actually works today,” Francis declared.

Joint testing

One of the most important elements of the regime is its emphasis on practical testing between regulated institutions and their technology providers.

“For critical third parties, the expectations are clear,” Francis pointed out. “They must identify and manage risks relating to the critical services they provide.”

He added: “They need to test and improve their resilience arrangements, and engage openly with regulators and firms, especially during incidents.”

The regime is expected to promote joint testing exercises, greater transparency and the sharing of resilience self-assessments. This could give firms more evidence about the controls protecting services outside their direct technology estates.

Joint exercises will also test whether information flows effectively during widespread incidents. When several banks or financial institutions are affected by the same underlying failure, regulators want providers and their clients to communicate quickly enough to support coordinated recovery.

“For firms, the regime should support better visibility of risks and improved communication during major incidents,” Francis continued.

“When many firms are affected by the same disruption, timely information and effective coordination become even more important.”

This makes testing about more than the technical availability of an outsourced platform. Firms may need to verify that alerts reach the right teams, dependencies can be mapped during an incident, severity is classified consistently and recovery information can be shared without delay.

The framework will not prevent every outage. Its purpose is to reduce the risk that disruption spreads unnecessarily across multiple institutions and essential financial services.

“This regime can’t and won’t end all disruptions,” Francis acknowledged. “But it is designed to make a practical difference, particularly when disruption occurs.”

Incident reporting

The CTP regime forms part of a wider FCA effort to improve its visibility into operational disruption and shared technology dependencies.

In March, the regulator introduced an incident and third-party reporting framework designed to standardise how firms identify, classify and notify the FCA about operational events. The rules demand earlier notification, clearer categorisation and more consistent follow-up reporting as incidents develop.

“These changes give firms clearer rules and practical guidance to better manage disruption, while supporting our ambition to be a smarter regulator, giving us better data to spot risks, share insights and strengthen sector wide resilience,” Francis said at the time.

For testing teams, incident reporting can no longer be treated as a process that begins only after production systems fail. Detection, classification, escalation and regulatory notification must themselves be tested under realistic conditions.


“Third parties should engage openly with regulators, including through testing.”

– Mark Francis

Firms need to establish whether monitoring tools can identify disruption across outsourced environments, whether alerts trigger at appropriate thresholds and whether reporting pipelines remain available during a serious operational event.

“Over time we will use this data to share insights and trends to help firms bolster their operational resilience and share relevant information with industry, where appropriate during widespread disruption, particularly in stressed market conditions,” Francis explained.

The resulting data should also help regulators examine interconnected supply chains and identify services whose failure could create wider instability.

“And where disruption occurs at a third party, the data will help us see through firms’ supply chains to identify which services are the most exposed and help us identify potential critical third parties to the UK financial system,” Francis added.

AI assurance

The emphasis on demonstrable resilience mirrors the FCA’s evolving approach to artificial intelligence. Through its AI Input Zone and AI Live Testing programme, the regulator is encouraging firms to produce practical evidence showing how AI behaves in real financial services environments.

The FCA has sought examples of good and poor practice covering governance, resilience, deployment controls, oversight, assurance and consumer outcomes.

Colin Payne, head of Innovation at the regulator, distilled that demand into a particularly direct message: “Not theory. Evidence.”

Colin Payne

The same principle applies to critical third-party assurance. Firms cannot rely exclusively on contracts, policy documents or untested recovery plans. They need evidence that controls, communication channels and recovery processes function under stress.

The FCA’s AI Live Testing programme has already brought organisations including Barclays, UBS, Lloyds Banking Group and Experian into supervised testing.

Its scope encompasses agentic AI, small language models and other emerging approaches used in areas such as payments, credit scoring, anti-money laundering and Know Your Customer processes.

That programme defines an AI system more broadly than its underlying model. Deployment context, governance, human oversight, evaluation techniques and input and output controls are all brought within the assurance perimeter.

When these systems depend on cloud platforms, external datasets or specialist technology vendors, AI assurance and critical third-party testing begin to overlap.

A bank may be able to demonstrate that a model performs correctly in isolation, but still needs to prove that the complete service can remain controlled when an external component fails or behaves unexpectedly.

The FCA’s regulatory direction therefore points towards full-system testing: validating the institution, the AI application, its third-party dependencies and the operational processes surrounding it.

Shared testing mission

The launch of direct CTP oversight reinforces the growing regulatory expectation that operational resilience must be continuously exercised rather than periodically documented.

“As the regime is now live, firms should continue to consider how they identify, test and manage dependencies on critical services,” Francis said.

“Designated CTPs should engage openly with regulators and firms, including through testing and information-sharing.”

That means mapping critical services to third-party components, incorporating supplier failures into resilience scenarios and testing how technical and regulatory processes operate together during disruption.

It also elevates the role of quality engineering. Test results, incident exercises, control evidence and recovery measurements are increasingly becoming regulatory artefacts that demonstrate whether firms genuinely understand their operational dependencies.

“No framework can eliminate operational incidents entirely,” Francis concluded. “But strengthening resilience across the wider system that supports financial services can help reduce the likelihood that disruption escalates or spreads unnecessarily.”

The FCA’s position is increasingly clear: resilience cannot be established by testing one firm, platform or model at a time. In an interconnected financial system, the supply chain itself has become part of the test environment.


THIS SEPTEMBER IN LONDON

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


READ MORE


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS