Summary
- The FCA says 27% of incidents reported by firms in 2025 were attributed to a third-party issue.
- Cyber was involved in 37% of those third-party incidents.
- The regulator is placing more weight on shared cloud, technology, data, and specialist service providers as system-wide dependencies.
The Financial Conduct Authority has said UK financial services resilience increasingly depends on common third-party providers, including cloud, technology, data, and specialist operational service firms.
In a new resilience note, the FCA said 27% of incidents reported by firms in 2025 were attributed to a third-party issue. Of those third-party incidents, 37% were cyber-related.
The figures put the UK’s critical third party regime into a practical operational frame. Banks, insurers, payment firms, and financial market infrastructure providers already have duties to manage their own operational resilience, outsourcing arrangements, and third-party risk. The additional concern is concentration: many firms rely on the same external providers for services that support payments, online banking, data processing, cloud infrastructure, software operations, and customer access.
The FCA and Prudential Regulation Authority now have direct oversight powers for designated critical third parties, alongside the Bank of England. Those powers are intended to address system-level risks where disruption at one provider could affect many firms at once. The regime does not replace firms’ existing responsibilities, but it adds a supervisory view of providers whose services sit beneath multiple regulated organisations.
The FCA pointed to recent events that showed how disruption can spread across sectors and organisations. It cited the global CrowdStrike outage in 2024, as well as cyber incidents affecting retailers including Marks & Spencer and Jaguar Land Rover, to show how operational disruption can move beyond one company.
Financial firms have long managed suppliers through contracts, service levels, assurance questionnaires, and exit plans. Those tools remain necessary, but they do not always reveal concentration risk. A provider may appear well controlled from the perspective of one firm while still representing a systemic dependency across many institutions.
Cyber incidents intensify that dependency. A supplier compromise can create confidentiality, integrity, availability, regulatory notification, and customer communication issues at the same time. If the supplier supports many firms, incident updates, forensic evidence, service restoration, and legal obligations can become crowded and difficult to coordinate.
The FCA’s data also gives regulators a clearer reason to demand better incident visibility. Individual reports may reveal isolated outages or breaches, while aggregated reporting can show a common provider, vulnerability, or operational dependency behind multiple events. That wider view is central to the critical third party regime.
Risk committees will need to treat shared supplier dependency as more than procurement oversight. Material service mapping, joint testing, recovery evidence, incident notification clauses, concentration analysis, privileged access controls, and exit planning all form part of resilience. Firms also need to know how they would operate during a supplier-led outage affecting multiple institutions at once.
The regime will not remove disruption from financial services. Its effect will be measured by whether firms, regulators, and designated third parties can communicate faster, test more realistically, and prevent supplier failures from spreading unnecessarily through services that households and businesses use every day.





