top of page

Third Party Risk Management in Financial Services: What Good Looks Like Now

  • Writer: i-confidential
    i-confidential
  • 1 day ago
  • 3 min read

Third party risk management has become an increasingly important part of how financial services organisations manage operational resilience, regulatory obligations and business risk.


As organisations become more dependent on technology providers, outsourced services and complex supply chains, understanding third-party exposure requires more than maintaining a supplier register or completing periodic questionnaires.


The key question is:


Do you understand which third parties matter most, where your greatest dependencies sit and whether your approach provides sufficient confidence?

With new reporting requirements taking effect from 18 March 2027, this is becoming an increasingly important consideration for UK financial services firms.


Why is the traditional approach to third-party risk no longer enough?


Many organisations have established supplier due diligence and assurance programmes. These remain important, but they do not always provide a complete picture of risk.


Supplier populations can run into thousands, making the same level of assessment for every relationship impractical. At the same time, the most consequential dependencies are not necessarily those with the largest contracts.


A technology provider supporting an important business service may represent considerably more risk than a higher value supplier with limited operational impact.


Risk can also sit further down the supply chain, through fourth and fifth party relationships that are not always visible through traditional TPRM processes.

This means organisations need to focus increasingly on business consequence, dependency and resilience.


third party risk consultancy

What is changing in third party risk regulation?


Several regulatory developments are strengthening the focus on third-party risk.


Operational resilience: FCA PS21/3 and PRA SS1/21 require firms to identify important business services, establish impact tolerances and understand the resources and dependencies supporting those services. Third parties form part of this dependency mapping.

Critical third parties: The critical third parties regime took effect on 1 January 2025, giving regulators direct oversight of providers whose failure could affect UK financial stability. Importantly, designation does not remove the financial firm's responsibility for managing its own third-party dependencies.

Third-party reporting: FCA PS26/2 and PRA PS7/26 establish coordinated reporting requirements. From 18 March 2027, in-scope firms will need to notify regulators about material third-party arrangements and maintain an annual register.


Firms with EU operations may also need to consider DORA. Where multiple regimes apply, a common underlying data set can provide a more effective approach than separate processes.


How should organisations identify their most important third parties?


A strong starting point is mapping suppliers to important business services.

This provides greater insight than relying solely on contract value or spend and creates a foundation for:

    

  • Supplier segmentation

  • Risk assessment

  • Assurance

  • Concentration analysis

  • Operational resilience

  • Regulatory reporting

  • Exit planning


Third parties can then be assessed according to factors such as criticality, concentration, substitutability, data and access.


The objective is a proportionate approach that directs the greatest level of attention towards the relationships that could have the greatest impact.


What should effective third party assurance look like?


Not every supplier requires the same level of scrutiny.

For lower risk relationships, questionnaires supported by relevant independent certifications may provide proportionate assurance.


For higher risk relationships, organisations may need stronger evidence, including:

  • Control testing

  • Independent assurance reports

  • Penetration testing results

  • Incident history

  • Remediation evidence

  • On-site assessment where appropriate


The focus should be on establishing whether controls operate effectively, rather than simply documenting what a supplier says it has in place.


Are contracts, exit plans and testing sufficient?


Effective TPRM should support resilience as well as oversight.

Contracts should contain practical audit and notification provisions. Exit plans should identify realistic alternatives, data requirements, timescales and costs.

Organisations should also test scenarios involving third-party failure and consider whether important business services could remain within their impact tolerances.


How can i-confidential help?


i-confidential helps financial services organisations assess and strengthen their Third Party Risk Management capability.

Our approach considers supplier risk, dependency mapping, governance, assurance and operational resilience to identify gaps and establish practical priorities for improvement.

The objective is not simply to produce another assessment. It is to give organisations a clearer understanding of where third-party risk sits, what needs to improve and how capability can be strengthened.

If you want to understand where your TPRM capability stands ahead of the March 2027 reporting requirements, contact i-confidential to discuss how we can help.


Frequently Asked Questions


What is a critical third party?

A critical third party is a provider designated by HM Treasury because disruption to its services could threaten the stability or confidence of the UK financial system.


How should financial services firms assess third party risk?

Organisations should take a proportionate approach based on criticality, concentration, substitutability, data and access, while mapping suppliers to important business services.


What is the difference between TPRM and supply chain security?

TPRM covers the broader risks associated with third-party relationships, including operational, financial, regulatory and security risks. Supply chain security is a specific component of this wider discipline.

 
 
bottom of page