The PRA and FCA Rewrote the Third-Party Rules. Here’s What Changes Before March 2027.

5 minute read

September 2026

by Ed Thomas

When the Prudential Regulation Authority published PS7/26, most third-party risk teams filed it under “reporting requirements” and moved on. That was a mistake twice over. First, because the updated SS2/21 buried in its appendices changes what regulators expect firms to know about every material third party they rely on. And second, because the PRA didn’t act alone: the Financial Conduct Authority published its own matching rules, PS26/2, on the same day. Together they form a single framework that reaches well beyond the banks and insurers who usually pay attention to supervisory statements. The rules take effect on 18 March 2027.

What changed

The original SS2/21, published in 2021, set the PRA’s expectations for outsourcing and third-party risk management. Its centre of gravity was outsourcing: banks were expected to keep a register of outsourcing arrangements and apply heightened scrutiny to material ones.

The new framework shifts that centre of gravity. Both regulators now expect firms to identify material third-party (MTP) arrangements of any kind — including intragroup relationships and the sub-contractor dependencies sitting beneath direct vendors. A market data feed, a claims-processing service, a group service company: if its failure could seriously harm the firm, its clients, or the market, it belongs in scope whether or not it meets the definition of outsourcing.

Three obligations arrive together:

Operational incident reporting. A standardised incident report (aligned with the FSB’s FIRE format and the EU’s DORA) for incidents meeting regulatory thresholds. Payment service providers must report within 4 hours of detection; other firms as soon as practicable and within 24 hours of determining a threshold has been met.

MTP notifications. Firms must notify their regulator of new material arrangements and of material changes to existing ones — and the FCA expects this early in the decision-making process, before the firm is contractually committed.

The annual MTP register. A structured register of all MTP arrangements, accurate as of 31 December, submitted within a 90-day reporting window on templates aligned across the supervisory authorities. Dual-regulated firms submit once, through a shared system.

Who it affects

On the PRA side: UK banks, building societies, PRA-designated investment firms, branches of overseas banks, and UK Solvency II insurers, including the Society of Lloyd’s and its managing agents.

On the FCA side, the third-party reporting rules cover enhanced-scope SM&CR firms, banks and designated investment firms, Solvency II firms and building societies, CASS large firms, UK recognised investment exchanges, authorised payment and e-money institutions, and consolidated tape providers. In plain terms: asset managers, brokers, wealth managers, payment firms, and trading venues are in — a far larger universe than SS2/21’s original audience. The FCA’s incident reporting rules reach wider still, to all firms with Part 4A permission plus payment service providers.

What’s actually required by 18 March 2027

The template is the easy part. The hard part is what the template assumes you already have:

A complete third-party inventory. Most firms hold vendor data across procurement systems, contract repositories, and business-unit spreadsheets. The register requires one consolidated view connecting four data layers: third party, service, arrangement, and sub-contractor.

A materiality methodology. Deciding which arrangements are material, consistently and with documented rationale, across hundreds or thousands of relationships. The regulators provide guidance and examples (the FCA’s sits in FG26/4), but no scoring methodology. You build and defend your own.

Register-grade data. Service descriptions, substitutability, sub-contractor chains, exit strategies. And the formatting is unforgiving: one arrangement can expand into dozens of report rows once every service type, cloud model, and governing law is counted — the FCA’s guidance requires a new row for every value in a multi-select field. Firms that built DORA’s register of information in the EU consistently report the same finding: the data gathering, not the reporting, was the project.

A change-monitoring process. This is not an annual form-filling exercise. A significant change to any live arrangement — scope, data location, ownership, sub-contractor — can trigger a fresh notification at any point in the year.

What to do now

Sequence matters more than speed. Consolidate the inventory first; everything downstream depends on it. Then define and document materiality criteria, and run assessments with governance sign-off on borderline calls. Close data gaps and remediate arrangements missing exit plans or resilience evidence. Then dry-run a register submission early, so you find your gaps before the regulator does.

One more reason to move early: regulators will use MTP register data to identify concentration risk and inform Critical Third Party designations. Your register is not an internal artefact. It’s a supervisory dataset.

How we think about this

ProcessUnity’s view is that the new framework rewards firms that treat third-party risk as a system rather than a filing exercise. A live third-party inventory with configurable materiality assessments produces the register as a byproduct. And because the UK regulators deliberately aligned with each other and with DORA, the same data serves every regime. That’s the design principle behind our platform, and it’s the difference between a compliance scramble and a plan.

Frequently Asked Questions

SS2/21 is the Bank of England PRA’s supervisory statement on outsourcing and third-party risk management, first published in 2021 and updated under PS7/26. It sets out how PRA-regulated firms (banks, building societies, designated investment firms, and insurers) are expected to govern, assess, and monitor outsourcing and material third-party arrangements.
PS26/2 is the FCA’s policy statement on operational incident and third-party reporting, published alongside the PRA’s PS7/26 as part of a single coordinated UK framework. It applies aligned requirements to FCA-regulated firms — including enhanced-scope SM&CR firms, CASS large firms, asset managers, brokers, payment and e-money institutions, and exchanges — from 18 March 2027, supported by guidance documents FG26/3 (incidents) and FG26/4 (third parties).
18 March 2027, for both the PRA and FCA regimes. The regulators published final rules in March 2026, giving firms a one-year transition period.
SS2/21 and PS26/2 are UK rules applying to PRA- and FCA-regulated firms respectively, while DORA applies to EU financial entities. The UK regulators deliberately aligned their incident reporting and third-party register with DORA and the FSB’s FIRE format, so firms operating in both jurisdictions can run one third-party risk programme that produces outputs for every regime.
Start with a consolidated third-party inventory covering vendors, intragroup arrangements, and sub-contractors. Then apply a documented materiality assessment methodology, close register data gaps (exit strategies, sub-contractor chains, substitutability), and dry-run the register submission before the deadline. Most firms need six months or more for this work.

Related Articles

About Us

ProcessUnity is the Third-Party Risk Management (TPRM) company. Our software platforms and data services protect customers from cybersecurity threats, breaches, and outages that originate from their ever-growing ecosystem of business partners. By combining the world’s largest third-party risk data exchange, the leading TPRM workflow platform, and powerful artificial intelligence, ProcessUnity extends third-party risk, procurement, and cybersecurity teams so they can cover their entire vendor portfolio. With ProcessUnity, organizations of all sizes reduce assessment work while improving quality, securing intellectual property and customer data so business operations continue to operate uninterrupted.