How One TPRM Programme Can Satisfy SS2/21, PS26/2, DORA and the EBA Guidelines

5 minute read

September 2026

by Ed Thomas

When the UK’s financial regulators finalised their new third-party reporting rules, they did something regulators rarely do: they told firms, explicitly, that the requirements were designed to line up. The PRA and FCA published aligned rules on the same day, with shared templates and a single submission system for dual-regulated firms. The incident report matches the Financial Stability Board’s FIRE format. The register of material third-party arrangements is interoperable with DORA’s register of information. Consultation respondents asked for that alignment, and the regulators delivered it.

That alignment signals where third-party risk supervision is heading. It also raises an awkward question for firms that still organise this work one regulation at a time.

Different statutes, same data model

Look at what the major regimes now ask for and the pattern is hard to miss. DORA requires EU financial entities to maintain a register of information on ICT third-party arrangements. The updated SS2/21 and the FCA’s PS26/2 require UK-regulated firms — from banks to asset managers and payment firms — to maintain and submit a register of all material third-party arrangements. The EBA Outsourcing Guidelines, which SS2/21 implemented in the UK, require a register of outsourcing arrangements. Each regime wants materiality or criticality assessments with documented rationale. Each wants incident reporting against defined thresholds. Each wants exit strategies, sub-contractor visibility, and concentration awareness.

Underneath the different statutes sits one data model: know your third parties, know which ones matter, prove you’re watching them, tell us when things break.

Why firms still run four projects

If the regimes converge, why do so many firms handle them separately? Partly structure: DORA landed with the CIO or operational resilience team, SS2/21 with prudential compliance, the FCA rules with the conduct compliance team, EBA guidelines with procurement or legal. Each owner scoped a project, hired advisers, and built a spreadsheet. Partly timing: each deadline spawned its own workstream.

The result is familiar to anyone in a firm with UK and EU entities: multiple inventories that disagree with each other, multiple materiality methodologies producing different answers about the same vendor, and vendors fielding several near-identical questionnaires from one client. None of that makes the firm more resilient. It makes it slower.

The cost difference is stark. Consultation respondents told the PRA that DORA implementation ran far over its estimated costs, and the data gathering was the culprit. Firms that do that gathering once, in one system, pay the cost once. Firms that do it per-regulation pay it every time a regulator publishes.

What a single programme looks like

The alternative is not a bigger spreadsheet. It means treating the third-party inventory as a permanent, governed asset, the way finance treats the general ledger, and letting each regime’s output fall out of it.

One inventory, mapped to business services. Every third-party relationship — direct vendors, intragroup arrangements, sub-contractor dependencies — tied to the services it supports. This is the foundation every regime silently assumes.

One materiality methodology with regime overlays. The core questions (impact, substitutability, data sensitivity, concentration) are common to every regime. Regime-specific criteria become overlays on one assessment, not separate assessments.

One control library, mapped many-to-many. A single due-diligence control set mapped to each regime’s articles and chapters, so evidence collected once satisfies every mapped requirement.

Reporting as an output, not a project. If the inventory and assessments are live, the SS2/21 register, the FCA register, the DORA register of information, and the EBA register are exports with different templates rather than annual archaeology.

The register era

Regulators aren’t collecting these registers to file them away. The UK regulators have said MTP data will be used to spot concentration risk and inform Critical Third Party designations. UK and EU supervisors have agreed to cooperate on oversight of critical third parties. The registers are the raw material for a supervisory map of the financial sector’s dependencies — one that regulators will increasingly compare across firms and across borders.

That changes the standard your data has to meet. A register that’s internally “good enough” becomes a liability when a supervisor cross-references it against your peers’ submissions, or against a CTP’s own reporting. Firms whose registers are generated from a live, governed inventory will look coherent under that scrutiny. Firms whose registers are assembled by hand each year will not.

The March 2027 deadline is real, and firms should treat it with urgency. But the deadline is the beginning of the register era, not the finish line. Build the programme once, and every future regulation becomes a template change.

Frequently Asked Questions

Yes. The UK regulators deliberately aligned their reporting requirements with each other, with DORA, and with the FSB’s FIRE incident format, and the updated SS2/21 explicitly permits a single, holistic third-party risk management policy. A shared inventory, one materiality methodology with regime overlays, and a mapped control library can produce compliant outputs for every regime.
DORA’s register covers ICT third-party arrangements for EU financial entities; the UK MTP register covers all material third-party arrangements for PRA- and FCA-regulated firms and is submitted annually within a 90-day window. The formats are deliberately interoperable, so both can be generated from the same underlying third-party data.
Supervisors use register data to identify concentration risk across the financial sector and to inform Critical Third Party designations; in the UK, MTP data will support CTP recommendations to HM Treasury. Registers give regulators a sector-wide map of dependencies, which they increasingly compare across firms and jurisdictions.
Start with one consolidated third-party inventory mapped to business services, covering vendors, intragroup arrangements, and sub-contractors. Define a single materiality/criticality methodology and add regime-specific overlays. Map one due-diligence control library to each regulation’s requirements so evidence is collected once. Generate each regime’s register or report as an export from that shared data.

Related Articles

About Us

ProcessUnity is the Third-Party Risk Management (TPRM) company. Our software platforms and data services protect customers from cybersecurity threats, breaches, and outages that originate from their ever-growing ecosystem of business partners. By combining the world’s largest third-party risk data exchange, the leading TPRM workflow platform, and powerful artificial intelligence, ProcessUnity extends third-party risk, procurement, and cybersecurity teams so they can cover their entire vendor portfolio. With ProcessUnity, organizations of all sizes reduce assessment work while improving quality, securing intellectual property and customer data so business operations continue to operate uninterrupted.