What Is SS2/21?
SS2/21 is the Prudential Regulation Authority’s supervisory framework for managing outsourcing and third-party risk.
Together with the PRA’s updated requirements and the FCA’s aligned PS26/2 rules, it establishes how regulated financial services firms identify, assess, manage, monitor, and report material third-party arrangements.
The requirements extend beyond traditional outsourcing to include a broader range of third-party relationships, including intragroup arrangements and subcontracted services.
Blog
How One TPRM Programme Can Satisfy SS2/21, PS26/2, DORA and the EBA Guidelines
The Deadline, in Four Numbers
18 March 2027
One deadline. Both regimes take effect 18 March 2027.
2 Regulators
PRA PS7/26 and FCA PS26/2, deliberately aligned.
All Material Third Parties
Outsourcing, intragroup, and subcontractors alike.
90 Days
Window to file the annual register, accurate as of 31 December.
Firms must report qualifying operational incidents, notify their regulator of material third-party arrangements before committing to them, and submit a structured annual register of every material arrangement they hold.
The Third-Party Data Problem
The templates are published and the fields are known. What takes the time is connecting the data behind them.
How ProcessUnity Solves It
Built for Regulatory Reporting
Outsourcing and material third-party registers
Regulatory notifications
Intragroup arrangements
Nth party and sub-contractor mapping
Concentration risk analysis
Contract record and lifecycle
Offboarding and termination activities
Dashboards and real-time reporting
Report library
End-user configuration, no code required
Microsoft Word and Excel connectors
One Program, Every Regime
The UK regulators aligned their framework with each other and with the European Union’s Digital Operational Resilience Act (DORA).
Firms reporting across jurisdictions run one program on one set of data: a single inventory, one materiality methodology with regime-specific overlays, and one control library where evidence collected once satisfies every mapped requirement.
Each register becomes an export with a different template, and the next regulation becomes a template change rather than a new project.
Why It Matters Now
Why It Matters Now
Frequently Asked Questions
SS2/21, as updated by PS7/26, applies to PRA-regulated firms: banks, building societies, PRA-designated investment firms, Solvency II insurers, and UK branches of overseas banks and insurers. The FCA’s PS26/2 applies matching third-party reporting rules to its own population, including enhanced-scope Senior Managers and Certification Regime firms, Client Assets Sourcebook large firms, authorised payment and e-money institutions, recognised investment exchanges, and consolidated tape providers. Many firms that have ignored SS2/21 because it is a PRA document are in scope through the FCA instead.
A material third-party arrangement is one whose failure or disruption could cause intolerable harm to your clients, threaten your firm’s safety and soundness, or pose a risk to the stability and integrity of the UK financial system. The definition covers any product or service provided to your firm, including intragroup arrangements and sub-contracted services, not only formal outsourcing. Your regulator sets out factors to weigh but does not provide a scoring methodology, so each firm builds and defends its own materiality assessment.
The structure carries over, but the scope does not. The new rules reach every material third-party arrangement rather than outsourcing alone, so most firms need to add intragroup arrangements, non-outsourcing services, and visibility into the sub-contractors beneath their direct providers. The data also has to be re-cut so that third party, service, arrangement, and sub-contractor records connect to one another rather than sitting in separate lists.
No. Firms regulated by both the PRA and the FCA submit once, through a shared system, on aligned templates. The underlying data still has to satisfy both regulators’ guidance, which is a further argument for holding one source of truth rather than maintaining separate records per regime.
Yes. The UK regulators deliberately aligned their framework with each other and with the European Union’s Digital Operational Resilience Act, so the same third-party data serves all three. A single inventory, one materiality methodology with regime-specific overlays, and one control library let firms collect evidence once and generate each regulator’s register as an export in the format that regulator expects.
Bring Your Hardest Scoping Question
Book a 30-minute readiness session with the ProcessUnity EMEA team and see this applied to your own third-party estate.

