What Is SS2/21?

SS2/21 is the Prudential Regulation Authority’s supervisory framework for managing outsourcing and third-party risk.

Together with the PRA’s updated requirements and the FCA’s aligned PS26/2 rules, it establishes how regulated financial services firms identify, assess, manage, monitor, and report material third-party arrangements.

The requirements extend beyond traditional outsourcing to include a broader range of third-party relationships, including intragroup arrangements and subcontracted services.

Blog

How One TPRM Programme Can Satisfy SS2/21, PS26/2, DORA and the EBA Guidelines

The Deadline, in Four Numbers

18 March 2027

One deadline. Both regimes take effect 18 March 2027.

2 Regulators

PRA PS7/26 and FCA PS26/2, deliberately aligned.

All Material Third Parties

Outsourcing, intragroup, and subcontractors alike.

90 Days

Window to file the annual register, accurate as of 31 December.

Firms must report qualifying operational incidents, notify their regulator of material third-party arrangements before committing to them, and submit a structured annual register of every material arrangement they hold.

The Third-Party Data Problem

The templates are published and the fields are known. What takes the time is connecting the data behind them.

Problem 01

Expanded Scope

The obligation covers every material third-party arrangement, including the intragroup relationships many firms have never tracked as rigorously as external ones. Direct providers, intragroup arrangements, and fourth- and fifth-party dependencies typically sit in unconnected systems, where they are tracked at all.

Problem 02

Fragmented Data

Third-party, service, arrangement, and sub-contractor data usually live in separate datasets, and the register needs them linked. The same attribute, like where a third party actually hosts your data, gets entered differently depending on which regime it was recorded for. When those records do not share a source, concentration risk across your portfolio stays invisible until it matters.

Problem 03

Row Multiplication

A single arrangement turns into dozens of report rows once you account for every service type, cloud model, and governing law involved. The FCA’s guidance requires a new row for every additional value in a multi-select field. Build that by hand and you risk merging things that should stay separate, or asserting combinations that were never true.

Problem 04

Continuous Compliance

Any significant change to a live arrangement, whether in scope, data location, ownership, or sub-contractor, triggers a fresh notification at any point in that arrangement’s life. Data that is not kept accurate year-round gets assembled under pressure when the submission window opens.

Problem 05

Assessment Bottlenecks

Every material arrangement needs four separate assessment tracks covering risk, audit, financial due diligence, and cyber due diligence. Your regulator provides no scoring methodology for any of them, so you build and defend your own, across a population that has just expanded.

Problem 06

Disconnected Tooling

Contracts sit in one system, procurement in another, and third-party risk in a third, so the same third party gets re-entered and reconciled across all three every time something changes.

How ProcessUnity Solves It

Solution 01

One Record, Every Regime

Your register and your notifications generate straight out of your existing third-party risk program rather than a reporting exercise bolted on afterwards. Capture a fact once and ProcessUnity reuses it across SS2/21, PS26/2, DORA, and whatever follows.

Resolves Problem 01
·
Expanded Scope

Solution 02

Correct by Construction

The workflow surfaces gaps as analysts work rather than at submission, when it is too late to fix them. Where an arrangement genuinely carries multiple services, materiality reasons, or function categories, ProcessUnity holds them as the separate true facts they are.

Resolves Problem 02
·
Fragmented Data

Solution 03

Full Scope, One Architecture

A direct provider, a fourth- or fifth-party dependency buried in the supply chain, and a pre-determined intragroup arrangement all live in one view. New arrangements pre-fill from your existing service library.

Resolves Problem 03
·
Row Multiplication

Solution 04

Governed by Design

Materiality decisions route to the right risk function and get signed off by the right accountable person, rather than falling to whoever owns the contract. Every live arrangement stays watched for the changes that trigger a fresh notification.

Resolves Problem 04
·
Continuous Compliance

Solution 05

Accelerated Assessment

Each stakeholder follows a guided path to contribute exactly the data they are responsible for, with due diligence built into the workflow at the right step. AI-accelerated cyber and financial due diligence, plus risk domain scores that arrive ready to use, take the weight off the four assessment tracks.

Resolves Problem 05
·
Assessment Bottlenecks

Solution 06

A Partner, Not Just a Platform

ProcessUnity configures the program to fit your operating model, and your own team can adjust it as templates evolve or hand that to ProcessUnity entirely. It connects natively with your contract lifecycle and procurement systems.

Resolves Problem 06
·
Disconnected Tooling

Built for Regulatory Reporting

01
Outsourcing and material third-party registers
02
Regulatory notifications
03
Intragroup arrangements
04
Nth party and sub-contractor mapping
05
Concentration risk analysis
06
Contract record and lifecycle
07
Offboarding and termination activities
08
Dashboards and real-time reporting
09
Report library
10
End-user configuration, no code required
11
Microsoft Word and Excel connectors

One Program, Every Regime

The UK regulators aligned their framework with each other and with the European Union’s Digital Operational Resilience Act (DORA).

Firms reporting across jurisdictions run one program on one set of data: a single inventory, one materiality methodology with regime-specific overlays, and one control library where evidence collected once satisfies every mapped requirement.

Each register becomes an export with a different template, and the next regulation becomes a template change rather than a new project.

Why It Matters Now

18 March 2027

The rules take effect, and the inventory and assessment work takes months.

Both Regulators,
One Framework

Scope reaches from global banks to asset managers, brokers, and payment firms.

Your Register Feeds Critical
Third Party Designation

Regulators are studying third-party concentration risk across the sector.

Why It Matters Now


1

18 March 2027

The rules take effect, and the inventory and assessment work takes months.


2

Both Regulators,
One Framework

Scope reaches from global banks to asset managers, brokers, and payment firms.


3

Your Register Feeds Critical
Third Party Designation

Regulators are studying third-party concentration risk across the sector.

Frequently Asked Questions

SS2/21, as updated by PS7/26, applies to PRA-regulated firms: banks, building societies, PRA-designated investment firms, Solvency II insurers, and UK branches of overseas banks and insurers. The FCA’s PS26/2 applies matching third-party reporting rules to its own population, including enhanced-scope Senior Managers and Certification Regime firms, Client Assets Sourcebook large firms, authorised payment and e-money institutions, recognised investment exchanges, and consolidated tape providers. Many firms that have ignored SS2/21 because it is a PRA document are in scope through the FCA instead.

A material third-party arrangement is one whose failure or disruption could cause intolerable harm to your clients, threaten your firm’s safety and soundness, or pose a risk to the stability and integrity of the UK financial system. The definition covers any product or service provided to your firm, including intragroup arrangements and sub-contracted services, not only formal outsourcing. Your regulator sets out factors to weigh but does not provide a scoring methodology, so each firm builds and defends its own materiality assessment.

The structure carries over, but the scope does not. The new rules reach every material third-party arrangement rather than outsourcing alone, so most firms need to add intragroup arrangements, non-outsourcing services, and visibility into the sub-contractors beneath their direct providers. The data also has to be re-cut so that third party, service, arrangement, and sub-contractor records connect to one another rather than sitting in separate lists.

No. Firms regulated by both the PRA and the FCA submit once, through a shared system, on aligned templates. The underlying data still has to satisfy both regulators’ guidance, which is a further argument for holding one source of truth rather than maintaining separate records per regime.

Yes. The UK regulators deliberately aligned their framework with each other and with the European Union’s Digital Operational Resilience Act, so the same third-party data serves all three. A single inventory, one materiality methodology with regime-specific overlays, and one control library let firms collect evidence once and generate each regulator’s register as an export in the format that regulator expects.

Bring Your Hardest
Scoping Question

Book a 30-minute readiness session with the ProcessUnity EMEA team and see this applied to your own third-party estate.