9 June 2022
On 8 June, HM Treasury published a Policy Statement on “Critical third parties to the finance sector”. The Statement confirms the government’s intention to legislate for new and extensive powers to directly oversee certain technology providers to the finance sector for the first time, with significant implications for technology providers that are designated as ‘critical’.
Financial services ("FS") firms are increasingly reliant on third parties outside the finance sector for key functions or services, for example cloud-based computing services, given the advantages that outsourcing can provide. However, the government and FS regulators are concerned that use of third party technology by firms across the financial sector could potentially be a source of systemic risk (eg in the event of failure or disruption of the relevant technology, in particular where multiple firms rely on a select few providers.
Under the current regulatory framework, UK financial regulators do not generally have direct powers to regulate technology providers such as cloud infrastructure providers and other technology firms that are outside the finance sector. The FCA and PRA do require UK FS firms to implement requirements relating to their own use of technology, through requirements on outsourcing and third-party risk management, and operational resilience. This includes requiring firms to ensure certain contractual terms with third parties on areas such as data security, business continuity and exit planning.
However, the UK FS regulators currently have no powers to directly supervise those third parties. Certain limited information gathering powers exist under the Financial Services and Markets Act 2000 (FSMA), in particular where financial stability concerns are identified, but there is no overarching power to exercise powers or give directions. The government considers the existing framework as "not sufficient to tackle the systemic risk that disruption at a third party providing key services to multiple firms could cause". Although each individual firm can manage the risks that it is exposed to individually, the UK regulators are mindful that individual firms are not able to manage systemic risks that might arise where third party firms provide material services to multiple firms.
The new legislative powers would be specific to third parties that the Treasury designates as "critical". At this stage, the Policy Statement does not explain in detail how this would operate or set out detailed criteria for what constitutes "critical" (in the way that the EU's equivalent proposal has, for example). However, earlier commentary from the UK regulators suggest that designation will focus on third parties that "may be a source of systemic risk to the financial stability of the UK", for example because their services support material functions across a broad range of FS firms in the UK.
Key points to be aware of regarding the designation process:
Once designated, the UK regulators would have a broad range of powers, exercisable in respect of "material services" (being those that are of relevance to the regulators' objectives) provided to the finance sector:
However, the paper emphasizes that it is important that the finance sector and its supply chain remains competitive and innovative, and therefore the regime needs to be "flexible", "proportionate", and still allow UK firms to harness the benefits of outsourcing, while managing the risks.
No. The government has been clear that firms remain accountable for managing risks to their own operational resilience, and that this will continue to be the case following the new legislation. The regime is intended to manage potential systemic risks arising from concentration among certain key providers -this will not replace the individual responsibilities of firms to manage their own risks.
Those third parties designated as critical will need to adjust to direct supervision and oversight from the UK FS regulators for the first time. Directions from the UK regulators on areas such as resilience and cyber security could restrict providers' flexibility over service offerings and operational arrangements. Businesses could be subject to detailed oversight of their compliance, governance and operational arrangements, with the potential for investigative powers, enforcement action, public disclosure, or even restrictions on service provision.
Service providers to the finance sector might want to start considering whether any services they offer to UK FS firms could make them potential targets for designation.
Service providers should also be mindful of the potential change to the regulatory dynamic when negotiating with FS firms. The Statement notes the possibility that firms could make representations to HM Treasury concerning their own third parties. If firms are having difficulties obtaining the necessary contractual terms with tech providers, they might seek to use this as leverage.
Compared to the UK, the EU is closer to finalising a legislative framework for oversight of critical third parties, under the digital operational resilience act ("DORA"). Both regimes seek to address potential systemic risks with critical third parties in FS, but with differences in approach.
Interestingly, the UK government makes no reference to the EU's work on DORA, despite referencing the need to coordinate with international regulators. Once more detail on the UK legislation is available it will be possible to assess to what extent the two regimes align, or whether providers operating in both the UK and EU will need to adjust to two different regimes as the UK charts its own post-Brexit path.
The UK government states that it intends to legislation for the regime "when parliamentary time allows". Shortly after that, the financial regulators will publish a joint Discussion Paper, setting out how any statutory powers granted to them might be exercised and seeking views from industry on effective and proportionate ways to do so. It will also explore how coordination with overseas financial regulators might take place.
Following Royal Assent of the legislation, the paper anticipates a further Consultation Paper from the UK financial regulators on their proposed rules, building on the feedback to the Discussion Paper and based on their proposed new statutory powers. HM Treasury then expects to begin designating the first critical third parties under the new regime once the regulators' rules have been finalised.
Keep an eye out for, and consider responding to, the upcoming Discussion Paper, which will seek feedback from industry on how the new powers should be exercised in an effective and proportionate way.
We are following this topic closely. If you're interested in discussing the potential impact on your business, do get in touch.
by multiple authors
by multiple authors