The opinions expressed here are those of the authors. They do not necessarily reflect the views or positions of UK Finance or its members.

While this does shift oversight upstream, it does not reduce accountability for firms: firms must work with, rather than simply oversee, their CTPPs to ensure that resilience expectations can be met in practice. The dynamic is defined not just by how firms manage their own risks, but by how effectively they work with the technology providers they rely on. Resilience is a shared obligation, and suppliers should be seen as collaborators when it comes to operational resilience, rather than simply providing a service to firms.

Why traditional TPRM approaches are no longer sufficient

Under DORA, designated CTPPs are directly overseen by European Supervisory Authorities (ESAs), ending the historical reliance on firm-level assurance alone. For firms, this means regulators will expect much deeper visibility into their dependency on critical suppliers, and much stronger evidence that they can withstand disruption, even when their suppliers are under parallel supervision and face their own challenges.

In this context, traditional third-party risk management (TPRM) approaches are built around bilateral oversight, contractual assurances, and periodic reviews. These models struggle to address:

  • Market-wide concentration risk
  • Sector-wide dependencies on large ICT suppliers
  • Limited individual leverage over hyperscalers; DORA responds to these challenges by introducing sector‑level oversight, but firm‑level practices must now evolve to align with this reality.

Four Actions Firms much ensure they are undertaking 

1. Strengthen transparency with suppliers

CTPPs cannot align to resilience expectations without understanding how their services support important business services and where failure would cause intolerable harm. Firms must go beyond contractual labels and actively explain why services are critical, how impact tolerances have been set, and which assumptions and scenarios underpin them. This transparency enables CTPPs to set meaningful recovery objectives and design credible resilience measures.

2. Align contracts and governance with the new oversight environment

DORA raises the bar for contractual clarity, rights of access, reporting expectations, and the treatment of subcontractors. Firms should ensure their contractual frameworks remain fit for purpose. Well-designed contracts reduce ambiguity, support regulatory assurance, and enable fast, more effective responses during disruption by:

  • embedding contractual obligations that reflect both DORA and local regulatory requirements;
  • ensuring timely and consistent access to data, testing results, incident information, and subcontractor disclosures;
  • updating escalation, communication, and joint‑response arrangements to reflect the shared resilience model;
  • ensuring governance structures at both parties enable rapid decision‑making, especially during crisis events.

3. Test resilience together, not in isolation

Evidence of end-to-end resilience is no longer optional. Regulators expect firms and CTPPs to demonstrate that recovering works across organisational boundaries. This requires a shift from isolated testing to joint activities, including multi-party scenario exercises, coordinated failover and recovery tests, and joint incident simulations and post-incident learning. Testing together exposes vulnerabilities in controls that are invisible when conducted in silos.

4. Actively support suppliers on their regulatory journey

Firms are further advanced in regulatory-driven resilience than many technology providers, who have not experienced direct oversight. This experience is valuable. Firms can reduce friction and rise by:

  • Sharing lessons learned from prior resilience requirements, such as the EBA Outsourcing Guidelines and local authority rulebooks
  • Walking through what "good" looks like for impact tolerances, scenario testing, and mapping
  • Sharing examples of vulnerabilities identified through previous testing cycles
  • Aligning control environments between suppliers and firms to improve overall supply chain resilience
  • Clarifying what supervisors expect boards and executives to articulate

DORA marks the end of "arm's length" documentation-driven third-party oversight for critical services. For Financial Services firms, the new model presents three core implications: 

  • Regulators expect suppliers to be resilience partners, not just vendors
  • Firms remain fully accountable for managing third‑party risk, regardless of regulatory oversight
  • The quality of collaboration between firms and critical providers will increasingly influence supervisory confidence

As regulatory expectations are rising, and the cost of failure is no longer confined to supervisory findings. Public disclosure, remediation costs, customer confidence, and market positioning are all at stake. 

Financial Services firms that treat CTPPs as resilience partners, rather than compliance subjects, will be better positioned to withstand scrutiny, build trust, and differentiate themselves in an increasingly transparent ecosystem. Those that do not may find that regulation, reputation, and revenue converge and impact faster than expected.