You can use the search function to find a range of UK Finance material, from consultation responses to thought leadership to blogs, or to find content on a range of topics from Capital Markets & Wholesale to Payments & Innovation.
29 Jun 2026
The opinions expressed here are those of the authors. They do not necessarily reflect the views or positions of UK Finance or its members.While this does shift oversight upstream, it does not reduce accountability for firms: firms must work with, rather than simply oversee, their CTPPs to ensure that resilience expectations can be met in practice. The dynamic is defined not just by how firms manage their own risks, but by how effectively they work with the technology providers they rely on. Resilience is a shared obligation, and suppliers should be seen as collaborators when it comes to operational resilience, rather than simply providing a service to firms.
Why traditional TPRM approaches are no longer sufficient
Under DORA, designated CTPPs are directly overseen by European Supervisory Authorities (ESAs), ending the historical reliance on firm-level assurance alone. For firms, this means regulators will expect much deeper visibility into their dependency on critical suppliers, and much stronger evidence that they can withstand disruption, even when their suppliers are under parallel supervision and face their own challenges.
In this context, traditional third-party risk management (TPRM) approaches are built around bilateral oversight, contractual assurances, and periodic reviews. These models struggle to address:
Four Actions Firms much ensure they are undertaking
1. Strengthen transparency with suppliers
CTPPs cannot align to resilience expectations without understanding how their services support important business services and where failure would cause intolerable harm. Firms must go beyond contractual labels and actively explain why services are critical, how impact tolerances have been set, and which assumptions and scenarios underpin them. This transparency enables CTPPs to set meaningful recovery objectives and design credible resilience measures.
2. Align contracts and governance with the new oversight environment
DORA raises the bar for contractual clarity, rights of access, reporting expectations, and the treatment of subcontractors. Firms should ensure their contractual frameworks remain fit for purpose. Well-designed contracts reduce ambiguity, support regulatory assurance, and enable fast, more effective responses during disruption by:
3. Test resilience together, not in isolation
Evidence of end-to-end resilience is no longer optional. Regulators expect firms and CTPPs to demonstrate that recovering works across organisational boundaries. This requires a shift from isolated testing to joint activities, including multi-party scenario exercises, coordinated failover and recovery tests, and joint incident simulations and post-incident learning. Testing together exposes vulnerabilities in controls that are invisible when conducted in silos.
4. Actively support suppliers on their regulatory journey
Firms are further advanced in regulatory-driven resilience than many technology providers, who have not experienced direct oversight. This experience is valuable. Firms can reduce friction and rise by:
DORA marks the end of "arm's length" documentation-driven third-party oversight for critical services. For Financial Services firms, the new model presents three core implications:
As regulatory expectations are rising, and the cost of failure is no longer confined to supervisory findings. Public disclosure, remediation costs, customer confidence, and market positioning are all at stake.
Financial Services firms that treat CTPPs as resilience partners, rather than compliance subjects, will be better positioned to withstand scrutiny, build trust, and differentiate themselves in an increasingly transparent ecosystem. Those that do not may find that regulation, reputation, and revenue converge and impact faster than expected.
29.06.26
Craig Oliver, Third-Party Risk Management and Supplier Assurance Lead, PA Consulting
Karan Chao, Third Party Risk & Digital Trust Expert, PA Consulting
By downloading this document, you understand and agree that any sharing, distribution or republishing of the content, without prior written authorisation from the author or content managers at UK Finance, shall be constituted as a breach of the UK Finance website terms of use.