The FCA’s announcement that the UK’s Critical Third Parties (CTP) regime is now live marks a significant development in the supervision of operational resilience.
For the first time, the Financial Conduct Authority, Prudential Regulation Authority and Bank of England can oversee the cloud, technology, data and operational providers whose services have become integral to the UK’s financial system.
Banks, insurers, payment firms and financial market infrastructures increasingly depend on a relatively small number of common providers. When one encounters disruption, the consequences rarely stop with a single organisation.
The CrowdStrike outage in 2024 demonstrated how a single technology event could affect thousands of businesses at once, while the FCA’s own operational incident data points to the same concentration risk, with more than a quarter of incidents reported during 2025 linked to third parties and over a third of those involving cyber events.
The CTP regime doesn’t change where responsibility for operational resilience sits. Firms remain accountable for understanding and managing their own risks. What has changed is the level of scrutiny applied to the infrastructure that supports the wider financial system, creating a new layer of oversight across organisations whose services have become systemically important.
That development has implications beyond technology. Broadgate’s Daniel Tapsell explores in more detail below.
A Different Kind of Leadership Challenge
Many of the organisations now within the regime have built sophisticated technology and operational capabilities without direct experience of UK financial regulation. Others already sit inside regulated firms, where expectations around operational resilience have become more exacting as dependencies on third parties continue to grow.
Senior leaders may be expected to explain how critical dependencies have been identified, defend resilience testing, support self-assessments and engage openly with supervisors during periods of disruption. Those conversations demand a combination of evidence, accountability and sound judgement that develops through experience rather than technical expertise alone.
For organisations entering this environment for the first time, leadership capability becomes part of operational resilience itself. The strength of a resilience framework will always matter, but so too will the confidence with which leaders can explain the decisions behind it when those decisions are tested.
Preparing for Greater Scrutiny
Many organisations are responding by looking beyond frameworks and controls alone. Greater regulatory engagement is prompting a broader conversation about how senior leaders prepare for supervisory relationships, while operational resilience programmes are evolving to place greater emphasis on governance, accountability and the quality of decision-making under pressure.
That combination reflects the direction of travel. As resilience expectations mature, organisations are finding it increasingly difficult to separate technical preparedness from leadership capability. The two now reinforce one another.
Supporting that work has become a growing focus for Trinnovo Consulting, whether through executive coaching for leaders preparing to engage with regulators or through operational resilience and third-party risk programmes that strengthen governance across the organisation. In practice, those conversations often extend beyond advisory work into longer-term capability building, including the appointment of specialist operational resilience and governance professionals where new responsibilities require permanent ownership.
The CTP regime won’t eliminate operational disruption. No regulatory framework can. It does, however, raise expectations of how organisations prepare for disruption, how leadership teams respond when it occurs and how those decisions are evidenced under regulatory scrutiny.
For firms and providers entering this next phase of operational resilience, the question is becoming less about whether the regulator will engage, and more about whether leadership teams are prepared when that engagement begins.
How Broadgate Search Supports Operational Resilience
Through Trinnovo Consulting, its consulting division, Broadgate Search supports organisations preparing for direct regulatory engagement and strengthening operational resilience capability across financial services.
Whether your organisation is preparing for direct regulatory engagement or strengthening operational resilience capability, our team can provide support across:
- Succession by Design: Executive coaching delivered by former FCA and regulatory practitioners.
- Operational resilience programmes: Critical dependency mapping, resilience testing and governance support.
- Third-party risk (TPR): Framework design, maturity reviews and implementation.
- Regulatory preparedness: Self-assessment reviews and supervisory engagement support.
- Specialist hiring: Operational resilience, third-party risk and governance appointments through the wider Trinnovo Group.
If you’re stepping into regulatory engagement for the first time or strengthening operational resilience and third-party risk capability across your organisation, Broadgate Search’s consulting division, Trinnovo Consulting, can help. A short conversation is often enough to identify where support will have the greatest effect, whether that’s preparing senior leaders for supervisory engagement or strengthening the resilience work already underway. Contact Programme Director Daniel Tapsell to learn more.